Privacy Policy
Last Updated: August 2024
Introduction
Cor Astra Ltd. (referred to as CorAstra, we, us, or our throughout this document) is committed to protecting the privacy and security of every individual who interacts with our website, products, and services. This Privacy Policy explains in clear and transparent terms how we handle personal information, what data we collect, the purposes for which we use it, and the rights that you hold over your information.
This website is owned and operated by the development team behind CorAstra, a brand that represents excellence in computer systems design and integrated technology solutions. Our organization is headquartered at 411-1029 King Street West, Toronto, ON M6K 3M9, Canada. We operate within the Computer Systems Design and Related Services industry, which falls under the broader Professional, Scientific, and Technical Services sector. As a company that handles technical data and client information daily, we understand that privacy is not merely a compliance obligation but a fundamental pillar of trust between us and the people we serve.
By accessing or using the CorAstra website at https://www.corastra.buzz, or by engaging with any of our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any portion of this policy, you should discontinue use of our website and services immediately. We encourage you to review this document periodically, as it may be updated from time to time to reflect changes in our practices, legal requirements, or the operational landscape in which we function.
Scope of This Policy
This Privacy Policy applies to all personal information collected through the CorAstra website, any related subdomains, mobile applications, application programming interfaces (APIs), email communications, and all other interactions in which you engage with Cor Astra Ltd. in a digital context. It covers data collected from visitors to our website, prospective clients who submit inquiries, current clients who use our technology services, job applicants who apply through our careers portal, and any other individual whose personal information may come into our possession through the ordinary course of business operations.
This policy does not apply to information that is anonymized, aggregated, or otherwise rendered non-identifiable through processes that prevent re-identification. It also does not govern the practices of third-party websites, applications, or services that may be linked from our website, even if those links are provided as a convenience. We encourage you to review the privacy policies of any third-party services before providing them with your information. Additionally, this policy does not cover data processed by our clients in the course of using our systems design and integration services; for such data, we act as a data processor and follow the instructions of the respective client who serves as the data controller.
Information We Collect
We collect several categories of information to provide, maintain, and improve our services, to communicate with you effectively, and to meet our legal and regulatory obligations. The specific categories of personal information that we may collect include, but are not limited to, the following:
Identity and Contact Information: This includes your full name, email address, telephone number, company name, job title, physical mailing address, and any other contact details you voluntarily provide when you fill out a form on our website, subscribe to updates, request a consultation, or otherwise correspond with us.
Technical and Usage Information: When you visit our website, our servers automatically collect certain technical data including your Internet Protocol (IP) address, browser type and version, operating system, device type, referring website URLs, pages viewed, time and date of your visit, time spent on each page, and other diagnostic data. This information helps us understand how visitors interact with our website so we can improve its performance, security, and usability.
Communication Records: If you contact us by email, telephone, or through our website contact form, we retain copies of that correspondence, including the content of your messages and our responses. We do this to maintain accurate records of our interactions and to provide consistent and informed support across multiple touchpoints over time.
Business Information: In the course of providing our computer systems design and consulting services, we may collect information about your business operations, technology infrastructure, project requirements, strategic priorities, and other data necessary to deliver the professional services you have engaged us to perform.
Marketing and Preference Data: We collect information about your marketing preferences, including whether you have opted in or out of receiving promotional communications, your communication channel preferences, and any feedback or survey responses you choose to provide.
How We Collect Information
We obtain personal information through a variety of methods, each designed to be transparent and consistent with the expectations of a reasonable person in a professional technology services context. The primary collection methods are described below.
Direct Collection from You: The majority of the personal information we hold is collected directly from you when you voluntarily provide it. This occurs when you complete a contact form on our website, send us an email to chat@corastra.buzz, speak with one of our team members by telephone at +15096947082, register for an account or service, respond to a survey, submit a job application, or participate in a consultation or project kickoff meeting.
Automatic Collection Through Technology: As is standard practice across the internet, our website automatically collects certain technical information through server logs, cookies, web beacons, and similar technologies. This information is essential for the proper functioning and security of our digital platforms, and it enables us to deliver a reliable and performant browsing experience to every visitor.
Collection from Third Parties: In limited circumstances, we may receive personal information about you from third-party sources. These include publicly available databases, business partners, analytics providers, social media platforms where you have chosen to interact with our brand, and professional networking services. In all such cases, we take reasonable steps to verify that the third party has obtained the information lawfully and has the right to share it with us.
