Privacy Policy
1. Introduction
Merit Empowering You, operating under the trade name Merit Empower, with its registered office at 206-7880 Keele Street, in the city of Vaughan, province of Ontario, postal code L4K 4G7, Canada, is deeply committed to protecting the privacy and security of your personal information. This comprehensive Privacy Policy explains in thorough detail how we collect, use, disclose, retain, and safeguard information when you interact with our website at www.meritempower.lol, engage our computer systems design and integrated technology services, communicate with us through electronic mail, telephone, or written correspondence, or otherwise establish and maintain a business relationship with our organization.
This website and its associated digital properties were designed and developed by Merit Empower. The development and ongoing technical maintenance of our online presence are governed by rigorous data protection protocols that ensure any information accessed during the creation, maintenance, or enhancement of our digital properties is handled exclusively for authorized purposes and protected in accordance with the standards set forth in this policy and applicable Canadian privacy legislation.
By accessing or using our website, engaging with our professional services, submitting inquiries, or otherwise providing us with your personal data through any means, you acknowledge that you have read, understood, and agree to the terms set forth in this Privacy Policy. If you do not agree with any provision of this policy, you should discontinue use of our website and refrain from providing personal information to us. This policy applies to all users of our services, including prospective clients, active clients, website visitors, job applicants, and vendors, regardless of geographic location, to the maximum extent that applicable law permits.
We reserve the right to update, modify, amend, or replace this Privacy Policy at any time at our sole discretion. Material changes will be communicated through a prominent notice posted on our website at least thirty calendar days prior to the effective date of the change. Your continued use of our website or services following the posting of changes constitutes your acceptance of the revised policy. We strongly encourage you to review this page periodically to stay informed about our data practices and your rights.
2. Scope and Applicability
This Privacy Policy applies to all personal information collected, processed, stored, or otherwise handled by Merit Empower in the course of providing our professional computer systems design and related services. Personal information means any information about an identifiable individual, including but not limited to name, electronic mail address, physical address, telephone number, employment information, financial data, technical identifiers such as IP addresses, and any other information that could reasonably be used to identify an individual directly or indirectly.
As a Canadian organization, Merit Empower is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), which governs the collection, use, and disclosure of personal information in the course of commercial activities. Where applicable provincial legislation imposes additional or different requirements — such as the Personal Information Protection Act in Alberta or British Columbia, or Quebec's Act Respecting the Protection of Personal Information in the Private Sector — we comply with those requirements for individuals residing in those jurisdictions. We also recognize and respect the privacy rights of individuals located outside Canada to the extent that foreign privacy laws may apply to our processing activities involving their personal data.
This policy does not apply to anonymized, aggregated, or de-identified data that cannot reasonably be associated with an identifiable individual. Such data may be used for research, analytics, service improvement, and other legitimate business purposes without restriction under this policy.
3. Types of Information We Collect
Merit Empower collects several categories of information in the course of operating our business and providing professional technology services to our clients. The scope and nature of the information we collect depends on the context of your interactions with us, the services you engage, and the preferences and settings you select at the point of collection. We are committed to collecting only that information which is reasonably necessary to fulfill the purposes described in this policy and to deliver the services you have requested.
3.1 Personal Information You Provide Directly
We collect personal information that you voluntarily provide to us when you interact with our website, communicate with our team, or engage our professional services. This category includes but is not limited to the following types of data:
Contact and Identity Data — Your full legal name, electronic mail address, telephone number, physical mailing address, company or organizational affiliation, job title, and professional credentials. This information is collected when you submit our contact form, request a consultation, subscribe to our communications, register for events, or correspond with us directly through any communication channel.
Engagement and Project Data — Information relating to the professional services you request from us, including project requirements and specifications, technical infrastructure details, system architecture documentation, network topology information, security assessment parameters, business process descriptions, and any other business or technical data you choose to share during the course of our business relationship. This category also includes feedback you provide about our services and any preferences you express regarding project implementation.
Financial and Billing Data — Information necessary to process payments for our services, including billing addresses, purchase order numbers, wire transfer instructions, credit references, tax identification numbers, and records of invoices and payments. We do not directly store full credit card numbers or bank account credentials on our systems; payment processing is conducted through PCI-DSS compliant third-party payment processors who are contractually obligated to protect your payment information.
Communications Data — The content of any messages, inquiries, support requests, feedback, proposals, or other correspondence you send to us, whether through electronic mail, telephone conversations, contact forms, postal mail, or any other communication channel. We may retain records of these communications for quality assurance, compliance, legal defense, and service improvement purposes.
