This Privacy Policy describes how Ccjh Ehk Canada collects, uses, stores, and protects personal information. The policy applies when you visit this website, request our services, or communicate with our team by email, telephone, or any other channel. The company is a provider of computer systems design and computer integrated systems design services with an office at 80 Glen Park Ave, TORONTO - M6B 2C4, Canada (CA).
By using this website or engaging our services, you accept the practices described in this policy. If you do not agree with any part of this policy, please stop using our website and do not submit personal information to us. We may update this policy from time to time, and we encourage you to review it periodically so that you stay informed about how we handle information. We encourage you to read this policy alongside our Terms of Service, which describe the broader relationship between you and the company. The two documents together explain how our services work and how your information is treated.
The services presented on this website are developed and operated by the developer CCJH EHK on behalf of Ccjh Ehk Canada. The developer leads the design, engineering, and operation of the systems that power our service delivery. Ccjh Ehk Canada is the organisation responsible for the processing of personal information described in this policy, and its registered office is located at 80 Glen Park Ave, TORONTO - M6B 2C4, Canada (CA).
For any question about this policy, you may contact us at inquiry@ccjhehk.buzz or by telephone at +17758061383. All employees and contractors who handle personal information are required to follow this policy and applicable privacy law, and they receive regular training on their obligations. Any reference to the company, we, us, or our in this policy means Ccjh Ehk Canada. The developer CCJH EHK is the technical entity responsible for building and operating the platforms we use, and this division of responsibility ensures that every part of the service has a clear owner.
Personal information is any information that identifies you or can reasonably be linked to you. The categories of personal information we may collect include the following.
We only collect information that is relevant to the purpose for which it is used, and we avoid asking for more than we need to serve you well. We do not collect payment card numbers or other sensitive financial details on this website. When payment is needed, it is handled by a trusted third-party processor under its own security controls, and you will always be told what information we ask for and why.
We collect personal information through several channels. You provide information directly when you complete a form on this website, send us an email, call our telephone number, or share details during a meeting. We collect technical information automatically when you browse this website through cookies and similar technologies.
We may receive information from third parties, such as referrals from your partners, marketing platforms, or event organisers. When you engage us for a project, we collect additional information from you and from the systems you authorise us to access. Finally, we may collect information from public sources, such as business registries and professional directories, to verify details and improve the accuracy of our records. We may also collect information you provide in surveys, feedback forms, or community channels that we operate from time to time. In every case, the collection is limited to what the stated purpose requires, and we try to make our collection practices easy to understand.
We use personal information for purposes that are legitimate, specific, and limited. We use your information to respond to inquiries and provide the services you request. We use it to manage contracts, prepare proposals, deliver projects, and provide ongoing support. We use technical information to operate, protect, and improve this website and our services.
We may use your contact details to send service updates, security notices, and administrative messages that are necessary for the relationship. With your consent, we may send you information about our services that we think may be useful to you. We use aggregated and de-identified information for analytics, reporting, and service improvement, because that information cannot identify you. We do not use personal information for purposes that are incompatible with the purposes described here. If we intend to use your information for a new purpose, we will update this policy and, where needed, ask for your consent, because your trust depends on our restraint.
We process personal information only when we have a lawful basis to do so. The bases we rely on include consent, which you may withdraw at any time; contract performance, where processing is necessary to deliver services you have agreed to receive; legitimate interests, where our interest does not override your rights and freedoms; legal obligations, where we must process information to comply with law; and vital interests, where processing is necessary to protect someone.
When we rely on legitimate interests, we balance those interests against your expectations and rights. You may ask us to explain the specific basis we apply to your information, and we will respond within a reasonable time. Our privacy team maintains a record of processing activities that describes each purpose, the data involved, and the legal basis applied. This record helps us stay accountable, makes it easier to answer your questions, and you may request a summary of the bases that apply to you.
We keep personal information only for as long as necessary to fulfil the purposes described in this policy. Account and correspondence records are retained for the duration of the relationship and for a reasonable period afterwards to support the services we deliver. Technical logs and analytics data are retained for a shorter period, usually between twelve and twenty-four months.
Project documentation and configuration records are retained for the period agreed in the relevant contract. When information is no longer needed, we delete it securely or anonymise it so that it can no longer be linked to you. Retention periods are reviewed regularly and adjusted when laws or business needs change. Our deletion process covers databases, backups, logs, and documents so that no copy of your information survives by accident. Automated schedules flag records that have reached the end of their life, and you may ask us to confirm that a deletion has been completed.
