Privacy Policy

"Prevention is cheaper than a breach"

OnionGrid (“we”, “us”, “our”) is committed to protecting the privacy of the people and businesses we work with and to handling personal information with care.

This privacy policy explains how we collect, use, store and share personal information that you provide to us or that we collect from you. Please read it carefully to understand how we handle your personal information. By visiting oniongrid.com or doing business with us, you accept the terms of this policy and consent to the practices described below.

Scope

This policy covers:

  • Personal information collected through our website, oniongrid.com, including any landing pages, forms and assessment requests on it.
  • Personal information collected during your business engagement with us as a client, prospect, professional advisor, consultant, service provider or other third party, as needed to run our business and deliver our cybersecurity, network security, network data and cloud services to you.
  • Personal information we may encounter on your systems, devices or accounts while delivering a security assessment or other service. We treat this information as confidential, access it only as needed to perform the agreed work, and do not use it for any other purpose.

Information we collect from you

Information you provide on our website. This is information you give us when you fill out a contact form, request a security assessment, ask for information about a service, download a resource, or share content from oniongrid.com on social media. It may include:

  • Your name
  • Email address
  • Phone number
  • Company name and job title
  • The number of staff and devices in your business, and a short description of your IT setup or security concern, where you choose to tell us

You can choose not to give us this information by not filling out our forms. Without it, however, we may not be able to provide the information or assessment you requested.

Information we collect from prospects and clients. When you do business with us, you may provide personal information such as names, email addresses, company name, phone numbers, billing details and any other information you choose to share. During a security assessment or ongoing service, we may also collect technical information about your business systems, such as device names, network configuration, software versions and user account names, to the extent needed to perform the work.

Information we collect while conducting business. We also collect information from third parties such as our professional advisors, consultants, service providers and technology partners where this is needed to do business with you. For example, we may obtain business contact details and other information needed to engage third parties and evaluate their performance.

Information received from other sources. We may receive information about you from third parties, such as business directories, referral partners, or publicly available sources. Where we do, we work with those third parties to tell you what information we have received and how we intend to use it.

Cookies

Our website uses cookies and similar technologies to recognise visitors and distinguish between them. This helps us give you a smooth browsing experience, understand how our site is used, measure the performance of our marketing, and improve the site over time. You can control or disable cookies through your browser settings. Some parts of the site may not work as intended if cookies are disabled.

How we use your information

We use the information we collect for the following purposes:

  • To carry out our obligations under any agreement or contract between you and us, and to provide the information, assessments and services you request.
  • To respond to your enquiries and schedule security assessments, consultations and support.
  • To send you information about services, events and security updates we think may be of interest to you.
  • To process and complete business transactions and send related information, including confirmations and invoices.
  • To notify you about changes to our services or this policy.
  • To make sure content from our site is presented in the most effective way for you and your device.
  • To protect the security of our own systems, website and business.

If we cannot process your personal information, whether because you do not consent, you withdraw or limit your consent, or for any other reason, we may not be able to achieve the purposes listed above.

Disclosure of your information

We do not sell your personal information to anyone. We may share your personal information with third parties as follows:

  • Selected business partners, subcontractors and technology vendors (for example, cloud, email security and endpoint protection providers) where this is needed to perform a contract we enter into with them or with you.
  • Analytics, advertising and search engine providers that help us improve and optimise our website and marketing.

We will also disclose your personal information to third parties:

  • If we sell or buy any business or assets, in which case we may disclose your personal information to the prospective seller or buyer of that business or those assets.
  • If OnionGrid or substantially all of its assets are acquired by a third party, in which case personal information held about our clients will be one of the transferred assets.
  • If we are required to disclose or share your personal information to comply with a legal obligation, to enforce or apply our terms of use and other agreements, or to protect the rights, property or safety of OnionGrid, our clients or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and cybersecurity threat response.

Some of our service providers may store or process information outside Canada, including in the United States. Where this happens, the information may be subject to the laws of that jurisdiction.

Automated decision making

We do not use automated decision making, including profiling, in a way that produces legal or similarly significant effects for you.

Data security

As a cybersecurity company, we apply the same standards to our own data that we recommend to our clients. We use appropriate technical and organisational measures, including access controls, encryption and secure storage, to protect your personal information against unauthorised access, loss, misuse or alteration. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Retention of data

We retain your personal information only for as long as reasonably necessary for the purposes described above, to meet our legal, accounting and contractual obligations, and to resolve disputes. Technical information collected during an assessment is deleted or anonymised once the engagement and any agreed follow-up period are complete.

Your rights

We only process your personal information for marketing purposes where you have given us express permission or where we have a legitimate interest in doing so. The legitimate interests we rely on are listed above under “How we use your information”.

At any time, even if you have previously consented, you have the right to ask us not to process your personal information for marketing purposes and not to disclose it to third parties for marketing purposes. You can do this by emailing info@oniongrid.com or by using the unsubscribe link in any marketing email we send you.

You can also use this email address to tell us your preferences about how we process your information, for example how often you hear from us, through which channel, and on what subjects.

Under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, the EU and UK General Data Protection Regulation (GDPR), you also have the right to:

  • Access the personal information we hold about you
  • Request correction or deletion of personal information we hold about you
  • Withdraw your consent to our processing of your information, subject to legal or contractual restrictions
  • Object to or restrict the processing of your information
  • Request that your information be transferred to another organisation in a portable format
  • Complain to the relevant supervisory authority, including the Office of the Privacy Commissioner of Canada

Third-party sites

Our site may, from time to time, contain links to and from the websites of our partners, vendors and affiliates. If you follow a link to any of these websites, please note that they have their own privacy policies and that we do not accept any responsibility or liability for those policies. Please check them before you submit any personal information to those sites.

Changes to this privacy policy

Any changes we make to this privacy policy will be posted on this page and, where appropriate, notified to you by email. Please check back regularly to see any updates or changes.

Complaints procedure

If you have a complaint about how we have handled your personal information or about the exercise of your rights described above, please raise it with us first by emailing info@oniongrid.com. We will acknowledge your complaint and respond within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada or the supervisory authority in your jurisdiction.

Contact

Questions, comments and requests about this privacy policy are welcome and should be sent to:

OnionGrid Mississauga, Ontario, Canada Email: info@oniongrid.com

Scroll to top