io4 Technologies

Protection of personal information

Privacy policy.

How io4 Technologies inc. collects, uses, retains and protects your personal information, in accordance with Québec's Law 25, applicable Canadian laws and the General Data Protection Regulation (GDPR) for our French office in Lyon.

Effective date: September 22, 2024Last updated: May 17, 2026

In short

The essentials of our policy in 6 points.

  • We collect only the personal information necessary for the explicitly stated purposes (contact, downloaded resources, job applications, services).
  • We never sell your personal information. It is only shared with our operational subcontractors (hosting provider, email, Microsoft cloud) under a confidentiality agreement.
  • Your data is primarily hosted in the Canadian regions (Microsoft Azure Canada Central and Canada East).
  • At any time you have a right of access, rectification, withdrawal of consent, portability and de-indexing.
  • Our Privacy Officer responds to your requests within a maximum of 30 days.
  • No decision affecting a person (hiring, services, pricing) is made by io4 Technologies on an exclusively automated basis.

1. Our commitment

io4 Technologies inc. (“io4”, “we”, “our”) places fundamental importance on protecting the privacy and confidentiality of the personal information entrusted to it.

This policy describes, in clear and accessible terms, how we collect, use, disclose, retain and protect your personal information when you interact with our website (www.io4tech.com), our consulting services, our communications or any other point of contact with io4.

This policy is written in accordance with Québec's Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1, hereinafter “Law 25”) and, where applicable, the Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5).

2. Privacy Officer

In accordance with section 3.1 of Law 25, io4 Technologies inc. has designated a Privacy Officer (the person in charge of the protection of personal information), responsible for ensuring compliance with and the implementation of personal- information protection obligations.

To reach the Privacy Officer

  • Name: Louis-Philippe Rousseau
  • Role: Privacy Officer
  • Email: info@io4tech.com
  • Phone: 514-447-2851
  • Email subject: “Privacy Officer - protection of personal information”
  • Mailing address: io4 Technologies inc., attention of the Privacy Officer, 1010-666, Sherbrooke Ouest, Montréal, H3B 1E7

3. Scope

This policy applies to all personal information collected by io4 Technologies inc. in connection with:

  • your browsing on the www.io4tech.com Site and its subdomains
  • your use of the contact, assessment-request or booking forms
  • your request to download a white paper, guide or resource
  • your sign-up to a notification list (webinars, resources)
  • your application to a position posted on the Careers page
  • the delivery of Microsoft, Azure, Copilot or cybersecurity consulting services
  • your exchanges by phone, email or in meetings with our experts
  • your participation in an event, workshop or webinar organized by io4

It does not cover the privacy practices of third parties to which we may direct hyperlinks (partner sites, Microsoft documentation, press articles). We invite you to review their own policies.

4. Personal information collected

We limit collection to the personal information necessary for the purposes described in section 5. The following categories may be collected, depending on your interactions:

4.1 Identification and contact information

First name, last name, work email, phone number, role, organization name, organization size, industry, mailing address (where applicable).

4.2 Content of exchanges

Messages, requests, needs descriptions, meeting minutes, emails exchanged, documents voluntarily shared.

4.3 Application information

Résumé, cover letter, professional background, education, certifications, salary expectations where applicable, items submitted during a recruitment process.

4.4 Browsing and technical information

IP address (anonymized where possible), device type, browser type, operating system, pages visited, visit duration, referral source, browsing cookies (see section 16).

4.5 Professional information (clients and prospects)

Information about your technology environment voluntarily shared as part of a mandate (Microsoft 365 architecture, Azure, sector context) — strictly limited to what is necessary for delivering the services.

Sensitive information: we do not knowingly collect sensitive personal information within the meaning of Law 25 (health, racial origin, political opinions, biometric data, sexual orientation, convictions) through our Site. If you transmit such information to us on your own initiative, it receives enhanced protection and separate explicit consent will be requested.