Collection in the Course of Service Delivery: When we engage with a client to provide systems design, integration, or consulting services, we necessarily receive technical and operational information about the infrastructure of the client. This information is handled strictly in accordance with the terms of our service agreement and any applicable data processing addenda.
How We Use Your Information
We use the personal information we collect for purposes that are directly connected to our business operations and the services we provide. We do not use your information for purposes that are incompatible with those described in this policy without first providing notice and, where required by law, obtaining your consent. The specific purposes for which we use your information include:
Service Delivery and Fulfillment: We use your information to provide the products, services, and support you have requested from us. This includes designing and delivering computer systems solutions, managing ongoing client relationships, processing transactions, providing technical support, and communicating with you about your projects, timelines, and deliverables.
Communication and Customer Support: We use your contact information to respond to your inquiries, provide you with information you have requested, send administrative notifications about your account or our services, and deliver important security alerts and updates. We strive to keep these communications relevant, timely, and proportionate to your needs and expectations.
Website Improvement and Personalization: The technical and usage data we collect helps us understand how visitors navigate our website, which pages are most useful, and where improvements are needed. We use this insight to optimize site performance, enhance navigation, and personalize the browsing experience based on aggregate usage patterns.
Marketing and Promotional Activities: With your consent where required by law, we may use your contact information to send you newsletters, promotional materials, event invitations, and information about new services or features that we believe may be relevant to your interests. You may opt out of marketing communications at any time by using the unsubscribe link provided in each message or by contacting us directly.
Legal Compliance and Protection: We use and retain information as necessary to comply with applicable laws, regulations, legal processes, and enforceable governmental requests. We also use information to enforce our Terms of Service, investigate potential violations, detect and prevent fraud or security incidents, and protect the rights, property, and safety of Cor Astra Ltd., our clients, and the public.
Legal Bases for Processing
For individuals located in jurisdictions that require a specified legal basis for the processing of personal information (including the European Economic Area, the United Kingdom, and certain other regions), we rely on the following legal grounds:
Contractual Necessity: We process personal information where it is necessary for the performance of a contract with you, or to take steps at your request prior to entering into a contract. This applies to most of our service delivery and client relationship management activities.
Legitimate Interests: We process personal information where we have a legitimate business interest that is not overridden by your data protection rights. Our legitimate interests include improving our services, ensuring the security of our systems, conducting business analytics, marketing our services to prospective clients, and preventing fraud. We carefully balance our interests against your rights and freedoms before relying on this basis.
Consent: Where we rely on your consent as a legal basis, such as for certain marketing activities or the use of non-essential cookies, we will clearly request your consent and provide you with the ability to withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Legal Obligation: We process personal information where necessary to comply with applicable laws, regulations, court orders, or other legal mandates to which Cor Astra Ltd. is subject.
Sharing and Disclosure of Information
We do not sell, rent, or trade your personal information to third parties for their own marketing purposes. We may share your information only in the limited circumstances described below, and always subject to appropriate contractual and security safeguards.
Service Providers and Partners: We engage carefully selected third-party companies and individuals to perform certain business functions on our behalf. These may include website hosting providers, email delivery services, analytics platforms, cloud infrastructure providers, payment processors, and professional advisors such as lawyers and accountants. These service providers are contractually bound to process personal information only on our documented instructions and to implement appropriate technical and organizational measures to protect the data entrusted to them.
Legal and Regulatory Disclosures: We may disclose personal information if we determine in good faith that such disclosure is reasonably necessary to comply with a legal obligation, respond to a valid legal request from a competent authority, protect the rights or property of Cor Astra Ltd., prevent or investigate possible wrongdoing in connection with our services, protect the personal safety of our users or the public, or defend against legal claims.
Business Transfers: If Cor Astra Ltd. is involved in a merger, acquisition, reorganization, sale of assets, or similar corporate transaction, personal information may be transferred as part of that transaction. We will notify you before your personal information becomes subject to a different privacy policy as a result of such a transfer.
With Your Consent: We may share your personal information for any other purpose disclosed to you at the point of collection, provided we have obtained your explicit consent to do so.
Data Retention Practices
We retain personal information only for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable laws and regulations. Our retention periods are determined by considering the nature and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process the information, and whether those purposes can be achieved through other means, and the applicable legal, regulatory, accounting, or reporting requirements that apply to our operations.
