Privacy Policy

Last updated: August 6, 2026

Enterprotect Inc. ("EnterProtect", "we", "us") provides backup, disaster recovery and cybersecurity software to managed service providers and the organizations they serve. This notice explains what personal information we collect, why, who we share it with, how long we keep it, and the rights you have over it.

It covers www.enterprotect.com, the EnterProtect console, and the products described on this site.

1. Two kinds of information, handled differently

Most of what we hold falls into one of two categories, and the difference matters for your rights.

Information we collect for ourselves. When you fill in a form on this website, register for the console, or email us, we decide what to do with that information. Canadian law calls us the organization responsible for it; United States law generally calls us a business or controller.

Information we process for a customer. When a managed service provider uses EnterProtect to back up or scan systems, their data, and their own customers' data, passes through our platform. We handle that on their written instructions and for no purpose of our own. We do not sell it, mine it, or use it to train anything. If your data reached us this way, the organization that engaged us is the one to contact, and we will refer your request to them. Canadian law calls us a service provider in that role; United States law calls us a processor or service provider.

2. What we collect

2.1 When you use this website

Nothing measures you until you say so. When you first arrive we ask. Until you answer, no analytics or advertising script loads, no cookie is set, and nothing about your visit is sent anywhere. If you decline, that stays true.

The question is in two parts, and you can agree to one and refuse the other:

  • Analytics. Google Analytics 4, which tells us how many people visit, which pages they read, and where they arrived from.
  • Advertising. The Meta Pixel, which lets us measure whether our advertising reaches anyone. Meta also uses what it collects for its own purposes, which is why it does not run unless you agree.

Two things run whichever way you answer, because the site does not work without them: Cloudflare Turnstile on the corrections form, which is the check that stops a public form being used for spam, and a record of the answer you gave, so we do not ask again on every page. Neither builds a profile of you.

Changing your mind is the same control in the same place. "Your privacy choices", at the foot of any page, reopens it. If your browser sends a Global Privacy Control signal we honour it without asking, leave both categories off, and say so on the page rather than doing it silently.

If you agree to advertising, we also record where you first arrived from: the page you landed on, any campaign parameters in the link, and the advertising click identifier if the link carried one. It is stored alongside any form you later submit, so we can tell which advertising produced a real enquiry rather than guessing. If you decline, none of it is recorded, and the enquiry simply carries no source.

If you submit a form, we receive:

  • the name and work email address you enter, and any message you write;
  • the page you submitted from and the referring page, if your browser sent one;
  • the country your request came from, as reported by our content delivery network;
  • where you first arrived from, but only if you agreed to advertising measurement. Otherwise this is absent rather than blank.

We ask for a work address and refuse addresses at consumer mail providers. That is a business decision about who we sell to rather than a privacy measure, and it is worth knowing we make it.

We do not store your IP address. To stop one connection flooding our forms, we combine the address with a secret value and store only the resulting cryptographic hash. The hash cannot be reversed into an address, it is compared only against other hashes, and it is the sole thing we retain about the connection.

2.2 When you request a document

Guides, white papers and tools on this site are exchanged for a name and a work email address. We record what was requested and send it once.

Because you asked us for something, Canadian law treats that as an inquiry and allows us to follow up about it for six months. In practice that means someone from our team may get in touch about what you downloaded. That is the whole of what the download alone permits.

Marketing email is separate and requires you to ask for it. The form carries an unticked box offering occasional email about products, offers and events. Leaving it alone costs you nothing and changes nothing: you still get the document. If you do tick it, we record the date and the exact sentence you agreed to, because the law puts the burden of proving that on us rather than on you.

You can withdraw at any time, from the unsubscribe link in any such email or by writing to the address in section 11, and we will act on it within ten business days. We keep a record of the withdrawal, since a suppression list only works if it remembers.