Employment Application Data — If you apply for employment with Merit Empower, we collect information contained in your resume or curriculum vitae, cover letter, references, work samples, and any other information you choose to provide during the application and interview process. This may include employment history, educational background, professional certifications, language proficiencies, and eligibility to work in Canada.
3.2 Information Collected Automatically
When you visit our website, certain information is automatically collected through standard internet protocols and technologies embedded in your browsing session. This automatic collection helps us understand how our website is used, maintain security, improve the user experience, and comply with our legal obligations.
Technical and Usage Data — This encompasses your Internet Protocol (IP) address, browser type and version, operating system and platform, device type and hardware identifiers, screen resolution and color depth, referring and exit pages, date and time stamps of visits, pages viewed and the duration spent on each page, click patterns and scroll depth, mouse movements and hover events, and other diagnostic and analytics information about your browsing behavior on our website. This data is generally collected in aggregated or pseudonymized form and does not directly identify you unless combined with other information.
Server Log Data — Our web servers automatically log standard information for each request made to our servers, including the requesting IP address, the date and time of the request in Coordinated Universal Time, the HTTP method and full URL requested, the HTTP status code returned, the size of the response in bytes, the user agent string identifying the requesting client software, the referrer header indicating the page that linked to our resource, and the time taken to process the request. These logs are used exclusively for security monitoring, performance optimization, debugging technical issues, and aggregate traffic analysis.
Geolocation Data — We may derive approximate geographic location information from your IP address, such as the city, region or province, and country from which you are accessing our website. This information is used for purposes of analytics, content localization, compliance with regional legal requirements, and protection against fraudulent access attempts. We do not collect precise geolocation data using GPS, Wi-Fi triangulation, Bluetooth beacons, or similar high-accuracy positioning technologies.
3.3 Information from Third-Party Sources
We may receive information about you from third-party sources to supplement the information we collect directly from you. These sources include analytics providers such as Google Analytics, which furnish aggregated data about website traffic patterns and user behavior; advertising networks and social media platforms that may provide demographic and interest-based information; technology partners and resellers that may refer prospective clients to our organization; public databases and professional networking platforms that contain publicly available business information; and credit reference agencies where necessary to assess creditworthiness and establish business relationships. We require that all third parties from which we receive personal information have obtained that information lawfully and have provided appropriate notice and obtained any necessary consent for its disclosure to us.
4. How We Use Collected Information
Merit Empower uses the personal information we collect for the following business and commercial purposes, all of which are grounded in legitimate business interests, contractual necessity, legal compliance obligations, or your explicit consent where required by applicable law. We do not use personal information for purposes that are incompatible with those described in this policy without providing you with prior notice and, where legally required, obtaining your consent.
Service Delivery and Contract Fulfillment — We use your information to provide, maintain, and continuously improve the computer systems design, integrated systems architecture, cybersecurity, cloud infrastructure, data systems, and managed technology services you have requested. This includes assessing your technical requirements and organizational needs, developing comprehensive proposals and statements of work, allocating specialist resources and project teams, executing technical projects according to agreed timelines and methodologies, delivering deliverables that meet your specifications, and measuring project outcomes against defined success criteria.
Client Communication and Relationship Management — We use your contact information to send you service-related communications, including project status updates, milestone notifications, deliverable submissions, invoices and payment reminders, technical advisories, security notifications, scheduled maintenance announcements, and responses to your support inquiries. We may also contact you to solicit feedback about the quality of our services, conduct client satisfaction surveys, or inform you about material changes to our terms, conditions, and policies.
Internal Business Operations — We process your information as necessary to support our internal business operations and administrative functions, including financial accounting and auditing, billing, invoicing, and collections management, tax reporting and regulatory filings, insurance procurement and claims management, strategic planning and business development, performance analysis and resource allocation, and internal training and quality assurance. These processing activities serve our legitimate business interests in managing and operating our professional services firm effectively and in compliance with applicable legal and regulatory requirements.
Systems Security and Fraud Prevention — We use information to monitor, detect, investigate, and prevent fraudulent transactions, unauthorized access attempts, security incidents, denial-of-service attacks, malware infections, and other illegal or prohibited activities that could compromise the confidentiality, integrity, or availability of our systems and data. This includes continuous analysis of access logs, implementation of rate limiting and traffic filtering, execution of vulnerability assessments and penetration testing, deployment of security patches and configuration hardening, and maintenance of the overall security posture of our digital infrastructure.
