Privacy Policy
Applicable to All Cathrix Services
This Privacy Policy explains how Cathrix Network Inc., a corporation registered in Alberta, Canada (“Cathrix,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information.
It applies to personal information processed through websites, customer portals, software, applications, infrastructure, products, and other services operated by Cathrix that refer to this policy (collectively, the “Services”).
“Personal information” means information about an identifiable individual. It excludes irreversibly anonymized data or business contact information where applicable law exempts it.
1. Scope and Applicability
1.1 Our Role
This Privacy Policy applies when Cathrix determines the purposes and means of processing personal information. This includes information concerning website visitors, customers, authorized users, business contacts, and individuals interacting with our support or security teams.
1.2 Customer Content and Customer Personal Data
“Customer Content” has the broad meaning given in the General Terms and includes data, software, and materials processed by or for a customer through the Services.
“Customer Personal Data” means personal information contained in Customer Content that Cathrix processes on the customer’s behalf through the Services. For Customer Personal Data, Cathrix acts as a service provider (data processor) on behalf of the customer. The customer is responsible for providing privacy notices and obtaining consent. Our handling of Customer Personal Data is governed by our Data Processing Addendum and the applicable agreement, not this Privacy Policy. Cathrix does not sell Customer Personal Data or use it for unrelated advertising.
1.3 Third-Party Links
The Services may contain links to or integrations with third-party platforms. Cathrix is not responsible for the privacy practices of third parties. This policy does not apply to third-party services or a Cathrix customer’s independent privacy practices.
2. Information We Collect
2.1 Types of Personal Information
Depending on how you interact with our Services, we may collect the following categories of information:
- Account and Contact: name, organization, job title, email, phone number, billing address, and account identifiers.
- Billing and Transaction: payment method type, transaction history, tax or exemption documents, and fraud-verification results (complete payment card credentials are collected directly by our payment processors).
- Identity and Verification: proofs of identity, company registration, and compliance screening results (collected only when reasonably necessary).
- Service and Network: IP addresses, autonomous system numbers or prefixes, routing and peering data, DNS info, bandwidth usage, server identifiers, device and browser details, and security logs.
- Communications: contents of support tickets, emails, feedback, and diagnostic files.
- Website and Cookies: pages visited, referring URLs, approximate location based on IP addresses, and cookie identifiers.
2.2 Sources of Information
We collect personal information:
- Directly from you (e.g., when you create an account or contact support);
- Automatically (e.g., via cookies, network protocols, and service logs);
- From authorized parties (e.g., an account owner who provisions your access); and
- From third parties (e.g., payment processors, fraud-prevention providers, public routing registries, and business partners).
2.3 Cookies and Automated Processing
We use cookies, local storage, and similar technologies to authenticate accounts, ensure security, manage sessions, and analyze Service performance. You can manage non-essential cookies through your browser settings or our preference tool (if available).
We may also use automated tools to detect fraud, malware, or abusive traffic. Where automated processing results in significant legal effects, you may contact us for a review as permitted by applicable law.
2.4 Children and Minors
Our Services are not directed to children under 13. We do not knowingly collect personal information from children without appropriate authorization. If you believe a child has provided us with personal information, please contact us.
3. How We Use and Disclose Information
3.1 Purpose of Processing
We use your personal information to:
- provide, configure, and maintain the Services;
- process transactions, calculate usage, and issue invoices;
- verify identity, authority, and eligibility;
- detect and prevent fraud, spam, abuse, and security threats;
- communicate regarding support, billing, security, and contractual updates;
- analyze usage to improve functionality and user experience;
- establish, exercise, or defend legal rights; and
- comply with legal, regulatory, and tax requirements.
3.2 Consent and Marketing
We process personal information with express or implied consent unless a specific legal exception applies under Canadian law.
We may send you marketing communications if you have consented or where legally permitted based on an existing relationship. You can opt out of marketing emails at any time via the unsubscribe link or by contacting us. Opting out does not stop essential operational, billing, or security notices.
3.3 Disclosures to Third Parties
We do not sell your personal information. We may disclose information to:
- Service Providers: for cloud hosting, telecommunications, payments, support, and cybersecurity (subject to strict confidentiality agreements).
- Infrastructure Partners: upstream carriers, Internet Exchanges, and routing registries required for network connectivity.
- Authorized Users: the account owner and administrators associated with your organization.
- Legal and Safety Authorities: to comply with valid legal processes (e.g., subpoenas), protect against imminent harm, or enforce our agreements.
- Business Transactions: to counterparties in connection with a merger, acquisition, restructuring, or sale of assets.
3.4 Aggregated and De-identified Data
We may aggregate or de-identify personal information so it no longer identifies an individual. We use this data for research, capacity planning, and Service improvement.
4. Data Security, Storage, and Retention
4.1 Security Safeguards and Incidents
We employ administrative, technical, and physical safeguards (such as encryption, access controls, and network segmentation) designed to protect personal information. However, no system is entirely secure. You are responsible for securing your credentials.
In the event of a privacy or security incident creating a real risk of significant harm, we will notify affected individuals and relevant regulators as required by law.
4.2 International Data Processing
Cathrix and its service providers may process and store your information in:
- Canada;
- the United States; and
- Other regions selected by you when ordering localized infrastructure.
Information processed outside Canada is subject to the laws of that jurisdiction. We use contractual measures to ensure service providers protect your data.
4.3 Retention and Deletion
We retain personal information only for as long as reasonably necessary:
- Account and Billing Records: generally up to 7 years post-termination for tax and contract purposes.
- Service and Security Logs: generally up to 12 months.
- Support Communications: generally up to 3 years.
When no longer needed, information is deleted or irreversibly anonymized. Data in encrypted backups is overwritten automatically based on standard backup cycles.
5. Your Rights and Contact Information
5.1 Your Privacy Rights
Subject to local laws (e.g., PIPEDA, Alberta PIPA), you may have the right to:
- access the personal information we hold about you;
- request correction of inaccurate data;
- withdraw consent for specific processing (including marketing);
- request deletion of your information; and
- submit a privacy complaint.
5.2 Exercising Your Rights
To exercise your rights, please email us with the subject line Privacy Request. We may request additional details to verify your identity. We generally respond within 30 days, unless an extension is legally permitted.
Note: If your request concerns Customer Personal Data processed on behalf of a Cathrix customer, please contact that customer directly.
5.3 Changes to This Policy
We may update this Privacy Policy to reflect changes in law, technology, or business practices. We will provide reasonable electronic notice of material changes. Where legally required, we will obtain new consent for material new uses.
5.4 Contact Details
Questions, privacy requests, and complaints should be directed to our designated Privacy Officer:
Privacy Officer
Cathrix Network Inc.
[email protected]
If you are dissatisfied with our response, you may have the right to lodge a complaint with the Office of the Information and Privacy Commissioner of Alberta, the Office of the Privacy Commissioner of Canada, or another applicable data protection authority.
Last Updated on August 26, 2026
Effective as of August 26, 2026