Privacy Policy
(Effective November 22, 2024)
Welcome!
Welcome to darcy! We hope you will enjoy and appreciate using our “Services”, which may be visiting or using the Website at https://www.darcysecurity.com/ (the “Website”), and which includes using the darcy online “Application” that you forward suspicious emails and texts, or share a voice call (an “Ask”) in order to help you identify online, text and phone scams. The subdomains of the Website include but are not limited to https://app.darcysecurity.com, where you can access your “Account” if you have signed up for a “Subscription” to access the Application.
FixMeStick Technologies Inc., the company that owns and operates darcy and the Services, want you to know we take your privacy and protection of personal data very seriously. We are providing this Privacy Policy (the “Policy”) to tell you about who we are, what personal data we collect from you and about you, and what we do with your personal data, all while you use the Services or otherwise interact with us. The Policy also explains your rights under the law, and how you can contact us and the necessary authorities to enforce those rights. We ask that you please read it carefully.
Key Elements / Summary of this Policy
Here are the key elements of this Policy so you can know the important parts right away to make an informed decision about your consent for our collection, use and disclosure of your personal data. By submitting any personal data to us via any means, you consent to such collection, use and disclosure. You can find the details in the rest of the Policy.
Personal data we collect from you but only with your consent
1. Contact Information (your email address)
2. Newsletter Information (your email address)
3. Subscription Information (your email address)
4. Billing Information (credit card information)
5. Ask Information (email addresses, phone numbers and any personal data included in your Asks)
What we do with it
1. Communicate with you
2. Send you our Newsletter
3. Manage your Account, communicate with you about the Services, and enable logging in to your Account
4. Process the payments of your Subscription Fees
5. Provide you with a response to your Ask
Third parties we share it with
1. Companies that provide support and communications services, such as Zendesk
2. Companies that provide communications services such as MailChimp
3. Companies that provide the infrastructure and software for the Services, such as Google Cloud
4. Payment processors such as Stripe
5. Companies that provide the infrastructure and software for the Services such as Google Cloud
Some Terms
Before we get started with the details, here are a few terms we think you should know as you read this Policy.
1. The “GDPR”, the European Data Protection Law which stands for “General Data Protection Regulation”, with the official name Regulation (EU) 2016/679 of the European Parliament and of the Council;
2. The “UK GDPR” which applies to our activities in the United Kingdom; please note that when this Policy refers only to the “GDPR”, this includes the UK GDPR, as applicable;
3. “PIPEDA” (Personal Information Protection and Electronic Documents Act), which is the Canadian Data Protection Law that applies to our activities in Canada;
4. Quebec’s Act Respecting the Protection of Personal Information in the Private Sector as amended by Law 25 (the “Quebec Private Sector Act”), which applies to our activities in Quebec;
5. The California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act which applies to our activities in the United States in certain circumstances; and
6. Other state privacy laws in force in the United States, such as those which are currently in force in Colorado, Connecticut, and Virginia.
“Personal data” – this is information we collect from you or about you and which is defined in the GDPR as “any information relating to an identified or identifiable natural person.” It can be as simple as your name or your email, or something more complicated like an online identifier (usually a string of letters and / or numbers) that gets attached to you. Under PIPEDA and the Quebec Private Sector Act, the equivalent concept is “personal information”, which is roughly the same. Any mention of “personal data” in this Policy shall also mean personal information.
Other terms and definitions used in this Policy may be found in our Terms of Service, and will have the same meaning in this Policy as they do there.
About Us and Contacting Us
FixMeStick Technologies Inc. (“FixMeStick”) is a duly-incorporated company in the Province of Quebec, Canada that owns and operates the Services and the “darcy” and “darcy security” names and trademarks. Where this Policy refers to “darcy”, it may refer to FixMeStick Technologies Inc. and / or its affiliates, and their shareholders, officers, directors, employees, agents, partners, principals, representatives, successors and assigns, depending on the context.
Under the GDPR, FixMeStick is a “data controller”. That means we collect personal data directly from you and determine the purpose and means of “processing” that data. “Processing” is a broad term that means collection, use, storage, transfer or any other action related to your personal data; it is used in this Policy in that way. Under PIPEDA, FixMeStick is an “organization”, and under the Quebec Private Sector Act, FixMeStick is an “enterprise”. Under PIPEDA, FixMeStick “collects, uses, and discloses” your personal data, and under the Quebec Private Sector Act, FixMeStick “collects, holds, uses or communicates to third persons” your personal data. When you read “processing” in this Policy, you can substitute either of those phrases.