Legal Compliance and Regulatory Obligations — We process personal information as necessary to comply with applicable federal, provincial, and territorial laws, regulations, legal processes, court orders, and governmental requests in Canada and in jurisdictions where we conduct business. We also process information to enforce our contractual agreements, terms of service, and internal policies; to protect the rights, privacy, safety, and property of Merit Empower, our clients, employees, contractors, and the general public; to respond to claims of intellectual property infringement or violation of third-party rights; and to establish, exercise, or defend against actual or potential legal claims in any forum.
Marketing and Promotional Communications — With your consent where required by applicable law, we may use your contact information to send you electronic newsletters, industry insights, technology white papers, case studies, event invitations, and promotional materials about our services and capabilities. You may opt out of receiving marketing communications at any time by following the unsubscribe instructions included in each communication or by contacting us directly at info@meritempower.lol. Opting out of marketing communications does not prevent us from sending you service-related communications necessary for the ongoing management of our business relationship.
Website Improvement and User Experience Analytics — We analyze aggregated and de-identified usage data from our website to understand how visitors discover, navigate, and interact with our content; to identify areas where usability can be improved; to test and optimize navigation structures and page layouts through controlled experimentation; to measure the effectiveness of our content and marketing efforts; and to ensure that our digital properties remain accessible, performant, and compatible with the diverse range of devices and browsers used by our audience.
Research, Development, and Innovation — We may use anonymized and aggregated data derived from our service engagements and website analytics to conduct research, develop new service methodologies and offerings, improve existing technical approaches, contribute to industry knowledge through publications and presentations, and benchmark our performance against industry standards. Any data used for research and development purposes is de-identified using techniques that ensure individuals cannot be reasonably re-identified from the processed data.
5. Legal Bases for Processing
Under PIPEDA and other Canadian privacy legislation, Merit Empower relies on the following legal bases, as applicable, for the collection, use, and disclosure of personal information described in this Privacy Policy:
Consent — We rely on your knowledge and consent for the collection, use, and disclosure of personal information, except where PIPEDA or other applicable legislation provides an exception to the consent requirement. Consent may be express — given explicitly through a written or oral statement — or implied — reasonably inferred from your actions and the surrounding circumstances. At the time of collection, we identify the purposes for which information is being collected, and we seek new consent if we wish to use the information for a purpose not previously identified.
Contractual Necessity — Where you have entered into a contractual relationship with Merit Empower for the provision of our professional services, we process your personal information as necessary to perform our obligations under that contract, including delivering services, managing project resources, issuing invoices, and communicating about the status and progress of engagements.
Legitimate Business Interests — We process personal information where we have a legitimate business interest that does not override your fundamental rights and freedoms. Our legitimate interests include operating our business effectively, maintaining the security of our systems, improving our services, conducting analytics and research, and marketing our services to prospective clients. We carefully balance our legitimate interests against any potential impact on your privacy rights.
Legal Obligation — We process personal information where necessary to comply with our legal obligations under Canadian federal and provincial laws, including tax and accounting requirements, employment standards legislation, anti-spam legislation, and court orders or other binding legal demands.
6. Information Sharing and Disclosure
Merit Empower does not sell, rent, trade, or lease your personal information to third parties for monetary consideration or any form of economic benefit. We share your information only in the limited circumstances and for the specific purposes described below, and we require all recipients to protect your information with safeguards at least as robust as those we employ ourselves.
Service Providers and Subcontractors — We engage carefully selected and vetted third-party companies and individuals to perform essential business functions on our behalf. These service providers include cloud hosting and infrastructure providers that power our digital services; payment processors that facilitate financial transactions; analytics services that help us understand website usage; electronic mail and communication platforms; customer relationship management systems; project management and collaboration software; document management and electronic signature platforms; accounting and financial management software; and professional advisors including external legal counsel, independent auditors, and insurance brokers. These service providers are granted access to personal information only to the extent necessary to perform their designated functions and are bound by contractual confidentiality, data processing agreements, and data protection obligations that prohibit them from using your information for any unauthorized purpose.
Technology Partners and Subcontractors for Client Engagements — In the course of fulfilling certain client engagements, we may collaborate with specialized technology partners or independent subcontractors who bring specific domain expertise or technical capabilities to a particular project. In such cases, we share only the minimum information necessary for the partner or subcontractor to perform their designated role effectively, and we require them through written agreements to maintain confidentiality, implement appropriate security measures, and process data only in accordance with our documented instructions.
