Effective date: 6 July 2026 · Last updated: 6 July 2026 · Version 1.0
This Privacy Policy (the "Policy") explains how Fynaxis ("we", "us", "our") collects, uses, discloses, transfers, retains, and protects personal data (also called "personal information") when you visit fynaxis.com and any related pages (the "Site"), contact us, request a callback or pain-point intake, or otherwise engage with us. It also explains the rights available to you and how to exercise them.
Please read this Policy together with our Cookie Policy and Terms of Service. By using the Site or submitting information to us, you acknowledge that you have read and understood this Policy. Where the law requires consent, we rely on the consent you give (for example, through our cookie banner or a form checkbox), and you may withdraw it at any time.
Fynaxis is a Salesforce consulting company incorporated in the Province of Nova Scotia, Canada, with its office at:
Office 118, 1505 Barrington St., Halifax, Nova Scotia, B3J 3K5
Email: contact@fynaxis.com
Phone: +1 902-200-5503
For the personal data described in this Policy, Fynaxis is the data controller (the party that decides why and how the data is processed) when you interact with the Site. When we deliver consulting services to a client, we may instead act as a data processor / service provider handling data on that client's instructions; in that case the client's own privacy notice governs, and this Policy covers only our Site and direct enquiries.
We have not appointed a representative in the European Union or United Kingdom. Where applicable law requires us to designate a representative or data protection officer, we will do so and publish the details here; in the meantime you may contact us directly using the details in section 18.
We collect only what we need. We do not require you to provide personal data to browse the Site, but some features (such as contacting us) will not work without it.
| Category | Examples | Source |
|---|---|---|
| Contact form data | Name, email address, the content of your message | You, directly |
| Callback / pain-point intake data | Name, phone number, and any details you volunteer about your enquiry | You, directly |
| Correspondence | Emails, call notes, and other communications you send us | You, directly |
| Prospect / client business data | Company name, job title, business contact details, project requirements | You, or your employer |
| Technical & usage data | IP address, browser and device type, operating system, referring pages, pages viewed, dates/times, and similar server-log data | Collected automatically |
| Consent records | Your cookie choices and form consents, with a timestamp | Collected automatically / from you |
Special-category / sensitive data. We do not intentionally collect sensitive personal data such as health, race, religion, political opinions, sexual orientation, biometric or genetic data, government identifiers, or financial account numbers. Please do not include such information in form submissions. If you send it to us unsolicited, you consent to our handling it as described here, and we will delete it when it is no longer needed.
No purchase of data. We do not buy personal data from data brokers.
We use personal data for the purposes below. For individuals protected by the EU or UK GDPR, the applicable legal basis is shown; where we rely on legitimate interests, we have balanced those interests against your rights.
| Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|
| Respond to your enquiry, callback, or intake request and follow up | Steps taken at your request prior to a contract; legitimate interests (responding to and managing enquiries) |
| Provide, deliver, support, and administer our consulting services | Performance of a contract; legitimate interests |
| Operate, secure, monitor, and improve the Site and our systems | Legitimate interests (security, integrity, and improvement of our services) |
| Send service updates or, where permitted, relevant marketing | Consent, or legitimate interests, as applicable (see section 4) |
| Maintain business records and accounts | Legitimate interests; legal obligation |
| Comply with law and respond to lawful requests | Legal obligation |
| Establish, exercise, or defend legal claims and prevent fraud or misuse | Legitimate interests; legal obligation |
| Load optional third-party embeds (e.g. Google Maps) | Consent |
We will not use your personal data for a materially different, incompatible purpose without first telling you and, where required, obtaining your consent.
If we send commercial electronic messages, we do so in accordance with Canada's Anti-Spam Legislation (CASL) and comparable rules in other regions. That means we rely on your consent (express or implied, such as an existing business relationship), we identify ourselves and provide our contact details, and we include a working unsubscribe mechanism in every marketing message. You can opt out at any time by using the unsubscribe link or by emailing contact@fynaxis.com; we will action your request promptly and, in any event, within the time required by law. Opting out of marketing does not stop essential service or transactional messages relating to an active engagement.
The Site uses only essential cookies by default and does not load non-essential cookies, analytics, or third-party embeds until you consent through our cookie banner. Full details, including the categories and specific items we use and how to change your choice, are in our Cookie Policy.
