Privacy Policy
Last updated: August 6, 2026
Enterprotect Inc. ("EnterProtect", "we", "us") provides backup, disaster recovery and cybersecurity software to managed service providers and the organizations they serve. This notice explains what personal information we collect, why, who we share it with, how long we keep it, and the rights you have over it.
It covers www.enterprotect.com, the EnterProtect console, and the products described on this site.
1. Two kinds of information, handled differently
Most of what we hold falls into one of two categories, and the difference matters for your rights.
Information we collect for ourselves. When you fill in a form on this website, register for the console, or email us, we decide what to do with that information. Canadian law calls us the organization responsible for it; United States law generally calls us a business or controller.
Information we process for a customer. When a managed service provider uses EnterProtect to back up or scan systems, their data, and their own customers' data, passes through our platform. We handle that on their written instructions and for no purpose of our own. We do not sell it, mine it, or use it to train anything. If your data reached us this way, the organization that engaged us is the one to contact, and we will refer your request to them. Canadian law calls us a service provider in that role; United States law calls us a processor or service provider.
2. What we collect
2.1 When you use this website
This site sets no cookies. It runs no analytics, no advertising tags, no session recording and no third party tracking scripts of any kind. Visiting it leaves nothing on your device and produces no profile of you.
If you submit a form, we receive:
- the name and work email address you enter, and any message you write;
- the page you submitted from and the referring page, if your browser sent one;
- the country your request came from, as reported by our content delivery network.
We ask for a work address and refuse addresses at consumer mail providers. That is a business decision about who we sell to rather than a privacy measure, and it is worth knowing we make it.
We do not store your IP address. To stop one connection flooding our forms, we combine the address with a secret value and store only the resulting cryptographic hash. The hash cannot be reversed into an address, it is compared only against other hashes, and it is the sole thing we retain about the connection.
2.2 When you request a document
Guides, white papers and tools on this site are exchanged for a name and a work email address. We record what was requested and send it once.
Because you asked us for something, Canadian law treats that as an inquiry and allows us to follow up about it for six months. In practice that means someone from our team may get in touch about what you downloaded. That is the whole of what the download alone permits.
Marketing email is separate and requires you to ask for it. The form carries an unticked box offering occasional email about products, offers and events. Leaving it alone costs you nothing and changes nothing: you still get the document. If you do tick it, we record the date and the exact sentence you agreed to, because the law puts the burden of proving that on us rather than on you.
You can withdraw at any time, from the unsubscribe link in any such email or by writing to the address in section 11, and we will act on it within ten business days. We keep a record of the withdrawal, since a suppression list only works if it remembers.
2.3 When you use the console
Creating an account produces a record of the account holder's name, work email address, organization, and role. Using the platform produces operational records: backup and recovery job history, alerts, vulnerability scan results, and an audit trail of significant actions taken in the account.
Protected data itself, meaning the files, mailboxes and system images our customers back up, is handled under section 1 as information we process for a customer.
2.4 Payment information
Card details are entered directly with our payment processor and are never transmitted to or stored on our systems. We receive a token, the last four digits, the card brand, and the outcome of each charge.
3. Why we use it
- To answer you. Form submissions exist so a person can reply.
- To deliver what you asked for. A requested document is emailed to the address given.
- To provide the service. Account and operational data is what makes backup, recovery, alerting and scanning work.
- To keep the service safe. Rate limiting, abuse prevention, and the audit trail.
- To follow up on an inquiry, for six months after you make one, as Canadian anti-spam law permits.
- To send marketing email, only to people who have ticked the box asking for it.
- To bill. Subscription and usage records.
- To meet legal obligations, including tax records and responses to lawful requests.
We do not sell personal information. We do not share it for cross context behavioural advertising. We do not use it for automated decision making that produces legal or similarly significant effects about anyone.
4. Our legal basis
In Canada, we rely on your consent. Submitting a form or creating an account is express consent for the purposes described where you gave it. For ordinary operation of a service somebody has asked for, we rely on implied consent, as PIPEDA permits where the purpose is obvious and the information is not sensitive. You can withdraw consent at any time, subject to legal and contractual limits, by contacting us at the address in section 11. Withdrawing consent may mean we can no longer provide the service.
In the United States, we process personal information to provide a service you or your organization requested, for our legitimate business purposes as described above, and to comply with law.