5. Purposes of processing

Your personal information is processed only for specific, explicit and legitimate purposes:

5.1 Responding to your requests

Handling your contact, assessment or quote requests, or any question addressed to io4. Basis: performance of a pre-contractual or contractual step at your initiative.

5.2 Providing a requested resource

Giving you access to the white papers, guides, checklists or other resources you explicitly requested via a form. Basis: fulfilling your request.

5.3 Commercial and marketing communications

With your separate prior consent, sending you webinar invitations, blog publications, and news about our services. You can withdraw this consent at any time, free of charge. Basis: consent.

5.4 Delivering consulting services

Carrying out the mandates you entrust to us (Microsoft 365, Azure, Copilot, security, Law 25, etc.) and following up on them. Basis: performance of a contract.

5.5 Managing applications

Assessing your application for a position, contacting you as part of a recruitment process, and keeping your file for future opportunities with your consent. Basis: a step at your initiative + consent for extended retention.

5.6 Improving the Site and the user experience

Analyzing traffic statistics (in aggregated and anonymized form where possible) to improve the content and performance of the Site. Basis: legitimate interest, with minimization measures.

5.7 Security and incident prevention

Detecting and preventing attempts at fraud, intrusion, abuse or breach of the terms of use. Basis: legitimate interest and legal obligations.

5.8 Legal and regulatory compliance

Meeting our legal and tax obligations (invoicing, accounting retention, filings), and cooperating where applicable with the competent authorities (CAI, CRA, Revenu Québec, etc.).

Your information is never used for purposes incompatible with those for which it was collected without your prior consent, except as provided by law.

6. Consent

In accordance with Law 25, your consent to the collection and processing of your personal information is clear, free, informed and given for specific purposes. It is requested separately from any other information and on a granular basis for distinct purposes (for example, consent to receive marketing communications is separate from the consent needed to process a contact request).

You can withdraw your consent at any time, free of charge and without justification, by writing to our Privacy Officer. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal. Depending on the purpose, withdrawing consent may prevent us from continuing to provide you with certain services.

7. Recipients and subcontractors

Your personal information is accessible only to the people who need it for the stated purposes, following the principle of least privilege:

  • Authorized personnel of io4 Technologies inc. (experts, executives, administrative team) bound by a contractual confidentiality obligation
  • Technical subcontractors acting on behalf of io4, under a contract ensuring a level of protection equivalent to Law 25
  • Competent public authorities where required by law (CAI, courts, tax authorities, law enforcement on a legal basis)

Main subcontractors:

SubcontractorPurposeLocation
Microsoft CorporationMicrosoft 365 and Azure hosting, internal productivity, business email, document managementCanada Central (Toronto) and Canada East (Québec City) by default. Azure France Central (Paris) available on request for European clients.

Each subcontractor is bound to io4 by a written agreement governing confidentiality, security, retention period and the return or destruction of data at the end of the relationship.

We never sell or rent your personal information to third parties for commercial purposes.

8. Disclosure of information outside Québec (article 17)

In accordance with article 17 of Law 25, we inform you that some of your personal information may be disclosed or hosted outside Québec:

  • Within Canada: primary hosting on Microsoft Azure Canada Central (Toronto, Ontario) and Canada East (Québec) infrastructure, along with the associated geo-redundant backup.
  • In the United States: the Site's application hosting (Vercel), certain transactional email services and certain CRM modules may process data in the United States or through operators with U.S. facilities.

Before any disclosure outside Québec, io4 carries out a privacy impact assessment (PIA) that takes into account:

  • the adequacy of the legal protection offered in the destination jurisdiction,
  • the contractual measures imposed on the recipient (confidentiality clauses, audit, return, destruction),
  • the technical measures in place (encryption at rest and in transit, access controls, logging, segmentation, data segregation),
  • the sensitivity of the information disclosed and the purposes pursued.

Disclosure outside Québec is carried out only if the PIA concludes that protection is equivalent. To obtain the summary of a PIA on a specific processing activity, you may write to the Privacy Officer.

