Law 25 Compliant

Privacy Policy

Appollon Inc. - Compliant with Quebec's Law 25

Last Update: December 2025

Data Protection Officer: Ferhat Abbas

Email: [email protected]

Table of Contents

  1. Who are we?
  2. What data do we collect?
  3. Why do we collect this data?
  4. How do we protect your data?
  5. How long do we keep your data?
  6. Do we share your data?
  7. Your rights under Law 25
  8. Cookies and similar technologies
  9. Changes to this policy
  10. Contact us

1. Who are we?

Appollon Inc. is a Quebec-based cybersecurity company located in Quebec, Canada. We offer managed security operations center (SOC) services and develop bank-level mobile security solutions.

As a Quebec organization, we are subject to Law 25 (Law modernizing legislative provisions respecting the protection of personal information) and are committed to protecting your privacy with the highest standards.

Our contact information:

2. What data do we collect?

2.1 Directly collected data

When you interact with our website:

  • First and last name
  • Professional email address
  • Phone number (optional)
  • Company name
  • Job title/Position held
  • IP address
  • Browser type and operating system
  • Pages visited on our site

When using our SOC services:

  • Contact information of system administrators
  • Security logs of your infrastructure
  • IP addresses of your network
  • Network traffic metadata (no communication content)
  • Information about detected security events
  • Technical data about your infrastructure (servers, equipment)
Important: We NEVER collect:
  • Social insurance number
  • Medical information
  • Personal banking information (we offer bank-level security, not banking services)
  • Content of your internal communications
  • Biometric data

2.2 Automatically collected data

Cookies and similar technologies:

  • Session cookies (necessary for operation)
  • Analytical cookies (with your consent)
  • Preference cookies (with your consent)

See section 8 for more details on cookies.

3. Why do we collect this data?

We collect and use your data solely for the following purposes, in accordance with Law 25:

3.1 Provision of our services

Legal basis: Contract execution

  • Provide our 24/7 SOC security monitoring services
  • Detect and respond to cybersecurity threats
  • Generate incident reports and recommendations
  • Ensure maintenance and technical support

3.2 Customer communication and support

Legal basis: Consent or contract execution

  • Respond to your information requests
  • Send critical security notifications
  • Provide technical support
  • Inform you of important service updates

3.3 Service improvement

Legal basis: Legitimate interest

  • Analyze use of our website (anonymized data)
  • Improve our threat detection algorithms
  • Develop new security features
  • Conduct cybersecurity research (anonymized data)

3.4 Legal and regulatory compliance

Legal basis: Legal obligation

  • Comply with our legal obligations in Quebec and Canada
  • Respond to requests from competent authorities (with warrant)
  • Maintain a record of privacy incidents
  • Preserve evidence in case of litigation

We NEVER sell your personal data to third parties.

4. How do we protect your data?

Security is at the heart of our business. We implement bank-level security measures to protect your data:

4.1 Technical measures

✅ AES-256 Encryption
  • All data in transit is encrypted with TLS 1.3
  • All data at rest is encrypted with AES-256
  • Encryption keys are managed securely
✅ Strict access controls
  • Mandatory multi-factor authentication (MFA)
  • Least privilege principle applied
  • Quarterly access review
✅ Continuous monitoring
  • 24/7 monitoring of our systems
  • Real-time intrusion detection
  • Complete audit logs of all access
✅ Secure infrastructure
  • Servers hosted in Canada (jurisdictional compliance)
  • Next-generation firewall
  • Advanced network segmentation
  • Daily encrypted backups

4.2 Organizational measures

✅ Staff training
  • Regular privacy awareness training
  • Signed confidentiality agreements (NDA)
  • Data access limited by business need
✅ Policies and procedures
  • Documented information security policy
  • Incident management procedure
  • Data breach response plan
  • Regular security audits
✅ Third-party management
  • Rigorous supplier evaluation
  • Contracts with data protection clauses
  • Continuous compliance monitoring

5. How long do we keep your data?

We respect the principle of minimization: your data is kept only as long as necessary.

5.1 Retention periods

Data type Retention period Reason
Données de contact Duration of business relationship + 1 year Customer follow-up and compliance
Logs de sécurité SOC 7 years Legal obligation and forensic analysis
Incidents de sécurité 10 years Compliance and prevention
Cookies analytiques 13 months maximum Usage analysis
Données de navigation 90 days Site improvement
Demandes d'accès (Loi 25) 3 years Legal obligation

5.2 Data deletion

At the end of these periods:

  • Data is securely deleted (irreversible erasure)
  • Backups containing this data are also purged
  • You can request early deletion (see section 7)
Exception: We may retain data longer if:
  • Required by law
  • Necessary to defend our legal rights
  • You have given us explicit consent for extended duration

6. Do we share your data?

6.1 General principle

We do not sell, rent, or share your personal data, except in cases explicitly mentioned below.

6.2 Authorized sharing

With your explicit consent:

  • Technology partners to improve our services (with your prior agreement)
  • Other companies in your group (if you ask us)

To execute our services:

Technical subcontractors (hosting, infrastructure)

  • All located in Canada
  • Bound by strict confidentiality contracts
  • Subject to regular audits

Essential service providers (support, maintenance)

For legal obligations:

  • Police or judicial authorities (only with a court order)
  • Regulatory bodies (Quebec Access to Information Commission)
  • Lawyers in case of litigation

6.3 Data transfer outside Quebec

Principle: Your data is stored and processed in Canada (primarily Quebec).

