The purpose of this Privacy Notice is to provide information about how Xiphos collects and uses personal information, with whom we share information, and your rights and choices with respect to the information. This Privacy Notice also describes some of the security measures we take to protect your information, and how you may contact us about our privacy policies.
Personal Information We Collect
Xiphos collects and processes personal data that you, as the data subject, provide to us.
- a. Information collected automatically: Xiphos collects certain information automatically when you visit our websites: like many web sites, we also collect information that your browser sends whenever you visit our site (“Log Data”): This Log Data may include information such as your Internet Protocol (IP) address, browser type, browser version, the pages of our website that you visit, the time spent on those pages and other statistics: In addition, we may use third-party service providers who collect, monitor and analyze Log Data in order to help us improve our website and product and service offerings.
- b. Identifiers and Contact Information: This may include, but is not limited to, name, postal address, Internet Protocol (IP) address, email address, telephone number, and similar identifiers.
For job applicants and employees, this may also include other information such as social security number / social insurance number, date of birth, driver’s license number, passport number, or other similar identifiers.
- c. Personal Records: This may include, but is not limited to, education, employment, employment history, other information required for background checks, credit card number, banking information or any other financial information.
- d. Internet Usage Information: This may include, but is not limited to, browsing history, search history, and information regarding your interaction with a web site, application, or advertisement: We collect this information for the purpose of tracking the use of the web site.
How We Use Information We Collect
Xiphos may use the personal information we collect about you or that you provide to us for the following purposes:
- Responding to requests for information, including requests made through forms found on our websites;
- Providing products and services, performing our contracts, and otherwise operating our business
- Processing employment applications, evaluating candidate employment qualifications, and contacting individuals regarding employment opportunities where appropriate
- Performing human resources functions for Xiphos and its employees
- Providing marketing, partner or corporate communication notices
- Preparing and submitting bids and proposals to customers, including government and private sector entities
- Managing our relationship with you and the organization you represent
- Protecting Xiphos, its employees, and its business partners against cybersecurity and other security events, espionage, fraud, insider threats, and other unlawful activity, and claims and other liabilities
- Protecting Xiphos’ personnel and property;
- Exercising Xiphos’ legal rights; and
- Complying with and enforcing applicable legal requirements, industry standards, and Xiphos’ policies.
Except in rare circumstances where we are required by law to disclose or otherwise process your personal information, we will only process your personal information as necessary for the purposes explained to you when the information is collected or as otherwise described in this notice.
How We Share Information We Collect
Xiphos does not sell, lease, rent, or license the personal information it collects to third parties.
Xiphos may disclose personal information to third parties in the following circumstances:
- To third-party service providers to facilitate the services they provide
- To submit bids for proposals from the government or commercial customers
- To perform contractual services for customers (including, for example, with a subcontractor or a prime contractor for which we are a subcontractor)
- To protect Xiphos’ rights, privacy, safety, or property, and that of its customers, employees, its affiliates, users, and others
- To support an investigation of cybersecurity and other security events, espionage, fraud, insider threats, and other illegal activity
- In the event of a merger, sale, transfer, or other disposition of all or any portion of Xiphos’ business assets or stock
- When requested by law enforcement or other government authorities
- When required by law, regulation, court order, or other legal process; and
- For any other legal purpose.
Xiphos routinely requires the third-party business partners to which it provides personal information to protect and maintain that information in confidence, and not to license, sell or otherwise transfer such information except as directed by Xiphos.
To enrich and optimize your online experience, Xiphos uses “cookies”, similar technologies and third-party service providers to display personalized content, appropriate advertising, and store your preferences on your computer.
Children Under the Age of 13
Xiphos’ website is not directed to or intended for children under the age of 13: We do not knowingly solicit, store, or use personal information of children under the age of 13, except as permitted by law: Children under the age of 13 should not register for services or provide any personal information, including name, address, telephone number or email address to Xiphos: If Xiphos becomes aware it has inadvertently collected personal information of children under the age of 13, it will promptly delete such information.
