PRIVACY AND DATA PROTECTION POLICY

June 10, 2026

This Privacy and Data Protection Policy (“Policy”) describes how Alt-Tech Inc. (“Alt-Tech”, “we”, “us”, or “our”) collects, uses, stores, protects, and discloses Personal Information and Client Data in the course of providing managed information technology services to its clients (“Client”, “you”). This Policy is incorporated by reference into the Managed Services Agreement between Alt-Tech and the Client and forms part of the contractual commitments between the parties.

Alt-Tech is committed to protecting the privacy and security of all Personal Information and Client Data entrusted to us. We operate in accordance with applicable Canadian privacy legislation, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and the Alberta Personal Information Protection Act (PIPA), and align our operational controls to the CompTIA Trustmark certification framework.

1. DEFINITIONS

Capitalized terms used in this Policy that are not defined here have the meanings given to them in the Managed Services Agreement. The following terms apply throughout this Policy:

“Client Data” means all data and information (including Personal Information) provided by, generated by, or processed on behalf of the Client in the course of Alt-Tech delivering Services under the Managed Services Agreement.

“Personal Information” means information about an identifiable individual, as defined under PIPEDA and Alberta PIPA, including but not limited to names, contact information, employee identifiers, login credentials, and any other data that can be used directly or indirectly to identify a natural person.

“Processing” means any operation performed on Personal Information or Client Data, including collection, recording, storage, retrieval, use, disclosure, transfer, and destruction.

“Subprocessor” means any third party engaged by Alt-Tech to assist in the delivery of the Services that may access, store, or process Personal Information or Client Data.

“Data Controller” means the party that, alone or jointly, determines the purposes and means of Processing Personal Information.

“Data Processor” means the party that Processes Personal Information on behalf of, and on the documented instructions of, the Data Controller.

“Data Custodian” means the party with operational responsibility for the secure storage, handling, and protection of Personal Information and Client Data under documented instructions from the Data Controller.

2. ROLES OF THE PARTIES AND DATA CUSTODIANSHIP

This Policy applies to all Personal Information and Client Data that Alt-Tech Processes in the course of delivering Services under the Managed Services Agreement. This Policy does not govern the Client’s own collection or use of Personal Information from its employees, customers, or other data subjects.

(a) Client as Data Controller

The Client is, and at all times remains, the sole Data Controller of all Personal Information and Client Data Processed by Alt-Tech under the Managed Services Agreement. The Client is solely responsible for determining the purposes and means of Processing, establishing the lawful basis for collection and use, providing required privacy notices, obtaining required consents, responding to data subject access, correction, and erasure requests, carrying out any required privacy impact assessments, and complying with all applicable privacy and data protection laws to which it is subject as Data Controller.

(b) Alt-Tech as Data Processor and Data Custodian

Alt-Tech acts solely as a Data Processor and Data Custodian on behalf of the Client. Alt-Tech Processes Personal Information and Client Data only on the documented instructions of the Client, including as set out in the Managed Services Agreement, the Proposal, this Policy, and any subsequent written instructions issued by an authorized representative of the Client. Alt-Tech does not determine the purposes or means of Processing, does not act as Data Controller in respect of Client Data, and does not Process Client Data for any independent commercial purpose of its own.

(c) Allocation of Liability

Because Alt-Tech acts solely as Data Processor and Data Custodian and not as Data Controller, Alt-Tech’s liability in respect of Personal Information and Client Data is limited to losses arising directly from Alt-Tech’s breach of its documented obligations as a Data Processor and Data Custodian under the Managed Services Agreement and this Policy. The Client is solely responsible for losses, claims, fines, penalties, or regulatory action arising from: (i) the Client’s determination of the purposes and means of Processing; (ii) the Client’s failure to provide required privacy notices or obtain required consents; (iii) the Client’s instructions to Alt-Tech, where Alt-Tech has acted in accordance with those instructions; (iv) the accuracy, quality, or lawfulness of Personal Information provided to Alt-Tech by or on behalf of the Client; or (v) the Client’s own breach of applicable privacy and data protection laws. All limitations of liability set out in the Managed Services Agreement apply to this Policy and to the Processing of Personal Information and Client Data hereunder.

(d) Notification of Unlawful Instructions

If Alt-Tech reasonably believes that an instruction received from the Client would result in a violation of applicable privacy or data protection law, Alt-Tech will promptly notify the Client’s Primary Contact in writing and may suspend performance of the affected instruction until the matter is resolved, without such suspension constituting a breach of the Managed Services Agreement.

3. COMPLIANCE FRAMEWORK

Alt-Tech operates in accordance with the following Canadian privacy laws and industry frameworks:

  • Personal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 5, as amended;
  • Alberta Personal Information Protection Act (PIPA), S.A. 2003, c. P-6.5, as amended;
  • CompTIA Trustmark certification framework, which governs Alt-Tech’s internal information security, data protection, incident response, and vendor management practices;
  • Industry-recognized cybersecurity controls aligned with the National Institute of Standards and Technology (NIST) Cybersecurity Framework.

