OpsGate

Privacy Policy

Effective date: July 19, 2026

Last updated: July 19, 2026

This Privacy Policy (the "Policy") governs the collection, use, disclosure, retention, and protection of personal information by Cyber Eclipse in connection with the OpsGate service (the "Service"). This Policy is issued in accordance with the Québec Act respecting the protection of personal information in the private sector, CQLR c. P-39.1 ("Law 25"); the Canadian Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 ("PIPEDA"); Regulation (EU) 2016/679 (the "GDPR") and the UK GDPR, where applicable; and applicable United States state privacy legislation, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (the "CCPA"), where applicable.

Capitalized terms have the meaning given to them in this Policy. "Personal Information" means information about an identifiable individual, and includes "personal data" as defined under the GDPR and "personal information" as defined under the CCPA.

1. Identity and contact details of the controller

The controller responsible for your Personal Information is Cyber Eclipse, the operator of the OpsGate service ("Cyber Eclipse", "we", "us" or "our").

Cyber Eclipse has designated a person responsible for the protection of personal information (the "Privacy Officer"), who oversees compliance with this Policy and with applicable privacy law. The Privacy Officer may be contacted at privacy@opsgate.ca. Cyber Eclipse has not appointed a representative in the European Union or United Kingdom at this time; individuals in those jurisdictions may exercise their rights by contacting the Privacy Officer.

2. Categories of Personal Information and sources

We collect the following categories of Personal Information directly from you and from your use of the Service:

  • Identifiers and account data — your name and email address, provided when you register and administer an account.
  • Authentication and security records — a session identifier, together with the network address and browser characteristics associated with your session, generated when you sign in and use the Service.
  • Service and diagnostic data — technical configuration and diagnostic signals from the sites you connect, generated through your use of the Service.

We do not collect Personal Information relating to your site's visitors or customers, their credentials, their orders or payment details, or the content of your posts, pages, or media. We do not collect special categories of data or sensitive Personal Information as those terms are defined under the GDPR or CCPA.

3. Purposes and legal bases of processing

We collect and process Personal Information only for the following purposes, and, to the extent the GDPR applies, on the legal bases indicated:

  • To create, administer, and secure your account, and to provide the Service, including its site-intelligence, reporting, and alerting functions — necessary for the performance of our contract with you (GDPR art. 6(1)(b)).
  • To authenticate you and protect the Service and your account against unauthorized access — our legitimate interest in the security of the Service (GDPR art. 6(1)(f)).
  • To process payments for paid plans and maintain related records — performance of contract and compliance with legal obligations (GDPR art. 6(1)(b) and (c)).
  • To comply with our legal, accounting, and regulatory obligations — compliance with a legal obligation (GDPR art. 6(1)(c)).

Collection is limited to what is necessary for these purposes, and Personal Information is not used for any incompatible purpose without your consent.

4. Consent

Where consent is the basis for processing, you consent to the collection, use, and disclosure of your Personal Information as described in this Policy by creating an account and using the Service. You may withdraw your consent at any time in accordance with section 9, subject to legal or contractual restrictions; withdrawal may prevent us from continuing to provide the Service to you.

5. Categories of persons with access within our organization

Access to Personal Information within our organization is restricted, on a need-to-know basis, to the personnel who require it to carry out their functions — namely those responsible for account support, billing, and the technical operation and security of the Service. Each such person may access only the Personal Information necessary for their role.

6. Cookies and similar technologies

The Service uses a single strictly necessary cookie for the sole purpose of maintaining your authenticated session in the web console. This cookie is essential to the operation of the Service and is not used for tracking, profiling, advertising, or analytics. As we deploy no advertising or analytics technologies, no consent banner is required and no consent is sought for non-essential technologies, because none are used.

7. Disclosure to service providers and third parties

We engage a limited number of service providers (processors) to perform functions on our behalf. We disclose to each only the Personal Information necessary for its function, under written arrangements requiring it to protect the information and to use it solely for the purposes we specify. The categories of recipients are:

  • Payment processor — to bill and manage paid plans. Payment card details are collected and processed directly by the processor and are not retained by us.
  • AI summary provider — for optional AI-generated summaries where you enable that feature; only technical scan data, containing no Personal Information, is transmitted.
  • Vulnerability intelligence providers — to compare your site's software against known-vulnerability databases; only technical software identifiers are transmitted.
  • Messaging channels you configure — where you elect to receive alerts through a third-party channel, only the alert content is transmitted to that channel at your direction.

We do not sell your Personal Information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA. We do not disclose Personal Information to advertisers, data brokers, or analytics networks. We may disclose Personal Information where required by law, legal process, or to protect our rights, the security of the Service, or the safety of others.