Xiphos is committed to maintaining the security of the information collected on our website: Xiphos implements commercially reasonable and appropriate technical, physical, procedural, and administrative measures to prevent the loss of, misuse of, disclosure of, alteration of, destruction of, and unauthorized access to the personal information you provide: However, no Internet-based information system is completely secure and Xiphos cannot eliminate all security risks associated with the electronic transfer and storage of information, including your personal information: Xiphos accepts no liability for events for which Xiphos is not responsible or for which Xiphos does not have control: If you have reason to believe that your interaction with Xiphos is no longer secure, please immediately notify Xiphos using the contact information on the website.
Changes to Our Privacy Notice
Xiphos reserves the right to amend this Privacy Notice at any time, for any reason, without notice, other than posting of the amended Privacy Notice at this website: Xiphos suggests you check this page regularly to see our most up-to-date Privacy Notice: Changes are effective on the date Xiphos posts the revised Privacy Notice to its website and supersedes all previous versions of the Privacy Notice.
If you are located within the European Union or another country that has adopted the EU General Data Protection Regulation (“GDPR”), the following applies:
- You have the right to access, modify, rectify, limit and/or delete any personal information as well as a right of opposition, if necessary, subject to legitimate and imperative reasons, to the processing of these data. If you wish to exercise your rights, you can contact us via the contact information on our web site.
- You also have the right to lodge a complaint with a supervisory authority.
- For data processing based on your consent, you have the right to withdraw your consent to the processing of your data at any time. The withdrawal does not affect the lawfulness of processing based on your consent before its withdrawal: If you would like to withdraw your consent please contact via the contact information on our web site.
- You have the right to object to the processing of your personal data at any time on grounds relating to your particular situation. We may ask you to provide the reasons and legitimate interest to back up your objection. In case of a legal objection, we shall no longer process your personal data unless we have compelling legitimate grounds for the processing which override your interests, rights and freedoms of the data subject or for the establishment, exercise or defense of legal claims. We shall inform you on the grounds of our decisions.
Purpose for Processing. Xiphos collects and processes your personal data, as the data subject, for the purpose of communicating with you regarding the business of Xiphos, its subsidiaries, or affiliates: We are also obliged to comply with regulatory requirements for export control, screening of visitors, and various other requirements: The processing of your personal information may also be automatically processed or screened as necessary for entering into, or performance of, a contract between you as the data subject and us as the data Controller: For these reasons, if you choose not to provide personal information, you may not be able to do business with us or access our facility.
Legal Basis for Processing. The legal basis for processing the personal information of the data subject is a) the data subject’s consent; b) it is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; c) it is necessary for compliance with a legal obligation to which the Controller is subject.
Third Party Data Processing: We may process the information to third parties for the purpose set out above. Some third-party recipients of data may reside outside the European Union. In the event that the recipient country does not ensure a level of data protection equivalent to that of the European Union, the company undertakes to take all appropriate guarantees, either on the basis of an adequacy decision such as that for the Privacy Shield, or, in the absence of such a decision, on the basis of appropriate guarantees.
Transfer of Information to Canada: Xiphos is headquartered in Canada and in the Province of Quebec, and its business information systems are primarily located in Canada: If you are not located in Canada, we want to advise you that any personal information you provide through Xiphos’ website and third-party online services will be transferred out of your country and to Canada: By providing personal information through Xiphos’ website and third-party online services, you expressly consent to the transfer of this information to Canada and other countries in which we or our affiliates may operate in support of our customers: If you do not want your personal information to be transferred to Canada or to other countries in which we or our affiliates may operate in support of our customers, please do not use Xiphos’ website and third-party online services or provide personal information through them.
Data Retention: The retention period for information depends on and is determined by company policies, regulatory requirements, and other factors such as the need for data storage space.
