In short
The essentials of our policy in 6 points.
- We collect only the personal information necessary for the explicitly stated purposes (contact, downloaded resources, job applications, services).
- We never sell your personal information. It is only shared with our operational subcontractors (hosting provider, email, Microsoft cloud) under a confidentiality agreement.
- Your data is primarily hosted in the Canadian regions (Microsoft Azure Canada Central and Canada East).
- At any time you have a right of access, rectification, withdrawal of consent, portability and de-indexing.
- Our Privacy Officer responds to your requests within a maximum of 30 days.
- No decision affecting a person (hiring, services, pricing) is made by io4 Technologies on an exclusively automated basis.
1. Our commitment
io4 Technologies inc. (“io4”, “we”, “our”) places fundamental importance on protecting the privacy and confidentiality of the personal information entrusted to it.
This policy describes, in clear and accessible terms, how we collect, use, disclose, retain and protect your personal information when you interact with our website (www.io4tech.com), our consulting services, our communications or any other point of contact with io4.
This policy is written in accordance with Québec's Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1, hereinafter “Law 25”) and, where applicable, the Personal Information Protection and Electronic Documents Act (PIPEDA, S.C. 2000, c. 5).
2. Privacy Officer
In accordance with section 3.1 of Law 25, io4 Technologies inc. has designated a Privacy Officer (the person in charge of the protection of personal information), responsible for ensuring compliance with and the implementation of personal- information protection obligations.
To reach the Privacy Officer
- Name: Louis-Philippe Rousseau
- Role: Privacy Officer
- Email: info@io4tech.com
- Phone: 514-447-2851
- Email subject: “Privacy Officer - protection of personal information”
- Mailing address: io4 Technologies inc., attention of the Privacy Officer, 1010-666, Sherbrooke Ouest, Montréal, H3B 1E7
3. Scope
This policy applies to all personal information collected by io4 Technologies inc. in connection with:
- your browsing on the www.io4tech.com Site and its subdomains
- your use of the contact, assessment-request or booking forms
- your request to download a white paper, guide or resource
- your sign-up to a notification list (webinars, resources)
- your application to a position posted on the Careers page
- the delivery of Microsoft, Azure, Copilot or cybersecurity consulting services
- your exchanges by phone, email or in meetings with our experts
- your participation in an event, workshop or webinar organized by io4
It does not cover the privacy practices of third parties to which we may direct hyperlinks (partner sites, Microsoft documentation, press articles). We invite you to review their own policies.
4. Personal information collected
We limit collection to the personal information necessary for the purposes described in section 5. The following categories may be collected, depending on your interactions:
4.1 Identification and contact information
First name, last name, work email, phone number, role, organization name, organization size, industry, mailing address (where applicable).
4.2 Content of exchanges
Messages, requests, needs descriptions, meeting minutes, emails exchanged, documents voluntarily shared.
4.3 Application information
Résumé, cover letter, professional background, education, certifications, salary expectations where applicable, items submitted during a recruitment process.
4.4 Browsing and technical information
IP address (anonymized where possible), device type, browser type, operating system, pages visited, visit duration, referral source, browsing cookies (see section 16).
4.5 Professional information (clients and prospects)
Information about your technology environment voluntarily shared as part of a mandate (Microsoft 365 architecture, Azure, sector context) — strictly limited to what is necessary for delivering the services.
Sensitive information: we do not knowingly collect sensitive personal information within the meaning of Law 25 (health, racial origin, political opinions, biometric data, sexual orientation, convictions) through our Site. If you transmit such information to us on your own initiative, it receives enhanced protection and separate explicit consent will be requested.
5. Purposes of processing
Your personal information is processed only for specific, explicit and legitimate purposes:
5.1 Responding to your requests
Handling your contact, assessment or quote requests, or any question addressed to io4. Basis: performance of a pre-contractual or contractual step at your initiative.