Where the Client is subject to additional or more stringent privacy or data protection obligations (including but not limited to PHIPA, HIPAA, GDPR, or sector-specific regulations), the Client is responsible for notifying Alt-Tech in writing, and the parties will document any incremental obligations in a written Change Order or addendum to the Managed Services Agreement.

4. CATEGORIES OF INFORMATION WE PROCESS

In delivering the Services, Alt-Tech may Process the following categories of Client Data and Personal Information:

  • Authentication and access credentials, including usernames, password hashes, and multi-factor authentication tokens, processed solely for the purpose of administering the Client’s systems;
  • User and device identifiers, including email addresses, device names, IP addresses, and device serial numbers, processed for service delivery, security monitoring, and asset management;
  • Support ticket content, including descriptions of issues, screenshots, log files, and related communications submitted by the Client’s users;
  • System and security telemetry, including endpoint health data, antivirus and EDR alerts, patch status, configuration metadata, and audit logs;
  • Microsoft 365 administrative data, including mailbox configuration, SharePoint and Teams permissions, license assignments, and conditional access policies;
  • Backup data, including copies of files, mailboxes, and system images held in encrypted backup storage for disaster recovery purposes;
  • Strategic and operational data, including IT roadmaps, budgets, and reporting outputs generated as part of monthly customer success and quarterly executive reviews.

Alt-Tech does not deliberately collect Personal Information beyond what is necessary to deliver the Services described in the Managed Services Agreement and the Proposal.

5. HOW WE USE PERSONAL INFORMATION AND CLIENT DATA

Alt-Tech uses Personal Information and Client Data only for the following purposes:

  • Delivering the Managed Services Package, Onboarding Services, Hosting Services, and Microsoft 365 Licensing Services described in the Managed Services Agreement and the Proposal;
  • Providing helpdesk, ticketing, and incident response support to the Client’s users;
  • Monitoring the security, availability, and performance of the Client’s systems and identifying threats;
  • Performing backup, recovery, patching, and configuration management activities;
  • Generating reports, dashboards, and strategic reviews for the Client;
  • Complying with Alt-Tech’s legal, regulatory, and contractual obligations.

Alt-Tech does not sell, rent, or otherwise commercialize Personal Information or Client Data. Alt-Tech does not use Personal Information or Client Data to train artificial intelligence or machine learning models without the Client’s express written consent.

6. INFORMATION SECURITY AND DATA PROTECTION

Alt-Tech maintains administrative, technical, and physical safeguards designed to protect Personal Information and Client Data against loss, theft, unauthorized access, disclosure, copying, use, modification, or destruction. These safeguards include:

6.1 Encryption

  • Data at rest is protected using industry-standard encryption, including BitLocker for endpoint storage and provider-managed encryption for cloud and backup storage;
  • Data in transit is protected using Transport Layer Security (TLS 1.2 or higher) for all external transfers and authenticated channels for internal communications.

6.2 Access Control

  • Role-based access control is enforced across Alt-Tech’s internal systems, with access rights granted on a least-privilege basis and reviewed on a periodic basis;
  • Multi-factor authentication (MFA) is enforced for all Alt-Tech personnel accessing Client systems or Client Data, including through Microsoft Entra ID (Azure Active Directory) conditional access policies;
  • Privileged access to Client environments is subject to additional controls, including just-in-time elevation and session logging where applicable.

6.3 Endpoint and Network Security

  • Endpoint detection and response (EDR), antivirus, encryption enforcement, ring-fencing, and Zero Trust policies are deployed across Alt-Tech systems used to deliver the Services;
  • Dark web monitoring and advanced email protection are deployed for Alt-Tech accounts that interact with Client environments;
  • Network traffic is segmented and monitored to detect anomalous activity.

6.4 Physical Security

  • Alt-Tech offices are physically secured with controlled access and visitor management;
  • Asset management procedures track all hardware that may store or process Client Data, including assignment, return, and secure destruction.

6.5 Audit and Logging

  • Alt-Tech maintains audit and security logs for systems used to deliver the Services, including Microsoft Azure and Microsoft 365 sign-in logs and administrative actions;
  • Logs are retained in accordance with Section 8 below and reviewed for security and compliance purposes.

7. SUBPROCESSORS

Alt-Tech engages a limited number of trusted Subprocessors to support the delivery of the Services. As of the Effective Date, our principal Subprocessors include:

  • Microsoft Corporation (including Microsoft Azure and Microsoft 365), used for cloud hosting, identity and access management, productivity, and security services. Where data residency is configurable, Alt-Tech provisions Canadian region storage by default;
  • Acronis International GmbH, used for backup, disaster recovery, and cyber protection services;
  • ThreatLocker Inc., used for application control, ring-fencing, and Zero Trust endpoint security;
  • Halo Service Solutions Ltd., used for service desk, ticketing, and asset management;
  • Such additional Subprocessors as Alt-Tech may engage from time to time to support the Services.

