LEGAL

Privacy Policy

Effective date: March 30, 2026

BluePeak Systems Inc. ("BluePeak", "we", "us", or "our") operates VimyHQ, a cloud-based, AI-native cybersecurity detection and response platform. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our Website or use our Service. We are committed to protecting your privacy in compliance with PIPEDA, Quebec Law 25, BC PIPA, and other applicable Canadian privacy legislation.

By accessing or using our Website or Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Website or Service.

1. Introduction

BluePeak Systems Inc. operates VimyHQ, accessible at vimyhq.com (the "Website") and through our platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our Website, use our Service, or otherwise interact with us.

If you have questions about this policy, contact us at [email protected].

2. Information We Collect

2.1 Information You Provide Directly

Account Information

Name, email address, company name, job title, phone number, and billing address when you register for an account or subscribe to VimyHQ.

Billing Information

Payment card details and billing address. Payment processing is handled by our third-party payment processor; we do not store full credit card numbers on our systems.

Communications

Information you provide when you contact us for support, submit inquiries, participate in surveys, or communicate with us via email or other channels.

Onboarding Information

Technical details about your infrastructure provided during onboarding to configure the Service, such as server details, IP ranges, and integration endpoints.

2.2 Information Collected Automatically

Device and Browser Information

IP address, browser type and version, operating system, device type, screen resolution, and language preferences.

Usage Data

Pages visited, time spent on pages, click patterns, referring URLs, and navigation paths through our Website.

Log Data

Server logs including access times, error logs, and request details.

Analytics Data

We use Google Analytics to collect aggregate usage statistics about our Website. Google Analytics uses cookies and similar technologies to collect information about how visitors use our Website.

2.3 Security Telemetry Data

In the course of providing the Service, our Agent software and platform collect security telemetry data, including system logs, network events, authentication events, and other security-relevant data. This data may incidentally contain personal information (such as usernames, email addresses, or IP addresses of your employees or end-users). The processing of this data is governed by our Data Processing Agreement (DPA).

3. Cookies and Tracking Technologies

We use cookies and similar tracking technologies on our Website. You can manage your cookie preferences through your browser settings. For Google Analytics, you can opt out by installing the Google Analytics Opt-Out Browser Add-on.

Cookie Type
Purpose
Duration
Essential
Required for authentication, session management, security, and basic platform functionality. These cannot be disabled.
Session / up to 1 year
Analytics
Google Analytics cookies used to understand how visitors interact with our Website, measure traffic, and improve user experience.
Up to 2 years
Marketing
Used to deliver relevant advertisements, measure campaign effectiveness, and track visitor activity across websites.
Up to 2 years
Preference
Remember your settings and preferences (such as language or region) to personalize your experience.
Up to 1 year

4. How We Use Your Information

We use personal information for the following purposes:

  • Service Delivery: To create and manage your account, provide the Service, process transactions, and deliver customer support.
  • Security Operations: To detect, investigate, and respond to cybersecurity threats on your behalf, including AI-powered threat analysis and autonomous response actions.
  • Service Improvement: To analyze usage patterns, improve our AI models and detection capabilities, fix bugs, and develop new features.
  • Communications: To send you service-related notifications, security alerts, billing information, technical updates, and support responses.
  • Marketing: With your consent, to send you marketing communications about our products, services, and events. You can opt out at any time.
  • Compliance: To comply with legal obligations, enforce our Terms of Service, and protect our rights and the rights of others.
  • Analytics: To understand how visitors use our Website and Service and measure the effectiveness of our marketing campaigns.

5. Legal Bases for Processing

Under Canadian privacy law, we process personal information based on the following legal grounds:

Consent: Where you have given express or implied consent, such as when you create an account, subscribe to our newsletter, or accept cookies.
Contractual Necessity: Where processing is necessary to perform our contract with you, including delivering the Service and processing payments.
Legitimate Interest: Where processing is necessary for our legitimate business interests, such as improving our services, preventing fraud, and ensuring platform security, provided these interests do not override your privacy rights.
Legal Obligation: Where processing is required to comply with applicable laws, regulations, or legal proceedings.

6. How We Share Your Information

We do not sell, rent, or trade your personal information. We may share personal information in the following limited circumstances:

  • Service Providers: Trusted vendors who assist in operating our platform (e.g., payment processing, analytics, customer support) under strict data processing agreements.
  • Legal Requirements: If required by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to protect rights or safety. We will notify you where legally permitted.
  • Business Transfers: In the event of a merger, acquisition, reorganization, or sale of assets. We will notify you of any such change and any choices you may have.
  • With Your Consent: Any other sharing will require your explicit consent.

