Effective date: 15 September 2026
Last updated: 15 September 2026
1. Who we are
CG Technologies Corp. (“CG Technologies”, “we”, “us”, “our”) is a managed IT services provider incorporated in Ontario, Canada, with offices at Unit 8, 2499 Rutherford Road, Concord, Ontario L4K 0J9. We have provided outsourced IT, cybersecurity and cloud services to businesses across Toronto and the Greater Toronto Area since 1996.
This policy explains what personal information we collect, why we collect it, how we protect it, who we share it with, and the choices available to you. It applies to cgtechnologies.com and to the services we deliver to our clients.
We handle personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
2. The two roles we play
Our privacy obligations differ depending on the relationship, so it is worth being explicit about which one applies to you.
- As an organization in our own right. When you visit our website, enquire about our services, attend an event, apply for a job or act as a contact at a client or vendor, we decide why and how your information is used. This policy governs that information.
- As a service provider to our clients. When we support a client’s systems, we necessarily encounter personal information belonging to that client, their staff and their customers. We handle that information on our client’s instructions, under the terms of our service agreement with them, and only to deliver, secure and support the services they have engaged us for. We do not sell it, mine it or use it for our own purposes. If you are an employee or customer of a CG Technologies client and you have a privacy question about your data, your enquiry is best directed to that organization; we will support them in responding.
3. Information we collect
3.1 Information you give us
- Enquiry and consultation forms. Name, business email address, telephone number, company name, job title and whatever you choose to write in the message field.
- Service desk contact. When you raise a ticket by phone, email or portal, we record your contact details, the nature of the issue and the correspondence and remote session notes needed to resolve it.
- Newsletter and content subscriptions. Name and email address, where you have asked to receive them.
- Commercial and contractual records. Billing contacts, purchase orders, signed agreements and payment records for clients and vendors.
- Recruitment. Where you apply for a role with us, the contents of your application, CV and interview notes.
3.2 Information collected automatically on this website
- Server and security logs. IP address, user agent, referring page, pages requested and timestamps, retained for security monitoring, abuse prevention and diagnostics.
- Analytics. We use Google Analytics, deployed via Google Tag Manager, to understand how the site is used in aggregate: pages viewed, time on page, approximate geographic region, device type and traffic source.
- Spam and bot protection. Our forms are protected by Google reCAPTCHA, which collects device and behavioural signals to distinguish people from automated traffic. Your use of reCAPTCHA is subject to Google’s Privacy Policy and Terms of Service.
- Cookies and similar technologies. See section 6.
3.3 Information we encounter while delivering services
Delivering managed IT necessarily involves systems that hold or transmit personal information belonging to our clients. Depending on the services contracted, this can include:
- User account records and directory data in Microsoft 365 and on-premises directory services;
- Device inventory, configuration, patch status, performance and security telemetry gathered by our remote monitoring and management tooling;
- Ticket contents, remote session records and correspondence held in our professional services automation platform;
- Email security metadata, quarantined messages and message trace data;
- Backup and disaster recovery images, which may contain whatever personal information resides in the source systems;
- Credentials for client systems, held in an access-controlled password management platform.
Access to these systems is restricted to the technical staff who require it to perform their duties.
4. Why we use personal information
- To respond to enquiries, prepare proposals and provide quotations;
- To deliver, support, monitor, secure and invoice the services our clients have engaged us for;
- To investigate, contain and remediate security incidents and service faults;
- To meet contractual, accounting, tax, insurance and regulatory obligations;
- To improve our website, our service delivery and our published content;
- To send service notices and, where you have opted in, marketing communications about our services.
We do not sell personal information. We do not share it with third parties for their own marketing purposes.
5. Consent
We collect, use and disclose personal information with your knowledge and consent, except where the law permits or requires otherwise. Submitting a form on this site, engaging our services or contacting our service desk constitutes consent to use the information provided for the purpose it was given.
You may withdraw consent for marketing communications at any time using the unsubscribe link in any marketing email or by contacting our Privacy Officer. Consent for information required to deliver a contracted service cannot practically be withdrawn without ending that service; we will tell you plainly if that is the case.
6. Cookies and tracking
This website uses cookies and similar technologies for the following purposes:
- Strictly necessary. Session handling, security and load balancing. The site does not function correctly without these.