In general, we retain contact and communication information for the duration of our business relationship with you and for a reasonable period thereafter to respond to any follow-up inquiries. Technical usage data is typically retained for a shorter period and is regularly purged from our systems. Information related to financial transactions is retained in accordance with applicable tax and accounting laws, which in Canada generally require retention for a period of at least seven years following the relevant tax year.
When personal information is no longer needed for the purposes described in this policy, we take reasonable steps to securely delete, destroy, or anonymize it. In some cases, residual copies may persist in our backup systems for a limited additional period, during which they remain subject to the same security protections as our active data stores.
Data Security Measures
Protecting the confidentiality, integrity, and availability of your personal information is a responsibility we take seriously. We implement and maintain a comprehensive set of administrative, technical, and physical safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Our technical security measures include industry-standard encryption of data in transit using Transport Layer Security (TLS) protocols, encryption of sensitive data at rest, multi-factor authentication for administrative access to our systems, regular vulnerability scanning and penetration testing, network segmentation and firewall protection, intrusion detection and prevention systems, and continuous security monitoring and logging.
Our organizational measures include comprehensive data protection policies and procedures, regular privacy and security training for all personnel, role-based access controls that limit data access to those with a legitimate business need, confidentiality agreements with all employees and contractors, and an incident response plan that ensures prompt detection, containment, and notification of any data security breach in accordance with applicable legal requirements.
While we implement robust security measures, no method of electronic transmission or storage is one hundred percent secure. We cannot guarantee absolute security, but we continuously monitor and improve our defenses to address evolving threats. If you have reason to believe that your interaction with us is no longer secure, please notify us immediately using the contact information provided in this policy.
Your Rights and Choices
We respect your rights regarding your personal information and provide you with meaningful choices and mechanisms to exercise those rights. Depending on your jurisdiction of residence, you may have some or all of the following rights:
Right to Access: You have the right to request confirmation of whether we are processing your personal information and, if so, to obtain a copy of that information along with details about how it is being used.
Right to Rectification: You have the right to request that we correct any inaccurate or incomplete personal information we hold about you. We encourage you to keep your information up to date so we can serve you most effectively.
Right to Erasure: In certain circumstances, you have the right to request that we delete your personal information from our systems. This right is not absolute and may be limited by our legal obligations or legitimate business needs to retain certain data.
Right to Restrict Processing: Under certain conditions, you may request that we limit the ways in which we process your personal information, such as while we verify the accuracy of data you have contested.
Right to Data Portability: Where processing is based on consent or contract and carried out by automated means, you may request that we provide your personal information to you or to another data controller in a structured, commonly used, and machine-readable format.
Right to Object: You have the right to object to processing of your personal information based on our legitimate interests or for direct marketing purposes. We will honor object-based requests to cease direct marketing without undue delay.
Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted before the withdrawal took effect.
To exercise any of these rights, please contact us using the email address or phone number provided in the Contact section of this policy. We will respond to your request within the timeframe required by applicable law. We may need to verify your identity before processing your request, and we reserve the right to decline requests that are manifestly unfounded, excessive, or repetitive.
Privacy for Children
Our website and services are not directed at or intended for individuals under the age of eighteen. We do not knowingly collect, use, or disclose personal information from anyone under the age of eighteen without verifiable parental consent. If we become aware that we have inadvertently collected personal information from a child under the age of eighteen without appropriate consent, we will take prompt and diligent steps to delete such information from our records.
If you are a parent or legal guardian and you believe that your child has provided personal information to us without your authorization, please contact us immediately using the contact details provided in this policy. We will investigate the matter and take all necessary corrective actions, including the removal of the relevant data from our systems. We encourage parents and guardians to monitor and supervise the online activities of the minors in their care and to educate them about the importance of protecting personal information online.
International Data Transfers
Cor Astra Ltd. is headquartered in Canada, and our primary data processing activities occur within Canadian territory. However, as a provider of technology services that may involve cloud-based infrastructure and global service delivery, we may transfer, store, or process your personal information in countries other than your country of residence, including countries that may have data protection laws different from those in your jurisdiction.
When we transfer personal information across international borders, we implement appropriate safeguards to ensure that the data receives a level of protection consistent with this Privacy Policy and applicable law. These safeguards may include transferring data only to countries that have been recognized as providing an adequate level of data protection, using contractual clauses that have been approved by relevant regulatory authorities, and implementing supplementary technical and organizational measures where necessary to ensure compliance with international data transfer requirements.