5.2 Providing a requested resource
Giving you access to the white papers, guides, checklists or other resources you explicitly requested via a form. Basis: fulfilling your request.
5.3 Commercial and marketing communications
With your separate prior consent, sending you webinar invitations, blog publications, and news about our services. You can withdraw this consent at any time, free of charge. Basis: consent.
5.4 Delivering consulting services
Carrying out the mandates you entrust to us (Microsoft 365, Azure, Copilot, security, Law 25, etc.) and following up on them. Basis: performance of a contract.
5.5 Managing applications
Assessing your application for a position, contacting you as part of a recruitment process, and keeping your file for future opportunities with your consent. Basis: a step at your initiative + consent for extended retention.
5.6 Improving the Site and the user experience
Analyzing traffic statistics (in aggregated and anonymized form where possible) to improve the content and performance of the Site. Basis: legitimate interest, with minimization measures.
5.7 Security and incident prevention
Detecting and preventing attempts at fraud, intrusion, abuse or breach of the terms of use. Basis: legitimate interest and legal obligations.
5.8 Legal and regulatory compliance
Meeting our legal and tax obligations (invoicing, accounting retention, filings), and cooperating where applicable with the competent authorities (CAI, CRA, Revenu Québec, etc.).
Your information is never used for purposes incompatible with those for which it was collected without your prior consent, except as provided by law.
6. Consent
In accordance with Law 25, your consent to the collection and processing of your personal information is clear, free, informed and given for specific purposes. It is requested separately from any other information and on a granular basis for distinct purposes (for example, consent to receive marketing communications is separate from the consent needed to process a contact request).
You can withdraw your consent at any time, free of charge and without justification, by writing to our Privacy Officer. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal. Depending on the purpose, withdrawing consent may prevent us from continuing to provide you with certain services.
7. Recipients and subcontractors
Your personal information is accessible only to the people who need it for the stated purposes, following the principle of least privilege:
- Authorized personnel of io4 Technologies inc. (experts, executives, administrative team) bound by a contractual confidentiality obligation
- Technical subcontractors acting on behalf of io4, under a contract ensuring a level of protection equivalent to Law 25
- Competent public authorities where required by law (CAI, courts, tax authorities, law enforcement on a legal basis)
Main subcontractors:
| Subcontractor | Purpose | Location |
|---|---|---|
| Microsoft Corporation | Microsoft 365 and Azure hosting, internal productivity, business email, document management | Canada Central (Toronto) and Canada East (Québec City) by default. Azure France Central (Paris) available on request for European clients. |
Each subcontractor is bound to io4 by a written agreement governing confidentiality, security, retention period and the return or destruction of data at the end of the relationship.
We never sell or rent your personal information to third parties for commercial purposes.
8. Disclosure of information outside Québec (article 17)
In accordance with article 17 of Law 25, we inform you that some of your personal information may be disclosed or hosted outside Québec:
- Within Canada: primary hosting on Microsoft Azure Canada Central (Toronto, Ontario) and Canada East (Québec) infrastructure, along with the associated geo-redundant backup.
- In the United States: the Site's application hosting (Vercel), certain transactional email services and certain CRM modules may process data in the United States or through operators with U.S. facilities.
Before any disclosure outside Québec, io4 carries out a privacy impact assessment (PIA) that takes into account:
- the adequacy of the legal protection offered in the destination jurisdiction,
- the contractual measures imposed on the recipient (confidentiality clauses, audit, return, destruction),
- the technical measures in place (encryption at rest and in transit, access controls, logging, segmentation, data segregation),
- the sensitivity of the information disclosed and the purposes pursued.
Disclosure outside Québec is carried out only if the PIA concludes that protection is equivalent. To obtain the summary of a PIA on a specific processing activity, you may write to the Privacy Officer.