If you want to ask us anything about what’s in this Policy, or anything else privacy- or data- related, or exercise any of your available privacy rights, you can email:
darcy Privacy and Data Protection Officer
privacy@darcysecurity.com
Here is the mailing address for you as well:
darcy Privacy and Data Protection Officer
642 Rue de Courcelle, Suite 317
Montreal, QC
Canada
H4C 3C5
Your Rights
You have the following rights regarding your personal data held by darcy, and other privacy rights. Please note that not necessarily all of these rights may be available to you; this depends on the Data Protection Laws where you are located that apply to you. These rights may be exercised without affecting the price you pay for any of the Services. Notwithstanding that, exercising certain of these rights may affect your ability to use some or all of the Services.
1. The right to withdraw at any time your consent for darcy to process your personal data;
2. The right to have your personal data erased from darcy’s records;
3. The right to have any hyperlink from the Services that is attached to your name removed;
4. The right to access your personal data and any relevant information around its processing and use;
5. The right to have a copy of your personal data given to you in an easy-to-read format so that you can transfer it to another data processor;
6. The right to have your personal data corrected or updated if you believe it is inaccurate or out of date;
7. The right to opt out of marketing communications we send you, at any time;
8. The right to know whether darcy sells or shares your personal data (and if so, who gets it). Please refer to that information elsewhere in this Policy, though you can contact our Privacy Officer if you need additional information or clarifications;
9. The right to restrict the processing of your personal data if it is inaccurate or if our processing or use of it is against the law; and
10. The right to refuse any marketing or advertising targeted at you by darcy.
If you wish to exercise any of these rights, please contact our Privacy and Data Protection Officer at the contact information above, or refer to certain relevant sections further in this Policy.
Personal Data Collected from You and What We Use It For
In the table below, please find all the personal data we may collect from you directly, what we use it for, and the legal basis under the GDPR for us having and processing this personal data. Under PIPEDA and the Quebec Private Sector Act, the legal basis is your informed consent, and by submitting this personal data you acknowledge having granted this consent to darcy.
Personal data category
1. Contact Information
2. Newsletter Information
3. Subscription Information
4. Billing Information*
5. Billing Information
6. Ask Information
Personal data processed
1. Email address
2. Email address
3. Email address
4. Credit card number, credit card expiry date, card security code (CVV), and billing address
5. Your billing address
6. Email addresses, phone numbers and any personal data included in your Asks
What we use it for(the “purpose” of processing)
1. Communicate with you2. Send you our Newsletter
3. Manage your Account, communicate with you about the Services, and enable logging in to your Account
4. Process the payments of your Subscription Fees
5. Create invoices and receipts for you as needed, and determine which local taxes to apply to your purchase of a Subscription
6. Provide you with a response to your Ask
Legal basis for processing under the GDPR
1. Your consent in giving us this information
2. Your consent in giving us this information
3. Your consent and performance of a contract between you and us
4. Your consent in giving us this information
5. Your consent in giving us this information
6. Your consent and performance of a contract between you and us
*Please note that your Billing Information, with the exception of your billing address, is collected via the Website, but is only ever stored on servers controlled by Third-Party Payment Processors; darcy does not have access to your credit card number, expiry date, or CVV code.
Where you have provided personal data by your consent, if you withdraw your consent to use such data, we will no longer be able to provide certain Services to you.
Personal Data Collected About You from Third Parties and What We Use It For
Sometimes we get personal data about you from third parties. This table explains the details about this personal data – what it is, where it came from and what we do with it. Under Data protection Laws, the legal basis for the processing of this personal data is your informed consent, and by using the Services, you agree that you have granted such consent to the person who collected it. None of this data comes from publicly-available sources.
Personal data category: Ask Information
Personal data collected by the third party: Email address and phone number
Who collects the personal data: An individual who signed up for a Subscription which has multiple email addresses and phone numbers, which may belong to you
What we use it for: Allow you to submit Asks to the Application and provide you with responses to your Asks
To the extent that analytics and advertising identifiers are generated from third parties, these may be considered personal data collected from third parties, and you can find details about that elsewhere in this Policy.
Sensitive Personal Data
We do not collect any of what the GDPR or the Quebec Private Sector Act considers sensitive personal data from you, unless you voluntarily submit it to us, which we encourage you not to do.
