• Now booking Q3 · Montréal · Toronto · Miami · Rabat · • Odoo 17 migrations scheduling 6 weeks out

Home/Legal/Privacy policy

Legal · Privacy

Privacy policy.

How Noordev Technologies Inc. collects, uses, shares and protects personal information — on this website, in our sales and recruitment, and in the delivery of our services.

Effective

29 August 2026

Last updated

29 August 2026

Version

1.0

Frameworks we apply

Québec — Law 25Act respecting the protection of personal information in the private sector, as amended by Law 25.

Canada — PIPEDAPersonal Information Protection and Electronic Documents Act.

EU / UK — GDPRApplied where we process information of people in the EEA or the UK.

Morocco — Law 09-08Applied to processing carried out by our Rabat office.

Privacy Officer · Mohamed Rida Allah – CEO
privacy@noordev.com

At a glance

The short version.

A plain-language summary of what follows. It is a summary only — the numbered sections below are the policy that actually applies.

01

We do not sell your information

We do not sell personal information, and we do not share it for cross-context behavioural advertising or targeted ads.

02

We collect what the work requires

Contact details, the content of what you send us, billing information, and aggregate site analytics. Not more, and not “just in case”.

03

You can ask what we hold

Access, correction, deletion, de-indexing and portability. We answer within 30 days, free of charge in ordinary cases.

04

Client data stays the client’s

When we build or maintain your systems, we act on your instructions as a processor. Your data is governed by our agreement with you, not by this page.

05

We tell you when something goes wrong

Confidentiality incidents that present a risk of serious injury are reported to you and to the regulator, on the statutory clock.

06

Changes are dated and versioned

Every revision carries an effective date and a version number. Material changes get 30 days notice where we hold your email.

This summary does not replace the full policy. Where the summary and the detailed sections differ, the detailed sections govern.

Section 1

Who we are and what this covers.

Noordev Technologies Inc. is the organisation responsible for the personal information described here — the controller under the GDPR and the person carrying on an enterprise under Québec law.

In this policy, “Noordev”, “we” and “us” mean Noordev Technologies Inc., a company incorporated in Canada with its head office in Montréal, Québec, and offices in Toronto, Miami and Rabat.

This policy applies to:

  • this website and its subdomains, including forms, downloads and scheduling links;
  • our sales, marketing and client-relationship activity;
  • recruitment and applications for work with us;
  • the administration of our engagements — contracts, invoicing and support tickets.

This policy does not apply to personal information we handle inside a client’s own systems when we build, host or maintain them. In that work we act as a processor (a “service provider” under Québec law) on the client’s documented instructions. That processing is governed by our services agreement and data processing addendum with the client, and by the client’s own privacy policy — not by this page. If you are a customer of one of our clients and want to exercise a right, contact that client directly; if you contact us, we will route your request to them.

Our websites contain links to third-party sites and services we do not control. This policy does not cover them, and we are not responsible for their practices.

Legal entity

Noordev Technologies Inc.

Head office

2572 Bd Daniel-Johnson, 2nd Floor

Laval, QC H7T 2R3, Canada

Offices

Montréal · Toronto · Miami · Rabat

Privacy Officer

Mohamed Rida Allah – CEO

Privacy contact

Business number

Noordev technologies inc.

Section 2

Personal information we collect.

Grouped by where it comes from. We collect only what a stated purpose in Section 3 requires, and we do not require more information than is necessary for that purpose.

Category

What it includes

Where it comes from

Identity & contact

Name, work email address, telephone number, employer, job title, and the city or country you tell us you are in.

You — contact and quote forms, email, calls, scheduling links, events.

Enquiry content

The message, brief, RFP, requirements document or attachment you send us, and the notes we take about the engagement you are asking about.

You — directly, in whatever channel you use to reach us.

Contract & billing

Billing name and address, tax registration numbers, purchase-order references, invoices, payment status and correspondence.We do not store full payment card numbers. Card payments, where offered, are handled by a payment processor.

You, and your finance or procurement team.

Technical & usage

IP address, browser and device type, operating system, referring URL, pages viewed, time on page, and approximate location derived from IP at city level.

