Privacy Policy
What we collect, how we handle it, and what rights you have under Canadian privacy law.
Last updated: July 23, 2026
CyberConnect IT Services ("CyberConnect", "we", "us") provides cybersecurity and managed IT services to businesses in Saskatchewan, Canada. This policy explains what information we collect, how we handle it, and what rights you have. It applies to this website and to the data we access while delivering services to clients.
We operate under the Personal Information Protection and Electronic Documents Act (PIPEDA). Where a client's obligations require it, we also support GDPR, HIPAA-conscious, and PCI DSS-aligned workflows as agreed in the client's service scope.
1. Who is responsible for your information
CyberConnect is a solo-operated business. All personal information we collect or access is handled directly by Dorian Balogh, owner and sole operator. We do not use subcontractors, offshore support desks, or third-party support vendors to access client systems or data.
Privacy contact: Dorian Balogh, CyberConnect IT Services, Regina, Saskatchewan, Canada.
2. Information collected through this website
When you submit the general contact form, we collect your name, company or organization, email address, phone number, and the content of your message.
When you submit the priority incident form, we additionally collect the incident type, when it was first detected, the current impact level, affected systems or accounts, actions already taken, and any incident details you provide.
Provide only what is necessary to describe your situation. Do not include passwords, credential material, payment card numbers, health information, or other sensitive data in a web form. If sensitive disclosure is required, request an encrypted response path in your first message and we will provide one.
3. Why we collect it
Website submissions are used solely to respond to your inquiry, triage a reported incident, scope proposed work, and maintain a record of the engagement. We do not sell personal information. We do not share it with advertisers, data brokers, or marketing platforms. We do not use it for automated decision-making or profiling.
4. How submissions are handled
Both the general contact form and the priority incident form are processed by Formspree, a third-party form service. When you submit a form, its contents are transmitted to Formspree, which relays them to a CyberConnect-controlled mailbox and retains a copy in our Formspree account. Formspree is operated from the United States, which means form submissions are stored outside Canada. See Section 9.
This is the reason for the warning in Section 2: because submissions pass through and are retained by a third-party service, a web form is not an appropriate place for credentials, payment card numbers, or health information. Request an encrypted path instead.
Contact details from inquiries that do not become engagements are deleted within 12 months.
Our phone number is published in plain text in the footer of every page, so that people and search engines can find it without running scripts. Our email address is handled differently: it is not present in this site's HTML source and is assembled in your browser only when you choose to reveal it. That reduces automated scraping of the inbox and is a protection for us, not a restriction on you.
5. Client data accessed during service delivery
When delivering managed IT and security services, we necessarily access client systems that may contain personal information about your staff, customers, or patients. Our practices:
- Direct access only. Access is performed by Dorian Balogh. No other person accesses client environments.
- Access in place, not extraction. We work within your systems. Data is not copied to other devices without your explicit permission.
- Retention limits where copying is approved. If you approve a copy - for example for forensic investigation or migration - it is retained for a maximum of 30 days. In regulated or medically sensitive contexts, the maximum is 14 days. Retention windows can be shortened further at your written request.
- Least privilege. We request the minimum access required for the work in scope and remove access that is no longer needed.
- Client ownership. You own your administrative accounts, infrastructure, and documentation. You can revoke our access at any time without our involvement.
- Client-specific mapping. During onboarding, our technical controls and policies are mapped to your specific compliance scope.
6. Cookies, analytics, and tracking
CyberConnect sets no cookies of its own. This website uses no advertising cookies, no third-party analytics, no tracking pixels, and no cross-site trackers.
A single browser-local preference is stored to remember your light or dark theme choice. It contains no personal information, never leaves your browser, and is never transmitted to us.
Every page asset - stylesheets, scripts, fonts, and images - is served from this site. Your browser is not asked to contact any other company's servers in order to display a page, so no advertising or analytics network learns that you visited.
