Privacy Policy

Last updated: 3 September 2026

This Privacy Policy (the “Policy”) describes how Adsy Media (operated by Kairen Whittock), carrying on business as Adsy Media (“we”, “us” or “our”), collects, uses, discloses, retains, safeguards and disposes of personal information in the course of operating the online technology and startups magazine published at adsy-media.com (the “Site”). We are established in Canada and our handling of personal information in the course of commercial activity is governed principally by the federal Personal Information Protection and Electronic Documents Act (“PIPEDA”), together with the other laws described in this Policy where they apply to a particular reader.

In this Policy, “personal information” means information about an identifiable individual, as that expression is understood under PIPEDA. “Processing” is used in the sense given to it by the European Union General Data Protection Regulation. “You” means any visitor to, subscriber of, or contributor to the Site.

1. Who we are and how to reach us

The organization accountable for the personal information described in this Policy is Adsy Media (operated by Kairen Whittock), 2090 Lonsdale Cres, Abbotsford, British Columbia, V2T 1C4, Canada. Consistent with the Accountability principle in Schedule 1 of PIPEDA, we have designated an individual who is accountable for our compliance with this Policy. You may contact that person:

  • by email, for privacy matters, at [email protected];
  • by email, for general enquiries, at [email protected];
  • by email, for legal notices, at [email protected];
  • by telephone at +1 604-850-8125; or
  • by post at the address above, marked “Attention: Privacy Officer”.

2. The ten fair information principles

Schedule 1 of PIPEDA sets out ten fair information principles that we treat as the backbone of this Policy: accountability; identifying purposes; consent; limiting collection; limiting use, disclosure and retention; accuracy; safeguards; openness; individual access; and challenging compliance. Each of the sections that follow maps to one or more of those principles, and the Office of the Privacy Commissioner of Canada publishes a plain-language explanation of them on its website at priv.gc.ca.

3. Personal information we collect

3.1 Information you give us directly

  • Contact and enquiry forms. Your name, email address, the subject of your message and the message body, plus anything you choose to attach. Where a form relates to a pitch, tip or press release, we also collect the organization you say you represent.
  • Newsletter subscriptions. Your email address, the date, time and IP address of the subscription request, the double opt-in confirmation event, and your engagement history with our emails (whether a message was delivered, opened or clicked, where those signals are available).
  • Comments. The display name and email address you enter, the comment text, and the URL of the page commented on. Our commenting system is built on WordPress, which by default records the commenter’s IP address and browser user-agent string as an anti-abuse measure.
  • Gravatar. WordPress may transmit a one-way cryptographic hash of your comment email address to the Gravatar service operated by Automattic Inc. so that an avatar can be displayed next to your comment. Gravatar’s handling of that hash is described in the Automattic Privacy Policy.
  • Correspondence. Email, telephone and messaging correspondence you initiate with our editorial, legal or commercial contacts, including any information you volunteer in it.
  • Contributor and applicant information. If you pitch as a freelance contributor or apply to work with us, the contact details, biography, work samples and payment-administration information necessary to assess and, if applicable, engage you.

3.2 Information collected automatically

  • Server logs. Our web servers and content delivery network record the requesting IP address, the date and time of the request, the URL requested, the HTTP status and bytes served, the referring URL and the user-agent string. These logs are generated for every visitor and are used for delivery, security and fraud prevention.
  • Cookies and similar technologies. Cookies, browser localStorage, tracking pixels and embedded software development kits. A full inventory, including named cookies and durations, is set out in our Cookie Policy.
  • Analytics. Pseudonymous measurement data collected through Google Analytics 4, including a randomly assigned client identifier, session and engagement metrics, approximate location derived from IP address, device and browser characteristics, and the pages viewed.
  • Advertising identifiers. Cookie identifiers and, on mobile platforms, advertising identifiers made available by the operating system, used by advertising partners to cap frequency, measure performance and, where permitted, personalise advertising.

3.3 Information from third parties

We may receive personal information from our newsletter platform (bounce and complaint feedback), from advertising partners (aggregated and, occasionally, pseudonymous performance data), from payment and invoicing providers used for commercial arrangements, and from publicly available sources where we are verifying a story. We do not purchase marketing lists.

