Privacy Policy
Effective Date: June 1, 2026
Last Updated: June 1, 2026
The Jennic Group Inc. (“The Jennic Group,” “TJG,” “we,” “our,” or “us”) respects your privacy and is committed to protecting personal information in our care. This Privacy Policy explains how we collect, use, disclose, store, and protect personal information through our website, business communications, client relationships, cybersecurity services, managed IT services, and related professional services.
The Jennic Group is based in Ontario, Canada and provides cybersecurity-first technology services to businesses and organizations. We may work with clients, partners, vendors, and service providers in Canada, the United States, and other jurisdictions.
This Privacy Policy is intended to support our compliance with applicable privacy laws, including Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”), provincial privacy laws where applicable, and other privacy or data protection requirements that may apply to specific client relationships.
1. Scope of This Policy
This Privacy Policy applies to personal information we collect or process in connection with:
Visits to our website
Contact forms, email, phone, video meetings, and other communications
Business development and client relationship management
Cybersecurity, monitoring, managed IT, consulting, support, and related services
Billing, administration, contracting, and account management
Events, referrals, partnerships, and vendor relationships
Where The Jennic Group processes information on behalf of a client as part of contracted services, that information may also be governed by the applicable master services agreement, statement of work, data processing terms, confidentiality agreement, or other written agreement between The Jennic Group and the client.
2. Information We May Collect
The type of information we collect depends on the nature of our relationship with you or your organization.
We may collect:
Business Contact Information
This may include your name, title, company name, business address, email address, phone number, and related communication details.
Website and Communication Information
When you visit our website or communicate with us, we may collect information such as your IP address, browser type, device information, pages visited, referring website, form submissions, email communications, and other information you choose to provide.
Client and Service Information
In providing cybersecurity, managed IT, monitoring, support, consulting, and related services, we may access or process limited information necessary to deliver those services. This may include:
Usernames, business email addresses, and account identifiers
Device names, endpoint information, system information, and network information
Security alerts, log data, monitoring data, and event information
Cloud service, email, identity, and SaaS application security data
Support tickets, service history, diagnostic information, and troubleshooting notes
Backup, configuration, asset, documentation, and operational information
Information required for onboarding, implementation, support, reporting, billing, and administration
We do not intentionally collect more personal information than is reasonably necessary for the services we provide.
3. How We Collect Information
We may collect information directly from you, from your organization, from authorized client representatives, from our website, from technology platforms used to deliver our services, from third-party service providers, and from security, monitoring, support, or administrative tools configured for client environments.
We may also receive information from referrals, professional advisors, partners, vendors, and other lawful business sources.
4. How We Use Information
We use personal information and service-related information for purposes such as:
Responding to inquiries and communications
Providing cybersecurity, managed IT, monitoring, consulting, and support services
Onboarding clients and configuring services
Managing client accounts and business relationships
Detecting, investigating, responding to, and reporting security events
Monitoring systems, devices, users, cloud environments, and applications where authorized
Providing service reports, recommendations, documentation, and support
Managing billing, contracts, payments, and administration
Improving our services, systems, security, and operations
Meeting legal, regulatory, contractual, audit, insurance, and compliance obligations
Protecting The Jennic Group, our clients, users, systems, and data from fraud, misuse, unauthorized access, cyber threats, and operational risk
We use information only for purposes that are reasonable and appropriate in the circumstances, or as otherwise permitted or required by law.
5. Legal Basis and Consent
Where required by applicable law, we rely on consent to collect, use, or disclose personal information. Consent may be express or implied, depending on the context and sensitivity of the information.
In some cases, we may collect, use, or disclose information without consent where permitted or required by law, including for security, fraud prevention, legal compliance, contractual performance, or legitimate business purposes.
For clients subject to privacy laws such as the GDPR or UK GDPR, The Jennic Group may process personal information under the legal basis determined by the client, where the client acts as the controller or equivalent decision-maker and The Jennic Group acts as a service provider or processor.
6. Client Data and Service Data
The Jennic Group may process information on behalf of clients as part of contracted cybersecurity, monitoring, support, and managed IT services. In these situations, our client generally determines the purposes for which the information is processed, and The Jennic Group processes the information to provide the agreed services.
Examples may include security event data, user activity indicators, device information, email security information, cloud application data, identity-related security signals, support records, and other technical or operational data.
We do not sell client data or use client service data for unrelated marketing purposes.
7. Disclosure of Information
We may disclose information where reasonably necessary to:
Provide services to clients
Work with trusted technology providers, cloud providers, cybersecurity platforms, monitoring tools, vendors, subcontractors, and professional advisors
Respond to authorized client instructions
Comply with legal, regulatory, contractual, audit, or insurance requirements
Investigate or respond to security incidents, cyber threats, fraud, misuse, or unauthorized activity
Protect the rights, safety, systems, data, property, or operations of The Jennic Group, our clients, users, or others
Complete a business transaction, such as a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate safeguards
We do not sell personal information.
8. Third-Party Service Providers and Technology Partners
The Jennic Group uses trusted third-party service providers, cloud platforms, cybersecurity tools, software vendors, professional advisors, and subcontractors to support the delivery of our services and business operations.