8. International transfers of Personal Information

We operate from Canada and store Personal Information in Canada. Certain service providers identified in section 7 process limited data in the United States. Prior to communicating Personal Information outside Québec, we conduct an assessment of the transfer as required by Law 25 and apply contractual and technical safeguards intended to afford the information a level of protection comparable to that required in Québec. Where the GDPR applies, transfers outside the European Economic Area are made under an appropriate transfer mechanism recognized by the GDPR. By using the Service, you acknowledge that your Personal Information may be processed outside Québec and Canada and may be subject to the laws of the jurisdictions in which it is processed.

9. Your rights, by jurisdiction

Your rights depend on where you reside. Regardless of jurisdiction, you may access, export, correct, or delete your account data directly from your account settings, or by contacting our Privacy Officer at privacy@opsgate.ca. We verify your identity before acting on a request and respond within the period prescribed by the applicable law below.

9.1 Residents of Québec — Law 25

Under the Québec Act respecting the protection of personal information in the private sector (Law 25), you have the right to be informed of, and to access, the Personal Information we hold about you; to have inaccurate, incomplete, or equivocal information rectified; to receive a copy of the computerized Personal Information you provided to us in a structured, commonly used technological format (data portability); to request that we cease disseminating your Personal Information or that a hyperlink to it be de-indexed where the law so provides; and to withdraw your consent. If you are dissatisfied with our handling of a request, you may file a complaint with the Commission d'accès à l'information du Québec.

9.2 Residents elsewhere in Canada — PIPEDA

Under the federal Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to access the Personal Information we hold about you and to be told how it has been used and to whom it has been disclosed; to challenge the accuracy and completeness of that information and have it amended as appropriate; and to withdraw your consent, subject to legal or contractual restrictions. If your concern is not resolved to your satisfaction, you may file a complaint with the Office of the Privacy Commissioner of Canada.

9.3 Residents of the EEA and the United Kingdom — GDPR

Where the EU or UK General Data Protection Regulation applies, you have the rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), and data portability (Article 20); the right to object to processing carried out on the basis of our legitimate interests (Article 21); and, where processing is based on consent, the right to withdraw that consent at any time without affecting the lawfulness of prior processing. The legal bases on which we process your Personal Information are set out in section 3. You also have the right to lodge a complaint with your national data protection supervisory authority.

9.4 Residents of California — CCPA/CPRA

Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, you have the right to know the categories and specific pieces of Personal Information we have collected, the sources, the purposes, and the categories of third parties to whom it is disclosed; the right to delete Personal Information; the right to correct inaccurate Personal Information; the right to opt out of the sale or sharing of Personal Information; the right to limit the use of sensitive Personal Information; and the right not to be discriminated against for exercising these rights. We do not sell or share Personal Information, and we do not process sensitive Personal Information for purposes requiring a limitation right; accordingly, no "Do Not Sell or Share My Personal Information" or "Limit the Use of My Sensitive Personal Information" link is required.

10. Retention and destruction

We retain Personal Information only for as long as necessary to fulfil the purposes for which it was collected and to satisfy our legal, accounting, and security obligations. Diagnostic and operational data is retained for a limited period and then deleted. Upon deletion of your account, your Personal Information is destroyed or anonymized in our active systems, and any residual copies contained in secure backups are purged in the ordinary course of our backup-retention cycle.

11. Safeguards

We implement technological, physical, and administrative safeguards appropriate to the sensitivity of the Personal Information, including encryption, access controls that restrict data to the account to which it pertains, and internal security governance. In the event of a confidentiality incident presenting a risk of serious injury (as that term is used in Law 25 — namely a risk of bodily, moral, or material harm, such as financial loss, identity theft, or reputational damage), we will take reasonable measures to reduce the risk, notify the affected individuals and the Commission d'accès à l'information du Québec as required by Law 25, notify the Office of the Privacy Commissioner of Canada where PIPEDA so requires, and maintain a register of confidentiality incidents. Suspected security vulnerabilities may be reported through our security page.

12. Complaints

Any question or complaint concerning our handling of Personal Information should be addressed to the Privacy Officer at privacy@opsgate.ca. We will investigate and respond within the period prescribed by applicable law. If you are not satisfied with our response, you may lodge a complaint with the Commission d'accès à l'information du Québec, the Office of the Privacy Commissioner of Canada, or, where applicable, the competent supervisory authority in your jurisdiction.

13. Changes to this Policy

We may amend this Policy from time to time. The "Effective date" above indicates when the current version took effect. Where a change is material, we will notify you at the email address associated with your account before the change takes effect.

Privacy questions or requests? privacy@opsgate.ca