All Subprocessors are required to maintain security and privacy commitments substantially equivalent to those set out in this Policy. Alt-Tech conducts due diligence on Subprocessors prior to engagement, including review of their security certifications, data residency commitments, and contractual privacy obligations.

Alt-Tech will provide the Client with an updated list of principal Subprocessors upon written request. If Alt-Tech proposes to engage a new Subprocessor that would result in a material change to Client Data Processing, Alt-Tech will provide the Client with reasonable advance notice in writing.

8. DATA RETENTION AND DESTRUCTION

Alt-Tech retains Personal Information and Client Data only as long as is necessary to fulfill the purposes for which it was collected, to comply with legal and regulatory obligations, and to support the Services. Default retention periods are as follows:

  • Operational and support data (including ticket records and configuration metadata): retained for the duration of the Managed Services Agreement plus one (1) year;
  • Backup data: retained in accordance with the backup schedule applicable to the Services and the retention period specified in the Managed Services Agreement or applicable Statement of Work;
  • Audit and security logs: retained for the duration of the Managed Services Agreement plus one (1) year, or longer where required by law;
  • Archived data: retained only where required by applicable law or under written instruction from the Client.

On termination or expiry of the Managed Services Agreement, and subject to the Client’s written instructions, Alt-Tech will return or securely destroy Client Data in accordance with the offboarding procedures set out in the Managed Services Agreement. Secure destruction is performed using industry-standard methods consistent with NIST SP 800-88 guidelines.

9. INCIDENT RESPONSE AND BREACH NOTIFICATION

Alt-Tech maintains a documented incident response process aligned with the CompTIA Trustmark framework. In the event of a confirmed or suspected security incident that affects, or is reasonably likely to affect, the Client’s Personal Information or Client Data, Alt-Tech will:

  • Notify the Client’s Primary Contact without undue delay, and in any event within seventy-two (72) hours of confirming a reportable incident affecting Client Data;
  • Provide reasonable details regarding the nature of the incident, the categories of data affected, the steps taken to contain and remediate the incident, and any recommended actions for the Client;
  • Cooperate reasonably with the Client to support the Client’s own breach notification obligations under PIPEDA, Alberta PIPA, and other applicable laws.

Alt-Tech’s notification obligations are without prejudice to its own legal and regulatory reporting obligations, including notification to the Office of the Privacy Commissioner of Canada or other applicable regulators.

10. INTERNATIONAL TRANSFER AND DATA RESIDENCY

Alt-Tech provisions Canadian region storage for Client Data where the underlying Subprocessor (including Microsoft Azure and Microsoft 365) makes that option available, and where the Client has not requested otherwise in writing.

Certain Subprocessor services, including global identity and security services provided by Microsoft Corporation and certain backup and security services provided by Acronis International GmbH and ThreatLocker Inc., may involve the transfer of Client Data outside of Canada. Where such transfers occur, Alt-Tech relies on contractual safeguards imposed by the relevant Subprocessor that are substantially equivalent to the privacy protections set out in this Policy.

11. CLIENT RESPONSIBILITIES

The Client acknowledges and agrees that:

  • The Client is responsible for obtaining all necessary consents and providing all required notices to data subjects (including the Client’s employees, customers, and end users) in connection with the Processing of Personal Information by Alt-Tech in the course of delivering the Services;
  • The Client is responsible for ensuring that the Personal Information and Client Data provided to Alt-Tech is accurate, lawful, and provided to Alt-Tech with appropriate authority;
  • The Client is responsible for complying with its own legal and regulatory obligations as a Data Controller, including its obligations under PIPEDA, Alberta PIPA, and any sector-specific privacy or data protection laws to which it is subject;
  • The Client will notify Alt-Tech in writing of any sector-specific privacy or data protection obligations that require Alt-Tech to implement incremental safeguards beyond those set out in this Policy.

12. CHANGES TO THIS POLICY

Alt-Tech may update this Policy from time to time to reflect changes in applicable law, industry frameworks, or operational practice. Where this Policy is incorporated into the Managed Services Agreement by reference, material changes that affect the Client’s rights or obligations will be communicated to the Client’s Primary Contact in writing, and will take effect on the date specified in that notice, subject to the change management provisions of the Managed Services Agreement.

13. GOVERNING LAW

This Policy is governed by the laws of the Province of Alberta and the federal laws of Canada applicable therein, consistent with the Managed Services Agreement.

14. CONTACT INFORMATION

Questions, requests, or concerns regarding this Policy or the Processing of Personal Information by Alt-Tech may be directed to:

Privacy Officer

Alt-Tech Inc.

Email: customersuccess@alt-tech.ca

End of Policy