Collected automatically by our servers and, where you consent, by analytics cookies. See Section 4.

Support & account

Ticket history, the accounts we hold for you in our project tools, and the credentials you choose to share with us for systems we maintain.Shared credentials are held in an access-controlled secret manager and rotated at the end of an engagement.

You, and our own systems during the engagement.

Recruitment

CV, cover letter, work history, education, references and right-to-work information, plus interview notes and assessment results.

You, referees you nominate, and recruiters where you applied through one.

Third-party sources

Publicly available business information and, where used, company data from business-information providers used to qualify an enquiry.

Public registers, company websites, professional networks, referral partners.

Sensitive information. We do not seek out sensitive personal information — health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sexual orientation, or government identifiers such as a social insurance number. Please do not send it to us in an enquiry. If sensitive information is genuinely necessary for an engagement, we will ask for your express consent first and tell you why it is needed.

If you do not provide it. Most fields on our forms are optional. Where information is required to answer you or to perform a contract, we mark it as such; without it we may not be able to respond or to deliver the service.

Section 3

Why we use it, and on what basis.

Under Québec law and PIPEDA we must identify the purpose before we collect. Under the GDPR we must also have a lawful basis. Both are set out below.

Purpose

Information used

Lawful basis (GDPR Art. 6)

Answering your enquiry

Identity & contact, enquiry content.

Steps taken at your request before entering a contract (Art. 6(1)(b)).

Delivering our services

Identity & contact, contract & billing, support & account.

Performance of a contract (Art. 6(1)(b)).

Invoicing, tax and accounting

Contract & billing.

Compliance with a legal obligation (Art. 6(1)(c)).

Securing our site and systems

Technical & usage, server and access logs.

Legitimate interests — preventing abuse, fraud and unauthorised access (Art. 6(1)(f)).

Measuring and improving the site

Technical & usage, analytics cookie identifiers.

Consent, given through the cookie banner and withdrawable at any time (Art. 6(1)(a)).

Marketing emails and invitations

Identity & contact, engagement history.

Consent, withdrawable at any time. Every message carries an unsubscribe link, as required by Canada’s anti-spam legislation (Art. 6(1)(a)).

Recruitment

Recruitment information.

Steps taken at your request before entering a contract, and our legitimate interest in assessing candidates (Art. 6(1)(b) and (f)).

Establishing or defending legal claims

Whatever is strictly relevant to the claim.

Legitimate interests, and compliance with a legal obligation (Art. 6(1)(f) and (c)).

Automated decision-making. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, and we do not profile you for that purpose. If that ever changes, we will say so here and — as Law 25 requires — tell you at the time of the decision, explain the personal information used, and give you a chance to submit observations to a human.

Using information for a new purpose. If we need to use your information for something not described above, we will tell you and, where the law requires it, ask for your consent before we do.

Withdrawing consent. Where we rely on consent, you can withdraw it at any time by writing to privacy@noordev.com. Withdrawal does not affect processing already carried out.

Section 4

Cookies and similar technologies.

Only strictly necessary cookies are set before you choose. Everything else waits for your consent, and you can change your mind at any time.

Category

What it does

Consent needed

Lifetime

Strictly necessary

Keeps your session, remembers your cookie choice, balances load and protects forms against abuse. The site cannot work without these.

No — exempt.

Session to 12 months.

Preferences

Remembers your language (EN / FR / AR) and interface choices so you do not have to set them again.

Yes.

Up to 12 months.

Analytics

Tells us which pages are read, how people arrive and where they give up, in aggregate. We use it to fix the site, not to build profiles.

Yes.

Up to 13 months.

Marketing

Measures advertising campaigns and attribution. Confirm whether ad or remarketing pixels are deployed, and list the vendors.

Yes.

Up to 13 months.

Changing your choice. Use the Cookie settings link in the footer to review or withdraw consent at any time. You can also block or delete cookies in your browser settings; strictly necessary cookies cannot be refused without breaking parts of the site.

Global Privacy Control. Where your browser sends a GPC or “Do Not Track” signal, we treat it as a withdrawal of consent for analytics and marketing cookies.

