Legal information

Privacy policy

We collect little, and for a single reason: to answer your request. This page sets out what we collect, who can see it, how long we keep it and how you take it back.

/01

Who handles your information

The groupitcs.ca website is operated by Information Technologie Cyber Sécurité Inc., doing business as Groupe ITCS. The company is registered with the Quebec enterprise registrar under NEQ 1178764289 and its place of business is 1700-2001, boulevard Robert-Bourassa, Montreal, Quebec H3A 2A6, Canada.

Any question, access request or complaint about your personal information goes to the officer designated within the company.

  • Title: Privacy Officer
  • Email: [email protected]
  • Phone: +1 (438) 701-0624
  • Mailing address: 1700-2001, boulevard Robert-Bourassa, Montreal, Quebec H3A 2A6, Canada
/02

What we collect

We only collect the information you send us yourself, and only what is needed to handle your request.

The site has no user accounts, no payments and no client portal. No browsing data is collected to build a profile or serve advertising.

Never send us a password, an access key, a card number or technical evidence from an ongoing incident through a form. For those, we agree on a suitable channel with you first.

  • Contact form: your name, email address, message and consent.
  • Callback form in the assistant: the same fields, plus an optional phone number.
  • The page the request came from, so we can place your question in context.
  • IP address and timestamp of the submission, used for the duration of the request to rate limit and filter out automated submissions.
/03

Why we collect it

Your information is used for the following purposes only.

Fields marked as required are the ones without which we cannot answer. You consent to the transmission by ticking the box provided, and you may withdraw that consent at any time.

  • answering your request and calling you back;
  • preparing a service proposal and, where applicable, carrying out the engagement you entrust to us;
  • protecting the site against abusive and automated submissions;
  • meeting our legal, accounting and professional obligations.
/04

What we do not do

These commitments do not depend on any setting on your side: they describe how the site normally works.

  • We do not sell, rent or trade personal information.
  • We send no newsletter and no prospecting email. The only messages you receive from us are answers to your own requests.
  • We do not use your information for targeted advertising or to build a profile.
  • We do not buy lists and we do not enrich your file with information obtained from third parties.
/05

Service providers involved

The site relies on the providers listed below. Each one only accesses the information required for its role and cannot use it for any other purpose.

Your message passes through a forwarding service we operate ourselves before it is delivered to our business mailboxes. No access key to those services is present in your browser.

We also disclose information where the law requires it, in particular under a court order, and we then limit ourselves to what is required.

  • Cloudflare, Inc.: website hosting and delivery, execution of the server function that receives form submissions (United States).
  • Netlify, Inc.: hosting of the related site virementfrauduleux.com (United States).
  • Brevo: delivery of the notification emails sent to our team (France, European Union).
/06

Disclosure outside Quebec

Website hosting and email delivery rely on providers established in the United States and in the European Union. Your information may therefore be processed and stored outside Quebec, where it is subject to local law, including requests the authorities of those countries may address to a provider.

If that disclosure is a concern for you, the phone remains a route that involves no form at all.

/07

How long we keep it

We keep information for as long as the stated purposes require, then destroy or anonymize it.

Periods that outlast the engagement itself follow from our tax and professional obligations and from the limitation periods that apply under Quebec civil law.

  • Contact request that leads to no engagement: 24 months from the last exchange.
  • Engagement file and deliverables provided to a client: 7 years after the end of the engagement.
  • Record of the consent collected through a form: duration of the relationship, then 3 years.
  • Technical and security logs kept by the hosting layer: 12 months at most.
/08

How we protect it

The following measures apply to the information you entrust to us.

No measure makes a system impregnable. When an incident occurs, we follow the procedure described below.

  • the entire site is served over HTTPS, and the function receiving form submissions rejects requests coming from any origin other than our domains;
  • payload size is capped, a minimum typing delay and a bot trap filter out automated submissions, and the rate is limited per address;
  • no access key to a third-party service is placed in your browser;
  • access to the mailboxes receiving requests is restricted to the people who need it and protected by multi-factor authentication;
  • engagement files are encrypted and access to them is logged.
/09

Cookies and trackers

The site sets no advertising cookie, embeds no third-party tracker and uses no analytics tool. Nothing is written to your browser local storage.

Our host may set a strictly technical cookie used to tell a visitor from a bot. It serves no advertising, no profiling and no cross-site tracking.

Were we to add an analytics or advertising tool, it would be preceded by a consent request offering refusal as plainly as acceptance, with identification, location and profiling functions off by default, in line with section 8.1 of Law 25.

/10

Site assistant and automated processing

The assistant answers from rules and pre-written responses drawn from the published pages. It calls no external language model and sends your question to no server.

The conversation stays in your browser tab and disappears when you close it. Nothing is transmitted unless you deliberately fill in the callback form.

No decision producing legal effects or otherwise significantly affecting you is made solely on the basis of automated processing. A member of the team reads and answers every request.

/11

Your rights

Law 25 and the Personal Information Protection and Electronic Documents Act give you the following rights, which you exercise free of charge with the privacy officer.

We answer within 30 days of receiving your request. If our answer does not satisfy you, you may complain to the competent authority.

  • access the information we hold about you and obtain a copy of it;
  • have it corrected where it is inaccurate, incomplete or ambiguous;
  • withdraw your consent and ask us to stop using it;
  • ask for its deletion where keeping it is no longer justified;
  • receive the computerized information you provided to us in a structured, commonly used technological format;
  • ask for the de-indexing of a hyperlink giving access to your information where the conditions set out in the Act are met.
/12

Confidentiality incidents

We keep a register of confidentiality incidents. Where an incident presents a risk of serious injury to you, we promptly notify the Commission d’accès à l’information and the people concerned, then take the measures needed to reduce the risk and prevent a recurrence.

/13

Internal governance

Internal policies frame the life cycle of personal information within the company.

The detailed version of those policies is provided on request by the privacy officer.

  • a designated officer, whose title and contact details appear at the top of this page;
  • a minimization rule: we ask only for the information the stated purpose requires;
  • roles and access rights granted on a need-to-know basis;
  • retention periods and a destruction procedure, described above;
  • an incident register and a complaint handling procedure, with an answer within 30 days.
/14

Minors

Our services are addressed to organizations. We do not solicit information from people under 14 years of age and we destroy any that reaches us by mistake.

/15

Changes

This policy may change following a change of service, provider or legal obligation. The version in force is the one published on this page, and a significant change is flagged on the site.

Last revised: August 18, 2026