By using our website and services, you understand that your personal information may be transferred to and processed in countries outside your country of residence. We take all commercially reasonable steps to ensure that your data is treated securely and in accordance with this policy, regardless of the jurisdiction in which it is processed.
Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, understand user behavior, and improve our services. A cookie is a small text file that is placed on your device when you visit a website; it allows the website to recognize your browser on subsequent visits and to remember certain preferences and settings.
We use essential cookies that are strictly necessary for the operation of our website, including those that enable core functionality such as security features, session management, and accessibility settings. These cookies do not require your consent under most data protection frameworks. We may also use performance and analytics cookies that help us understand how visitors interact with our website, including which pages are most frequently visited and how users navigate between them. If and when we deploy non-essential cookies, we will provide you with a cookie consent mechanism and the ability to manage your preferences.
You can control cookies through your browser settings at any time. Most browsers allow you to refuse cookies, delete existing cookies, or alert you when a website attempts to place a cookie on your device. Please note that disabling certain cookies may affect the functionality and performance of our website, and some features may not be available to you.
Third-Party Services and Links
Our website may contain links to external websites, services, or applications that are not operated by Cor Astra Ltd. This Privacy Policy does not apply to those third-party properties. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services. The inclusion of any link on our website does not imply our endorsement of the linked site or its operators.
We strongly encourage you to review the privacy policies of every website you visit, particularly those to which you are directed from our website. If you choose to interact with a third-party service that is integrated with or linked from our website, the information you share with that third party will be governed by its own privacy policy, not by this document.
In the course of delivering our computer systems design and integration services, we may also interact with third-party platforms, tools, and vendors selected by our clients. In those contexts, the privacy practices and data handling policies of those platforms apply to the data processed through them. We work with our clients to ensure that their chosen third-party services align with their own privacy commitments and regulatory obligations.
Changes to This Privacy Policy
We reserve the right to update, modify, or replace this Privacy Policy at any time and at our sole discretion. Changes may be prompted by developments in our business operations, changes in applicable laws or regulations, feedback from regulators or privacy advocates, or the evolving expectations of the communities we serve. When we make material changes to this policy, we will post the updated version on this page and update the effective date at the top of the document.
For significant changes that materially affect your rights or the way we handle your personal information, we will provide additional notice, which may include sending an email notification to users who have provided their contact information, displaying a prominent notice on our website, or both. We encourage you to review this Privacy Policy periodically so you remain informed about our current privacy practices.
Your continued use of our website and services after any modification to this Privacy Policy will constitute your acknowledgment and acceptance of the updated terms. If you do not agree with the revised policy, you should discontinue use of our website and services and contact us to discuss the deletion of your personal information, subject to any legal retention obligations that may apply.
How to Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, or if you wish to exercise any of your data protection rights, we encourage you to reach out to us through any of the following channels. Our team is committed to addressing privacy inquiries in a prompt, thorough, and respectful manner.
Email: chat@corastra.buzz
Phone: +1 (509) 694-7082
Postal Address: Cor Astra Ltd., 411-1029 King Street West, Toronto, ON M6K 3M9, Canada
Website: https://www.corastra.buzz
If you are located in a jurisdiction that provides you with the right to lodge a complaint with a data protection supervisory authority, you may do so in the country or region where you reside, where you work, or where you believe any infringement of data protection law has occurred. We would, however, appreciate the opportunity to address your concerns directly before you approach a supervisory authority, and we welcome direct communication as a first step toward resolution.
Glossary of Key Terms
To assist you in understanding this Privacy Policy and your rights, we provide the following definitions for important terms used throughout this document:
Personal Information: Any information that relates to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data, online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
Processing: Any operation or set of operations performed on personal information, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Data Controller: The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal information. Cor Astra Ltd. is the data controller for the personal information described in this policy.
Data Processor: A natural or legal person, public authority, agency, or other body which processes personal information on behalf of the data controller.
Cookies: Small text files that are stored on your device by a web server. Cookies enable websites to remember information about your visit, such as your preferred language and other settings, which can facilitate your next visit and make the site more useful to you.
Consent: Any freely given, specific, informed, and unambiguous indication of your wishes by which you, by a statement or by clear affirmative action, signify agreement to the processing of your personal information.