9. Automated decisions and artificial intelligence
In accordance with article 12.1 of Law 25 (in force since 22 September 2023), we inform you that:
- No decision concerning an identifiable person (hiring, evaluation, refusal of service, individualized pricing) is made by io4 Technologies on an exclusively automated basis. Any significant decision involves qualified human intervention.
- Our experts use artificial-intelligence tools (notably Microsoft 365 Copilot) for internal productivity — drafting, summarizing, document research. These uses never result in an automated decision concerning you.
- If, as part of a future mandate, io4 were to implement a system making decisions exclusively through automated processing about you, you would be informed beforehand and would have the right to request review of the decision by a natural person.
10. Retention period and destruction
We retain your personal information only for as long as necessary for the stated purposes, or for the minimum period required by law:
| Type of information | Retention period |
|---|---|
| Contact requests (prospects) | 24 months from the last exchange, unless a subsequent contractual relationship |
| Resource downloads (white papers) | 36 months from the download, unless marketing consent is withdrawn |
| Active client files | Duration of the mandate + 7 years (accounting and tax obligations under Québec's Taxation Act and Canada's Income Tax Act) |
| Successful applications | Duration of the employment relationship + applicable legal periods |
| Unsuccessful applications | 12 months, extendable with explicit consent (candidate pool) |
| Browsing cookies | See section 16 |
| Privacy incident register | 5 years from the date of the incident (legal obligation) |
At the end of the retention period, personal information is either securely destroyed (logical and physical deletion of the media) or irreversibly anonymized where it is retained in aggregate form for statistical purposes.
11. Security measures
io4 Technologies, as a Microsoft Solutions Partner specialized in cybersecurity, implements rigorous technical and organizational measures to protect your personal information against unauthorized access, loss, alteration or disclosure:
- Encryption of data at rest (AES-256) and in transit (TLS 1.2+)
- Mandatory multi-factor authentication for all access to systems containing personal information
- Access controls based on the principle of least privilege, reviewed quarterly
- Microsoft Defender XDR for incident detection and response (endpoint, identity, email)
- Microsoft Purview for classification, labeling and data-loss prevention (DLP)
- Conditional Access and Privileged Identity Management (PIM) for administrative accounts
- Centralized logging and retention of audit logs for a minimum of 12 months
- Encrypted geo-redundant backups in Canada
- Mandatory annual training in cybersecurity and personal-information protection for all staff
- A signed contractual confidentiality commitment from every employee and every subcontractor
- A documented privacy impact assessment (PIA) procedure for any new processing activity
- An incident response plan with a CAI and affected-individual notification procedure
Despite these measures, no information system can guarantee absolute security. In the event of an incident, we apply the procedure described in section 12.
12. Privacy incidents
Any privacy incident (unauthorized access, use, disclosure or loss of personal information) is recorded in an internal register kept by the Privacy Officer.
When an incident presents a risk that serious injury could be caused to the individuals concerned, io4 proceeds without delay to:
- notify the Commission d'accès à l'information (CAI);
- individually notify the affected individuals, except in exceptional circumstances;
- implement mitigation, remediation and prevention measures.
13. Your rights
Subject to the exceptions provided by law, you have the following rights regarding your personal information:
Right of access
Obtain confirmation that information about you is held and receive a copy of it.
Right of rectification
Have inaccurate, incomplete or ambiguous information corrected.
Right to withdraw consent
Withdraw at any time a previously given consent, free of charge and without justification.
Right to portability
Receive your computerized personal information in a structured, commonly used technological format, or request its direct transfer to a third party.
Right to de-indexing
Request that dissemination cease, or that information be de-indexed or re-indexed, where dissemination causes serious injury to your reputation or privacy.
Right to information on automated decisions
Know the main factors that led to an automated decision concerning you and request human review.
