Legal
Privacy Policy
Last updated 7 August 2026
Our position
Privacy is not a compliance exercise for us. We collect the minimum information needed to provide a service, we keep it in Canada, we hold it only as long as we have a reason to, and we do not sell or share it. If we cannot justify collecting something, we do not collect it.
This policy describes what we actually do, not the maximum the law would allow us to do. Where the two differ, this policy binds us.
Who we are
Silentweb is a small technical practice in Kingston, Ontario, Canada, providing web hosting, design and development, cybersecurity, and training services. We are the party responsible for the personal information described here. Privacy questions and requests go to support@silentweb.ca.
What we collect from website visitors
Our website carries no advertising, no third-party trackers, no social media pixels, and no externally hosted fonts or scripts that would report your visit to another company.
Our web server records standard log entries for each request: IP address, timestamp, the resource requested, response status, referrer, and user-agent string. These logs exist to keep the server running and secure — diagnosing faults, identifying abuse, and investigating attacks.
Visit statistics are produced by analytics software we run ourselves, on our own servers in Montreal. No visitor data is sent to any analytics company. We measure aggregate figures — pages viewed, referring sites, rough device categories — and we do not build profiles of individual visitors or attempt to identify you across sessions.
Cookies
The public website sets no cookies. There is no cookie banner on silentweb.ca because there is nothing to consent to.
The hosting control panel is a separate matter, and we would rather over-explain it than let you assume it is as clean as the website. The panel is Plesk, licensed from WebPros International GmbH. When you log in it sets a session cookie that keeps you signed in, plus a number of small session cookies that remember how you have arranged the interface — which columns you are showing, how lists are sorted, whether a notice is dismissed. These clear when your session ends and none of them identify you outside your own account.
Plesk ships with an activity-tracking facility that reports how the panel is used back to its vendor, along with promotional, product-rating, error-reporting, and advertising integrations. We have disabled all of them at the server level, so those cookies are never set and nothing is sent to WebPros or to any advertising or analytics service. You will still see Plesk's own cookie prompt offering to accept all cookies when you first log in — that prompt is built into the software and we cannot remove it. Accepting everything on it does not enable tracking, because the tracking it refers to is switched off underneath. If you prefer, choose necessary cookies only; nothing will behave differently.
Some panel tools open with their own cookies when you use them — the database manager is the common example — and a few optional panel extensions set a longer-lived cookie to remember a preference, such as trusting a device for two-factor authentication. These exist to make the tool work, not to observe you. Plesk publishes a complete cookie inventory in its own cookie policy, and we would rather point you at it than paraphrase it here.
What we collect when you contact us
When you send us an enquiry we collect the name, email address, organisation, and message content you choose to provide. We use it to answer you and, if we work together, to carry out the engagement.
Contacting us does not add you to a mailing list. We do not operate a marketing list, and we will not send you anything you did not ask for.
What we collect when you hold an account
For hosting and client accounts we collect the contact and billing details needed to invoice you, the domain and DNS records needed to operate the service, and the technical records our servers generate in the course of running your site.
Content you host with us — your files, databases, and email — is yours. We access it only when you ask us to, when it is necessary to resolve a fault or restore service, or where we are legally compelled. We do not mine, scan, or analyse client content for any purpose of our own.
Security engagements
Security work necessarily involves sensitive material, so it is governed more tightly than anything else we do. All testing happens under a written engagement that defines scope, timing, and authorisation before any work begins.
Credentials and access granted for testing are held only for the duration of the engagement, kept in an encrypted store, used only within the agreed scope, and revoked or destroyed on completion. We ask that you issue us dedicated test accounts rather than sharing anyone’s personal credentials.
Where testing incidentally exposes real personal data — records visible through a flaw we have found — we record only what is needed to evidence the finding, redact identifying detail wherever the finding can still be understood without it, and never copy data out in bulk. Evidence lives in encrypted storage, is delivered to you with the report, and is destroyed within thirty days of engagement close unless you ask us in writing to hold it longer.
Findings and reports are confidential to you. We do not publish, share, or reuse them, we do not name clients as references without written permission, and we do not disclose vulnerabilities to any third party. Anonymised patterns may inform how we teach and test generally, never in a form that could identify an organisation.
Phishing and social engineering campaigns
Simulated phishing exists to measure how an organisation responds, not to catch individuals out. Our default deliverable is aggregate: click rates, credential-submission rates, and reporting rates for the organisation and, where useful, by department.
