Legal
Privacy Policy
This page explains how Ecodemy handles personal information across the Ecodemy S-211 Compliance Hub, supplier portal, related tools, and public website.
Effective date: June 18, 2026
Last updated: July 14, 2026
What this page covers
This page explains how personal information is collected, used, disclosed, retained, and protected. It should be read together with our Terms of Service.
Who This Policy Covers
This Privacy Policy explains how Ecodemy Education Inc. collects, uses, discloses, and protects personal information in connection with the Ecodemy S-211 Compliance Hub, S-211 Filer, questionnaire workspace, supplier portal, training tools, report-generation tools, related websites, APIs, downloads, and services.
This policy applies to account users and administrators, reporting-entity personnel recorded in a workspace, supplier representatives who receive a portal link or submit a self-assessment, visitors to our public website, and recipients of our emails.
When you use the service on behalf of an organization, that organization controls its workspace and the customer data in it. For most workspace information, the customer decides what is collected and why, and Ecodemy processes that information on the customer's behalf as a service provider. This policy describes Ecodemy's own practices and does not override a customer's privacy notices to its own personnel or suppliers.
Information We Collect
We collect account and profile information, including name, email address, password credentials, organization name, business size, role or job function, and workspace and membership details.
Workspace and customer data may include information you or your users submit to or generate in the service, such as:
- Reporting-entity profile details, including legal name, business number, entity type, jurisdiction, industry, fiscal year, website, reporting lead, and contact details.
- Supplier records, supplier contact details, due-diligence responses, risk inputs and scores, and procurement-impact configurations and decisions.
- Incident, investigation, corrective-action, remediation, and outcome records.
- Training records, including employee names, identifiers, departments, roles, course completion, certificates, and SCORM activity.
- Policy documents, evidence files, document attachments, workbook content, comments, notes, configuration settings, and audit-log activity.
- S-211 questionnaire answers, supporting narratives, attached evidence, board or governing-body approval and attestation records, and readiness data.
Supplier portal submissions may include contact details and responses about a supplier's practices. Billing information may include plan, subscription, and transaction details. Payments are processed by our payment provider, and we do not store full payment-card numbers.
We may also collect usage, device, and log information, including IP address, browser and device information, pages and features used, events, timestamps, diagnostic data, and error data. Communications and consent records may include emails we send, unsubscribe status, and consent or implied-consent records used to support compliance with anti-spam law.
We and our providers may use cookies, local storage, and similar technologies to keep users signed in, remember preferences, secure the service, and measure usage.
How We Use Information
We use personal information to provide, operate, and secure the service and customer workspaces; draft S-211 questionnaire answers and report narratives from workspace data; calculate readiness indicators; generate reports and exports; and produce templates and decision-support outputs that customers are responsible for reviewing.
We also use information to authenticate users, apply role-based access controls, enforce plan limits, process subscriptions and billing, send service and administrative communications, provide support, monitor and troubleshoot the service, improve existing features, develop new features, detect and investigate misuse or security incidents, comply with legal obligations, and enforce our agreements.
Where permitted by law and, for Customer Data, where the customer expressly allows Ecodemy to do so through plan terms, workspace settings, or a separate written agreement, we may create aggregated, anonymized, or de-identified information from service usage and Customer Data and use it for analytics, benchmarking, security, research, product improvement, and business purposes, provided it does not identify an individual or customer.
We do not sell personal information.
Legal Basis and Consent
We rely on the consent and authority provided when the service is used, the need to perform our agreement with customers, and our legitimate interests in operating, securing, and improving the service, as permitted by applicable Canadian privacy law, including PIPEDA and applicable provincial legislation.
For commercial electronic messages, we rely on consent or on an existing business relationship as permitted under Canada's Anti-Spam Legislation. You can withdraw consent to non-transactional email at any time using an unsubscribe link or by contacting us. We may still send essential transactional, security, or account messages.
We process unsubscribe requests within the time required by Canada's Anti-Spam Legislation.