14. How to exercise your rights
To exercise one of these rights, send your written request to io4 Technologies inc.'s Privacy Officer:
- By email: info@io4tech.com (subject: “Privacy Officer - Law 25 rights request”)
- By mail: io4 Technologies inc., attention of the Privacy Officer, 1010-666, Sherbrooke Ouest, Montréal, H3B 1E7
To protect your personal information, we may ask you to confirm your identity before acting on your request (for example, by replying from the email address used at the time of collection).
We respond to your request within a maximum of 30 days of receiving it. If we cannot act on your request, we will explain the reasons and indicate the available remedies.
For the right to portability, the computerized information is provided to you in a structured, commonly used format (for example JSON or CSV), or can be transferred directly to a designated third party, subject to technical feasibility.
Exercising your rights is free of charge. However, if a request is manifestly abusive or repetitive, we may charge reasonable minimal fees or decline to act on it, explaining the reasons to you.
15. Recourse to the Commission d'accès à l'information
If you are not satisfied with how our Privacy Officer handled your request, or if you believe your rights have not been respected, you may file a complaint with the Commission d'accès à l'information du Québec (CAI):
Commission d'accès à l'information du Québec
- 2045 Stanley Street, Suite 900
- Montreal (Québec) H3A 2V4
- Phone: 1 888 528-7741
- Email: cai.communications@cai.gouv.qc.ca
- Website: www.cai.gouv.qc.ca
Where PIPEDA applies (interprovincial commercial activities), you may also contact the Office of the Privacy Commissioner of Canada (OPC): www.priv.gc.ca.
16. Cookies
The Site uses cookies and similar technologies to ensure it works properly, measure its audience and, if you consent, improve your experience.
In accordance with the CAI's position, non-essential cookies are disabled by default and are only activated after your explicit consent (opt-in). You can change your preferences at any time from the cookie management banner.
| Category | Purpose | Consent | Duration |
|---|---|---|---|
| Essential cookies | Security, session, load balancing, remembering your consent choice | Not required (necessary) | Session to 12 months |
| Audience measurement — Google Analytics 4 & Google Tag Manager | Aggregated traffic statistics (page views, referral source, visit duration), truncated IP address. Service provided by Google. | Opt-in | 13 months maximum |
| Preferences and improvement | Remembering your display and language preferences | Opt-in | 12 months |
Measurement tools and consent
To measure Site traffic, we use Google Analytics 4 and Google Tag Manager, services provided by Google LLC. We apply Google Consent Mode v2: by default, no measurement or advertising cookie is set. These cookies are only activated after your explicit consent (clicking “Accept all” in the banner). If you decline, no audience measurement is performed.
You can change or withdraw your choice at any time via the “Manage my cookies” link at the bottom of every page, which reopens the consent banner.
These tools may involve a transfer of data to the United States (Google's headquarters). This transfer is governed by appropriate safeguards (the European Commission's standard contractual clauses and Google's adherence to the EU–U.S. Data Privacy Framework). The IP address is truncated to limit identification.
You can also configure your browser to block or delete cookies, bearing in mind that this may affect how some parts of the Site work.
17. Information concerning minors
The Site and services of io4 Technologies inc. are intended for a professional audience (businesses, public bodies, nonprofits) and are not aimed at minors under 14 years of age.
We do not knowingly collect personal information concerning minors under 14. If you believe that a minor has provided us with personal information without the required authorization, please contact our Privacy Officer immediately so that we can delete it.
18. Policy updates
This policy may be amended to reflect changes in our practices, the technologies used or the applicable legal framework. The date of the last update appears at the top of this page.
In the event of a substantial change affecting your rights, we will inform you by an appropriate means (notice on the Site, email if you are subscribed to a list, a request for new consent where applicable) before the changes take effect.
We recommend that you review this page periodically.
19. Contact us
For any question, concern or request relating to this policy or the protection of your personal information:
io4 Technologies inc. - Privacy Officer
Email: info@io4tech.com
Phone: 514-447-2851
1010-666, Sherbrooke Ouest, Montréal, H3B 1E7