These providers may access or process information only as reasonably required to perform services for us or for our clients. We take reasonable steps to select providers that maintain appropriate privacy, security, confidentiality, and data protection practices.
Depending on the services provided to a client, technology partners may include providers of cybersecurity monitoring, endpoint security, backup, cloud services, email security, identity protection, documentation, remote management, ticketing, billing, reporting, and related business systems.
Additional vendor, subprocessor, or platform details may be provided to clients where required by contract, security review, or applicable law.
9. Cross-Border Processing and Storage
The Jennic Group is based in Canada, and information may be processed or stored in Canada, the United States, or other jurisdictions where we, our clients, our service providers, or our technology partners operate.
Where information is processed outside the country or region where it was originally collected, it may be subject to the laws of that jurisdiction, including lawful access by courts, law enforcement, regulators, or government authorities.
We use contractual, technical, administrative, and organizational safeguards designed to protect information in accordance with applicable privacy and security requirements.
Where required for international clients or regulated environments, The Jennic Group may enter into appropriate data protection agreements, data processing addenda, standard contractual clauses, or equivalent contractual safeguards.
10. Security Safeguards
As a cybersecurity-first organization, The Jennic Group takes the protection of information seriously. We use reasonable physical, technical, administrative, and organizational safeguards designed to protect information against unauthorized access, disclosure, copying, use, modification, loss, theft, and misuse.
Safeguards may include access controls, authentication controls, monitoring, logging, encryption where appropriate, least-privilege access, endpoint protection, backup controls, security awareness practices, vendor review, internal procedures, and other measures appropriate to the sensitivity of the information.
No system, network, platform, or method of transmission is completely secure. We work to reduce risk and maintain safeguards appropriate to the nature of the information and services involved.
11. Security Incidents and Breach Notification
If The Jennic Group becomes aware of a security incident involving personal information under our control, we will assess the incident and take reasonable steps to contain, investigate, remediate, and document the matter.
Where required by applicable law or contract, we will notify affected clients, individuals, regulators, or other parties. Notification obligations may vary depending on the nature of the incident, the type of information involved, the jurisdiction, and the applicable agreement.
12. Retention of Information
We retain personal information and service-related information only as long as reasonably necessary for the purposes described in this Privacy Policy, or as required for service delivery, security, business administration, legal compliance, contractual obligations, dispute resolution, audit, insurance, backup, and operational requirements.
Retention periods may vary depending on the nature of the information, the service involved, client instructions, legal requirements, and business needs.
When information is no longer required, we will take reasonable steps to securely delete, anonymize, or dispose of it, subject to legal, contractual, backup, and operational limitations.
13. Accuracy and Access
We take reasonable steps to ensure that personal information in our care is accurate, complete, and up to date for the purposes for which it is used.
Individuals may request access to, correction of, or information about their personal information, subject to legal, contractual, security, and confidentiality limitations.
Where The Jennic Group processes information on behalf of a client, requests from individuals may need to be directed to the client organization that controls the information.
14. Your Choices and Rights
Depending on your location and applicable law, you may have the right to:
Request access to your personal information
Request correction of inaccurate personal information
Withdraw consent, where processing is based on consent
Ask questions about our privacy practices
Request information about how your personal information is used or disclosed
Request deletion, restriction, portability, or objection where applicable under specific privacy laws
These rights may be subject to limitations under applicable law, contract, security requirements, and our need to retain certain information for legitimate business, legal, or operational reasons.
15. Marketing Communications
We may use business contact information to communicate with clients, prospects, partners, and other business contacts about our services, events, updates, or related business matters.
You may unsubscribe from marketing communications where applicable. We may still send service-related, security-related, contractual, billing, or administrative communications when necessary.
16. Cookies and Website Analytics
Our website may use cookies, analytics tools, or similar technologies to improve website performance, understand visitor activity, and support business operations.
You may be able to adjust your browser settings to refuse or limit cookies. Some website features may not function properly if cookies are disabled.
17. Links to Other Websites
Our website may contain links to third-party websites, tools, platforms, or resources. The Jennic Group is not responsible for the privacy practices, security, or content of third-party websites or services. We encourage you to review the privacy policies of any third-party websites you visit.
18. Children’s Privacy
Our services are intended for businesses and organizations, not for children. We do not knowingly collect personal information from children through our website or business services. If we become aware that we have collected personal information from a child without appropriate consent, we will take reasonable steps to delete it.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, technology, business operations, or privacy practices.
The updated version will be posted on our website with a revised “Last Updated” date. Continued use of our website or services after changes are posted means the updated Privacy Policy applies.
20. Contact Us
If you have questions about this Privacy Policy, our privacy practices, or how personal information is handled, please contact us:
The Jennic Group Inc.
Waterloo, Ontario, Canada
Website: https://www.jennicgroup.com
Email: privacy@jennicgroup.com
Phone: 519-651-6332 ext. 200
For privacy-related requests, please include your name, organization, contact information, and a description of your request so we can respond appropriately.