Privacy policy
Custodyne Canada Inc. (“Custodyne”, “we”, “us”, or “our”) provides a platform that documents the Chain of Custody of data-bearing media and produces disposal approvals and certificates of destruction. We treat the personal information entrusted to us as a matter of record integrity and legal defensibility. This policy explains what personal information we collect, why we collect it, how we protect it, and the choices available to you.
1. Who we are and how to reach us
Custodyne is operated by Custodyne Canada Inc., a company with its head office in Surrey, British Columbia, Canada. We are responsible for the personal information under our control.
Questions about this policy, or requests concerning your personal information, may be directed to our privacy contact:
- Privacy contact: support@custodyne.ca
- Mailing address: 300 - 15300 Croydon Drive, Surrey, BC V3Z 0Z5, Canada
- Privacy officer: a designated Privacy Officer of Custodyne Canada Inc., reachable at the contact address above
2. Scope, and the two roles we play
This policy applies to the Custodyne website at custodyne.ca and to the Custodyne platform (together, the “Service”). We handle personal information in two distinct roles, and the role determines who is accountable for it:
- As the accountable organization. For our own business contacts, for the administrators and staff of subscribing organizations who hold Custodyne accounts, and for visitors to our website, we determine the purposes for which personal information is used and are directly accountable for it.
- As a service provider acting for a subscriber. A subscribing organization — typically a Managed Service Provider (a “Subscriber”) — uses the Service to document media that belongs to the Subscriber’s own customers, and to collect approvals from the individuals who sign them (“Signers”). For that information, the Subscriber is the accountable organization, and we process it on the Subscriber’s documented instructions under a data processing addendum, which is available to a Subscriber on request. Where this policy and that addendum differ for Signer or customer information, the addendum governs.
3. Personal information we collect
3.1 From website visitors
The Custodyne website loads no third-party trackers, no advertising cookies, and no externally hosted fonts or scripts. When you submit the contact or beta program request form, we collect the name, company, work email address, and user count you provide. Our servers keep standard technical logs — including internet protocol (IP) address and browser user-agent — for security and diagnostics.
If you use the assistant on our website, we record the conversation: the messages you send, the assistant’s replies, and any name, email address or company name you choose to give so that we can respond to you. Please do not enter personal information about your own customers, or details of a specific drive, device or certificate — the assistant has no access to those records and does not need them in order to help you. We do not record your IP address in connection with the assistant.
3.2 From Subscriber staff (account users)
When an individual is given access to a Subscriber’s Custodyne account, we collect their name, work email address, assigned role, authentication metadata, and a record of the actions they take in the Service (an administrative audit log). Custodyne does not store staff passwords: staff sign in using a single-use link sent to their work email address. Sign-in through an organization’s Microsoft Entra ID is planned, and this policy will be updated before it is introduced.
3.3 Information we process on behalf of a Subscriber
In the course of documenting a media disposal, the Service records the following on the Subscriber’s behalf:
- Signer identity: the first name, last name, and email address the Signer types, together with the Signer’s attestation that the Signer is authorized to approve the disposal.
- Signature evidence: the signature (drawn or typed), a server-side timestamp recorded in Coordinated Universal Time (UTC), the Signer’s IP address, browser user-agent and device information, an explicit electronic-signature consent indicator, and a cryptographic hash of the exact document presented at signing.
- Media and custody records: drive make, model, serial number, and capacity; photographs of the drive and its label; custody-transfer events; and the recorded result of any wipe or destruction.
- Records pulled from a connected professional services automation (PSA) system: where a Subscriber connects its PSA, we retrieve the associated company, site, telephone number, contact name, and email address for the relevant ticket.
4. Why we use personal information
We use personal information to:
- provide, maintain, and secure the Service;
- create and preserve the Chain-of-Custody record and the resulting disposal approvals and certificates of destruction;
- authenticate staff users and administer accounts;
- send transactional email — specifically signature-request and signature-completed messages — in connection with a disposal;
- detect, prevent, and investigate security incidents, fraud, and misuse, and to debug and improve the Service;
- comply with legal and regulatory obligations; and
- where you have consented, send you product and service communications.
We do not sell personal information, we do not use it for third-party advertising, and we do not use Subscriber, Signer, or customer information to train external artificial-intelligence models, except as described for label extraction in section 5.
5. Automated processing and cross-border transfer
To reduce manual entry, photographs of a drive label may be transmitted to Anthropic, PBC, a provider located in the United States, for the sole purpose of extracting text fields — manufacturer, model, serial number, and capacity — from the label. This is a transfer of personal information outside Canada. The extracted values are proposed to a technician for review; the Service does not make any automated decision that produces legal effects about an individual. Anthropic processes the images under its commercial terms, which provide that inputs are not used to train its models (Anthropic Commercial Terms of Service, effective 17 June 2025: “Anthropic may not train models on Customer Content from Services”). A Subscriber that does not wish to use automated extraction may enter label fields manually.
Website assistant. Messages you send to the assistant on our website, and the replies it gives, are transmitted to Anthropic, PBC in the United States in order to generate a response. This is a transfer of personal information outside Canada, and the information is therefore subject to the laws of the United States and may be accessible to authorities there under those laws. Anthropic acts as our service provider for this purpose and processes the conversation under the same commercial terms cited above. Using the assistant is entirely voluntary: if you would prefer not to have a conversation processed in this way, the contact form and support@custodyne.ca reach us just as well.
6. Consent and legal basis
We handle personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. We rely on consent and on legitimate business purposes appropriate to the sensitivity of the information. For Signer and customer information, the Subscriber is the accountable organization and is responsible for obtaining any consent required before that information is entered into the Service. Where other privacy laws apply to a Subscriber or its customers, we will support the Subscriber’s compliance as agreed in the applicable addendum.
