Privacy Policy
What we collect, how we handle it, and what rights you have under Canadian privacy law.
Last updated: July 27, 2026
CyberConnect IT Services ("CyberConnect", "we", "us") provides cybersecurity and managed IT services to businesses in Saskatchewan, Canada. This policy explains what information we collect, how we handle it, and what rights you have. It applies to this website and to the data we access while delivering services to clients.
We operate under the Personal Information Protection and Electronic Documents Act (PIPEDA). Where a client's obligations require it, we also support GDPR, HIPAA-conscious, and PCI DSS-aligned workflows as agreed in the client's service scope.
1. Who is responsible for your information
CyberConnect is a solo-operated business. All personal information we collect or access is handled directly by Dorian Balogh, owner and sole operator. We do not use subcontractors, offshore support desks, or third-party support vendors to access client systems or data.
Privacy contact: Dorian Balogh, CyberConnect IT Services, Regina, Saskatchewan, Canada.
2. Information collected through this website
When you submit the general contact form, we collect your name, company or organization, email address, phone number, and the content of your message.
When you submit the priority incident form, we additionally collect the incident type, when it was first detected, the current impact level, affected systems or accounts, actions already taken, and any incident details you provide.
Provide only what is necessary to describe your situation. Do not include passwords, credential material, payment card numbers, health information, or other sensitive data in a web form. If sensitive disclosure is required, request an encrypted response path in your first message and we will provide one.
3. Why we collect it
Website submissions are used solely to respond to your inquiry, triage a reported incident, scope proposed work, and maintain a record of the engagement. We do not sell personal information. We do not share it with advertisers, data brokers, or marketing platforms. We do not use it for automated decision-making or profiling.
4. How submissions are handled
Form submissions are handled entirely on CyberConnect's own infrastructure. When you submit a form, its contents are delivered by a form handler we run ourselves, on our own server in Canada, which emails them to our mailbox. Submissions are not sent to or stored by any third-party form service.
The email itself is delivered through our email provider, Zoho, on its Canadian infrastructure (see Sections 8 and 9).
Even so, a web form is not the place for credentials, payment card numbers, or health information - email is not end-to-end encrypted in transit to every recipient. If sensitive disclosure is required, request an encrypted path in your first message instead.
Contact details from inquiries that do not become engagements are deleted within 12 months.
Our phone number is published in plain text in the footer of every page, so that people and search engines can find it without running scripts. Our email address is handled differently: it is not present in this site's HTML source and is assembled in your browser only when you choose to reveal it. That reduces automated scraping of the inbox and is a protection for us, not a restriction on you.
5. Client data accessed during service delivery
When delivering managed IT and security services, we necessarily access client systems that may contain personal information about your staff, customers, or patients. Our practices:
- Direct access only. Access is performed by Dorian Balogh. No other person accesses client environments.
- Access in place, not extraction. We work within your systems. Data is not copied to other devices without your explicit permission.
- Retention limits where copying is approved. If you approve a copy - for example for forensic investigation or migration - it is retained for a maximum of 30 days. In regulated or medically sensitive contexts, the maximum is 14 days. Retention windows can be shortened further at your written request.
- Least privilege. We request the minimum access required for the work in scope and remove access that is no longer needed.
- Client ownership. You own your administrative accounts, infrastructure, and documentation. You can revoke our access at any time without our involvement.
- Client-specific mapping. During onboarding, our technical controls and policies are mapped to your specific compliance scope.
6. Cookies, analytics, and tracking
CyberConnect sets no cookies of its own. This website uses no advertising cookies, no third-party analytics, no tracking pixels, and no cross-site trackers.
A single browser-local preference is stored to remember your light or dark theme choice. It contains no personal information, never leaves your browser, and is never transmitted to us.
Every page asset - stylesheets, scripts, fonts, and images - is served from this site. Your browser is not asked to contact any other company's servers in order to display a page, so no advertising or analytics network learns that you visited.