Who We Transfer Your Personal Data To
We routinely share some of your personal data with certain types of third parties who are identified in the table below along with what they do with it. Some of those third-party recipients may be based outside your home jurisdiction. If you are in the European Economic Area or the U.K., please see the “Transfer of Your Personal Data Outside of the European Economic Area” further down in this Policy for more information including on how we safeguard your personal data when this occurs. If you are in Quebec, please see the “Transfer of Your Personal Data Outside of Quebec” section further down in this Policy for information on how we safeguard your personal data when this occurs.
We will share personal data with law enforcement or other public authorities if: (1) we are required by applicable law in response to lawful requests, including to meet national security or law enforcement requirements; (2) if we believe it is necessary in order to investigate, prevent, or take action regarding illegal activities, fraud, or situations involving potential threats to the safety of any person, or any violation of darcy’s Terms of Service; or (3) if we believe it is necessary to investigate, prevent, or take action regarding situations that involve abuse of the Services infrastructure or the Internet in general (such as voluminous spamming or denial of service attacks).
We may also share personal data: (1) to a parent company, subsidiaries, joint ventures, or other companies under common control with darcy (in which case we will require such entities to honour this Policy); or (2) if darcy merges with another entity, is subject to a corporate reorganization, sells or transfers all or part of its business, assets or shares (in which case we will require such entity to assume our obligations under this Policy, or inform you that you are covered by a new privacy policy).
We will never share your personal data with other third parties except under these circumstances. We do not sell or rent your personal data to any third party for direct marketing purposes or any other purpose.
Personal data category
1. Contact Information
2. Newsletter information
3. Subscription Information
4. Billing Information
5. Ask Information
6. Advertising identifiers
7. Analytics identifiers and IP addresses
Who we transfer it to
1. Companies that provide support and communications services, such as Zendesk
2. Companies that provide email services, specifically MailChimp, as detailed more fully in the Email Communications section below
3. Companies providing technical infrastructure and software for the Services, such as Google Cloud
4. Payment processing companies, such as Stripe
5. Companies providing technical infrastructure and software for the Services, such as Google Cloud
6. Companies providing online advertising
7. Companies that provide data analytics, specifically Google Analytics
What they do with it
1. Store it so that we may retrieve it and reply to your inquiry
2. Store it and send you the newsletter
3. Control your logging in to your Account so you can access the Application
4. Process the payments of your Subscription Fees
5. Store it so that we can provide you with the Application and responses to your Asks
6. Show you ads for darcy and the Services when you are on the internet, as further detailed in the darcy Advertising section below
7. Provide us with analytics as to how the Services are used, and to trace fraudulent activities, as further detailed in the Limited Gathering of Information section below
Email Communications and Compliance with Anti-Spam Laws
darcy uses Intuit’s MailChimp (the “Email Service Provider”) to manage our mailing list and send out our newsletter, and to send out emails related to various Services functions. Personal data is transferred to the Email Service Provider in order to manage the mailing list and for the emails to be sent out properly. Your Newsletter Information and Subscription Information is only used to send out emails; the Email Service Provider does not use this personal data for any other purpose, and will not transfer or sell your personal data to any other third party. For more information, please refer to Intuit/MailChimp Privacy Policy.
You may unsubscribe from darcy’s newsletter mailing list at any time, by following the link at the bottom of those darcy emails. Other types of emails, such as transactional, relational, and other emails related to certain Services functions will not have an opt-out option as they are necessary for the use of the Services.
darcy’s practices in regards to its email are designed to be compliant with anti-spam laws, specifically the law unofficially called “CASL”, or Canada’s Anti-Spam Law (S.C. 2010, c. 23), and the American CAN-SPAM Act. If you believe you have received email in violation of these laws, please contact us using the contact information further up in this Policy.
darcy Advertising and Opting Out
darcy is continuously evaluating and modifying our use of various advertising networks, which may change from time to time. In this section you will find all the advertising networks that darcy currently uses and instructions for opting out of them. You may also opt out or decline such advertising by refusing or deleting the appropriate cookie, as described further in this Policy. For a more permanent solution, you may also opt out of such advertising by using the NAI (Network Advertising Initiative) online opt-out tool.
Generally, these ad networks work by delivering you advertisements that will be of particular interest to you when you use their website and / or apps, based on your browsing and activity history interacting with the Website.
The table below identifies the Advertising networks we currently use, as well as links and instructions on opting out. By visiting the Website or using the Services and accepting the appropriate cookie through our cookie banner, you consent to our advertising to you in this manner, understanding that you can opt out any time.