5. Who else touches it
We use a small number of service providers, each bound by contract to handle personal information only on our instructions.
| Provider | What it does | Where it runs |
|---|---|---|
| Supabase | Database, authentication and server side application code | Canada, Montreal region |
| Cloudflare | Website hosting, content delivery and file storage | Global edge network |
| Resend | Transactional email, including document delivery | United States |
| Stripe | Payment processing and subscription billing | United States |
| Microsoft | Identity and Microsoft 365 connections, where a customer enables them | Per the customer's own tenant |
We also disclose personal information where the law requires it, to professional advisers under a duty of confidence, and to an acquirer if the business is sold, in which case this notice continues to apply until it is replaced and you are told.
6. Where it goes
Our database and the data in it are hosted in Canada. Some of the providers above operate in the United States, or route traffic through a global network, which means personal information may be stored or processed outside the province or country you live in and may be accessible to the courts and law enforcement of those jurisdictions under their laws.
We use providers that offer contractual protections for cross border transfers, and we remain accountable for information we transfer to them.
7. How long we keep it
Operational records in the platform are deleted automatically on a schedule that runs nightly:
| Record | Kept for |
|---|---|
| Backup and recovery job history | 90 days |
| Completed recovery operations | 365 days |
| Resolved alerts | 180 days |
| Vulnerability scan runs | 180 days |
| Resolved vulnerability findings | 180 days |
| Audit trail | 400 days |
| Expired invitations | 30 days |
Form submissions and document requests are kept while they are useful to the conversation they started and are reviewed periodically. Account records are kept for the life of the account and for as long afterwards as tax and corporate law require. Protected data is retained and destroyed according to the retention the customer configures, and is deleted when their subscription ends.
8. How we protect it
Access to customer data is restricted at the database itself, so a request carrying the wrong credentials cannot read another organization's rows regardless of what the application asks for. Traffic is encrypted in transit. Passwords are hashed by our authentication provider and are never visible to us. Administrative access is limited to the people who need it.
No system is immune. If a breach of security safeguards creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as PIPEDA requires, keep a record of the breach as required, and meet the notification deadlines that apply in United States jurisdictions where affected people live.
9. Your rights in Canada
Under PIPEDA, and under provincial law including Quebec's Law 25 where it applies to you, you may:
- ask what personal information we hold about you and how we have used and disclosed it;
- ask us to correct it if it is wrong or incomplete;
- withdraw consent, subject to legal and contractual limits;
- ask for your information in a structured, commonly used technological format, where Law 25 gives you that right;
- complain about how we have handled it.
We will respond within 30 days. If we cannot, we will tell you why and when we will. If you are not satisfied with our answer you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to your provincial regulator.
10. Your rights in the United States
Depending on where you live, state privacy law may give you the right to:
- know what personal information we collect, the categories of source, the purpose, and the categories of third party we disclose it to;
- obtain a copy of it, and have it transferred where technically feasible;
- correct inaccurate information;
- delete it, subject to the exceptions the law allows;
- opt out of sale, of sharing for cross context behavioural advertising, and of profiling with legal or similarly significant effects;
- limit the use of sensitive personal information.
We do not sell personal information, and we do not share it for cross context behavioural advertising. We have not done so in the preceding twelve months. There is therefore nothing to opt out of, and we provide no "Do Not Sell or Share My Personal Information" mechanism because it would have nothing to act on. If that ever changes, this notice will change first.
We will not discriminate against you for exercising any of these rights. An authorized agent may make a request on your behalf with written proof of authority. We may need to verify your identity before acting, which for account holders normally means a request from the address on the account.
To exercise a right, contact us at the address in section 11. If we refuse, you may appeal by replying to our decision, and in several states you may then complain to your state Attorney General.
11. Contacting us
Our privacy officer is responsible for our compliance with this notice and can be reached at:
Privacy Officer
Enterprotect Inc.
Unit 36, 3033 King George Blvd
Surrey, British Columbia V4P 1B8
Canada
[email protected]
12. Children
EnterProtect is sold to businesses. It is not directed at children, and we do not knowingly collect personal information from anyone under 13, or under 16 in jurisdictions that set the line there. If you believe a child has given us personal information, contact us and we will delete it.
13. Changes
We will post any change here and update the date at the top. If a change materially affects how we handle information we already hold, we will give notice by email to account holders before it takes effect.