How we handle your information
You are being asked to describe a breach to software made by people you have not met. That is a reasonable thing to hesitate over, so here is what happens to it, in the order the question usually gets asked.
Everything below is in our privacy policy in the same terms. Where the two differ, the policy governs.
Breach details never reach us
The breach assessment runs entirely in your browser. What happened, what information was involved, how many people were affected, and everything else the verdict is calculated from, are never transmitted to ClearBreach. So that an assessment survives a closed tab, your answers are held in that browser, on that device, and are not resumed after 24 hours.
What we do record, and it is not the breach
A record of the assessment itself: the verdict, which privacy laws were evaluated and what each concluded, your operating provinces, whether information moves outside them, and the date. We use it to run the service and to count assessments against your subscription.
The other two workflows keep more, and we say so
The compliance assessment records a score per area. A privacy impact assessment stores the name of the initiative and of your privacy officer, because it is a document you file and return to a year later. The in-your-browser promise is true of the breach workflow and we do not stretch it over the other two.
Canadian hosting, stated as what it is
The application, the subscriber database, transactional email and staff email are processed in Canada. That is our configuration rather than a guarantee written into a provider’s contract, which is a real difference and the reason it is worded this way.
Payment processing is not in Canada
Billing and account information is processed in the United States by our payment provider. ClearBreach never stores payment card details. Our hosting, email and payment providers are US-incorporated and may be reachable under the US CLOUD Act even where the data sits in a Canadian data centre.
No behavioural tracking, anywhere
No advertising cookies, no third-party analytics that follow you between websites. The cookies we set keep you signed in and remember where you are in an assessment. A failed sign-in is recorded as a one-way value, never the address somebody typed, because in an attack most addresses tried belong to people who are not our customers.
How long it is kept
Assessment records for 24 months, then a verification record for five years. Failed sign-in records for 90 days. An early-access address until launch and the notification that follows it, then removed within 90 days, or on the day you ask.
And this website
clearbreach.ca stores nothing about you. Not your network address, not your browser, not where you came from, and not an address you could have typed in, because there is nowhere on this website to type one. No advertising and no cross-site tracking on any page.
That is a decision rather than an oversight. Anything we ever remember about a person is held in the application, in Canada. If you want to be told when ClearBreach opens, email us and a person adds you to a list they keep.
Still want to ask?
We name our service providers on request. Write to privacy@clearbreach.ca and a person answers.