4. Purposes for which we use personal information

Consistent with the Identifying Purposes and Limiting Use principles, we use personal information only for the following purposes:

  1. to publish, operate, secure and maintain the Site and deliver its content to you;
  2. to answer your enquiries, pitches, tips, complaints and legal notices;
  3. to publish and moderate comments, and to detect and block spam, brigading and abuse;
  4. to send the newsletter you asked for, and to administer subscriptions and unsubscribes;
  5. to measure and improve editorial performance and the technical health of the Site;
  6. to serve advertising, to measure its delivery and effectiveness, and to fulfil our reporting obligations to advertising partners;
  7. to administer commercial, contributor and supplier relationships, including invoicing and record-keeping;
  8. to establish, exercise or defend legal claims, to respond to lawful requests from public authorities, and to comply with our legal and regulatory obligations, including record-keeping obligations under PIPEDA and tax law.

We will not use personal information for a materially new purpose without first identifying that purpose to you and, where required, obtaining your consent.

5. Consent and legal bases

5.1 Under PIPEDA

Our lawful authority for most processing in Canada is your consent, which may be express or implied depending on the sensitivity of the information and the reasonable expectations of a reader. We rely on express consent (a deliberate, affirmative act such as double opt-in) for the newsletter and for non-essential cookies. We rely on implied consent for the operational logging that is inseparable from serving a web page you have requested. Certain limited processing proceeds without consent where PIPEDA permits it, for example where collection is clearly in your interests and consent cannot be obtained in a timely way, or where use or disclosure is required by law. You may withdraw consent at any time, subject to legal and contractual restrictions and on reasonable notice, and we will tell you the likely consequences of withdrawal before giving effect to it.

5.2 Under the GDPR and UK GDPR

Where the GDPR or UK GDPR applies to our processing of your personal data, we rely on the following Article 6 lawful bases:

Processing activity Article 6 lawful basis
Serving requested pages; essential security and abuse prevention logging Art. 6(1)(f) legitimate interests — operating and protecting a publication
Responding to your enquiry, pitch or complaint Art. 6(1)(b) performance of a contract or steps at your request; Art. 6(1)(f)
Newsletter delivery Art. 6(1)(a) consent
Publishing and moderating your comment Art. 6(1)(a) consent, and Art. 6(1)(f) for moderation records
Analytics through non-essential cookies Art. 6(1)(a) consent
Advertising and ad measurement through non-essential cookies Art. 6(1)(a) consent
Invoicing, accounting and statutory record-keeping Art. 6(1)(c) legal obligation
Establishing, exercising or defending legal claims Art. 6(1)(f) legitimate interests

Where the lawful basis is consent, you may withdraw it at any time without affecting the lawfulness of processing already carried out. Where the basis is legitimate interests, you may object, and we will stop unless we can demonstrate compelling grounds that override your interests.

5.3 Electronic messages and CASL

Our commercial electronic messages are sent in accordance with Canada’s Anti-Spam Legislation (“CASL”), which the Canadian Radio-television and Telecommunications Commission enforces. Every newsletter identifies us, gives a mailing address that remains valid for at least 60 days after the message is sent, and includes an unsubscribe mechanism that can be readily performed and that remains valid for at least 60 days. We give effect to unsubscribe requests without delay and in any event within 10 business days, as CASL requires.

6. Advertising, analytics and other third parties

We disclose personal information to service providers and partners only as needed for the purposes above, and under contractual terms requiring a comparable level of protection. The categories, and the principal named recipients, are:

  • Advertising. Google LLC, through Google AdSense and associated Google publisher services. As Google requires of its publishers, we disclose that third-party vendors, including Google, use cookies to serve ads based on your prior visits to this Site or other websites, and that Google’s use of advertising cookies enables it and its partners to serve ads to you based on your visit to this Site and/or other sites on the internet. Google’s practices are described in the Google advertising technologies notice and in How Google uses information from sites or apps that use our services. You may opt out of personalised advertising in Google My Ad Center.
  • Analytics. Google Analytics 4, operated by Google LLC and governed by the Google Privacy & Terms for business. We have enabled IP address handling consistent with Google’s regional data-handling controls and we do not upload directly identifying information into Analytics.
  • Comment avatars. Automattic Inc. (Gravatar), under the Automattic Privacy Policy.
  • Hosting, content delivery and security. Infrastructure providers that store and transmit the Site and filter malicious traffic.
  • Email delivery. The email service provider that transmits our newsletter and transactional messages.
  • Professional advisers and authorities. Lawyers, auditors, insurers, and law enforcement or regulators where disclosure is required or permitted by law.

We do not sell personal information for money, and we do not disclose personal information to data brokers.