Advertising network
1. Facebook / Meta Ads
Link(s) and instructions to opt out
1. Adjust your Ad Preferences settings while logged in to Facebook
Limited Gathering of Information for Statistical, Analytical and Security Purposes
darcy automatically collects certain information using the “Third-Party Analytics Program” Google Analytics, to help us understand more about our Website visitors and Services users and how they use the Services, but none of this information identifies you personally, except via an alphanumeric string. For example, each time you visit the Website, we automatically collect (as applicable) your IP address, browser and computer or device type, access times, the web page from which you came, the web page(s) or content you access, and other related information. We use information collected in this manner only to better understand your needs and the needs of Website visitors and Services users in the aggregate. darcy also makes use of information gathered for statistical purposes to keep track of the number of visits to the Website, the specific pages on the Website, and users with a view to introducing improvements to the Website and our marketing activities.
Your IP address and other relevant information we collect using the Third-Party Analytics Program may be used in order to trace any fraudulent or criminal activity, or any activity in violation of the darcy Terms of Use.
Tracking Technology (“Cookies” and Related Technologies)
darcy uses tracking technology (“cookies” and related technology such as tags, pixels and web beacons) in the Services and by interacting with the Services you agree to their use. Cookies are small text files placed on your computer or device when you visit a website or use an online service, in order to track use of the website or service and to improve the user experience by storing certain data on your computer or device. By default, all non-necessary cookies are turned off when you first visit the Website.
Specifically, we use cookies and related technologies for the following functions:
1. to enable your logging-in to the Services and track your logged-in status to your Account;
2. for the proper functioning of the Services, including the proper functioning of payment processing;
3. to provide general internal and user analytics on the Website and to conduct research to improve the content of the Services using the Third-Party Analytics Program as discussed above in this Policy;
4. to facilitate the advertising as discussed in the advertising section above in this Policy;
5. to track information about emails you receive, for example whether you opened it or clicked on any links in it; and
6. to assist in identifying possible fraudulent activities.
Your browser can be set to refuse cookies or delete them after they have been stored. You can refer to your browser’s help section for instructions, but here are instructions for the most commonly-used browsers and operating systems:
Google Chrome
Mozilla Firefox
Microsoft Edge
Opera
Apple Safari
iOS
Android
Please note that deleting or blocking certain cookies may reduce your user experience by requiring you to re-enter certain information, including information required to use our Services. Furthermore, deleting certain necessary cookies may prevent certain functions, or the entirety of the Services, from working at all.
How We Protect Your Personal Data
We have implemented very strict technical and organisational procedures for ensuring that, by default, only the personal data which is necessary for each specific purpose of the processing are processed by us. These procedures prevent your personal data from being lost; or used or accessed in any unauthorised way.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable supervisory authority of a suspected data security breach where the Data Protection Laws requires us to do so, and within the time frame required by the applicable Data Protection Law.
darcy uses only industry best practices (physical, electronic and procedural) in keeping any data collected (including personal data) secure. In addition, we use third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to operate the Services, and these third parties have been selected for their high standards of security, both electronic and physical. For example, darcy uses Google Cloud, a recognized leader in secure data, for hosting of the Application and related data, and storage of data including personal data.
All information, including personal data, is transferred with encryption using Secure Sockets Layer (“SSL”) or Transport Layer Security (“TLS”), robust security standards for Internet data transfer and transactions. You can use your browser to check darcy’s valid SSL security certificates on the Website.
darcy uses Stripe for processing of secured credit card payments for payments of Subscription Fees made through the Services. Stripe is certified as a PCI-DSS (Payment Card Industry Data Security Standard) Service Provider Level 1, the most stringent level of certification available in the payments industry.
Internal Procedures and Policies
In addition to the measures to protect your personal data described in the previous section, we have drafted and implemented certain internal procedures and policies regarding personal data, including the following:
1. A framework for the keeping and destruction of the personal data, including where we may keep anonymized data;
2. Defining and describing the roles and responsibilities of the members of darcy personnel throughout the life cycle of the personal data;
3. A process for dealing with individual complaints and requests for personal data and exercising of the individual’s rights under Data Protection Laws;
4. A management and IT policy and procedure for addressing potential data breach incidents involving personal data in the custody of darcy.
Transfer of Your Personal Data Outside of the European Economic Area (EEA) and the U.K.
