LegalPrivacy Policy
Privacy Policy
What this policy covers
This policy covers kna-group.com. KNA Group is a trading name. The firm operates from Ottawa, Ontario, and works with incorporated companies across Canada.
The federal law that applies is the Personal Information Protection and Electronic Documents Act, usually called PIPEDA. It governs how private-sector organisations in Canada handle personal information in the course of commercial activity. Ontario has no general private-sector privacy statute of its own, so PIPEDA is the applicable law here.
Personal information we receive while working with a client is handled on the same principles set out below. The specific confidentiality terms of an engagement are set out in that engagement, not on this page.
What the site collects, which today is almost nothing
As of the date at the top of this page:
- There are no accounts, no logins and no user profiles. There is nothing to sign up for.
- The site does not set cookies and does not write to your browser’s local storage.
- No analytics tool and no tag container is installed. Nothing on the site measures your visit.
- The contact page has no submission endpoint wired to it. There is no form that transmits what you type to anyone, because there is nowhere for it to go yet.
- There are no advertising pixels, no retargeting tags and no social media widgets.
The honest summary is that the site is a set of static pages describing a firm, and reading it tells us nothing about you.
Hosting, and the records any web server keeps
The site is served by Firebase Hosting, a Google service. Loading a page means your browser makes a request to that host, and hosts keep records of requests: typically the time, the address requested, the network address it came from and the browser’s user agent string. That is a property of how the web works rather than a decision we made about you.
We do not use those records to build a profile, we do not combine them with anything else, and we do not attempt to identify a visitor from them. Google handles that data as our hosting provider, under its own terms.
Cookies and tracking
The site sets none.
If analytics or any other tool that sets a cookie is added later, this section will name the tool, say what it collects, say why, and say how to refuse it, and it will say so before the tool goes live rather than afterwards. We have not written a cookie section in advance for a site that has no cookies, because a policy describing tracking that does not happen is a false statement about the thing it exists to describe honestly.
When you get in touch
If you email, call or write to us, we receive whatever you choose to send: your name, your contact details, and whatever you tell us about your company and how its month-end runs.
We use that to reply to you and to work out whether the engagement is a fit. That is the whole purpose. We do not add enquirers to a mailing list, and we do not run one.
Please do not send confidential company information in a first enquiry. Send enough to describe the situation. Until an engagement is agreed in writing there is no professional relationship, and nothing you send is protected by one.
Who we share it with
We do not sell, rent or trade personal information, and we do not disclose it to anyone for their own marketing.
We may disclose information where the law requires it, such as a court order, a warrant or a lawful demand from a regulator.
We currently use no third party to process enquiry information on our behalf, because there is no form handler, no scheduling tool and no customer relationship system in use. If one is engaged later, it will be named in this section before it starts receiving anything.
How long we keep it
Enquiries that do not lead to an engagement are kept only while there is a reason to keep them, and are then deleted. Records connected to an actual engagement are kept for as long as the applicable record-keeping obligations require, which is considerably longer.
Safeguards
We take reasonable steps to protect what we hold, appropriate to how sensitive it is, and we keep the amount we hold deliberately small, because information that was never collected cannot be lost.
No system is perfectly secure and this policy does not claim otherwise. No certification, audit, standard or third-party attestation is claimed here.
If something goes wrong
PIPEDA requires an organisation to report a breach of security safeguards to the Office of the Privacy Commissioner of Canada, and to notify the affected individuals, where it is reasonable to believe the breach creates a real risk of significant harm. It also requires a record of every breach of security safeguards, whether or not it meets that threshold, kept for twenty-four months.
Those are the obligations, and we would meet all three.
Your rights
Under PIPEDA, and specifically the individual access principle, you may ask to be told whether we hold personal information about you, what it has been used for and whether it has been disclosed. You may ask for access to it, challenge its accuracy and completeness, and have it amended where that is warranted.
Ask through the contact page. We will respond within the time PIPEDA allows, and if we need longer we will tell you that and why.
There are limits. We may have to withhold information whose release would reveal personal information about someone else, and there are other narrow exceptions in the Act. Where we withhold something, we will say that we have and give the reason.
Who is accountable
PIPEDA requires an organisation to designate an individual accountable for its compliance with the Act. At a firm this size that is the principal, who can be reached through the contact page.
Complaints
Raise it with us first, through the contact page. If you are not satisfied with how we handled it, you can complain to the Office of the Privacy Commissioner of Canada, the federal regulator for PIPEDA, at priv.gc.ca.
What this policy does not claim
It is written for PIPEDA and for a firm operating in Ontario, Canada. It does not claim compliance with the General Data Protection Regulation, with California privacy law, or with any certification scheme, and it does not assert a compliance status that has not been assessed.
If you are contacting us from a jurisdiction with its own privacy law, what this page gives you is an accurate account of what the site and the firm actually do, which is the part we can stand behind.
Changes to this policy
The date at the top of this page is when it was last changed. A material change gets a new date and a rewritten section rather than a quiet edit.
Because the site does so little today, most future changes will be additions: the day analytics is installed, the day a form endpoint is wired to the contact page, or the day any third party starts receiving what you send us.
Contacting us
Through the contact page. Access requests, corrections and complaints all go to the same place.