Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Last updated: July 31, 2026
The short version. This policy says what personal information TrazTech Inc. collects, why we collect it, how long we keep it, and who else touches it. We have listed the actual fields rather than writing "information such as".
Three groups are covered separately: people who visit the marketing site, people who use traztech Workspace, and people who fill in a vendor questionnaire because one of our users sent them a link. That third group matters, because for those answers our user is in charge of the data and we are only the processor.
We do not sell personal information, and we do not use customer data to train AI models. You can ask us what we hold, get a copy, correct it, or have it deleted, by emailing [email protected].
Cookies are covered separately on the Cookie Policy page.
TrazTech Inc. is a security and compliance firm incorporated in Ontario, Canada. We run the website at traztech.ca and traztech Workspace at traztech.ca/portal, and we deliver paid security and compliance services.
For personal information we decide the purposes of, TrazTech Inc. is the controller, or in Canadian terms the organisation accountable for it. Our privacy officer can be reached at:
Privacy Officer, TrazTech Inc.
145 1/2 Church Street, Unit 5, Office 876
Toronto, Ontario, M5B 1Y4
Canada
[email protected]
For personal information our customers put into their own workspace, they are the controller and we act on their instructions. Section 5 explains that split.
You can read traztech.ca without telling us who you are. If you interact with it, we collect what you give us.
Analytics run on the marketing site only. The Workspace at /portal carries no analytics tags and is excluded from search indexing.
When you create a workspace, this is what ends up in our database. It is worth reading properly, because a compliance workspace holds more about your organisation than a typical SaaS account does.
We do not use the contents of your workspace to train machine learning models, and we do not sell or rent it. See the AI Policy.
Evidence files and policy documents are stored outside the web root. They are never served as static files. Every download goes through an authenticated handler that checks your session and confirms the file belongs to your organisation before it releases a single byte.
Please upload only what a control genuinely needs. Redacted screenshots and extracts are usually enough, and are a better idea than uploading a production data export.
If you landed on a questionnaire link and have no idea who we are, this section is for you.
One of our customers is assessing you or your company as a vendor. They sent you a tokenised link to a questionnaire that runs on our platform. You do not have an account with us and you do not need one.
We collect your email address, your answers to the questionnaire, and basic delivery timestamps: when the questionnaire was sent, opened, and submitted. That data goes into the workspace of the customer who sent it.
They decide what to ask you, what to do with your answers, and how long to keep them. They are the controller. We are the processor, acting on their instructions. That means requests about your answers, including access, correction, and deletion, should go to the organisation that sent you the link. If you contact us instead, we will point you to them and help them respond, but we will not change or delete their records on our own initiative unless the law requires it.
Questionnaire links expire. If you were not expecting the request, or the link looks wrong, do not fill it in. Contact the company that says it sent it, and you are welcome to flag it to us at [email protected].
Under Canadian law our basis is your consent, express or implied by the circumstances, together with the exceptions PIPEDA allows for business contact information and for information needed to perform a transaction you asked for.
Where the GDPR or UK GDPR applies, we rely on:
Where we process a customer's workspace data on their instructions, the legal basis for that processing is theirs to establish.
We do not sell personal information and we do not share it for anyone else's advertising. We use a small set of service providers, and each of them only gets what they need:
Within your workspace, data is shared with the people you invite, at the role you gave them. Read-only auditors can see your assessments, evidence, policies, risks, and vendor records but cannot change anything. Where your workspace was created under a white-label partner, that partner's administrators can access it, because that is the relationship you have with them.
We will also disclose information where the law requires it, in response to a valid legal demand, or to protect our rights, our users, or the public from serious harm. If we are ever bought or merged, personal information transfers with the business and you will be told before it is used for a materially different purpose.
Our servers are in Canada. Some of our processors are American companies and may process data in the United States or elsewhere. That means foreign courts and law enforcement may in some cases be able to compel access to it under the law of that country.
Where personal information leaves the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses, the UK Addendum, and the adequacy decision Canada holds for commercial organisations under PIPEDA. Under PIPEDA and Quebec's Law 25, we remain accountable for personal information we transfer to a service provider, and we use contractual protections to keep it at a comparable level of protection.
No system is perfectly secure, and we will not claim otherwise. If a breach creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as PIPEDA requires, and meet the equivalent obligations under Quebec's Law 25 and the GDPR where they apply. To report a vulnerability, email [email protected].
Whoever you are and wherever you live, you can email [email protected] and ask what we hold about you, ask for a copy, ask us to fix it, or ask us to delete it. We answer within 30 days. We will ask you to verify your identity first, and we do not charge for a reasonable request.
If your request relates to data held inside a customer's workspace, including vendor questionnaire answers, we will forward it to that customer and support them in responding, because it is their record and their decision.
What we set, what third parties set, and how to turn it off is all on the Cookie Policy page. We keep it there rather than repeating it here, so there is one version to maintain and one version to be accurate.
We send marketing email only to people who asked for it or who contacted us about our services, which is what Canada's anti-spam legislation requires. Every marketing message carries an unsubscribe link and our mailing address, and unsubscribing takes effect immediately. Transactional email, such as sign-in links and service notices, is separate and continues while you have an account.
The Service is for businesses. It is not directed at children and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, email [email protected] and we will delete it.
We update this policy when what we do changes. The date at the top is always the current version. For a material change, we will notify account holders by email or by a notice in the platform before it takes effect. Please re-read it occasionally.
Start with us, at [email protected]. We would rather fix a problem than argue about it.
If you are not satisfied, you can complain to the Office of the Privacy Commissioner of Canada, 30 Victoria Street, Gatineau, Quebec, K1A 1H3, at priv.gc.ca or 1-800-282-1376. Quebec residents can complain to the Commission d'acces a l'information du Quebec. Residents of the EEA or the UK can complain to their national supervisory authority or to the Information Commissioner's Office.
Privacy requests and questions: [email protected].
Security reports: [email protected].
Everything else: [email protected] or the form at traztech.ca/contact.
Related reading: the Terms of Service, the Cookie Policy, the AI Policy, and what the traztech Workspace stores.