2.3 When you use the console

Creating an account produces a record of the account holder's name, work email address, organization, and role. Using the platform produces operational records: backup and recovery job history, alerts, vulnerability scan results, and an audit trail of significant actions taken in the account.

Protected data itself, meaning the files, mailboxes and system images our customers back up, is handled under section 1 as information we process for a customer.

2.4 Payment information

Card details are entered directly with our payment processor and are never transmitted to or stored on our systems. We receive a token, the last four digits, the card brand, and the outcome of each charge.

2.5 When you report a correction

Breach reports in our resource centre carry a form for telling us one of them is wrong. It asks for your name, an email address, how you are connected to the report, the passage you say is inaccurate and what it should say instead. You can also attach a supporting source, and ask for a report to be removed rather than corrected.

This form accepts any email address. The rule described above about work addresses does not apply here and would defeat the purpose: a report about you is worth taking whoever you are, and the people most entitled to complain are often writing personally or through a lawyer.

We use what you send to assess the report and to correct the entry. We contact you only if we cannot act on it without asking you something. It is never used for marketing, it puts you on no list, and ticking nothing is not available because there is nothing to tick.

The form is protected by Cloudflare Turnstile, which checks that a person rather than a script is submitting it. Turnstile is described in Cloudflare's own privacy documentation and does not profile you across sites.

3. Why we use it

  • To answer you. Form submissions exist so a person can reply.
  • To deliver what you asked for. A requested document is emailed to the address given.
  • To provide the service. Account and operational data is what makes backup, recovery, alerting and scanning work.
  • To keep the service safe. Rate limiting, abuse prevention, and the audit trail.
  • To follow up on an inquiry, for six months after you make one, as Canadian anti-spam law permits.
  • To send marketing email, only to people who have ticked the box asking for it.
  • To bill. Subscription and usage records.
  • To meet legal obligations, including tax records and responses to lawful requests.

We do not sell personal information. We do not share it for cross context behavioural advertising. We do not use it for automated decision making that produces legal or similarly significant effects about anyone.

In Canada, we rely on your consent. Submitting a form or creating an account is express consent for the purposes described where you gave it. For ordinary operation of a service somebody has asked for, we rely on implied consent, as PIPEDA permits where the purpose is obvious and the information is not sensitive. You can withdraw consent at any time, subject to legal and contractual limits, by contacting us at the address in section 11. Withdrawing consent may mean we can no longer provide the service.

Analytics and advertising are not covered by that. Neither is an obvious purpose, so neither relies on implied consent. Both are off until you turn them on, and turning them off again takes the same control in the same place. That is a stricter standard than the law requires of us here, and we apply it to every visitor rather than deciding which rules each one falls under.

In the United States, we process personal information to provide a service you or your organization requested, for our legitimate business purposes as described above, and to comply with law.

5. Who else touches it

We use a small number of service providers. Most are bound by contract to handle personal information only on our instructions. The analytics and advertising providers are not in that position, and the difference is the reason they are behind a choice: they also use what they collect for their own purposes. Nothing reaches them unless you agree first.

ProviderWhat it doesWhere it runs
SupabaseDatabase, authentication and server side application codeCanada, Montreal region
CloudflareWebsite hosting, content delivery and file storageGlobal edge network
ResendTransactional email, including document deliveryUnited States
StripePayment processing and subscription billingUnited States
MicrosoftIdentity and Microsoft 365 connections, where a customer enables themPer the customer's own tenant
GoogleWebsite analytics, only if you agree to itUnited States and other countries
MetaAdvertising measurement, only if you agree to it. Also uses the data for its own purposesUnited States and other countries

We also disclose personal information where the law requires it, to professional advisers under a duty of confidence, and to an acquirer if the business is sold, in which case this notice continues to apply until it is replaced and you are told.

6. Where it goes

Our database and the data in it are hosted in Canada. Some of the providers above operate in the United States, or route traffic through a global network, which means personal information may be stored or processed outside the province or country you live in and may be accessible to the courts and law enforcement of those jurisdictions under their laws.