9. Automated decisions and artificial intelligence

In accordance with article 12.1 of Law 25 (in force since 22 September 2023), we inform you that:

  • No decision concerning an identifiable person (hiring, evaluation, refusal of service, individualized pricing) is made by io4 Technologies on an exclusively automated basis. Any significant decision involves qualified human intervention.
  • Our experts use artificial-intelligence tools (notably Microsoft 365 Copilot) for internal productivity — drafting, summarizing, document research. These uses never result in an automated decision concerning you.
  • If, as part of a future mandate, io4 were to implement a system making decisions exclusively through automated processing about you, you would be informed beforehand and would have the right to request review of the decision by a natural person.

10. Retention period and destruction

We retain your personal information only for as long as necessary for the stated purposes, or for the minimum period required by law:

Type of informationRetention period
Contact requests (prospects)24 months from the last exchange, unless a subsequent contractual relationship
Resource downloads (white papers)36 months from the download, unless marketing consent is withdrawn
Active client filesDuration of the mandate + 7 years (accounting and tax obligations under Québec's Taxation Act and Canada's Income Tax Act)
Successful applicationsDuration of the employment relationship + applicable legal periods
Unsuccessful applications12 months, extendable with explicit consent (candidate pool)
Browsing cookiesSee section 16
Privacy incident register5 years from the date of the incident (legal obligation)

At the end of the retention period, personal information is either securely destroyed (logical and physical deletion of the media) or irreversibly anonymized where it is retained in aggregate form for statistical purposes.

11. Security measures

io4 Technologies, as a Microsoft Solutions Partner specialized in cybersecurity, implements rigorous technical and organizational measures to protect your personal information against unauthorized access, loss, alteration or disclosure:

  • Encryption of data at rest (AES-256) and in transit (TLS 1.2+)
  • Mandatory multi-factor authentication for all access to systems containing personal information
  • Access controls based on the principle of least privilege, reviewed quarterly
  • Microsoft Defender XDR for incident detection and response (endpoint, identity, email)
  • Microsoft Purview for classification, labeling and data-loss prevention (DLP)
  • Conditional Access and Privileged Identity Management (PIM) for administrative accounts
  • Centralized logging and retention of audit logs for a minimum of 12 months
  • Encrypted geo-redundant backups in Canada
  • Mandatory annual training in cybersecurity and personal-information protection for all staff
  • A signed contractual confidentiality commitment from every employee and every subcontractor
  • A documented privacy impact assessment (PIA) procedure for any new processing activity
  • An incident response plan with a CAI and affected-individual notification procedure

Despite these measures, no information system can guarantee absolute security. In the event of an incident, we apply the procedure described in section 12.

12. Privacy incidents

Any privacy incident (unauthorized access, use, disclosure or loss of personal information) is recorded in an internal register kept by the Privacy Officer.

When an incident presents a risk that serious injury could be caused to the individuals concerned, io4 proceeds without delay to:

  • notify the Commission d'accès à l'information (CAI);
  • individually notify the affected individuals, except in exceptional circumstances;
  • implement mitigation, remediation and prevention measures.

13. Your rights

Subject to the exceptions provided by law, you have the following rights regarding your personal information:

Right of access

Obtain confirmation that information about you is held and receive a copy of it.

Right of rectification

Have inaccurate, incomplete or ambiguous information corrected.

Right to withdraw consent

Withdraw at any time a previously given consent, free of charge and without justification.

Right to portability

Receive your computerized personal information in a structured, commonly used technological format, or request its direct transfer to a third party.

Right to de-indexing

Request that dissemination cease, or that information be de-indexed or re-indexed, where dissemination causes serious injury to your reputation or privacy.

Right to information on automated decisions

Know the main factors that led to an automated decision concerning you and request human review.

