Privacy Policy
Last Updated: March 14, 2026
1. Introduction & Controller Identity
This Privacy Policy explains how Northstack Academy (“we”, “us”, “our”) collects, uses, shares, and protects personal data when you visit our website or contact us about training programmes and admissions. This policy applies to the site available at northstackacademy.ca and any forms or communications connected to it.
Data Controller: Northstack Academy Inc., 100 King St W, 57th Floor, Toronto, ON M5X 1C7, Canada. Contact email: [email protected]. Phone: +1 416 915 2867.
We do not appoint a Data Protection Officer as a matter of course because we do not conduct large-scale processing of special-category data. If you have questions about how we handle personal data, contact us using the details above.
2. Personal Data We Collect
The personal data we collect depends on how you interact with the site. We collect data you provide directly and data collected automatically by the site and its infrastructure.
- Identity and contact data: name, email address, phone number (if provided).
- Form content: messages you send through our forms, including programme interests, timelines, role goals, and any context you choose to include.
- Technical data: IP address, browser type/version, device type, operating system, language preferences, and approximate location derived from IP (city/region level).
- Usage data: pages viewed, time spent on pages, referrer/entry page, click paths, and interaction events (for example, form starts and submissions).
- Cookies and identifiers: cookie identifiers and consent state stored in your browser (see Section 4).
- Conversion events: events that indicate an action was taken (for example, a successful form submission and redirect to the thank-you page).
We do not intentionally collect special-category personal data (such as health information, religious beliefs, political opinions), government identification numbers, or financial account details through this website. Please do not include that type of information in free-text form fields.
3. Why We Process Personal Data & Legal Bases
If you are located in the European Economic Area (EEA) or the United Kingdom, we rely on the legal bases in Article 6 of the General Data Protection Regulation (GDPR) and the UK GDPR. Where Canadian law applies, we process personal information for reasonable purposes and with consent where required.
- Contact and admissions enquiries: to respond to your request, recommend a programme path, and coordinate next steps. Legal basis: GDPR Art. 6(1)(b) (steps prior to entering a contract) and Art. 6(1)(a) (consent where you provide it).
- Analytics and site improvement: to understand which pages are useful, fix confusing flows, and reduce errors. Legal basis: GDPR Art. 6(1)(a) (consent) where required by law.
- Marketing and remarketing: to measure ad performance and (if enabled) to show relevant ads on third-party platforms. Legal basis: GDPR Art. 6(1)(a) (consent).
- Security and abuse prevention: to protect the website, detect malicious traffic, and prevent fraud. Legal basis: GDPR Art. 6(1)(f) (legitimate interests).
- Legal compliance: to meet applicable legal obligations (for example, recordkeeping where required). Legal basis: GDPR Art. 6(1)(c).
Automated decision-making: We do not engage in automated decision-making or profiling that produces legal or similarly significant effects within the meaning of GDPR Article 22.
4. Cookies & Tracking Technologies
Cookies are small text files stored on your device. We also use similar technologies such as pixel tags and server-side event calls (where enabled) to measure performance, improve usability, and (with consent) support advertising attribution.
We group cookies and tracking into three categories, which align with the preferences you can set via the cookie banner and cookie preferences panel:
Essential (always active)
Essential cookies are required for the site to function properly. They include items that maintain session continuity and store your cookie choices. These cookies do not require consent in many jurisdictions, because without them the site cannot operate reliably.
- _site_session (first-party): supports basic session continuity.
- cookie_consent (first-party): stores your cookie category choices for up to 12 months.
Analytics (consent-based)
Analytics cookies help us understand traffic and improve pages. When analytics is enabled, we may use Google Analytics 4 (GA4) with IP anonymization. GA4 uses identifiers such as _ga and _ga_XXXXXXXXXX to distinguish visits and sessions. Analytics data retention is typically set to 14 months.
Marketing (consent-based)
Marketing cookies are used for personalized advertising, conversion attribution, and remarketing audiences. When marketing is enabled, cookies may include identifiers such as _gcl_au (Google Ads) and _fbp / _fbc (Meta). These can be used to measure which ads led to a form submission and to build audiences for future campaigns.
For additional cookie details, see our Cookie Policy.
5. Consent and Managing Preferences
Users in the EEA and UK receive a consent notice under GDPR/UK GDPR. Analytics and marketing cookies activate only after explicit, informed, freely given consent (GDPR Art. 6(1)(a)). Your consent choice is recorded in the cookie_consent browser cookie and retained for up to 12 months.
You may withdraw consent at any time by using the “Manage cookie preferences” link in the footer or by clearing cookies in your browser. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
6. Sharing With Advertising & Service Partners
We share personal data only as needed to operate the website, respond to enquiries, and (if you consent) measure and improve advertising. We do not sell personal data.
- Google LLC (Analytics, Ads, Tag Manager, remarketing): may receive cookie identifiers, usage data, and conversion events for measurement and audience creation. Privacy policy: policies.google.com/privacy.
