Privacy Policy Shyftlabs

Version 2.0 · Effective 18 September 2026

1. Who we are

Illuminz Solutions Inc., a company incorporated in Canada and operating as ShyftLabs, is the organization responsible for the personal information described in this policy. In this policy, “ShyftLabs”, “we”, “us” and “our” mean Illuminz Solutions Inc.

Illuminz Solutions Inc. (operating as ShyftLabs)
100 Yonge St, Suite 1501
Toronto, Ontario M5C 2W1
Canada

2. What this policy covers

This policy explains how we handle personal information about:

  • people who visit shyftlabs.io;
  • people who contact us, request information, or meet us at events;
  • people who apply for jobs with us;
  • our contacts at client, prospect, partner and supplier organizations.

This policy does not cover two things.

When we deliver services to a client, we usually handle personal information on that client’s instructions and on their behalf. In that situation the client decides what happens to the information and we act as their service provider. The applicable agreement with the client, which may include our Data Processing Agreement, sets out the terms, and the client’s own privacy notice explains the processing to the people concerned. If you believe we hold information about you on a client’s behalf, see section 11.

Our products have their own privacy notices, which describe processing specific to each product. Where a product notice applies, it takes precedence over this one for that product.

3. How to reach us about privacy

Our Data Protection Officer is also our Privacy Officer for Canadian and Quebec purposes. All privacy inquiries, including requests to exercise your rights, can be directed to the same place.

Data Protection Officer and Privacy Officer

dpo@shyftlabs.io
Illuminz Solutions Inc.
Attn: Data Protection Officer
100 Yonge St, Suite 1501, Toronto, Ontario M5C 2W1, Canada

Representative in the European Union

Illuminz Solutions Inc. has appointed EU Rep as its Representative under Article 27 of the EU General Data Protection Regulation. GDPR queries from EU data subjects or data protection authorities should be submitted through the dedicated form at eurep.ie.
BizLegal Ltd, trading as EU Rep, registered office 27 Cork Road, Midleton, Co. Cork, Ireland. Company number 635921.

4. Information we collect, and why
When you visit our website

Our servers and analytics tools may automatically collect technical information such as IP address, browser type and version, device type, operating system, referring page, the pages you view, and the date and time of your visit.

We use this to keep the site running and secure, to understand which content is useful, and to detect and investigate misuse. Our lawful basis is our legitimate interest in operating and protecting our website. Where analytics or similar non-essential technologies are involved, we rely on your consent, given through our cookie banner or privacy settings.

When you contact us

If you complete a form, email us, or speak to us at an event, we collect your name, contact details, the organization you represent, and whatever you tell us in your message.

We use this to respond to you, and to keep a record of our discussions. Our lawful basis is our legitimate interest in responding to inquiries and managing our business relationships, or the steps necessary to enter into a contract with you.

When you apply for a job

We collect your CV and application, your contact details, your work history and qualifications, your right to work where relevant, interview notes and assessments, and references where you have agreed we may take them.

We use this to assess your application and run our hiring process. Our lawful basis is the steps necessary to enter into a contract with you, and our legitimate interest in recruiting for our business. We do not require you to provide sensitive personal information that is not relevant to your application, and we ask you not to include it unless we request it for a legitimate recruitment or legal purpose.

When we work with you

For our contacts at client, prospect, partner and supplier organizations, we may hold business contact details, role and organization, correspondence, meeting records, and the commercial details of our relationship.

We use this to deliver our services, manage the relationship, meet our legal and tax obligations, and keep our own records. Our lawful basis is the performance of our contract with your organization, our legitimate interest in managing business relationships, and compliance with our legal obligations.

Marketing

If you have asked to hear from us, or you are a business contact with a relevant interest in what we do, we may send you occasional updates. Every message we send identifies us and includes a way to unsubscribe, as Canada’s Anti-Spam Legislation requires. Our lawful basis is your consent, or our legitimate interest in business communications where permitted by applicable law. You can unsubscribe at any time, from any message or by emailing us.

5. Cookies

We use cookies and similar technologies. Some are strictly necessary for the site to work and cannot be switched off. Others help us understand how the site is used, or remember your preferences, and those are only used where we have obtained any consent required by applicable law.

You can accept or decline non-essential cookies through our cookie banner or privacy settings, and change your choice at any time through the cookie settings link on our site. You can also block or delete cookies through your browser, though parts of the site may then not work properly.

6. Automated decisions

ShyftLabs does not currently engage in automated decision-making using the personal information covered by this policy that has a legal or similarly significant effect on you, and we do not use that personal information for automated profiling of that kind.

7. Who we share information with

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

We use service providers to run our website and our business. They act on our instructions, are bound by written agreements including confidentiality and data protection terms, and are required to process personal information in accordance with those agreements and applicable law. They fall into these categories:

  • cloud infrastructure and website hosting;
  • website analytics and tag management;
  • cookie consent management;
  • customer relationship management and email delivery;
  • recruitment and applicant tracking;
  • security monitoring and error reporting.