7. International transfers

We are based in Canada, and our providers may store or process personal information in Canada, the United States and the European Union. As the Office of the Privacy Commissioner of Canada has explained, a transfer for processing is a use rather than a disclosure, and the transferring organization remains accountable for the information. Personal information handled outside Canada may be accessible to the courts, law enforcement and national security authorities of the receiving jurisdiction. Where we transfer personal data out of the European Economic Area or the United Kingdom to a country without an adequacy decision, we rely on the European Commission’s standard contractual clauses or, for the United Kingdom, the International Data Transfer Agreement or Addendum, supplemented where necessary by a transfer risk assessment. Canada continues to benefit from a European Commission adequacy finding in respect of commercial organizations subject to PIPEDA.

8. Retention

We retain personal information only as long as necessary for the purpose for which it was collected, or as required by law, and we then delete or de-identify it. Our current schedule is:

Category Retention period Basis
Contact-form and enquiry correspondence 24 months from last contact Editorial follow-up and dispute resolution
Newsletter subscriber record and consent evidence Duration of subscription, then 36 months after unsubscribe Proof of consent and unsubscribe under CASL
Published comments and associated commenter details Indefinitely while the article remains published, or until you ask us to remove them Integrity of the published record
Spam and moderation queue entries 30 days Abuse prevention
Raw web server and CDN logs 90 days, then aggregated Security, diagnostics and fraud prevention
Google Analytics event and user data 14 months (property-level retention setting) Measurement
Advertising cookie identifiers Per the durations in our Cookie Policy, maximum 24 months Ad delivery and measurement
Contributor, supplier and invoicing records 7 years from the end of the relevant tax year Tax and accounting obligations
Breach records under PIPEDA s. 10.3 24 months from the day the breach was determined to have occurred Statutory record-keeping
Records of access, correction and rights requests 36 months from closure Demonstrating compliance

9. Security safeguards

We protect personal information with safeguards appropriate to its sensitivity, comprising physical, organizational and technological measures. These include HTTPS/TLS encryption in transit across the whole Site; encryption at rest for databases and backups where the provider supports it; multi-factor authentication and role-based access control for administrative accounts; least-privilege access limited to staff and contractors with a need to know; patching and dependency monitoring for the content management system and plugins; web application firewalling and rate limiting; logging and alerting on administrative activity; written confidentiality obligations in contributor and supplier contracts; and periodic review of this Policy and of the vendors named in it. No method of transmission or storage over the internet is perfectly secure, and we cannot guarantee absolute security.

10. Breach of security safeguards

If a breach of security safeguards involving personal information under our control occurs and it is reasonable in the circumstances to believe that the breach creates a real risk of significant harm to an individual, we will report the breach to the Privacy Commissioner of Canada and notify the affected individuals as soon as feasible, as PIPEDA requires. In assessing real risk of significant harm we consider the sensitivity of the personal information involved and the probability that it has been, is being, or will be misused, along with any other prescribed factor. “Significant harm” includes bodily harm, humiliation, damage to reputation or relationships, loss of employment or professional opportunity, financial loss, identity theft, negative effects on a credit record, and damage to or loss of property. We also notify any other organization or government institution that may be able to reduce the risk of harm. Independently of whether a breach is reportable, we keep a record of every breach of security safeguards for 24 months and will make those records available to the Commissioner on request. Where the GDPR or UK GDPR applies, we will notify the competent supervisory authority within 72 hours of becoming aware of a notifiable personal data breach and inform affected individuals where the breach is likely to result in a high risk to their rights and freedoms.

11. Children

The Site is a business and technology publication written for an adult, professional readership. It is not directed to children, and we do not knowingly collect personal information from a child. We treat the personal information of any individual we know to be a minor as sensitive, and we do not rely on consent obtained from a young child. If you believe a child has provided us with personal information, please write to [email protected] and we will delete it. We do not knowingly permit advertising partners to serve personalised advertising to users we know to be children.

12. Your rights under PIPEDA

Subject to the limited exceptions in the Act, you have the right to:

  1. Access — be told whether we hold personal information about you, what it is used for, and to whom it has been disclosed, and to receive a copy of it;
  2. Correction — challenge the accuracy and completeness of that information and have it amended as appropriate, with the amendment transmitted to third parties who have the information where practicable;
  3. Withdraw consent — withdraw consent to a use or disclosure at any time, subject to legal and contractual restrictions and reasonable notice;
  4. Challenge compliance — complain to our Privacy Officer about our handling of your personal information and receive a substantive response.