7. Service providers and disclosure
We share personal information only as needed to operate the Service, and with providers bound to protect it:
- Hosting and storage: Custodyne-controlled infrastructure located in British Columbia, Canada. Microsoft Azure, in the Canada Central region, is the planned destination; this policy will be updated before any such move.
- Network delivery and encryption in transit: Cloudflare, Inc. (United States), which provides authoritative DNS for custodyne.ca and terminates the encrypted connection through which the Service is reached.
- Authentication: single-use sign-in links issued by the Service itself. No third-party identity provider is used at present; Microsoft Entra ID is planned, and this policy will be updated before it is introduced.
- Label extraction: Anthropic, PBC (United States), as described in section 5.
- Website assistant: Anthropic, PBC (United States), which generates the assistant’s replies, as described in section 5.
- Transactional email delivery: SMTP2GO, operated by Sand Dune Mail Ltd (New Zealand).
- Connected PSA: a Subscriber’s own professional services automation system, at the Subscriber’s direction.
We may also disclose personal information where required to comply with applicable law, a subpoena, or other lawful request; to enforce our agreements; to protect the rights, safety, and property of Custodyne, our Subscribers, or others; and in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
8. Where your information is stored
Personal information in the Service is stored primarily in Canada. Some flows may cross a border: label extraction, which is processed in the United States (section 5); network delivery and encryption in transit, provided by Cloudflare, Inc. (United States); and transactional email delivery, provided by Sand Dune Mail Ltd (New Zealand). When personal information is located in, or accessible from, another country, it may be subject to the laws of that country, including lawful access by its courts and government authorities.
9. How we protect personal information
We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the information. These include:
- encryption of personal information in transit and at rest;
- write-once, immutable (WORM) storage for signed documents and signature evidence, so a completed record cannot be altered or deleted;
- an append-only custody ledger enforced at the database level, so custody events cannot be edited or removed — corrections are recorded as new events;
- strict separation of each Subscriber’s data (tenant isolation), enforced centrally and tested;
- role-based access controls and least-privilege access for staff and administrators;
- passwordless sign-in using single-use links sent to a staff member’s work email address, with no local passwords stored by Custodyne;
- cryptographic hashing (SHA-256) of documents and stored files to detect any tampering;
- rate limiting on signing and authentication endpoints, and validation of uploaded files; and
- audit logging of administrative and configuration changes.
No method of transmission or storage is perfectly secure. While we work to protect personal information, we cannot guarantee absolute security. This section describes safeguards designed into the Service; it does not assert any third-party certification or attestation.
10. How long we keep personal information
Because the purpose of a Chain-of-Custody record is to remain defensible over time, records and legal artifacts are retained for a period configured by the Subscriber, with a default of seven (7) years. Signature evidence and certificates of destruction are retained for that configured period. Information collected through the website, such as beta program requests, is kept only as long as needed for the purpose for which it was provided and is then deleted. Conversations with the website assistant are kept for ninety (90) days and are then deleted; where you give us your contact details through the assistant so that we can reply, those details are kept on the same basis as any other enquiry. On termination of a Subscriber’s account, information is handled as set out in the applicable agreement or data processing addendum.
11. Your privacy rights
Subject to applicable law and to reasonable limits, you may:
- ask whether we hold personal information about you, and request access to it;
- request correction of inaccurate or incomplete information;
- withdraw consent to a use of your personal information, subject to legal and contractual restrictions and to reasonable notice; and
- make a complaint about our handling of your personal information.
If your information was entered into the Service by a Subscriber — for example, if you are a Signer or a customer of a Subscriber — the Subscriber is the accountable organization, and you should direct your request to that Subscriber. We will assist the Subscriber in responding. To exercise a right, or to complain, contact us at support@custodyne.ca. You also have the right to complain to the Office of the Privacy Commissioner of Canada.
12. If a breach occurs
If a breach of security safeguards involving personal information under our control creates a real risk of significant harm to an individual, we will notify affected individuals and report to the Office of the Privacy Commissioner of Canada as required by PIPEDA, and we will keep records of breaches as the law requires. Where the affected information was processed on behalf of a Subscriber, we will notify the Subscriber without undue delay so that the Subscriber, as the accountable organization, can meet its own obligations.
13. Cookies and similar technologies
The Custodyne website does not set advertising or analytics cookies and does not load third-party resources. The Custodyne platform uses only strictly necessary cookies — for example, a secure session cookie and cross-site request forgery protection — required to sign you in and keep the Service secure.
The website assistant does not set a cookie. It holds a reference to your conversation in your browser for the duration of that conversation only, so that its replies follow on from what you have already said; nothing is retained on your device once you close the page.
14. Children
The Service is intended for use by businesses and their authorized representatives. It is not directed to children, and we do not knowingly collect personal information from children. The Service is not offered to individuals: access is granted only to personnel authorized by a subscribing organization, so no consumer age threshold applies.
15. Changes to this policy
We may update this policy from time to time. When we make a material change, we will update the “Last updated” date above and, where appropriate, provide additional notice. Continued use of the Service after a change takes effect means the updated policy applies to you.
Version 1.1 (2026/08/24). Added the website assistant: the conversation as a category of personal information collected (section 3), the transfer of conversations to Anthropic, PBC in the United States (sections 5 and 7), a ninety-day retention period for transcripts (section 10), and confirmation that the assistant sets no cookie (section 13). Corrected the rendering of Anthropic’s legal name to “Anthropic, PBC”.
16. How to contact us
To reach our privacy contact, or to exercise any right described above, contact support@custodyne.ca. You may also contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.
© 2026 Custodyne Canada Inc.