Server logs. Separately from cookies, our web servers keep short-lived access logs containing IP address, timestamp, requested URL and user agent. These are used for security and troubleshooting, are not used to identify you, and are deleted on the schedule in Section 6.

Embedded content. Pages may embed maps, video or scheduling widgets from third parties. Those providers can set their own cookies once the content loads; we defer loading until you consent where the law requires it.

Section 5

Who we share it with.

A short list, and a shorter one of things we never do. Every supplier below is bound by a written agreement limiting what they may do with the information.

We do not sell personal information. We do not rent or trade it, we do not share it for cross-context behavioural advertising, and we do not disclose it to data brokers. We have not done so in the preceding twelve months.

Recipient

Why

Safeguard

Service providers

Hosting, email delivery, analytics, payment processing, scheduling, project management and support tooling.Maintain a current subprocessor list and publish it or make it available on request: CONFIRM VENDOR LIST

Written agreement, processing limited to our instructions, confidentiality and security obligations, return or deletion at the end of the term.

Professional advisers

Lawyers, auditors, accountants and insurers where they need it to advise us.

Professional duty of confidence; disclosure limited to what is necessary.

Public authorities

Where we are legally required to disclose, or where disclosure is necessary to protect someone’s life, health or safety.

We check that the request is valid and lawful, disclose the minimum, and tell you unless we are prohibited from doing so.

A successor in a transaction

If Noordev is involved in a merger, acquisition or sale of assets, information may transfer as part of that transaction.

Confidentiality agreement before any disclosure; notice to you, and the protections in this policy continue to apply afterwards.

With your direction

Where you ask us to share something — with a partner agency, a referee or a colleague on your side.

Your instruction, which you can withdraw.

Client engagements. Where we act as a processor inside a client’s systems, we do not disclose that client’s data to anyone except as the client instructs or the law requires, and we notify the client before responding to any authority’s request unless prohibited.

Section 6

Transfers outside Québec, and how long we keep things.

We operate from four countries, so some information crosses a border. Law 25 requires us to assess that before it happens.

Where information is processed

Personal information described in this policy may be processed in Canada, the United States, the European Union and Morocco, by us or by the service providers in Section 5.

Before we entrust personal information to a provider outside Québec, we carry out the privacy impact assessment Law 25 requires, considering the sensitivity of the information, the purpose, the protections in place and the legal framework of the destination. We proceed only where the information will receive adequate protection, and we record that assessment.

Transfer mechanisms

For information moving out of the EEA or the UK, we rely on the European Commission’s adequacy decision for Canada where it applies, and otherwise on Standard Contractual Clauses together with any technical measures the transfer needs.

For our Rabat operations we apply Moroccan Law 09-08 and, where the information concerns people in the EEA, the GDPR as well.

You can ask us for a copy of the safeguards used for a specific transfer by writing to privacy@noordev.com.

How long we keep it

What

Kept for

Why that period

Enquiries that did not become work

24 months from last contact.

Long enough to pick up a conversation that restarts, short enough not to hoard.

Client contracts and records

7 years after the engagement ends.

Canadian tax and corporate record-keeping obligations, and the limitation period for contractual claims.

Invoices and accounting

7 years.

Required by tax law.

Candidate applications

12 months, or longer with your consent.

To consider you for a role that opens later. We ask before keeping it longer.

Marketing consent records

3 years after consent is withdrawn.

To prove we had consent, as anti-spam law requires.

Analytics

Up to 13 months.

Enough for a year-on-year comparison; nothing is retained at individual level beyond it.

Server and access logs

90 days.

Security investigation window.

Backups

30 days, then overwritten.

Deletion requests are applied to live systems immediately and work through backup rotation within this window.

Retention periods above are our standard schedule. Where a longer period is required by law, or a shorter one is agreed in a client contract, that period applies instead. When a period ends we delete the information or irreversibly anonymise it.

Section 7

Your rights, and how to use them.

These rights are free to exercise in ordinary cases. We answer within 30 days under Québec law and PIPEDA, and within one month under the GDPR.

Access

Ask whether we hold information about you and get a copy of it, together with the categories of people it has been given to.

