ActiveXchange Privacy Policy
Document Owner: Chief Information Security Officer (CISO) – fulfilled by CTO
Policy Classification: Public
Version: 2.1
Effective Date: 2025-01-01
Last Reviewed: 2026-04-13
Next Review Date: 2027-04-01
Approved By: Chris Patterson, CPO (acting CTO)
1. Purpose
This policy describes how ActiveXchange collects, uses, retains, safeguards, discloses, and disposes of first-party personally identifiable information (PII) of prospective and current clients, their members, personnel, and other "data subjects". ActiveXchange strives to meet or exceed legislative requirements in all jurisdictions where the ActiveXchange Platform, its products, and services are delivered (collectively "the Platform"). Any changes will be posted to the ActiveXchange website and the Platform, where appropriate.
2. Scope
The Privacy Policy applies to all data collected, aggregated, and processed by ActiveXchange for use in the Platform, including its web applications, APIs, data services, integrations, documentation, and any related tools or resources. This policy governs all forms of data processing, whether by manual or automated means, partners, or authorized third parties.
3. Objectives
- Clearly define the rights, obligations, controls, and legal basis for the collection, use, and processing of personal data by ActiveXchange, for the client and its users, and the data subjects.
- Prevent unauthorized access, disclosure, modification, and destruction of personal information.
- Comply with ISO/IEC 27001:2022 and all applicable legal and regulatory requirements (e.g. GDPR, PIPEDA, Australia Privacy Act).
- Maintain a continually improving Privacy Policy.
- Ensure business continuity and minimize risk.
4. Roles & Responsibilities
| Role | Responsibility |
|---|---|
| Executive Team | Ensure commitment, resourcing, and governance for the Privacy Policy |
| ISMS Owner / CISO | Oversee policy implementation and continuous improvement |
| Security Team | Enforce policy compliance, respond to threats, and manage incident response |
| System Administrators | Manage secure cloud infrastructure and configurations |
| Technology Team | Apply secure coding, deployment, and infrastructure best practices |
| All Staff | Comply with the policy, report incidents or risks |
| Users & Data Subjects | Comply with the policy, report incidents or risks |
5. Information & Data
5.1. First-party & Personal Information
5.1.1. Client (organization) and their user information; name, organization name & address, email address, title, and password, collectively "Client Information" or "User Information".
5.1.2. Personally identifiable information may be collected or accessed for a data subject; name, address, email, phone number, gender, date of birth, identification code.
5.1.3. Behavioral and historic information of a data subject regarding membership types and visit activity.
5.2. Third-party & Public Information:
Publicly available information such as Census or other statistical information from reputable recognized entities.
5.3. Usage & Diagnostic Analytics Information
5.3.1. IP address, device information, browser type.
5.3.2. Logs of actions with the Platform by users, such as features used, frequency, changes made.
5.4. Communication Data
5.4.1. Support requests, client service interactions.
5.4.2. Marketing preferences and consents.
5.5. Collection Methods
5.5.1. Directly entered by a client or user within the Platform.
5.5.2. Automatically collected via API, webhook, or similar direct access to a client’s system with authorization.
5.5.3. Automatically collected by the Platform, firewall, or access authorization element.
6. Purpose & Legal Basis of Processing
ActiveXchange shall only collect the information reasonably necessary to:
6.1.1. Deliver the products and services specified under a Service Agreement.
6.1.2. Provide, maintain, and improve the Platform, its products and services.
7. Acceptable Uses of Personal Information
In delivery of the Platform, personal information may be processed and used as follows;
7.1.1. Ensure an individual’s geographical, age, and gender information are consistent.
7.1.2. Analysis and statistical evaluation of individual or group trends in behaviors and insights.
8. Sharing Information
8.1. ActiveXchange may enlist third-party service providers to provide programs and support services consistent with this Privacy Policy.
8.2. Client and User Information may be shared with trusted service providers.
9. Data Retention
9.1. ActiveXchange shall maintain documents, records, and information for certain periods;
9.1.1. Personal data may be retained for five years after verified cessation of activity.
9.1.2. Client Information may be retained for at least five years after business relationship ceases.
10. Data Subject Consent & Rights
Individuals have rights regarding their personal information, including requesting disclosure, corrections, and the deletion of their identifiable information.
11. Security & Safeguards
ActiveXchange uses technical and organizational controls to protect personal information from unauthorized access and theft.
12. Privacy of Minors
The Platform is not intended for use by minors, and personal information on individual minors is not knowingly collected without proper consent.
13. Third-Party Links & Services
ActiveXchange is not responsible for the privacy practices of third-party sites.
14. Governing Law
This Privacy Policy shall be governed by the laws of the jurisdiction where the information originated.
15. Contact Information
For any questions or concerns regarding this Privacy Policy, contact ActiveXchange via the designated emails based on your location.
16. Compliance & Complaint Resolution
ActiveXchange will engage in good faith discussions to resolve any complaints related to this Privacy Policy.
17. General Provisions
This Privacy Policy constitutes the complete agreement between the user and ActiveXchange.
18. Revisions
ActiveXchange reserves the right to modify its Privacy Policy at any time, with changes posted on the website.
19. Acknowledgment and Acceptance
By accessing or using the ActiveXchange Platform, users agree to adhere to this Privacy Policy.
20. Review & Continuous Improvement
This policy will be reviewed annually to reflect organizational, technological, or regulatory changes.
21. Document Control
| Version | Date | Description | Author | Approved |
|---|---|---|---|---|
| 2.1 | 2026-04-13 | Update privacy contact info and other modifications | CP | CP |
| 2.0 | 2025-11-14 | Policy alignment with ISO27001, simplification, and standardization | CP | CP |
| 1.0 | 2025-01-01 | Initial privacy policy adapted from earlier documents | CP | CP |
Appendix A - Cloud-service Provider Security Documentation
- Microsoft Azure: Backend database and frontend software management.
Compliance and regulatory disclosures. - Google Cloud: Internal file management.
Compliance and regulatory disclosures.