Controller: For purposes of GDPR, the Controller is: Xiphos Systems, Inc., 3981 St-Laurent Blvd., Montreal, Quebec H2W 1Y5 CANADA
This California Privacy Notice applies to “Consumers” as defined by the California Consumer Privacy Act (“CCPA”) as a supplement to other privacy policies or notices: To aid in readability, in some places we have abbreviated or summarized CCPA terms or language. Terms defined in the CCPA that are used in this notice shall have the same meaning as in the CCPA: For more information on this notice or your California privacy rights please contact us using the contact information found on our web site.
- a. Personal Information We Collect: Please see section 1, above, for a description of the categories of personal information we may collect from Consumers as defined by the CCPA.
- b. Using and Sharing Personal Information: As described in sections 2 and 3, above, we may use and share personal information with third parties for a business purpose: We may disclose for a business purpose to the following categories of third parties:
- Our affiliates
- Service providers
- Third parties to whom you or your agents authorize us to disclose your personal information in connection with products or services we provide to you
As permitted by applicable law, we do not treat de-identified data or aggregate consumer information as personal information and we reserve the right to convert, or permit others to convert, your personal information into de-identified data or aggregate consumer information.
In the last twelve (12) months, we have not sold any personal information.
- c. California Privacy Rights: We provide California Consumers the privacy rights described in this section. You have the right to exercise these rights via an authorized agent who meets the agency requirements of the CCPA and related regulations. As permitted by the CCPA, any request you submit to us is subject to an identification process. We will not fulfill your CCPA request unless you have provided sufficient information for us to reasonably verify you are the Consumer about whom we collected personal information.
If we cannot comply with a request, we will explain the reasons in our response. We will use personal information provided in your request only to verify your identity or authority to make the request and to track and document request responses, unless you also gave it to us for another purpose.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive or clearly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
- i. Access to Specific Information and Data Portability Rights: You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months. Additionally, you have the right to make or obtain a transportable copy, no more than twice in a twelve-month period, of your personal information that we have collected in the period that is 12 months prior to the request date and are maintaining. Once we receive and confirm your request, we will disclose to you:
- The categories of personal information we have collected about you
- The categories of sources from which we collected your personal information
- The business or commercial purposes for our collecting or selling your personal information
- The categories of third parties to whom we have shared your personal information
- The specific pieces of personal information we have collected about you
- A list of the categories of personal information disclosed for a business purpose in the prior 12 months, or that no disclosure occurred
- A list of the categories of personal information sold about you in the prior 12 months, or that no sale occurred
If we sold your personal information, we will explain:
- The categories of your personal information we have sold.
- The categories of third parties to which we sold personal information, by categories of personal information sold for each third party.
- ii. Deletion Request Rights: Except to the extent we have a basis for retention under CCPA, you may request that we delete your personal information that we have collected directly from you and are maintaining. Our retention rights include, without limitation, to complete transactions and services you have requested or that are reasonably anticipated, for security purposes, for legitimate internal business purposes, including maintaining business records, to comply with law, to exercise or defend legal claims, and to cooperate with law enforcement. Note also that we are not required to delete your personal information that we did not collect directly from you.
- iii. Do Not Sell: We do not sell your personal information as such is defined under the CCPA, and until such time as we change this policy by updating this notice, will treat personal information collected under that policy as subject to a “do not sell” request.
- iv. Ours and Other’s Rights: Notwithstanding anything to the contrary, we may collect, use and disclose your personal information as required or permitted by applicable law and this may override your CCPA rights: In addition, we need not honor any of your requests to the extent that doing so would infringe upon our or any other person or party’s rights or conflict with applicable law.
- v. Changes to Our Privacy Notice: We reserve the right to amend this notice at our discretion and at any time. When we make changes to this notice, we will notify you through a notice on our website homepage.
- vii. Person in Charge of the Protection of Personal Information: The person in charge of the enforcement of the CCPA respecting the protection of personal information in the private sector is also charged with the compliance to this law. To provide feedback or a complaint related to the non-compliance with this law, you may contact:
Francesco Ricci, Xiphos Systems, Inc., 3981 St-Laurent Blvd., Montreal, Quebec H2W 1Y5 CANADA