1. Introduction and Scope
RFDA operates as a computer systems design and related services provider under the corporate umbrella of Loco Sky Ltd., a company duly incorporated under the laws of Canada, with its registered office located at 9759 Northville Crescent Rr 1, Thedford, Ontario, N0M 2N0, Canada. Our lead systems engineer and primary developer, Kara Small Opal, oversees all technical operations and data handling practices within the organization.
This Privacy Policy applies to all individuals who visit our website, communicate with us via electronic mail or telephone, engage our professional services, or otherwise interact with RFDA in any capacity where personal data may be collected. By accessing or using our Services, you acknowledge that you have read and understood the terms of this Privacy Policy.
We are committed to protecting your privacy in accordance with applicable Canadian federal and provincial privacy legislation, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and any substantially similar provincial laws that may apply to our operations. Where applicable, we also endeavor to align our practices with internationally recognized privacy frameworks such as the General Data Protection Regulation (GDPR) of the European Union, to the extent that such frameworks are relevant to our processing activities involving data subjects outside Canada.
This policy explains what personal information we gather, why we gather it, how we use it, with whom we may share it, how we protect it, and what choices and rights you have regarding your personal data. We encourage you to read this document thoroughly and to contact us with any questions or concerns you may have.
2. Information We Collect
In the course of operating our business and providing our professional services, RFDA may collect several categories of personal information. The specific types of data we collect depend on the nature of your interaction with us and the services you request.
Contact and Identification Data: When you fill out a contact form on our website, send us an email, or call our offices, we collect your full name, email address, telephone number, company name, job title, and any other contact details you voluntarily provide. This information is necessary for us to respond to your inquiries and to establish a business relationship.
Professional and Business Information: If you engage RFDA for consulting, systems architecture, software engineering, cybersecurity assessment, or any other professional service, we may collect information about your organizations technical infrastructure, business requirements, project specifications, and other operational data that is relevant to the scope of the engagement. This may include network diagrams, system configurations, source code repositories, and architectural documentation.
Communication Records: We retain copies of correspondence exchanged between you and our team, including emails, meeting notes, project briefs, support tickets, and telephone call summaries. These records help us maintain continuity in our professional relationship and ensure that we deliver consistent, high-quality service.
Technical and Usage Data: When you visit our website, our servers automatically log certain technical information, including your Internet Protocol (IP) address, browser type and version, operating system, referring URL, pages visited, time and date of your visit, and time spent on each page. This data is collected through server logs and may be supplemented by analytics tools that help us understand how visitors interact with our site.
Payment and Billing Information: For clients who engage our paid services, we collect billing addresses, purchase order numbers, tax identification information where applicable, and transaction records. We do not directly collect or store credit card numbers or full bank account details; payment processing is handled by third-party payment processors who maintain their own privacy and security standards.
3. Methods of Collection
RFDA collects personal information through a variety of channels, each of which is described below. In all cases, we strive to collect only the minimum amount of information necessary to fulfill the purpose for which it was gathered.
Direct Collection from You: The majority of the personal information we hold is provided directly by you when you contact us through our website forms, send us electronic mail, speak with our team members by telephone, attend meetings (whether in person or virtual), or submit project documentation and requirements. You are under no obligation to provide any personal information; however, certain services may not be available to you if you choose not to share the data that is reasonably necessary for us to deliver those services.
Automated Collection: As described in Section 2, certain technical data is collected automatically when you browse our website. This collection occurs through standard web server logging mechanisms and through the use of cookies and similar technologies, which are discussed in greater detail in Section 8 of this Policy.
Collection from Third Parties: In limited circumstances, we may receive personal information about you from third-party sources, such as business partners who refer you to our services, publicly available professional directories, or industry conference attendee lists. Whenever we receive information from a third party, we take reasonable steps to verify that the information was lawfully obtained and that we are authorized to process it for the intended purpose.
4. How We Use Your Information
RFDA uses the personal information we collect for a defined set of purposes, all of which are directly related to the operation of our business and the provision of our professional services. We do not use your personal data for purposes that are incompatible with those described in this Policy without first notifying you and, where required by law, obtaining your consent.
- Service Delivery: To provide the computer systems design, software engineering, cybersecurity, network engineering, data engineering, and cloud and DevOps services that you have requested from us.