Correction

Have inaccurate or incomplete information corrected, and have the correction passed on to anyone we disclosed it to.

Deletion

Ask us to delete information where it is no longer needed for the purpose it was collected, or where you withdraw the consent it rested on.

Withdraw consent

Withdraw consent at any time for anything that rests on it, including marketing and non-essential cookies.

Portability

Receive the computerised information you gave us in a structured, commonly used technological format, or have it sent to another organisation.

De-indexing

Ask us to stop disseminating information, or to de-index a link, where the dissemination causes serious injury to your reputation or privacy.

Objection & restriction

Object to processing based on legitimate interests, and ask us to restrict processing while a dispute about accuracy is resolved.

Complain

Take a complaint to us first, and then to the supervisory authority for your jurisdiction — see Section 11.

How to make a request

  • Email privacy@noordev.com and say which right you are exercising.
  • Tell us enough to find your records — the email address you used with us is usually sufficient.
  • We may ask for proof of identity. We ask for the least we can, and we do not keep the proof afterwards.
  • We confirm receipt, and answer within the statutory period. If a request is complex we may extend it, and we will tell you why before the deadline.
  • If we refuse, we tell you the reason, the legal provision we rely on, and how to ask the regulator to review the decision.

Where you are matters

Québec. Law 25 gives you access, correction, withdrawal of consent, de-indexing, and — since September 2024 — portability of the computerised information you provided.

Rest of Canada. PIPEDA gives you access and correction, and the right to challenge our compliance.

EEA and UK. The GDPR adds objection, restriction, portability and the right not to be subject to a solely automated decision with legal effect.

United States. Where a state privacy law applies to you, you may have the right to know, delete, correct and opt out of sale or targeted advertising. We do not sell or share information for targeted advertising, and we will not discriminate against you for exercising a right.

Morocco. Law 09-08 gives you access, rectification and objection through the CNDP.

Section 8

How we protect personal information.

We sell security work, so our own controls have to survive the same questions we ask our clients. No control set is perfect, and we do not claim otherwise.

Encryption

TLS 1.2 or better for everything in transit, and encryption at rest for databases, file storage and backups.

Access control

Least privilege, individual named accounts, multi-factor authentication, and quarterly access reviews. Shared client credentials live in a secret manager and are rotated at the end of an engagement.

Patching

Dependencies and infrastructure patched on a fixed cadence, with critical vulnerabilities addressed inside 24 hours.

Segregation

Client environments are separated from each other and from our corporate systems. Production access is logged.

Backups & recovery

Nightly offsite backups with a restore rehearsed quarterly — an untested backup is not a backup.

People

Confidentiality obligations in every contract, background checks where the role warrants, and security awareness training on joining and annually.

Framework alignment. Our controls are built around ISO/IEC 27001 Annex A, which is also the standard we implement for clients. You can read how we approach this work on our ISO 27001 and cybersecurity & GRC pages.

If something goes wrong. We keep a register of confidentiality incidents, as Law 25 requires. Where an incident presents a risk of serious injury, we notify the Commission d’accès à l’information and the people affected promptly, and we take reasonable measures to reduce the harm. Under the GDPR we notify the lead supervisory authority within 72 hours where the incident is reportable. Where we act as a processor for a client, we notify that client without undue delay and support their own notification duties.

Section 9

Children.

Our services are sold to organisations, and this website is aimed at people acting in a business capacity. It is not directed at children.

We do not knowingly collect personal information from a child under 14 — the age at which Québec law allows a minor to consent on their own behalf. Where the GDPR applies, the equivalent threshold is 16, or the lower age set by the relevant member state.

If you believe a child has given us personal information, write to privacy@noordev.com and we will delete it.

Section 10

Changes to this policy.

We review this policy at least once a year, and whenever we change something material about how we handle personal information.

Every version carries an effective date and a version number at the top of the page. When a change is material — a new purpose, a new category of recipient, a new transfer — we publish it here at least 30 days before it takes effect and, where we hold your email address and you are affected, we tell you directly.

Where a change requires your consent, we will ask for it rather than assume it. Continuing to use the site after a non-material change means the updated policy applies.

Earlier versions are available on request.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.