Business Transfers and Corporate Transactions — In the event of a merger, acquisition, corporate reorganization, consolidation, sale of assets, financing round, bankruptcy proceeding, or similar corporate transaction involving Merit Empower or any of its business divisions, your personal information may be transferred or disclosed as part of the transaction, subject to standard confidentiality arrangements and applicable legal requirements. We will notify you via a prominent notice on our website and, where technically feasible and legally permissible, through direct electronic mail communication, of any such change in ownership or control of your personal information, as well as any choices you may have regarding your information in connection with such a transaction.
Legal and Regulatory Disclosures — We may disclose your information to law enforcement agencies, government authorities, regulatory bodies, courts, or other authorized third parties when we have a good-faith belief, supported by reasonable grounds, that such disclosure is necessary to: comply with a binding legal obligation, judicial proceeding, court order, warrant, subpoena, or governmental request; enforce our Terms of Service, service agreements, or other contractual terms and conditions; investigate, prevent, or take action regarding suspected fraud, security incidents, intellectual property infringement, or illegal activity; protect the security, integrity, and availability of our systems, networks, and data; and protect the rights, property, and personal safety of Merit Empower, our employees, clients, business partners, and the general public.
With Your Explicit Consent — We may share your personal information for any other purpose not described in this section with your explicit, informed consent, which may be obtained at the time of collection or at a later time. You may withdraw your consent at any time, subject to legal or contractual restrictions, and upon reasonable notice. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Aggregated and De-Identified Data — We may produce and share aggregated, anonymized, or de-identified information that cannot reasonably be used to identify an individual with third parties for research, industry benchmarking, marketing analytics, academic publication, and other legitimate purposes. Information in this form does not constitute personal information under PIPEDA or other applicable privacy legislation and is not subject to the restrictions described in this policy.
7. Cross-Border Data Transfers
As a Canadian business that may utilize cloud services, technology platforms, and service providers located in various jurisdictions around the world, your personal information may be transferred to, stored in, or processed in countries outside Canada, including the United States of America and member states of the European Union. When we transfer personal information across international borders, we take reasonable steps to ensure that the information receives a level of protection comparable to that afforded under Canadian privacy law, regardless of the jurisdiction in which it is processed.
These protective measures include conducting due diligence assessments of the privacy laws and practices in the recipient jurisdiction; entering into contractual agreements that impose data protection standards equivalent to those required under PIPEDA and other applicable Canadian legislation; requiring service providers to implement appropriate technical and organizational security measures; limiting transfers to what is reasonably necessary for the specified purposes; and maintaining accountability for personal information transferred to third parties for processing on our behalf.
By using our website or engaging our services, you acknowledge that your personal information may be transferred across international borders for the purposes described in this policy. If you have specific questions or concerns about cross-border data transfers affecting your personal information, please contact us using the details provided in the Contact Information section below.
8. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, personalize content delivery, and continuously improve the quality of our digital services. This section explains what cookies are, how we use them, the types of cookies we deploy, and how you can exercise meaningful choice and control over their placement on your device.
8.1 Understanding Cookies
Cookies are small text files — typically consisting of letters and numbers — that websites place on your internet-connected device, including desktop computers, laptop computers, smartphones, and tablets, when you visit them. Cookies serve a variety of essential and useful functions: they enable websites to remember your preferences and settings between visits, recognize you when you return to a site, understand how you navigate through pages and interact with content, and deliver information and advertisements that are relevant to your interests based on your browsing patterns.
Cookies may be classified as session cookies, which expire and are automatically deleted when you close your web browser, or persistent cookies, which remain stored on your device for a predetermined period — ranging from minutes to years — or until you manually delete them through your browser settings. In addition to cookies, we may use similar technologies including web beacons — tiny graphic images, also called pixel tags or clear GIFs, embedded in web pages or electronic mail messages that allow us to determine whether you have accessed particular content or opened a message; local storage objects such as HTML5 web storage, which store key-value data directly in your browser that persists across browsing sessions; and client-side scripts that track user interaction patterns and performance metrics on our site. Collectively, we refer to all of these as tracking technologies throughout this policy.
8.2 Categories of Cookies We Use
Strictly Necessary Cookies — These cookies are absolutely essential for the basic operation, security, and core functionality of our website. They enable fundamental features such as maintaining your session state while navigating between pages, processing form submissions securely, remembering your cookie consent preferences, and enforcing security configurations. Our website cannot function properly without these essential cookies, and they are set automatically when you visit our site. Under most privacy regulations, including PIPEDA, strictly necessary cookies do not require prior consent because they are integral to the provision of the service you have explicitly requested by visiting our website.