One infrastructure provider does sit in the path. This site is served through Cloudflare, which provides our domain registration, DNS, and a reverse proxy in front of our web server. Because your connection reaches us through Cloudflare's network, Cloudflare processes it - including your IP address - and may set its own security cookies to detect automated abuse. Cloudflare acts as a service provider to us under its data processing terms and does not use this traffic to build advertising profiles. We use it so that our origin server's address is not directly exposed.
Standard server logs on our own hardware record IP address, user agent, and requested page for security and availability purposes. These are retained for 30 days and then deleted.
7. How we protect information
The controls described in our Trust Center apply to our own systems as well as our client work:
- Multi-factor authentication enforced on every system that supports it
- A 3-2-1 backup strategy with verified recovery paths, weekly restore spot-checks, and monthly full restore drills
- Weekly patch cycles with priority handling for high-severity issues
- Unnecessary endpoint services and exposed ports closed by default
- Credentials and 2FA secrets held in a self-hosted Bitwarden instance
- CIS Controls used as the practical hardening baseline
Our operational tooling is open-source and self-hosted wherever possible, including monitoring, remote management, backups, asset tracking, and AI tooling. Our AI workspaces run locally on self-hosted Open-WebUI and LM Studio, which means client data is never sent to a third-party AI provider.
8. Third parties
Because our stack is self-hosted, we use very few external processors. There are exactly two:
- Cloudflare - domain registration, DNS, and the reverse proxy through which this website is served (see Section 6).
- Zoho (Canadian infrastructure) - our business email provider. Correspondence with us, including form submissions once they are emailed to us, is stored in that mailbox.
The following are run by CyberConnect on its own hardware and involve no external provider at all:
- Website hosting. This site runs on a server owned and operated by CyberConnect, not on a rented hosting platform.
- Form handling. The contact and incident forms are processed by a handler we run ourselves on that same server. Submissions are not sent to any third-party form service.
- Invoicing and billing records. We use InvoiceShelf, a self-hosted invoicing application. Your billing details are not sent to a third-party invoicing or payment platform.
- Monitoring, backups, asset tracking, credential storage, and AI tooling. All self-hosted, as described in Section 7.
We do not disclose personal information to any other third party except where required by Canadian law, and where legally permitted we will notify the affected client before doing so.
9. Data location
CyberConnect's own systems and backups are located in Canada, on hardware we own and physically control in Saskatchewan. This includes the web server behind this site, the handler that processes form submissions, our monitoring and backup systems, our credential store, and our invoicing records. No rented cloud platform holds them, and form submissions are not sent outside Canada.
Email is held on Zoho's Canadian infrastructure.
One provider does sit at the network edge: connections to this site pass through Cloudflare's global network before reaching our server, so connection data such as your IP address may be processed at edge locations outside Canada (see Section 6). Information processed in another country may be accessible to that country's authorities under its laws. If you would prefer to avoid this entirely, phone us rather than using the website.
10. Incident and breach handling
Our incident workflow is: triage, contain and minimize risk, restore from validated backups, then verify recovery. If a breach of security safeguards involving personal information under our control creates a real risk of significant harm, we will notify affected clients and the Office of the Privacy Commissioner of Canada as required by PIPEDA, and maintain records of the breach.
Our response targets are 6 hours for active incidents and 48 hours for general requests.
11. Your rights
Under PIPEDA you may request access to the personal information we hold about you, request correction of inaccurate information, withdraw consent (subject to legal and contractual limits), ask about our handling practices, and complain about our handling.
Requests should go to the privacy contact in Section 1. We respond within 30 days. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.
12. Changes
Material changes will be posted here with an updated date. Active clients will be notified directly of changes affecting how their data is handled.
This policy describes CyberConnect's actual practices and is not legal advice. Clients in regulated industries should have it reviewed against their own compliance obligations.
Questions about how your data is handled?
Ask Before You Sign Anything