- Communication: To respond to your inquiries, send you project updates, deliver technical documentation, and otherwise communicate with you about the services we are providing or that you have expressed interest in receiving.
- Billing and Administration: To process invoices, manage accounts, maintain financial records, and comply with our tax and accounting obligations.
- Website Improvement: To analyze how visitors use our website so that we can improve its functionality, content, and user experience.
- Legal Compliance: To comply with applicable laws, regulations, court orders, and government requests, including those related to taxation, anti-money laundering, and data protection.
- Security: To monitor, detect, and prevent unauthorized access, fraud, abuse, and other harmful activities that could compromise our systems or the data we hold.
- Business Development: To send you information about our services, industry insights, and event invitations, but only where you have opted in to receive such communications or where permitted by applicable law.
5. Legal Basis for Processing
Depending on your jurisdiction and the nature of our relationship, RFDA relies on one or more of the following legal bases for processing your personal information:
Consent: In many cases, we process your personal information based on your explicit or implied consent. For example, when you submit a contact form on our website, you provide your consent for us to use the information you share to respond to your inquiry. You may withdraw your consent at any time by contacting us using the details provided in Section 16, subject to legal or contractual restrictions.
Contractual Necessity: When you engage RFDA to provide professional services, we process your personal information as necessary to perform our obligations under the service agreement between us. This includes using your contact details to communicate about project milestones, deliverable timelines, and billing matters.
Legitimate Interests: In certain circumstances, we process personal information based on our legitimate business interests, provided that those interests are not overridden by your privacy rights. Examples include analyzing website traffic to improve our online presence, maintaining the security of our systems, and keeping records of past projects for quality assurance purposes.
Legal Obligation: We may process your personal information where we are required to do so by applicable law, such as retaining financial records for tax purposes or responding to a binding request from a regulatory authority.
6. Data Storage and Retention
Personal information collected by RFDA is stored on secure servers located in Canada and, in some cases, on cloud infrastructure provided by reputable third-party service providers who maintain data centers in North America and Europe. We select our hosting and infrastructure providers based on their adherence to industry-recognized security standards and their contractual commitments to data protection.
We retain personal information only for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable law. The specific retention period varies depending on the type of data and the context in which it was collected:
- Contact and inquiry data: Retained for up to two (2) years from the date of your last interaction with us, unless a longer retention period is required by a contractual agreement or by law.
- Client project data: Retained for the duration of the project engagement plus seven (7) years following project completion, consistent with Canadian statutory limitation periods and professional standards for recordkeeping.
- Financial and billing records: Retained for seven (7) years in accordance with Canadian tax law requirements.
- Website usage logs: Retained for up to twelve (12) months, after which they are either anonymized or securely deleted.
When personal information is no longer needed, we take reasonable steps to securely destroy or permanently de-identify the data. Paper records are shredded, and electronic records are deleted using methods that prevent recovery.
7. Data Sharing and Disclosure
RFDA does not sell, rent, or trade your personal information to third parties for their own marketing purposes. We may, however, share your personal information in the following limited circumstances:
- Service Providers: We engage trusted third-party vendors to perform functions on our behalf, including web hosting, email delivery, payment processing, cloud storage, and analytics. These service providers are contractually bound to process personal information only in accordance with our instructions and to implement appropriate security measures to protect the data.
- Professional Advisors: We may share information with our legal counsel, accountants, auditors, and insurers as necessary to protect our legitimate business interests and to comply with our professional obligations.
- Business Transfers: In the event of a merger, acquisition, reorganization, or sale of all or a portion of our assets, personal information held by RFDA may be among the assets transferred to the successor entity. We will notify you of any such change in ownership or control of your personal data.
- Legal Compliance and Safety: We may disclose personal information to government authorities, law enforcement agencies, or other third parties if we believe in good faith that such disclosure is necessary to comply with a legal obligation, to protect the rights or property of RFDA or Loco Sky Ltd., to prevent fraud or illegal activity, or to protect the personal safety of our employees, clients, or the public.
8. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and understand how visitors interact with our content. A cookie is a small text file that is placed on your device by your web browser at the request of a website you visit.