To exercise any of these rights, write to [email protected] with enough information for us to locate your records. We will respond to an access request no later than 30 days after receiving it, or notify you within that period of an extension permitted by the Act and the reason for it. We may ask you to verify your identity, and we will not charge a fee without first telling you the approximate cost and obtaining your agreement to proceed. Where we refuse a request in whole or in part, we will tell you the reasons and the recourse available.

12.1 Quebec, Alberta and British Columbia

If you are in Quebec, Quebec’s Act respecting the protection of personal information in the private sector, as amended by the legislation commonly called Law 25, may give you additional rights, including rights relating to the confidentiality of technological products by default, notification when personal information is used to render a decision based exclusively on automated processing, and a right to data portability in a structured, commonly used technological format. Those rights are overseen by the Commission d’accès à l’information du Québec. If you are in Alberta or British Columbia, the provincial Personal Information Protection Act in force in your province has been declared substantially similar to PIPEDA and is administered by the Office of the Information and Privacy Commissioner of Alberta or the Office of the Information and Privacy Commissioner for British Columbia respectively. We will give effect to the provincial standard where it applies to us and is more protective.

12.2 Federal privacy reform

Canada’s federal private-sector privacy framework is under active reform. On 15 June 2026 the Government of Canada introduced Bill C-36, which proposes the Protecting Privacy and Consumer Data Act to replace Part 1 of PIPEDA and to consolidate oversight in a new federal commission. As at the date of this Policy the Bill had received first reading only and was not in force; PIPEDA continues to apply. We will update this Policy if and when the reform is enacted.

13. Rights of readers in the EU and the UK

If you are in the European Economic Area, Switzerland or the United Kingdom, you have the rights of access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, objection to direct marketing at any time, withdrawal of consent, and the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. We do not make such automated decisions. To exercise a right, write to [email protected]; we will respond within one month, extendable by two further months for complex requests. You may also lodge a complaint with your national supervisory authority, or in the United Kingdom with the Information Commissioner’s Office. A list of EEA authorities is maintained by the European Data Protection Board.

14. Rights of California readers

If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act may give you the rights to know what personal information we collect, use, disclose and share and the categories of sources and recipients; to obtain a copy of that information; to delete it; to correct inaccurate information; to opt out of the “sale” or “sharing” of personal information, including sharing for cross-context behavioural advertising; to limit the use and disclosure of sensitive personal information; and not to be discriminated against or retaliated against for exercising a right. We do not sell personal information for monetary consideration. Because advertising partners may set cookies that constitute “sharing” for cross-context behavioural advertising under that statute, you may opt out by declining or withdrawing consent to advertising cookies through the consent controls on the Site, and by sending a Global Privacy Control signal from your browser, which we treat as a valid opt-out request. Requests may be submitted to [email protected] and may be made by an authorised agent. The California Privacy Protection Agency and the California Attorney General enforce that statute.

15. Do Not Track and Global Privacy Control

There is no common industry standard for responding to browser “Do Not Track” headers, and we do not represent that we respond to them. We do honour the Global Privacy Control signal as an opt-out of the sale or sharing of personal information and of cross-context behavioural advertising, where it is transmitted by your browser.

16. Cookies

Detailed information about cookies, pixels, local storage and software development kits used on the Site, including named cookies, first- or third-party status, purpose, duration and the tools available to control them, is set out in our Cookie Policy, which forms part of this Policy.

17. Challenging our compliance and complaining to the OPC

Please raise any concern with us first, at [email protected]. We will acknowledge your concern, investigate it, and give you a written response. If you are not satisfied with our response, or if we do not respond, you may report your concern to the Office of the Privacy Commissioner of Canada. The OPC generally expects an individual to have raised the matter with the organization first. Following a Commissioner’s report of findings, PIPEDA also allows an individual to apply to the Federal Court for a hearing in respect of certain matters within the time limit set out in the Act.

18. Changes to this Policy

We may amend this Policy to reflect changes in our practices, our vendors, or the law. When we do, we will revise the “Last updated” date at the top of the page, and we will describe material changes prominently on the Site before they take effect. Where a change would involve using personal information already collected for a materially different purpose, we will seek your consent. Superseded versions are retained internally so that we can identify the terms that applied at any given time.

19. Contact

Privacy questions, access and correction requests, rights requests and complaints: [email protected]. General enquiries: [email protected]. Legal notices: [email protected]. Copyright notices: [email protected]. Telephone: +1 604-850-8125. Post: Adsy Media (operated by Kairen Whittock), 2090 Lonsdale Cres, Abbotsford, British Columbia, V2T 1C4, Canada.

This Policy is provided for transparency and does not constitute legal advice.