We also share information with our professional advisers, including auditors, lawyers, accountants and insurers, where they need it to advise us; with authorities, courts and regulators where the law requires it, or where we need to establish, exercise or defend legal claims; and, if we are ever part of a merger, acquisition or sale of assets, with those involved in the transaction. We will tell you if such a transaction changes how your information is handled.

You can ask us at any time for more information about the categories of service providers we use and, where required by applicable law, information about specific providers.

8. Where your information is held

We are based in Canada and generally process and store personal information in Canada, including through infrastructure located in Canada. Some of our service providers may process or store information in other countries, including the United States.

If you are in the EEA, the UK or Switzerland, your personal information may be transferred to and processed in Canada and other countries where we or our service providers operate. Where applicable, we rely on recognized adequacy decisions or other lawful transfer mechanisms. Where required, we use Standard Contractual Clauses approved by the European Commission and applicable UK transfer mechanisms for transfers from the UK. You can ask us for a copy of the safeguards we use.

If you are in Quebec, your personal information may be stored or processed outside Quebec, including as described above. Where required by applicable law, we assess such transfers before they occur.

9. How long we keep it

Information

How long we keep it

Website technical logs

generally up to 90 days

Inquiries and correspondence

generally up to 24 months after our last contact with you

Unsuccessful job applications

generally up to 12 months after we tell you our decision, unless you ask us to keep your details on file for future roles

Client and supplier records

for the duration of the relationship and generally up to 7 years afterwards, or longer where required by law

Marketing consents and unsubscribe records

for as long as reasonably necessary to demonstrate and respect your marketing preferences, including after you unsubscribe

Where a legal obligation, a limitation period, our legitimate business needs, or an ongoing dispute requires us to keep information for longer, we do, and we keep it only as long as reasonably necessary for that purpose.

10. How we protect it

Illuminz Solutions Inc. operates an information security management system certified to ISO/IEC 27001:2022 and a privacy information management system certified to ISO/IEC 27701:2019. Our controls include, as appropriate, measures such as encryption in transit and at rest, multi-factor authentication, role-based access control, background checks and confidentiality agreements for personnel, security training, vulnerability management, and documented incident response. Information about our certifications and compliance program is available at trust.shyftlabs.io.

No system is completely secure. If a breach affects your personal information, we will provide notifications to affected individuals and relevant authorities where required by applicable law.

11. Your rights

Subject to the law that applies to you, you have the following rights:

  • Right to be informed about how we collect and use your personal information. This policy is how we do that.
  • Right of access to the personal information we hold about you, and to a copy of it.
  • Right to rectification of personal information that is inaccurate or incomplete.
  • Right to erasure, also known as the right to be forgotten, where we no longer have a lawful reason to keep your information.
  • Right to restrict processing in certain circumstances, so that we store your information but do not otherwise use it.
  • Right to data portability, to receive the information you gave us in a structured, commonly used, machine-readable format, and to have it sent to another organization where technically feasible.
  • Right to object to processing based on our legitimate interests, and to object to direct marketing at any time.
  • Rights in relation to automated decision-making and profiling, including the right not to be subject to a decision based solely on automated processing that produces a legal or similarly significant effect. As set out in section 6, we do not carry out processing of that kind.

Where we rely on your consent, you can withdraw it at any time. That does not affect anything we did before you withdrew it.

If you are in Quebec, you also have the right to ask us to stop disseminating your information, or to de-index it, where the law provides. If you are in California, you have the right not to be discriminated against for exercising your rights. We do not sell personal information and we do not share it for cross-context behavioral advertising.

How to exercise your rights

Email dpo@shyftlabs.io. We will respond within the timeframe required by applicable law and, where permitted, may extend that period for complex or numerous requests. We may need to confirm your identity first. We generally do not charge a fee, except where permitted by applicable law.

If we hold the information on behalf of a client, we will handle your request in accordance with our obligations to that client and applicable law, which may include referring the request to the client.

If you are unhappy with how we have handled your request, please tell us so we can put it right. You also have the right to complain to your data protection or privacy regulator, which in Canada is the Office of the Privacy Commissioner of Canada, in Quebec the Commission d’accès à l’information, and in the EEA or the UK your national supervisory authority.

12. Children

Our website and our services are intended for businesses and for adults. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us their information, email dpo@shyftlabs.io and we will take appropriate steps to delete it.

13. Changes to this policy

We update this policy when our practices change or the law requires it. The current version is always on this page, with its version number and effective date at the top. If a change materially affects how we handle your information, we will provide notice in an appropriate manner, and where the law requires it we will contact you directly.

14. Contact

dpo@shyftlabs.io

Illuminz Solutions Inc. (operating as ShyftLabs)
Attn: Data Protection Officer
100 Yonge St, Suite 1501
Toronto, Ontario M5C 2W1
Canada