We use providers that offer contractual protections for cross border transfers, and we remain accountable for information we transfer to them.

7. How long we keep it

Operational records in the platform are deleted automatically on a schedule that runs nightly:

RecordKept for
Backup and recovery job history90 days
Completed recovery operations365 days
Resolved alerts180 days
Vulnerability scan runs180 days
Resolved vulnerability findings180 days
Audit trail400 days
Expired invitations30 days

Form submissions and document requests are kept while they are useful to the conversation they started and are reviewed periodically. Account records are kept for the life of the account and for as long afterwards as tax and corporate law require. Protected data is retained and destroyed according to the retention the customer configures, and is deleted when their subscription ends.

Correction requests are handled differently, on purpose. We keep the editorial record of what was reported and what we did about it indefinitely, because that record is how we can show a breach report gets corrected when it is wrong. We do not need to keep who told us. Your name, email address and organisation are erased from the record after two years, which leaves the correction intact and removes you from it. The connection hash described in section 2.1 is erased after thirty days, since it exists only to rate limit the form. A nightly job does both.

8. How we protect it

Access to customer data is restricted at the database itself, so a request carrying the wrong credentials cannot read another organization's rows regardless of what the application asks for. Traffic is encrypted in transit. Passwords are hashed by our authentication provider and are never visible to us. Administrative access is limited to the people who need it.

No system is immune. If a breach of security safeguards creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as PIPEDA requires, keep a record of the breach as required, and meet the notification deadlines that apply in United States jurisdictions where affected people live.

9. Your rights in Canada

Under PIPEDA, and under provincial law including Quebec's Law 25 where it applies to you, you may:

  • ask what personal information we hold about you and how we have used and disclosed it;
  • ask us to correct it if it is wrong or incomplete;
  • withdraw consent, subject to legal and contractual limits;
  • ask for your information in a structured, commonly used technological format, where Law 25 gives you that right;
  • complain about how we have handled it.

We will respond within 30 days. If we cannot, we will tell you why and when we will. If you are not satisfied with our answer you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to your provincial regulator.

10. Your rights in the United States

Depending on where you live, state privacy law may give you the right to:

  • know what personal information we collect, the categories of source, the purpose, and the categories of third party we disclose it to;
  • obtain a copy of it, and have it transferred where technically feasible;
  • correct inaccurate information;
  • delete it, subject to the exceptions the law allows;
  • opt out of sale, of sharing for cross context behavioural advertising, and of profiling with legal or similarly significant effects;
  • limit the use of sensitive personal information.

We do not sell personal information, and we do not share it for cross context behavioural advertising. We have not done so in the preceding twelve months. There is therefore nothing to opt out of, and we provide no "Do Not Sell or Share My Personal Information" mechanism because it would have nothing to act on. If that ever changes, this notice will change first.

We will not discriminate against you for exercising any of these rights. An authorized agent may make a request on your behalf with written proof of authority. We may need to verify your identity before acting, which for account holders normally means a request from the address on the account.

To exercise a right, contact us at the address in section 11. If we refuse, you may appeal by replying to our decision, and in several states you may then complain to your state Attorney General.

11. Contacting us

Our privacy officer is responsible for our compliance with this notice and can be reached at:

Privacy Officer Enterprotect Inc. Unit 36, 3033 King George Blvd Surrey, British Columbia V4P 1B8 Canada [email protected]

12. Children

EnterProtect is sold to businesses. It is not directed at children, and we do not knowingly collect personal information from anyone under 13, or under 16 in jurisdictions that set the line there. If you believe a child has given us personal information, contact us and we will delete it.

13. Changes

We will post any change here and update the date at the top. If a change materially affects how we handle information we already hold, we will give notice by email to account holders before it takes effect.

Talk to us

Data protection and cybersecurity for MSPs. Recovery you can prove.