We use the following categories of cookies on our website:
- Essential Cookies: These cookies are necessary for the website to function properly. They enable core functionality such as page navigation, secure form submissions, and access to protected areas of the site. The website cannot operate correctly without these cookies, and they do not require your consent under applicable privacy law.
- Analytics Cookies: These cookies help us understand how visitors engage with our website by collecting and reporting information anonymously. We use this data to identify which pages are most frequently visited, how long users spend on each page, and whether visitors encounter any technical errors. We may use third-party analytics services (such as Google Analytics) for this purpose.
- Functional Cookies: These cookies allow the website to remember choices you make (such as your preferred language or region) and provide enhanced, more personalized features.
Most web browsers allow you to control cookies through their settings. You can configure your browser to block all cookies, to delete existing cookies, or to alert you when a cookie is being set. Please note that disabling certain cookies may affect the functionality of our website and limit your ability to use some of its features.
Our website may also use web beacons (also known as pixel tags or clear GIFs) in our HTML emails to determine whether recipients have opened an email or clicked on a link. This helps us measure the effectiveness of our communications and tailor future content to your interests.
9. Third-Party Services
Our website and business operations may integrate with or rely on services provided by third parties. These third-party services are governed by their own privacy policies and terms of service, and we encourage you to review those documents to understand how your data is handled by each provider.
The third-party services we currently use or may use include, but are not limited to: cloud infrastructure providers (for hosting our website and client data), electronic mail delivery services, customer relationship management platforms, project management and collaboration tools, video conferencing platforms, payment processing gateways, and website analytics services.
We conduct due diligence on all third-party service providers before engaging them and periodically review their security practices and privacy policies. We require all providers to enter into data processing agreements that include contractual commitments to protect personal information in a manner consistent with this Privacy Policy and with applicable data protection laws.
Our website may contain links to external websites that are not operated by RFDA or Loco Sky Ltd. If you click on a third-party link, you will be directed to that third partys site. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party websites or services. We strongly advise you to review the privacy policy of every site you visit.
10. Data Security Measures
RFDA takes the security of your personal information seriously. We implement and maintain a comprehensive set of technical, administrative, and physical safeguards designed to protect the data we hold against unauthorized access, disclosure, alteration, and destruction.
Our technical security measures include, but are not limited to: encryption of data in transit using Transport Layer Security (TLS) protocols, encryption of certain sensitive data at rest, network firewalls and intrusion detection and prevention systems, regular vulnerability scanning and penetration testing, multi-factor authentication for all administrative access, role-based access controls limiting data access to authorized personnel only, automated security patch management, and continuous monitoring and logging of system access and activity.
Our administrative measures include: mandatory privacy and security training for all employees and contractors, documented information security policies that are reviewed and updated at least annually, background checks for personnel with access to sensitive data, confidentiality agreements that bind all staff and contractors, and a designated privacy officer responsible for overseeing compliance with this Policy.
Our physical measures include: restricted access to our office premises in Thedford, Ontario, secure storage for any paper records containing personal information, and secure disposal procedures for obsolete hardware and physical media.
While we strive to protect your personal information using industry-standard practices, no method of electronic storage or transmission over the Internet is entirely secure. We cannot guarantee absolute security, and you share information with us at your own risk. In the event of a security incident, we will follow our incident response procedures and notify affected individuals and regulatory authorities as required by applicable law.
11. Your Privacy Rights
Depending on your jurisdiction, you may have certain rights regarding the personal information we hold about you. RFDA is committed to honoring these rights to the fullest extent required by applicable law. The rights described below are available to individuals located in Canada under PIPEDA and, where applicable, to data subjects in the European Union under the GDPR.
- Right of Access: You have the right to request confirmation of whether we process your personal information and, if so, to obtain a copy of that information along with details about how and why it is being processed.
- Right of Rectification: If you believe that the personal information we hold about you is inaccurate or incomplete, you have the right to request that we correct or supplement it.
- Right of Erasure: In certain circumstances, you may request that we delete the personal information we hold about you. This right is not absolute and may be limited by our legal obligations to retain certain records or by our legitimate business interests.
- Right to Restrict Processing: You may request that we limit the processing of your personal information in certain situations, such as while we are verifying the accuracy of data you have challenged.
- Right to Data Portability: Where processing is based on consent or a contract and is carried out by automated means, you may request a copy of your personal information in a structured, commonly used, and machine-readable format, and you may request that we transmit that data directly to another organization where technically feasible.
