ClearBreach

Privacy Policy

Last updated: September 2026

Who we are

ClearBreach Technologies Inc. (“ClearBreach”, “we”, “us”) is an Alberta corporation providing automated privacy breach assessment services to Canadian small and medium-sized organizations and managed service providers. We are subject to the Alberta Personal Information Protection Act (Alberta PIPA) for intraprovincial commercial activity, and to the federal Personal Information Protection and Electronic Documents Act (PIPEDA) for cross-border and interprovincial commercial activity.

What information we collect and why

Waitlist signups (clearbreach.ca)

If you submit your email address on our early access page, we collect your email address for the sole purpose of notifying you when ClearBreach launches. We do not collect any other information at this stage.

Subscriber accounts (app.clearbreach.ca)

When you subscribe to ClearBreach, we collect your name, email address, organization name, and registered province. This information is required to create your account, process your payment, and provide the service.

Assessment sessions

Breach details never leave your browser. The ClearBreach assessment wizard runs entirely in your browser. Your answers about the breach, what happened, what information was involved, how many people were affected, and everything else the verdict is calculated from, are never transmitted to us.

So that an assessment survives a closed tab, your answers are saved in your browser’s local storage, on the device you are using. Saved answers more than 24 hours old are not resumed, and are removed the next time ClearBreach is opened in that browser. They are also removed when you sign out, and when a different account signs in on the same browser. You can remove them at any time with Clear my saved answers on your portal. Because they exist only on that device, we cannot see them or restore them for you.

What we record is a record of the assessment itself: the verdict, which privacy laws were evaluated and what each concluded, your operating provinces, whether personal information moves outside them, and, where an assessment stopped because no privacy law applied, the answer that led to that. We also record which version of the assessment engine and of the disclaimer applied, whether a consequence notice was shown, and the date. We use this to operate the service and to enforce the assessment limit included in your subscription.

We keep it for 24 months, then reduce it to a verification record kept for five years. See Data retention below.

Usage and technical data

We collect standard server logs (IP address, browser type, pages visited, timestamps) for security monitoring and service operation. We do not use third-party analytics platforms that track individual behaviour across websites.

Failed sign-in attempts

When a sign-in fails we record the time, the network address it came from, and a one-way value derived from the email address that was tried. We do not keep that email address in readable form. Anyone can type any address into a sign-in form, and in an attack most of the addresses tried belong to people who are not our customers. Keeping them readable would mean holding personal information about people who have no relationship with us.

We use these records for one thing: telling a customer locked out of their own account apart from somebody working through a list of addresses. Successful sign-ins are not recorded this way.

Cookies and similar technologies

We use a small number of essential cookies and similar technologies that are necessary to operate the Service, for example, to keep you signed in (authentication and session cookies) and to remember your assessment progress within your browser. We do not use advertising cookies or third-party cookies that track you across other websites. You can control or delete cookies through your browser settings; disabling essential cookies may prevent parts of the Service from working.

How we use your information

  • To provide and operate the ClearBreach service
  • To process payments and manage your subscription
  • To send transactional email (account setup, password reset, renewal reminders)
  • To notify waitlist subscribers when ClearBreach launches
  • To send triggered regulatory notifications to subscribers
  • To respond to support and privacy inquiries

Your consent

We collect, use, and disclose your personal information with your knowledge and consent, except where permitted or required by law. By using ClearBreach, you consent to the collection and use of your personal information as described in this policy. You may withdraw your consent at any time, subject to legal and contractual restrictions (see Your rights under Alberta PIPA and PIPEDA below).

Email communications and CASL consent

ClearBreach complies with Canada’s Anti-Spam Legislation (CASL). We send commercial electronic messages only to individuals who have provided express consent.

  • Waitlist subscribers consent to receive a one-time launch notification by submitting their email address on our early access page.
  • ClearBreach subscribers consent to receive subscription-related communications and triggered regulatory notifications by purchasing a subscription, as disclosed at the point of purchase.

You may withdraw consent at any time by clicking the unsubscribe link in any email or by contacting us at contact@clearbreach.ca. Unsubscribing from email communications does not cancel your subscription or affect your access to the assessment tool.

How we share and disclose your information

We do not sell, rent, or trade your personal information. We disclose your personal information only to the service providers described below, and we may disclose it where required or permitted by law, for example, in response to a valid court order, subpoena, or legal process, or where reasonably necessary to protect the rights, safety, or property of ClearBreach or others.