Personal Information Within Customer Data
Much of the information in a workspace concerns the customer's own personnel, suppliers, and operations and is provided under the customer's control. The customer is responsible for having the authority, notices, and consents required to submit personal information to the service, including employee training records and supplier contact details.
Customers are also responsible for configuring access, permissions, notifications, and supplier communications lawfully, and for responding to access, correction, or deletion requests from their own personnel and suppliers.
Customers should not submit sensitive personal information or identifying data unless it is necessary, authorized, and appropriate for their use of the service.
If you are an individual whose information appears in a customer's workspace, such as an employee or supplier contact, and you wish to access, correct, or delete that information, please contact the relevant organization directly. Where appropriate, we will refer such requests to the responsible customer.
How We Share Information
Information is visible to authorized users of the relevant workspace according to their roles and permissions, and to workspace administrators. Designated Ecodemy platform administrators may access workspace information where needed to operate, secure, and support the service.
We use third-party providers to host and run the service, including hosting, database, storage, and authentication providers; payment processors; email delivery providers; product analytics providers; and application hosting and delivery providers. These providers process information on our behalf under their own terms and privacy and security commitments.
We may disclose information to comply with law, respond to lawful requests, enforce our terms, protect the rights, safety, and security of users, the public, or Ecodemy, or as part of a merger, acquisition, financing, reorganization, or sale of assets, subject to this policy.
Supplier portal submissions are not independently verified by Ecodemy and are shared with the customer whose workspace generated the portal link.
International Transfers and Data Location
Some service providers may store or process information in Canada, the United States, or other countries. Where information is transferred outside your province or country, it may be subject to the laws of those jurisdictions, including lawful access by courts, law enforcement, and regulators.
We take steps intended to ensure a comparable level of protection through our provider arrangements. Contact us for information about where customer data is hosted for your plan.
Data Security
We use technical and organizational measures intended to protect information, which may include workspace-scoped data isolation, scoped storage paths, signed upload URLs, file-type and size restrictions, upload rate limits, role-based access controls, audit logging, and encryption of data in transit.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your credentials and portal links and for maintaining your own backups and security procedures.
Data Retention
We retain personal information for as long as an account or workspace is active and as needed to provide the service, and afterward as needed to comply with legal, tax, audit, accounting, dispute-resolution, and security obligations and to enforce our agreements.
Cancelling or downgrading a plan does not automatically delete customer data. Customer data may remain stored, subject to plan limits, backup cycles, and any separate written agreement, until deleted in the ordinary course or on request where we are able to do so. Backups are retained for a limited period and then overwritten or deleted on a rolling basis. Customers should export or preserve records they need before cancelling.
We do not guarantee indefinite retention of Customer Data after cancellation, downgrade, expiry, or termination.
Your Choices and Rights
Subject to applicable law and identity verification, you may access, update, or correct your account and profile information; request access to or correction of personal information we hold about you; ask questions about how it is handled; unsubscribe from non-transactional emails; withdraw email consent; or request deletion of account information, subject to legal and operational retention needs.
To exercise these rights, contact us using the details below. For information held within a customer's workspace, please see the section on personal information within customer data. You may also contact the Office of the Privacy Commissioner of Canada or your applicable provincial regulator about our handling of personal information.
Cookies and Analytics
We and our providers use cookies, local storage, and similar technologies for authentication, security, preferences, and analytics. You can control cookies through your browser settings, though disabling some technologies may affect how the service works. Analytics providers help us understand feature usage and improve the service.
Children
The service is intended for organizations and their authorized personnel and is not directed to children. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this policy from time to time. If changes are material, we will provide notice by posting an updated version, sending email, showing in-app notice, or using another reasonable method. The last updated date shows when this policy was last revised. Continued use of the service after the effective date of an updated policy means you accept the update.
Contact
For questions about this policy or our privacy practices, urgent privacy-related issues, or to exercise your rights, contact Ecodemy Education Inc. at privacy@ecodemy.ca, by phone at (519) 777-9241, or by mail at 126 Green St, Sarnia, Ontario, N7T 2K5.