- Right to Object: You may object to the processing of your personal information where we are relying on legitimate interests as the legal basis for processing. You also have the right to object to the use of your personal information for direct marketing purposes at any time.
- Right to Withdraw Consent: Where we rely on your consent as the basis for processing, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing that occurred before the withdrawal.
To exercise any of these rights, please contact us using the details provided in Section 16 of this Policy. We will respond to your request within the timeframe required by applicable law (generally within thirty days) and may ask you to verify your identity before processing your request. There is no fee for making a request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline to act on the request.
12. Childrens Privacy
Our Services are not directed to individuals under the age of sixteen (16), and we do not knowingly collect personal information from children. If we become aware that a child under the age of sixteen has provided us with personal information without verifiable parental consent, we will take prompt steps to delete that information from our records. If you are a parent or guardian and you believe that your child has provided us with personal information, please contact us immediately using the details in Section 16 so that we can take appropriate action.
We encourage parents and guardians to monitor their childrens online activities and to instruct them never to provide personal information through websites or online forms without permission. RFDA supports the goals of childrens online privacy legislation and is committed to compliance with all applicable laws in this area.
13. International Data Transfers
RFDA is headquartered in Canada, and our primary data storage and processing operations are based in Canada. However, certain of our third-party service providers may store or process data on servers located in other countries, including the United States and member states of the European Union. When we transfer personal information across international borders, we take appropriate measures to ensure that the data receives an adequate level of protection in the destination country, consistent with the standards set out in this Privacy Policy and in applicable data protection law.
For transfers of personal data from the European Economic Area (EEA) to countries that have not been deemed to provide an adequate level of data protection by the European Commission, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, or other lawful transfer mechanisms recognized under the GDPR.
By using our Services and providing us with your personal information, you acknowledge and consent to the transfer, storage, and processing of your data in Canada and in any other country where our service providers operate, subject to the safeguards described in this Policy.
14. Data Breach Notification
In the unfortunate event of a data breach that affects your personal information, RFDA has established procedures to respond promptly and effectively. A data breach includes any unauthorized access to, acquisition of, disclosure of, or loss of personal information under our control.
Upon discovering a breach, our incident response team will immediately take steps to contain the incident, assess the scope and impact, and restore the security of our systems. We will notify affected individuals and relevant regulatory authorities in accordance with the requirements of applicable law. Under PIPEDA, we are required to report any breach of security safeguards involving personal information that poses a real risk of significant harm to the affected individuals to the Office of the Privacy Commissioner of Canada, and to notify the affected individuals directly.
Our notification will include a description of the nature of the breach, the types of personal information involved, the steps we have taken to contain and remediate the breach, and recommendations for steps you can take to protect yourself against potential harm. We will also provide contact information for our privacy officer so that you can obtain further information or assistance.
15. Changes to This Privacy Policy
RFDA reserves the right to update or modify this Privacy Policy from time to time to reflect changes in our data processing practices, legal obligations, or business operations. When we make material changes to this Policy, we will update the Effective Date at the top of the document and post a notice on our website at least thirty (30) days before the changes take effect.
Where required by law, we will also notify you directly of material changes by sending an email to the address we have on file for you or by other reasonable means. Your continued use of our Services after the effective date of any revised Privacy Policy constitutes your acknowledgment and acceptance of the updated terms.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your personal information. Historical versions of this Policy are available upon request.
16. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or RFDAs data handling practices, please contact us using the information below. We take all privacy-related inquiries seriously and will make every effort to address your concerns promptly and thoroughly.
Data Controller: Loco Sky Ltd., operating as RFDA
Lead Engineer and Developer: Kara Small Opal
Registered Office: 9759 Northville Crescent Rr 1, Thedford, Ontario, N0M 2N0, Canada
Email: support@rfda.buzz
Telephone: +62 838 9182 9638
Website: www.rfda.buzz
If you are not satisfied with our response to your privacy concern, you have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada or with the data protection authority in your jurisdiction. We are committed to cooperating fully with any such investigation.
If you are located in the European Economic Area and believe that your data protection rights have been infringed, you may contact your local supervisory authority. A list of EU data protection authorities and their contact details is available on the European Data Protection Board website.