We apply technical and organisational measures to protect personal information against unauthorised access, loss, and alteration. Information is encrypted in transit using modern transport security protocols, and stored information is protected by access controls that follow the principle of least privilege. Access to systems that hold personal information is limited to staff who need it for their work, and every access is logged and reviewed.
We conduct regular security reviews, patch our systems promptly, and train our staff on privacy and security obligations. We test our incident response procedures so that a problem is handled quickly and in line with our documented plan. No method of transmission is completely secure, but we work hard to reduce risk to a level that is appropriate for the sensitivity of the information. We also review our security posture with outside experts from time to time, because independent assessments give us a fresh perspective on weaknesses we might have missed. The results of those reviews guide our improvement priorities.
The company operates primarily in Canada, and personal information may be stored or processed in Canada and in other countries where our service providers operate. When information is transferred outside Canada, we take steps to ensure it receives a comparable level of protection, including contractual safeguards with our providers and verification that their security practices meet our standards.
We review the location of our providers and the legal environment in each jurisdiction. You can ask us for a summary of the safeguards we apply to international transfers, and we will provide it in a reasonable timeframe. Before we choose a provider in another country, we confirm that the local legal framework offers adequate protection for personal information. Where that cannot be confirmed, we apply additional contractual or technical safeguards, and we document these decisions for review.
Depending on where you live, you may have rights over your personal information. These may include the right to access the information we hold about you, the right to request correction of inaccurate information, the right to request deletion of information, the right to restrict or object to certain processing, the right to data portability, and the right to withdraw consent at any time.
To exercise any of these rights, contact us using the details in the Contact Information section. We will verify your identity before acting on a request and will respond within the period required by applicable law. We may need to retain some information even after a deletion request where the law requires us to do so. You may also submit a request through a person who represents you, such as a lawyer or a family member, as long as that person has proper authority. We may ask for proof of identity and authority to protect your account and your information, and our process is designed to be simple and fair.
Our services are directed to professionals and businesses, and they are not intended for children. We do not knowingly collect personal information from children under the age of thirteen. If you believe that a child has provided personal information to us, please contact us using the details at the end of this policy, and we will delete the information promptly.
Parents and guardians who believe a child has interacted with our website may also request deletion of that information. We take these matters seriously and act quickly to remove any such information from our records. We also encourage parents to supervise the online activity of their children and to explain the importance of not sharing personal information without permission. Our tools do not target children, we do not market our services to them, and protecting young people is a shared responsibility.
This website may contain links to websites and services operated by third parties, including clients, partners, and public resources. This policy does not apply to those websites, and we are not responsible for their privacy practices. When you follow a link, the third party controls the information collected about you, and we encourage you to read its privacy policy.
We also use third-party software in the delivery of our own services, and the privacy practices of those vendors apply to the information they process on our behalf. We review the agreements we have with these vendors to ensure they meet our standards. When you leave our website, please note that your browser and the destination site may collect information that is outside our control, and the safest practice is to review the privacy practices of every site you visit. We update our link lists and remove resources that no longer meet our standards.
We maintain a documented incident response plan for security events that may affect personal information. When we become aware of a data breach that is likely to create a real risk of harm, we assess the nature and scope of the event, contain the impact, and investigate the cause.
We notify affected individuals and the relevant supervisory authorities as required by law, without undue delay. Notifications include a description of what happened, the categories of information involved, and the steps we have taken to respond. We also review our controls after any incident and implement improvements to reduce the chance of recurrence. Our notification process distinguishes between events that require public disclosure and those that are contained internally, and this judgement is made by senior staff with input from legal counsel. Transparency is our goal whenever we can share details without increasing risk.
We may revise this policy from time to time to reflect changes in our services, technology, or legal requirements. The date at the top of the policy shows when it was last updated. When we make material changes, we will take reasonable steps to inform you, including updating this page and, where appropriate, notifying you by email.
Continued use of our website or services after a change takes effect means you accept the revised policy. We encourage you to check this page regularly so that you remain aware of how we handle your information. Significant changes are also described in a short summary at the top of the page so that you can see at a glance what has altered. This summary does not replace the full policy; it exists to make change visible.
If you have any question about this policy or about how we handle your personal information, please contact us. You may reach us by email at inquiry@ccjhehk.buzz or by telephone at +17758061383. Our postal address is Ccjh Ehk Canada, 80 Glen Park Ave, TORONTO - M6B 2C4, Canada (CA).
We will respond to your message as soon as possible and usually within ten business days. If you are not satisfied with our response, you may also contact the privacy authority in your province or country for further assistance. Our team is committed to responding with honesty and speed, and even if the answer is complex you will receive a clear explanation and a realistic timeline. We value the trust you place in us and work to honour it.