One infrastructure provider does sit in the path. This site is served through Cloudflare, which provides our domain registration, DNS, and a reverse proxy in front of our web server. Because your connection reaches us through Cloudflare's network, Cloudflare processes it - including your IP address - and may set its own security cookies to detect automated abuse. Cloudflare acts as a service provider to us under its data processing terms and does not use this traffic to build advertising profiles. We use it so that our origin server's address is not directly exposed.
Standard server logs on our own hardware record IP address, user agent, and requested page for security and availability purposes. These are retained for 30 days and then deleted.
7. How we protect information
The controls described in our Trust Center apply to our own systems as well as our client work:
- Multi-factor authentication enforced on every system that supports it
- A 3-2-1 backup strategy with verified recovery paths, weekly restore spot-checks, and monthly full restore drills
- Weekly patch cycles with priority handling for high-severity issues
- Unnecessary endpoint services and exposed ports closed by default
- Credentials and 2FA secrets held in a self-hosted Bitwarden instance
- CIS Controls used as the practical hardening baseline
Our operational tooling is open-source and self-hosted wherever possible, including monitoring, remote management, backups, asset tracking, and AI tooling. Our AI workspaces run locally on self-hosted Open-WebUI and LM Studio, which means client data is never sent to a third-party AI provider.
8. Third parties
Because our stack is self-hosted, we use very few external processors. There are exactly three:
- Cloudflare - domain registration, DNS, and the reverse proxy through which this website is served (see Section 6).
- Zoho (Canadian infrastructure) - our business email provider. Correspondence with us is stored in that mailbox.
- Formspree - processes and stores submissions from this site's contact and incident forms (see Section 4).
The following are run by CyberConnect on its own hardware and involve no external provider at all:
- Website hosting. This site runs on a server owned and operated by CyberConnect, not on a rented hosting platform.
- Invoicing and billing records. We use InvoiceShelf, a self-hosted invoicing application. Your billing details are not sent to a third-party invoicing or payment platform.
- Monitoring, backups, asset tracking, credential storage, and AI tooling. All self-hosted, as described in Section 7.
We do not disclose personal information to any other third party except where required by Canadian law, and where legally permitted we will notify the affected client before doing so.
9. Data location
CyberConnect's own systems and backups are located in Canada, on hardware we own and physically control in Saskatchewan. This includes the web server behind this site, our monitoring and backup systems, our credential store, and our invoicing records. No rented cloud platform holds them.
Two exceptions involve providers outside that boundary, and we would rather state them plainly than imply everything stays on our premises:
- Form submissions. Anything sent through the contact or incident form is processed and stored by Formspree in the United States, as described in Section 4.
- Traffic routing. Connections to this site pass through Cloudflare's global network before reaching our server, so connection data may be processed at edge locations outside Canada.
Email is held on Zoho's Canadian infrastructure.
Information processed or stored in another country may be accessible to that country's authorities under its laws. If you would prefer your inquiry not pass through a United States service, phone us instead of using the web forms. A phone call reaches us without touching Formspree.
10. Incident and breach handling
Our incident workflow is: triage, contain and minimize risk, restore from validated backups, then verify recovery. If a breach of security safeguards involving personal information under our control creates a real risk of significant harm, we will notify affected clients and the Office of the Privacy Commissioner of Canada as required by PIPEDA, and maintain records of the breach.
Our response targets are 6 hours for active incidents and 48 hours for general requests.
11. Your rights
Under PIPEDA you may request access to the personal information we hold about you, request correction of inaccurate information, withdraw consent (subject to legal and contractual limits), ask about our handling practices, and complain about our handling.
Requests should go to the privacy contact in Section 1. We respond within 30 days. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.
12. Changes
Material changes will be posted here with an updated date. Active clients will be notified directly of changes affecting how their data is handled.
This policy describes CyberConnect's actual practices and is not legal advice. Clients in regulated industries should have it reviewed against their own compliance obligations.
Questions about how your data is handled?
Ask Before You Sign Anything