Third-party service providers

We use third-party service providers to operate ClearBreach. Each processes personal information only as necessary to deliver the service and is bound by contractual data protection obligations. The table below sets out what each is used for and where the processing happens. We will name the providers themselves on request, write to privacy@clearbreach.ca.

PurposeProcessed inData processed
Application and database hostingCanadaSubscriber account data and application data. We host these on servers we have chosen in Canada; this is our configuration rather than a guarantee written into the provider’s contract.
Payment processingUnited StatesPayment card information and billing details. ClearBreach does not store payment card information. Our contract is with the provider’s Canadian entity, and personal data is processed by its US entity in the United States.
Transactional email deliveryCanadaEmail address and email content (account setup, password reset, renewal reminders, payment failure notifications, triggered regulatory notifications). Does not process breach assessment content.
Staff email hostingCanadaClearBreach staff correspondence at @clearbreach.ca addresses.

US CLOUD Act: our hosting, transactional email, staff email and payment providers are all US-incorporated entities. They may be subject to the US Clarifying Lawful Overseas Use of Data Act (CLOUD Act), which permits US law enforcement to compel production of data stored outside the United States. This applies to the first three even though that data is held in Canadian data centres.

Data residency and cross-border transfers

The ClearBreach application, the subscriber database, transactional email and staff email are all processed in Canada. Payment processing is not: by using ClearBreach you acknowledge that your billing and account information is transferred to and processed in the United States. Every one of these providers is US-incorporated and therefore within the reach described above, whichever country the data sits in. Breach assessment answers are never transferred, they remain in your browser only.

Data retention

  • Failed sign-in records, kept for 90 days and then deleted. They hold the time, the network address, and a one-way value derived from the address that was tried, never the address itself.
  • Waitlist email addresses, retained until ClearBreach launches and the launch notification is sent, after which they are deleted within 90 days. They are deleted sooner on request. We store the address and the date it was given, and nothing else.
  • Subscriber account data, retained for the duration of your subscription and for 24 months following cancellation, after which it is deleted.
  • Assessment records, kept for 24 months, matching the period you are required to keep your own breach records, so we can answer questions about an assessment for as long as you are holding it. What the record contains is set out under Assessment sessions above.
  • Verification records, at 24 months an assessment record is reduced to a verification record: the date, the version of the assessment engine that produced the verdict and of the disclaimer you accepted, and a one-way hash. The hash lets us confirm that a document you produce is the one your assessment generated. It cannot be reversed, it contains nothing about the breach, and we cannot read anything from it without the copy of the document you hold. We keep it for five years from the date of the assessment so that a disputed verdict can be checked within the limitation period, and then delete it. It is kept on this schedule and is not deleted with your account.

Your rights under Alberta PIPA and PIPEDA

You have the right to request access to the personal information we hold about you, to request correction of inaccurate information, and to withdraw consent to our use of your personal information (subject to legal and contractual restrictions). These rights exist under both Alberta PIPA (ss.24, 28) and PIPEDA (Principles 9 and 3).

To exercise these rights, contact our Privacy Officer at privacy@clearbreach.ca. We will respond within 30 days for PIPEDA requests and within 45 days for Alberta PIPA requests, as required by each statute.

How to file a privacy complaint

If you believe ClearBreach has not handled your personal information in accordance with Alberta PIPA or PIPEDA, you may file a complaint with our Privacy Officer at privacy@clearbreach.ca. Please describe the nature of your concern and the personal information involved. We will acknowledge receipt of your complaint and respond within 30 days.

If you are not satisfied with our response, you may escalate your complaint to the applicable regulator:

  • Alberta PIPA complaints, Office of the Information and Privacy Commissioner of Alberta (OIPC Alberta) at oipc.ab.ca
  • PIPEDA complaints, Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca

Security

We implement appropriate technical and organizational safeguards to protect personal information against unauthorized access, disclosure, or loss. These include encrypted data transmission (TLS), database access controls, and the privacy-by-design architecture that keeps breach assessment answers in your browser only.

In the event of a breach of security safeguards involving your personal information that creates a real risk of significant harm, we will notify affected individuals and the applicable regulator (the OPC and/or OIPC Alberta) as required by PIPEDA and Alberta PIPA, and maintain records of the breach as required by law.

Children

ClearBreach is a business tool and is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us at privacy@clearbreach.ca and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated to subscribers by email. The date at the top of this page reflects the most recent update.

Contact

General inquiries: contact@clearbreach.ca
Privacy inquiries and access requests: privacy@clearbreach.ca

ClearBreach Technologies Inc.
Alberta, Canada