We do not sell your personal data and we do not "share" it for cross-context behavioural advertising. We disclose personal data only in the following circumstances, and only to the extent necessary:
Fynaxis is based in Canada and delivers services in North America and the Gulf Cooperation Council (GCC). Your personal data may be processed in, stored in, or accessed from countries other than your own, including Canada, which may have data-protection laws that differ from those in your country.
Where we transfer personal data out of the European Economic Area, the United Kingdom, or another jurisdiction that restricts transfers, we rely on a lawful transfer mechanism such as an adequacy decision (Canada benefits from a partial EU adequacy decision for commercial organisations subject to PIPEDA) or, where needed, the applicable Standard Contractual Clauses / International Data Transfer Agreement, together with any supplementary measures required. You may request information about the safeguards we use by contacting us.
We keep personal data only for as long as necessary for the purposes described in this Policy, after which we delete it or irreversibly anonymise it. Our general retention periods are:
| Data | Typical retention |
|---|---|
| Enquiries that do not lead to an engagement | Up to 24 months from your last contact with us |
| Client engagement records and correspondence | For the duration of the engagement and up to 7 years afterward (to meet tax, accounting, and limitation-period requirements) |
| Server / security logs | Up to 12 months |
| Cookie-consent records | Up to 12 months, then re-requested |
| Marketing suppression (unsubscribe) lists | Retained as long as needed to honour your opt-out |
Where a longer period is required by law, or where data is relevant to an actual or anticipated legal claim, we retain it until that requirement or claim ends.
We maintain technical and organisational measures appropriate to the risk, which may include encryption in transit (HTTPS), access controls and least-privilege permissions, secure hosting, input validation, logging, and staff confidentiality obligations. No website, transmission, or storage system is completely secure, and we cannot guarantee absolute security; you send information to us at your own risk, and you are responsible for keeping any credentials you hold confidential.
Subject to applicable law and any exemptions, you may have the right to:
How to exercise your rights. Email contact@fynaxis.com with the subject line "Privacy Request" and tell us what you would like to do. We may need to verify your identity before acting, and we may ask for information to locate your records. We will respond within the timeframe required by applicable law (generally within 30 days under PIPEDA and California law, and within one month under the GDPR/UK GDPR, extendable where permitted). We do not charge a fee unless the law allows it (for example, for manifestly unfounded or excessive requests). You may use an authorised agent where the law permits, subject to proof of authority.
You have the rights listed in section 10, the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office), and the right to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time.
You may access and request correction of your personal information and withdraw consent, subject to legal or contractual restrictions and reasonable notice. You may complain to the Office of the Privacy Commissioner of Canada or your provincial privacy regulator.
If you are a California resident, you may request to know what personal information we have collected, used, and disclosed; to delete it; and to correct inaccurate information. We do not sell or share your personal information as those terms are defined by the CCPA, and we do not use or disclose sensitive personal information for purposes that would trigger a right to limit. We will not discriminate against you for exercising your rights. You may submit a request using the contact details in section 18.
Where a GCC personal-data protection law applies to you, you may exercise the access, correction, deletion, objection, and consent-withdrawal rights that law provides, and complain to the competent authority in your jurisdiction. Contact us and we will handle your request in accordance with the applicable law.
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, and we do not carry out profiling of that kind.
The Site is intended for a business audience and is not directed to children under the age of 16, and we do not knowingly collect their personal data. If you believe a child has provided us personal data, contact us and we will delete it.
The Site may link to or embed third-party websites and services that we do not control. This Policy does not apply to them; please review their own privacy notices. We are not responsible for their content or practices.
If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and, where required by law, affected individuals, within the timeframes the applicable law prescribes.
We may update this Policy from time to time to reflect changes in our practices, technology, or the law. The "Last updated" date and version above indicate the current version. Material changes will be posted on this page and, where required, notified to you. Your continued use of the Site after changes take effect means you accept the revised Policy.
We would like the chance to resolve any concern first, so please contact us. You also have the right to complain to a supervisory authority, including: the Office of the Privacy Commissioner of Canada; the UK Information Commissioner's Office (ICO); your EEA data protection authority; the California Privacy Protection Agency / California Attorney General; or the competent GCC data-protection authority for your jurisdiction.
For any question or request about this Policy or your personal data:
Fynaxis
Office 118, 1505 Barrington St., Halifax, Nova Scotia, B3J 3K5
Email: contact@fynaxis.com (subject: "Privacy Request")
Phone: +1 902-200-5503