Exception: If we must transfer data outside Quebec:

  • We will obtain your explicit consent beforehand
  • We will implement appropriate contractual safeguards
  • We will conduct a Privacy Impact Assessment (PIA)
  • You will be informed of associated risks

Currently: No transfers outside Canada are being made.

7. Your rights under Law 25

As a Quebec citizen, you have enhanced rights under Law 25:

7.1 Right of access

You can request:

  • A copy of all your personal data we hold
  • The purposes for which we process this data
  • The categories of persons who have access to it
  • The origin of this data (if not collected directly)

Comment? Envoyez un courriel à [email protected]
Délai de réponse: 30 jours maximum (sans frais)

7.2 Right of rectification

You can request:

  • Correction of inaccurate or incomplete data
  • Update of your information

Comment? Contactez [email protected] avec les corrections
Délai de réponse: 30 jours maximum

7.3 Right of deletion (right to be forgotten)

You can request:

  • Deletion of your personal data
  • Cessation of processing of your data

Exceptions: We may refuse if:

  • Required by law (e.g., security logs 7 years)
  • Necessary to defend our legal rights
  • Execution of an ongoing contract

Comment? Envoyez un courriel à [email protected]
Délai de réponse: 30 jours maximum

7.4 Right to data portability

You can request:

  • Receive your data in a structured, machine-readable format (JSON, CSV)
  • Transfer your data to another provider

Comment? Contactez [email protected]
Délai de réponse: 30 jours maximum

7.5 Right of objection

You can object to:

  • Processing of your data for marketing purposes
  • Use of your data for secondary purposes
  • Automated decision-making concerning you

How? Click "Unsubscribe" in our emails or contact us

7.6 Withdrawal of consent

At any time, you can:

  • Withdraw your consent for specific processing
  • Modify your cookie preferences

Important: Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

7.7 How to exercise your rights?

Courriel: [email protected]
Courrier postal: Appollon Inc., 2278 rue cartier, Montreal, Canada

Required documents:

  • Copy of government-issued ID (to verify your identity)
  • Precise description of your request

We ALWAYS respond within 30 days.

7.8 Right to file a complaint

If you believe we are not respecting your rights, you can file a complaint with:

Quebec Access to Information Commission (CAI)

Site web: www.cai.gouv.qc.ca
Téléphone: 1-888-528-7741
Courriel: [email protected]

8. Cookies and similar technologies

8.1 What is a cookie?

A cookie is a small text file stored on your device that allows the website to remember your preferences and actions.

8.2 Types of cookies used

Strictly necessary cookies

(no consent required)

  • Session cookies (deleted on browser close)
  • Security cookies (attack prevention)
  • Authentication cookies (if you have an account)

Durée: Session uniquement

Preference cookies

(consent required)

  • Preferred language
  • Display settings

Durée: 12 mois maximum

Analytical cookies

(consent required)

  • Google Analytics (anonymized, truncated IP)
  • Traffic analysis and user behavior

Durée: 13 mois maximum

8.3 Cookie management

You control your cookies:

  • Accept or refuse via our consent banner
  • Modifier vos préférences à tout moment: Paramètres cookies
  • Block all cookies via your browser settings

Important: Blocking necessary cookies may affect website functionality.

8.4 Similar technologies

We also use:

  • Pixels invisibles (web beacons): Pour mesurer l'ouverture des courriels (avec consentement)
  • Stockage local (localStorage): Pour améliorer les performances du site
  • Empreinte digitale (fingerprinting): NON UTILISÉ

9. Changes to this policy

9.1 Updates

This policy may be modified to:

  • Reflect changes in our services
  • Comply with new legal obligations
  • Improve transparency

9.2 Notification of changes

Minor changes:
  • Update of the date at the top of this page
  • Notification on our homepage for 30 days
Major changes:
  • Email notification to all active clients
  • Consent required if necessary
  • 30-day grace period before implementation

We encourage you to review this policy regularly.

10. Contact us

Questions about this policy?

Data Protection Officer:

Name: Ferhat Abbas

Email: [email protected]

Guaranteed response within 5 business days

Technical or commercial questions?

Appollon Inc. Team:

General email: [email protected]

Website: www.appollon-inc.com

Phone: +1(819) 943-8591

Complaints?

If you are not satisfied with our response:

  1. Première étape: Contactez [email protected]
  2. Seconde étape: Demandez une révision interne (délai 15 jours)
  3. Dernière étape: Portez plainte auprès de la CAI (voir section 7.8)

Appollon Inc. Commitment

We are committed to:

✅ Protéger votre vie privée avec les plus hauts standards de sécurité
✅ Être transparents sur nos pratiques de traitement des données
✅ Respecter intégralement la Loi 25 et toutes les lois applicables
✅ Répondre rapidement à toutes vos demandes
✅ Améliorer continuellement nos pratiques de confidentialité

Trust is at the heart of our relationship with you.


Politique de confidentialité version 1.0 - Décembre 2025
Conforme à la Loi 25 (Québec) et aux meilleures pratiques internationales
Appollon Inc. - Cybersécurité de confiance