GDPR Privacy Policy
Last Updated: January 27, 2025
1. Introduction
Tracker Networks Inc. ("Company," "we," "us," or "our") provides software-as-a-service (SaaS) solutions to businesses. This Privacy Policy explains how we collect, use, and protect personal data in compliance with the General Data Protection Regulation (GDPR).
By logging into our software where this Privacy Policy is displayed, you agree to the terms of this Privacy Policy. If you do not agree, you should not log into the software and contact your client administrator (the individual who manages the system in your organization) to have your name removed as a User (see section 5 below).
2. Personal Data We Collect
We only collect and process limited personal data related to user authentication and identification:
- User Name (provided by the client administrator)
- Business Email Address (provided by the client administrator and used for login purposes)
This data is used solely to authenticate users, manage accounts, and provide access to our services.
3. How We Collect Personal Data
User data is provided by the client administrator in your organization, who manages user accounts within our software. We do not collect data directly from users.
4. Legal Basis for Processing
Our processing of user data is based on contract necessity (GDPR Article 6(1)(b)), as this data is required for user authentication and system access.
5. User Rights Under GDPR
Users have the right to:
- Access their personal data (Right of Access – Article 15)
- Request corrections to inaccurate data (Right to Rectification – Article 16)
- Request deletion of their data (Right to Be Forgotten – Article 17)
- Request data portability (Right to Data Portability – Article 20)
Users must contact their organization's administrator to request changes or deletions. If further assistance is required, users may contact us at erm-support@trackernetworks.com.
6. Data Retention
We retain user data only as long as necessary for account management and system access.
Upon client account termination, all user data is deleted within 60 days. Backup data is permanently deleted after 70 days.
7. Security Measures
We implement technical and organizational security measures to protect personal data, including:
- Encryption of data at rest and in transit
- Access controls and multi-factor authentication
- Regular security audits and compliance reviews
8. Data Transfers and Storage
Our servers are hosted in a tier-3 datacenter in Toronto, Canada. If personal data is transferred outside the EU, we use Standard Contractual Clauses (SCCs) to ensure compliance with GDPR.
9. Third-Party Processors
We may use third-party vendors for cloud hosting, email delivery, or customer support. All processors are GDPR-compliant and subject to Data Processing Agreements (DPAs).
10. Data Breach Notification
In case of a data breach affecting personal data, we will notify affected clients and relevant authorities within 72 hours in accordance with GDPR requirements.
11. Contact Information
For any questions regarding this Privacy Policy or GDPR compliance, contact:
Jason Doel, COO & CRO
Tracker Networks Inc.
2869 Bloor St. West, Suite 595
Toronto, Ontario, Canada M8X 1B3