Skip to main content
Back to home
Legal

Privacy Policy

Last updated: May 23, 2026

This Privacy Policy describes how StackArc (“StackArc”, “we”, “our”) collects, uses, and protects personal information when you visit stackarc.io, request a demo, sign up for a scan, or otherwise interact with our services.

This document is written to align with the obligations of Quebec Law 25 (the Act respecting the protection of personal information in the private sector) and the federal Personal Information Protection and Electronic Documents Act (PIPEDA).

1. Information we collect

We collect the minimum information required to deliver our services:

  • Contact information you provide voluntarily — email address, full name, organization, role — when you request a demo, subscribe to updates, or contact us.
  • Technical scan metadata when you onboard your AWS account for scanning: AWS account ID, scan timestamps, and findings generated by our deterministic rule engine. We do not collect or store AWS credentials.
  • Website usage data limited to the technical minimum required to operate stackarc.io (server logs, IP address, browser type, pages visited). No third-party analytics, advertising trackers, or session-replay tools are deployed on this site.

2. How we use information

We use personal information solely to:

  • Deliver, maintain, and improve the StackArc service;
  • Respond to your requests, questions, or support tickets;
  • Send service-related communications (scan results, security alerts, subscription notices);
  • Comply with applicable legal, accounting, regulatory, and security obligations.

We do not sell personal information. We do not share personal information with advertising networks or data brokers.

3. Lawful basis (Loi 25 / PIPEDA)

We rely on the following lawful bases for processing: consent (explicit, freely given, informed), performance of a contract, legal obligation, and our legitimate interests in operating a secure service. You may withdraw consent at any time by emailing privacy@stackarc.io.

4. Data location and transfer

Customer scan data is stored in encrypted form within Canadian AWS regions (ca-central-1) by default. We may use sub-processors located outside Canada strictly for infrastructure operations (e.g., deliverability of transactional email). The complete and current list is available at /sub-processors.

5. Retention

Scan output is retained for the duration of your subscription plus a thirty-day grace period after termination. Marketing contact information is retained until you unsubscribe. Server logs are retained for ninety days for security and troubleshooting purposes, then deleted.

6. Your rights

Under Loi 25 and PIPEDA, you have the right to:

  • Access the personal information we hold about you;
  • Request correction of inaccurate information;
  • Request deletion (subject to legal-retention exceptions);
  • Object to or limit certain processing;
  • Request data portability in a structured format;
  • Lodge a complaint with the Commission d'accès à l'information du Québec (CAI) or the Office of the Privacy Commissioner of Canada (OPC).

To exercise any of these rights, email privacy@stackarc.io. We respond within thirty days.

7. Security

We implement technical and organizational measures aligned with SOC 2 Type II and ISO 27001 expectations: encryption at rest and in transit, principle of least privilege, multi-factor authentication for all administrative access, continuous monitoring, and an incident-response plan.

8. Changes to this policy

Material changes are notified by email to active customers and posted on this page with a revised “last updated” date.

9. Privacy Officer

StackArc's Privacy Officer can be reached at privacy@stackarc.io.

Notice — template document. This Privacy Policy is provided as a working template and should be reviewed by qualified legal counsel familiar with Quebec Law 25 and PIPEDA before commercial launch. Specific provisions may need to be adapted to StackArc's final business model, sub-processors, and target jurisdictions.