- Performance and caching. Set by our content delivery and caching layer to serve pages faster.
- Analytics. Google Analytics cookies, used to measure site usage in aggregate.
Most browsers let you refuse or delete cookies through their settings. Blocking strictly necessary cookies may prevent parts of this site from working. You can opt out of Google Analytics across all sites using Google’s browser opt-out add-on.
7. Who we share information with
We disclose personal information only in the following circumstances:
- Service providers and subprocessors. We rely on established vendors for infrastructure, endpoint security, email security, backup, monitoring, ticketing, communications and payment processing. They are bound by contract to protect the information they handle and to use it only to provide services to us. A current list of the subprocessors involved in a given service is available to clients on request.
- Our clients. Where we hold information as a service provider, it is disclosed back to the client organization that owns it.
- Professional advisers. Accountants, auditors, insurers and legal counsel, bound by professional confidentiality obligations.
- Legal requirements. Where disclosure is required by law, by a court order, or to investigate a suspected breach of an agreement or of the law.
- Business transactions. In connection with a merger, acquisition or sale of assets, subject to appropriate confidentiality protections.
8. Where information is held
Our primary systems and our clients’ data are hosted in Canada wherever the platform allows it. Some vendors we rely on store or process information in the United States or other jurisdictions. Information held outside Canada may be accessible to the courts, law enforcement and national security authorities of that jurisdiction. We select vendors that offer contractual protections comparable to the safeguards we apply ourselves.
9. How we protect information
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the information we hold. These include role-based access control and least-privilege administration, multi-factor authentication on administrative accounts, encryption of data in transit and of backups at rest, endpoint detection and response on company devices, managed firewalls, logging and alerting, vendor due diligence, and mandatory security awareness training for our staff.
No safeguard is absolute. We cannot guarantee that transmission over the internet or electronic storage is completely secure, and we do not claim otherwise.
10. How long we keep information
- Website enquiries that do not become client relationships: up to 24 months from last contact.
- Client records, tickets and correspondence: for the duration of the engagement and for seven years afterwards, consistent with contractual, tax and limitation-period requirements.
- Backup images: according to the retention schedule agreed with each client; expired images are destroyed on that schedule.
- Security and server logs: typically 12 months.
- Unsuccessful job applications: up to 12 months, unless you ask us to keep your details on file.
When information is no longer required for the purpose it was collected and no legal obligation requires us to retain it, we destroy, erase or de-identify it.
11. Your rights
Subject to limited legal exceptions, you have the right to:
- Ask whether we hold personal information about you, and to be given access to it;
- Ask us to correct information that is inaccurate or incomplete;
- Withdraw consent, subject to legal and contractual restrictions and reasonable notice;
- Ask how your information has been used and to whom it has been disclosed;
- Complain about our handling of your information.
Write to our Privacy Officer using the details in section 15. We will respond within 30 days, or tell you why we need more time. There is no charge for a reasonable request; if a request requires significant effort we will give you a cost estimate before proceeding. We may ask you to verify your identity before releasing information.
12. Privacy breaches
We maintain an incident response process for security incidents affecting personal information. Where a breach of security safeguards creates a real risk of significant harm to an individual, we report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, as PIPEDA requires. We keep records of breaches of security safeguards for a minimum of 24 months. Where the affected information belongs to a client, we notify that client promptly and support their own notification obligations.
13. Children
Our services are sold to businesses and this website is not directed at children. We do not knowingly collect personal information from anyone under the age of majority. If you believe a child has provided us with personal information, contact us and we will delete it.
14. Third-party links and changes to this policy
This site links to third-party websites, including vendor and partner sites. We are not responsible for their privacy practices, and we encourage you to read their policies.
We review this policy periodically and may update it to reflect changes to our practices, our technology or the law. The effective date at the top of this page indicates when it was last revised. Material changes will be highlighted on this page.
15. Contact us
Questions, access requests and complaints about privacy should go to our Privacy Officer:
Privacy Officer
CG Technologies Corp.
Unit 8, 2499 Rutherford Road
Concord, Ontario L4K 0J9
Canada
Email: privacy@cgtechnologies.com
Telephone: 416-244-4357
If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada:
Office of the Privacy Commissioner of Canada
30 Victoria Street, Gatineau, Quebec K1A 1H3
Toll free: 1-800-282-1376
priv.gc.ca