14. How to exercise your rights

To exercise one of these rights, send your written request to io4 Technologies inc.'s Privacy Officer:

  • By email: info@io4tech.com (subject: “Privacy Officer - Law 25 rights request”)
  • By mail: io4 Technologies inc., attention of the Privacy Officer, 1010-666, Sherbrooke Ouest, Montréal, H3B 1E7

To protect your personal information, we may ask you to confirm your identity before acting on your request (for example, by replying from the email address used at the time of collection).

We respond to your request within a maximum of 30 days of receiving it. If we cannot act on your request, we will explain the reasons and indicate the available remedies.

For the right to portability, the computerized information is provided to you in a structured, commonly used format (for example JSON or CSV), or can be transferred directly to a designated third party, subject to technical feasibility.

Exercising your rights is free of charge. However, if a request is manifestly abusive or repetitive, we may charge reasonable minimal fees or decline to act on it, explaining the reasons to you.

15. Recourse to the Commission d'accès à l'information

If you are not satisfied with how our Privacy Officer handled your request, or if you believe your rights have not been respected, you may file a complaint with the Commission d'accès à l'information du Québec (CAI):

Commission d'accès à l'information du Québec

Where PIPEDA applies (interprovincial commercial activities), you may also contact the Office of the Privacy Commissioner of Canada (OPC): www.priv.gc.ca.

16. Cookies

The Site uses cookies and similar technologies to ensure it works properly, measure its audience and, if you consent, improve your experience.

In accordance with the CAI's position, non-essential cookies are disabled by default and are only activated after your explicit consent (opt-in). You can change your preferences at any time from the cookie management banner.

CategoryPurposeConsentDuration
Essential cookiesSecurity, session, load balancing, remembering your consent choiceNot required (necessary)Session to 12 months
Audience measurement — Google Analytics 4 & Google Tag ManagerAggregated traffic statistics (page views, referral source, visit duration), truncated IP address. Service provided by Google.Opt-in13 months maximum
Preferences and improvementRemembering your display and language preferencesOpt-in12 months

Measurement tools and consent

To measure Site traffic, we use Google Analytics 4 and Google Tag Manager, services provided by Google LLC. We apply Google Consent Mode v2: by default, no measurement or advertising cookie is set. These cookies are only activated after your explicit consent (clicking “Accept all” in the banner). If you decline, no audience measurement is performed.

You can change or withdraw your choice at any time via the “Manage my cookies” link at the bottom of every page, which reopens the consent banner.

These tools may involve a transfer of data to the United States (Google's headquarters). This transfer is governed by appropriate safeguards (the European Commission's standard contractual clauses and Google's adherence to the EU–U.S. Data Privacy Framework). The IP address is truncated to limit identification.

You can also configure your browser to block or delete cookies, bearing in mind that this may affect how some parts of the Site work.

17. Information concerning minors

The Site and services of io4 Technologies inc. are intended for a professional audience (businesses, public bodies, nonprofits) and are not aimed at minors under 14 years of age.

We do not knowingly collect personal information concerning minors under 14. If you believe that a minor has provided us with personal information without the required authorization, please contact our Privacy Officer immediately so that we can delete it.

18. Policy updates

This policy may be amended to reflect changes in our practices, the technologies used or the applicable legal framework. The date of the last update appears at the top of this page.

In the event of a substantial change affecting your rights, we will inform you by an appropriate means (notice on the Site, email if you are subscribed to a list, a request for new consent where applicable) before the changes take effect.

We recommend that you review this page periodically.

19. Contact us

For any question, concern or request relating to this policy or the protection of your personal information:

io4 Technologies inc. - Privacy Officer

Email: info@io4tech.com

Phone: 514-447-2851

1010-666, Sherbrooke Ouest, Montréal, H3B 1E7

This policy is written in French. An English version may be available as a courtesy. In accordance with Québec's Charter of the French Language, the French version prevails.
Let's talk about your project

30 minutes to frame what matters.

A direct conversation with one of our experts. No commitment, no sales pitch. You leave with a clear, reasoned perspective on your situation.

Or call us directly:514-447-2851