Important: We do not share security telemetry data between customers. Each customer's data is isolated using database-per-tenant architecture.

7. Data Location and Transfers

All personal data and customer data processed through VimyHQ is stored and processed exclusively within Canada. We do not transfer personal data outside of Canada for processing or storage.

Our infrastructure is hosted in Canadian data centres, and we require all subprocessors who handle personal data to maintain their processing operations within Canada. This commitment is reflected in our Data Processing Agreement.

In the limited case where a third-party service provider (such as a payment processor) may process data outside of Canada, we ensure that adequate contractual safeguards are in place in accordance with PIPEDA and applicable provincial privacy legislation.

8. Data Security

We implement and maintain commercially reasonable administrative, technical, and organizational security measures to protect personal information against unauthorized access, alteration, disclosure, or destruction:

  • Encryption of data at rest (AES-256) and in transit (TLS 1.3)
  • Database-per-tenant isolation to prevent data co-mingling
  • Multi-factor authentication for platform access
  • Role-based access controls with least-privilege principles
  • Regular vulnerability assessments and annual penetration testing
  • Comprehensive audit logging retained for a minimum of 2 years
  • Incident response procedures and breach notification protocols

While we strive to protect your personal information, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security, but we are committed to maintaining industry-appropriate safeguards.

9. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.

Data Type
Retention Period
Account Information
Account duration + reasonable period for legal obligations
Billing Records
As required by applicable tax and financial reporting laws
Security Telemetry (Sentinel)
90 days
Security Telemetry (Bastion)
1 year
Security Telemetry (Citadel)
Custom, up to 7 years
Audit Logs
2-year minimum
Website Analytics
Aggregated: up to 26 months
Marketing Data
Until you withdraw consent or unsubscribe

When personal information is no longer needed, we securely delete or anonymize it using commercially reasonable methods.

10. Your Privacy Rights

Under Canadian privacy law, including PIPEDA, BC PIPA, and Quebec Law 25, you have the following rights:

  • Right of Access: Request access to the personal information we hold about you, including how it is used and to whom it has been disclosed.
  • Right of Correction: Request that we correct or update inaccurate or incomplete personal information.
  • Right of Deletion: Request that we delete your personal information, subject to legal and contractual retention obligations.
  • Right to Withdraw Consent: Withdraw your consent to the processing of your personal information at any time, subject to legal or contractual restrictions.
  • Right to Data Portability (Law 25): Request a copy of your personal information in a structured, commonly used technological format, or request that it be transferred to another organization.
  • Right to De-indexation (Law 25): Request that we cease disseminating your personal information where the dissemination contravenes the law or a court order.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days, as required by applicable law. We may require verification of your identity before processing your request.

If you are not satisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada (OPC), the Commission d'accès à l'information du Québec (CAI), or your relevant provincial privacy commissioner.

11. Children's Privacy

VimyHQ is a business-to-business service and is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete it promptly. If you believe a child has provided us with personal information, please contact us at [email protected].

12. Third-Party Links

Our Website and Service may contain links to third-party websites, services, or resources that are not operated by us. We are not responsible for the privacy practices or content of these third parties. We encourage you to review the privacy policies of any third-party website you visit. This Privacy Policy applies only to VimyHQ and vimyhq.com.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Effective Date" at the top of this policy and post the revised version on our Website.

For material changes that significantly affect how we handle your personal information, we will provide prominent notice on our Website or through the Service, and where required by law, obtain your consent.

14. Canadian Anti-Spam Legislation (CASL)

We comply with Canada's Anti-Spam Legislation (CASL) in all electronic communications. We will only send you commercial electronic messages (CEMs) where we have your express or implied consent, as permitted by CASL.

Every marketing email we send includes clear identification of BluePeak Systems Inc. as the sender, our contact information, and a functional unsubscribe mechanism. You can withdraw your consent to receive marketing emails at any time by clicking the "unsubscribe" link in any marketing email or by contacting us at [email protected]. We will process your unsubscribe request within 10 business days, as required by CASL.

Service-related communications (such as security alerts, billing notices, and account notifications) are not considered CEMs under CASL and are necessary for the performance of our contract with you.

15. Contact Us

BluePeak Systems Inc.
Kelowna, BC, Canada
Privacy inquiries: [email protected]
For privacy-related complaints, you may also contact the Office of the Privacy Commissioner of Canada at priv.gc.ca, or your relevant provincial privacy commissioner.