For our European users, we endeavour to keep your personal data inside the EEA or the U.K. (as applicable). However, certain of our data processors (and darcy) are in other countries where your personal data may be transferred. However, these countries are limited to countries with particular circumstances that protect your data, specifically:
1. Canada. Canada has been determined to have an “adequate level of protection” for your personal data under European data protection law.
2. The United States. Your personal data is only transferred to companies in the United States that: (1) have signed agreements with us or have informed us that they are GDPR-compliant; and (2) have concluded the Standard Contractual Clauses for the transfer of personal data outside the EEA and the U.K.
That’s it! You have the right, however, to refuse to have your data transferred outside the EEA. Please contact our Privacy and Data Protection Officer to make that request. Please note that making this request may prevent you from being able to use a portion or all of the Services.
Transfer of Your Personal Data Outside of Quebec
For our Quebec users and visitors, we endeavour to keep your personal data in Quebec. However, certain of our third-party service providers are in other provinces or countries where your personal data may be transferred. When this happens, we do the following to safeguard your personal data:
1. We will perform what the Quebec Private Sector Act calls an “Assessment of the privacy-related factors” (what is generally called a “Privacy Impact Assessment,” or “PIA”) prior to the personal data leaving Quebec. If the PIA does not meet our standards and the standards required by the Quebec Private Sector Act, we will not transfer your personal data to such a service provider; and
2. If the PIA allows us to transfer the personal data to such a service provider outside Quebec, we will sign what is generally called a “Data Processing Agreement,” or DPA, with the service provider, which protects the personal data transferred to them and limits their use of it to what we have contracted with them to do. This DPA will adhere to the requirements of the Quebec Private Sector Act.
Supervisory Authorities and Complaints
If you are in the EEA or the U.K, under the GDPR you have the right to make a complaint to the appropriate supervisory authority. If you are not satisfied with the response received or the actions taken by our Privacy Officer, or if you would like to make a complaint directly about darcy’s data practises, we invite you to contact the supervisory authority in your country. For example, if you are in the U.K., you should contact the Information Commissioner’s Office who is the supervisory authority. You can reach them in a variety of ways, including by phone (0303 123 1113 in the UK) and mail (Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF). If you are in France, you should contact the Commission Nationale de l'Informatique et des Libertés who is the supervisory authority there. Their contact information can be found here.
The full listing of all Data Protection Authorities (the supervisory authorities) across the EEA can be found here.
If you are in Canada, you can make a complaint to the Office of the Privacy Commissioner here. If you are in Québec, you can make a complaint to the Commission d’accès à l’information, with the instructions for contacting them on their website.
Automated Decision-Making and Third-Party AI
As mentioned in the Terms of Service, the Application makes use of certain third-party Artificial Intelligence (AI) and Large Language Model (LLM) systems (the “Third-Party AI”), in order to respond to your Ask to give you a reply whether your Ask is safe or a potential scam. While the Third-Party AI has access to certain of your personal data and it is used to help provide a reply to your Ask, it is not used for general training of the Third-Party AI and is never stored by them.
Data Retention
Your personal data will only be kept for as long as it is necessary for the purpose needed for that processing. For example, we will only retain your Subscription Information for as long as you have a Subscription with us. Personal data that may be included in the body of your Asks is stored by darcy while you have an Account, but can be deleted by you at any time when you are a Logged-In User.
We may have to keep your data for a longer period of time to satisfy our requirements under any applicable law, including anti-spam laws, or to protect our legal interests.
In some cases, where permitted by the Data Protection Laws, we may keep personal data that has been anonymized, for our legitimate business purposes.
Children’s Privacy Statement
The Services are only intended for persons who are 18 years old for a resident of a Canadian province or the age of majority in any other country. However, a user of the Services can add persons under the age of majority as Additional Users to use the Application, if such Additional Users consent to being added.
The Data Protection Laws have various age limits as to the minimum age required for us to hold personal data about an individual. We do not knowingly collect any personal data from a child under those minimum ages. If we become aware that we have inadvertently received personal data from a person under the minimum ages through the Services, we will delete such information from our records.
Changes to This Privacy Policy
The date at the top of this page indicates when this Policy was last updated. Every now and then, we will have to update this Policy, and we will update it no less than once every 12 months. You can always find the most updated version at this URL, and we will always post a notice on the Services if we make significant changes. If you have a darcy Account, we will also email you to tell you the Policy has been updated, and what the important changes are.
Thanks for reading! Please keep your personal data safe; we promise to do the same.
© FixMeStick Technologies Inc. 2024
Get to know us more. Join our newsletter.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique.