NVTek

Privacy Policy

Effective date: September 3, 2026  ·  Applies to the website nvtek.ca and the NVTek Outreach application

1. Who we are

NVTek provides fractional IT leadership and vCIO services to small and mid-sized businesses in Ontario, Canada. NVTek is a registered business name in Ontario, Canada.

Mailing address: 18 King Street East, Suite 1400, Toronto, ON M5C 1C4, Canada
Privacy contact: privacy@nvtek.ca

This policy explains what personal information we collect, why, how it is used and protected, and the choices available to you. It is written to comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada's Anti-Spam Legislation (CASL), and with the Google API Services User Data Policy for the Google user data described in section 3.

2. This website

The nvtek.ca website is a static informational site. It has no user accounts, no login, and no forms. Contact links on the site open your own email or phone application; nothing you type is transmitted to us until you choose to send a message.

The website uses the following third-party services, each of which receives your IP address and standard browser information when a page loads:

We do not use advertising cookies, retargeting, or any other tracking on this site.

3. The NVTek Outreach application and Google user data

What the application is

"NVTek Outreach" is an internal software tool built and used by NVTek to run its own business-development email. It sends a small number of business emails per day from NVTek's own Google Workspace mailboxes on the connect.nvtek.ca subdomain, through the Gmail API, and checks whether those emails received a reply. It is not offered to the public, has no customers or end users other than NVTek, and is never connected to anyone else's Google account.

Which Google user data it accesses

The application requests exactly two Gmail API scopes, and only for NVTek's own mailbox:

The application does not read the body of any email, does not access contacts, calendar, Drive or any other Google service, and does not access, and cannot access, the Google account or mailbox of any third party. The only Google account it is ever authorised against is NVTek's own.

How that data is used

Google user data is not used for advertising, is not sold, is not shared with any third party, and is not used to train or improve any machine-learning or artificial-intelligence model. No person other than NVTek's operator has access to it.

Where it is stored

The OAuth credential that authorises the application, and the reply metadata it records (sender address, time detected, and a short text snippet of the reply), are stored on a server operated by NVTek, with access restricted to NVTek's operator. That server is a virtual machine hosted by DigitalOcean, LLC in its Toronto, Canada data centre, so this data stays in Canada. It is not stored with or transmitted to any third-party service other than Google itself.

How to revoke access

Because the application only ever connects to NVTek's own mailbox, no third party needs to revoke anything. For completeness: access granted to any Google application can be withdrawn at any time from your Google Account under Security → Third-party access (also labelled "Third-party apps & services"), which immediately invalidates the application's credential.

Limited Use disclosure. NVTek's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Information about the people we contact

What we hold

For the business contacts NVTek reaches out to, we hold: name, job title, company name, company website, and work email address; the public web page where that email address was published (recorded as a link and a screenshot, as our CASL evidence); notes and a short reply snippet if the person replies; and, for some companies, observations about the company's public-facing email and website configuration drawn only from publicly available DNS and web data.

Where it comes from

Why we are allowed to contact you

We send commercial electronic messages only where we have a lawful basis under CASL. In almost all cases this is implied consent through conspicuous publication (CASL s. 10(9)(b)): your business email address was published by you or your organisation without a statement that unsolicited commercial messages are unwelcome, and our message is relevant to your business role. We record the source of the publication for every address before sending. Every email identifies NVTek, includes our mailing address, and includes a working unsubscribe mechanism.

Unsubscribe

Reply to any NVTek email with the word "unsubscribe", or write to privacy@nvtek.ca. We add your address to our suppression list and stop all further email. CASL allows up to 10 business days to act on an unsubscribe request; in practice we process requests the same day. Addresses on the suppression list are kept indefinitely so that we never contact them again.

We do not sell contact information and do not share it with third parties, other than the service providers in section 5 who process it on our behalf.

5. Service providers

The following providers process data on NVTek's behalf, each only for the purpose stated:

6. Retention

7. Your rights and how to reach us

Under PIPEDA you may ask what personal information we hold about you, ask us to correct it, or ask us to delete it, and you may withdraw consent to further contact at any time. Write to privacy@nvtek.ca or to the mailing address in section 1. We respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada.

8. Changes to this policy

We will post any changes on this page and update the effective date above. Material changes to how the NVTek Outreach application uses Google user data will be reflected here before they take effect.

Terms of Service  ·  Back to home