Individual results are identified to management only where your own written policy requires individual accountability. Where that is the case, we ask that staff be told in advance that campaigns run and that results may be attributed — testing people without their knowledge that the programme exists is not something we will help you do.
We never use captured credentials. Passwords submitted during a campaign are discarded, not stored, and never tested against real systems. Campaign data is destroyed within thirty days of the final report.
Training records
Where we run awareness training we hold the participant names and email addresses needed to enrol people and record completion, along with completion dates and, where applicable, assessment scores. Completion reporting to your management, board, funders, or insurers covers who completed the training — not how anyone performed on individual questions, unless your policy requires it and staff have been told.
Training records are returned to you and deleted from our systems within ninety days of the programme ending.
Artificial intelligence
We do not put client data, client content, credentials, findings, or any material from a security engagement into any hosted AI service. There is no exception to this and no opt-in that would change it.
We teach AI-assisted development, and we use these tools on our own code and our own writing. They do not touch yours.
Third parties
We keep the list of companies that touch your data as short as we can, and we name every one of them here.
Our servers are dedicated hardware we lease from Leaseweb Canada in Montreal, Quebec. The hosting control panel is Plesk, licensed from WebPros International GmbH in Germany; it runs on our own servers rather than as a hosted service, so account data stays with us, the vendor receives licence validation only, and the panel's usage-tracking and error-reporting features are disabled so no account or usage data flows to it. Domain registrations are placed through a Canadian-operated registrar, which receives the registrant details ICANN requires. Card payments are handled by a payment processor that receives your name, billing details, and card data directly — we never see or store full card numbers. Invoices and accounts are kept in commercial accounting software, which holds your billing name, address, and transaction history.
That is the complete list. We use no ad networks, no data brokers, no marketing platforms, and no lead-generation services. We do not sell personal information, we do not trade it, and we do not disclose it for any purpose other than delivering the service you asked for.
Where your data lives
Client data, website content, email, and backups are stored on our own dedicated servers in a data centre in Montreal, Quebec, Canada. Backups stay in the same jurisdiction. We do not use United States cloud infrastructure for client data, which means your records are not routinely exposed to United States legal process.
Our payment processor and accounting software may process data outside Canada. This is the one place where full Canadian residency is not within our control, and we say so plainly rather than burying it.
How long we keep things
Web server logs are retained for ninety days and then deleted, except where a specific log is preserved as evidence in an active security investigation.
Enquiry correspondence is kept while it remains commercially relevant and reviewed periodically. Account and billing records are kept for the life of the account plus the seven years Canadian tax legislation requires. Security engagement evidence is destroyed within thirty days of close; reports are retained for the contractual period you agree to. Training records are deleted within ninety days of programme end.
When an account closes, your hosted content and backups are deleted after a short grace period so an account closed in error can be recovered. After that they are gone, and we cannot restore them.
Your rights
You may ask us what personal information we hold about you, ask for a copy of it, ask us to correct it, ask us to delete it where no legal obligation requires us to keep it, and withdraw consent for anything not necessary to a service you hold. Exercising any of these rights costs nothing and will never affect how you are treated as a client.
Write to support@silentweb.ca. We will acknowledge within five business days and respond substantively within thirty days. If we refuse a request we will tell you why, in writing, and tell you how to complain.
Legal requests
We respond to lawful, properly issued Canadian legal process, and to nothing less than that. We do not hand over client data on an informal request from police, an agency, or anyone else without a warrant, order, or subpoena that we are satisfied is valid.
Where we receive a request for a client’s data we will notify that client so they can seek their own legal advice, unless we are legally prohibited from doing so. Where a request appears overbroad or improperly issued, we will push back before complying.
Security incidents
If a breach affects your personal information in a way that creates a real risk of significant harm, we will notify you and the Office of the Privacy Commissioner of Canada as PIPEDA requires. We will tell you what happened, what data was involved, what we have done, and what you should do — promptly and without minimising it.
We will not wait for certainty before telling you something has gone wrong. Being informed early matters more than our being able to present a tidy account.
The law that applies
We operate under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Ontario and Quebec privacy legislation. Where a visitor or client is in the European Union or United Kingdom, we honour the access, correction, portability, erasure, and objection rights the GDPR provides, on the same terms as everyone else.
If you are unsatisfied with how we have handled a privacy matter, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to your local supervisory authority if you are in the EU or UK.
Changes to this policy
If we change this policy we will update the date at the top and, where the change is material, note it on our News page. We will not quietly broaden what we collect. If a change would mean using your information for something you would not expect, we will ask you first.