- Meta Platforms (Pixel, Custom/Lookalike Audiences, Conversion API where enabled): may receive events such as page views and conversions plus identifiers used for attribution and audience tools. Privacy policy: facebook.com/privacy/policy.
- Cloudflare (CDN and security): may process IP and traffic metadata to detect threats and improve delivery. Privacy policy: cloudflare.com/privacypolicy/.
We do not permit these providers to use site data for their own independent commercial purposes beyond providing services to us, subject to their contractual terms and applicable law. Some providers may act as independent controllers for certain processing, as described in their own privacy documentation.
7. International Transfers
Some of our service partners may process data outside Canada, including in the United States. Where GDPR/UK GDPR applies, international transfers may be supported by the EU–US Data Privacy Framework (including the UK Extension and Swiss–US DPF where relevant). Where needed, we rely on Standard Contractual Clauses (EU 2021/914) and UK IDTA-style safeguards as a fallback.
Transfer mechanisms and safeguards can evolve. If you want more detail about the safeguards applicable to a particular transfer, contact us using the details in Section 18.
8. Data Retention
We keep personal data only as long as it is reasonably needed for the purposes described in this policy, unless a longer retention period is required by law. Typical retention periods:
- Contact submissions: up to 2 years from last interaction (to keep admissions context consistent and avoid repeated questions).
- Email correspondence: for the duration of the relationship, then typically 1 year.
- Server and security logs: typically up to 90 days unless needed for investigation.
- Analytics data: typically 14 months (settings can vary by configuration).
- Marketing cookies: retained according to cookie lifetime (for example, 90 days) unless you withdraw consent earlier.
- Cookie consent record: up to 3 years for auditability of consent practices.
- Legal and compliance retention: where required by applicable law, which may be 6 to 10 years for certain records.
9. Your Rights (GDPR & UK GDPR)
If you are in the EEA or UK, you may have rights under GDPR/UK GDPR, including:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restrict processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right to withdraw consent at any time (Art. 7(3))
- Right to lodge a complaint with a supervisory authority (Art. 77)
To exercise a right, email [email protected]. We typically respond within 30 days. For complex requests, the response time may be extended by up to 60 additional days where permitted by law. We may need to verify identity before completing a request.
Supervisory authority resources: for EU guidance see edpb.europa.eu. For the UK, see ico.org.uk. National authorities include bfdi.bund.de (Germany), cnil.fr (France), uodo.gov.pl (Poland), and aepd.es (Spain).
10. Children
This site is not directed at individuals under 16. We do not knowingly collect personal data from children under 16 without verifiable parental consent. If we learn that we have collected such data, we will delete it promptly.
11. Do Not Track
This website does not respond to “Do Not Track” (DNT) browser signals. Third-party providers may have their own DNT handling or opt-out mechanisms, which you can access through their privacy pages and advertising settings.
12. Data Deletion Requests
You can request deletion of personal data by emailing us with the subject line “Data Deletion Request.” We will complete deletion within 30 days after verifying identity, unless we must retain certain information for legal compliance or to establish, exercise, or defend legal claims.
13. Business Transfers
In a merger, acquisition, asset sale, financing, or insolvency, personal data may be transferred to a successor entity as part of the transaction. If such a transfer materially changes how data is used, we will provide notice on the site.
14. California (CCPA / CPRA)
This section applies to California residents where the California Consumer Privacy Act (CCPA), as amended by the CPRA, is applicable.
Categories of personal information disclosed in the last 12 months may include: identifiers (such as name, email, IP address, device IDs), internet/network activity (such as page views and interactions), and inferences (such as interests inferred from pages viewed). We disclose these categories to service providers and, where consent is provided or otherwise permitted, advertising partners for measurement and cross-context behavioral advertising.
We do not sell personal information as defined by CCPA. We may share personal information for cross-context behavioral advertising. California residents may opt out via our cookie preferences panel (accessible through “Manage cookie preferences” in the footer).
Rights may include: right to know, delete, correct, and opt out of sale/sharing, and the right to non-discrimination. To submit a request, email [email protected] with the subject “California Privacy Request.” We will verify identity before responding. Authorized agents may submit requests with proof of authority.
15. Virginia (VCDPA)
Virginia residents may have rights to access, correct, delete, and obtain a portable copy of personal data, and to opt out of targeted advertising. We do not sell personal data and do not engage in profiling that produces legal or similarly significant effects.
Submit requests by emailing [email protected] with the subject “Virginia Privacy Request.” If we decline a request, you may appeal by emailing with the subject “Appeal of Refusal — Privacy Request.” We respond to appeals within 60 days where required.
16. Nevada
Nevada residents may submit a verified opt-out request by emailing us with the subject “Nevada Do Not Sell Request.” We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.
17. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will post a notice on the homepage at least 14 days before the changes take effect. The “Last Updated” date at the top of this page reflects the most recent revision.
18. Contact
If you have questions, requests, or complaints regarding this Privacy Policy or our handling of personal data, contact:
Northstack Academy Inc.
100 King St W, 57th Floor
Toronto, ON M5X 1C7, Canada
Email: [email protected]
Phone: +1 416 915 2867