Performance and Analytics Cookies — These cookies collect aggregated and pseudonymized information about how visitors use and interact with our website, including which pages are viewed most frequently, the sequence in which visitors navigate between pages, how long visitors spend on particular content sections, whether visitors encounter error messages or broken links, the approximate geographic distribution of our audience, and the types of browsers and devices used to access our site. We use this analytical data to compile statistical reports that help us measure and optimize website performance, identify and correct usability deficiencies, improve the relevance and quality of our content, and make informed decisions about our digital strategy. Our analytics cookies are primarily provided through Google Analytics and similar industry-standard platforms; the data collected through these services is aggregated and pseudonymized to the maximum extent technically feasible.
Functional Cookies — These cookies allow our website to remember choices and preferences you make during your visit and provide enhanced, more personalized features and functionality. They may be used to remember your language preference, regional selection, display settings, text size adjustments, and other customization options you select. Functional cookies may also enable certain interactive elements of our website, such as embedded video players, interactive maps, social media sharing tools, and comment systems. While these cookies are not strictly essential for the operation of our website, disabling them may impair certain features and reduce the degree of personalization and convenience available during your browsing experience.
Marketing and Targeting Cookies — These cookies are designed to deliver advertisements and promotional content that are more relevant to you and your professional and commercial interests; to limit the frequency with which you see the same advertisement; and to measure the effectiveness and return on investment of advertising campaigns. These cookies may be set through our website by our advertising partners and may be used by those partners to build a profile of your browsing interests and show you relevant advertisements on other websites that you visit. We currently do not deploy marketing or targeting cookies directly on our website; however, third-party services we integrate — such as embedded video content from platforms like YouTube or Vimeo, or social media widgets — may set their own cookies for which we are not directly responsible and over which we have no direct operational control.
8.3 Managing Your Cookie Preferences
You have the right to control and manage the use of cookies on our website through several mechanisms. Most modern web browsers automatically accept cookies by default, but you can modify your browser settings to decline all cookies, to delete existing cookies stored on your device, to alert you with a notification when a cookie is being set, or to accept or reject cookies on a site-by-site basis. The specific methods for managing cookie preferences vary considerably by browser; we recommend consulting the help documentation or visiting the official support website for your preferred browser — such as Google Chrome, Mozilla Firefox, Apple Safari, or Microsoft Edge — for detailed, step-by-step instructions specific to your browser version.
Please be aware that disabling certain categories of cookies, particularly strictly necessary cookies, may impair the functionality, security, and usability of our website. Some features may not function as designed, and you may be unable to access or use certain areas, interactive elements, or services. Disabling analytics cookies does not affect the functionality of our site but limits our ability to understand usage patterns and continuously improve your browsing experience based on empirical evidence.
You may also exercise choices regarding interest-based advertising through self-regulatory programs operated by industry associations. In Canada, the Digital Advertising Alliance of Canada (DAAC) provides an opt-out tool at www.youradchoices.ca that allows consumers to opt out of receiving targeted advertisements from participating companies across multiple platforms and devices. Residents of the European Economic Area, the United Kingdom, and Switzerland may manage their advertising preferences through the European Interactive Digital Advertising Alliance (EDAA) opt-out platform at www.youronlinechoices.com.
9. Data Security Measures
Merit Empower implements and continuously maintains comprehensive administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of your personal information against accidental, unlawful, or unauthorized destruction, loss, alteration, disclosure, access, use, or processing. Our security framework is built upon industry-recognized standards, guidelines, and best practices, including the risk management principles articulated in the NIST Cybersecurity Framework and the control objectives set forth in the ISO/IEC 27001 family of information security management standards.
Technical Security Safeguards — We deploy a multi-layered defense architecture that includes Transport Layer Security (TLS) encryption to protect the confidentiality and integrity of data transmitted between your browser and our servers over public networks; enterprise-grade firewalls with stateful packet inspection, intrusion detection and prevention systems, and logical network segmentation to protect our internal infrastructure from unauthorized external access; multi-factor authentication mechanisms and granular, role-based access controls that restrict access to personal information exclusively to authorized personnel who require such access to perform their legitimate job functions; comprehensive endpoint protection, anti-malware, and endpoint detection and response software deployed across all computing systems that process, store, or transmit personal data; automated vulnerability scanning and periodic penetration testing conducted by both internal security personnel and accredited independent third-party security assessors; and secure software development lifecycle practices — including static and dynamic code analysis, dependency vulnerability scanning, and mandatory peer code review — applied consistently to all of our digital properties and internal tools.
Administrative Security Safeguards — We maintain comprehensive, documented information security policies and operational procedures that are formally reviewed and updated at least annually, or more frequently as material changes in our operations, service offerings, or the evolving threat landscape necessitate. We conduct background screening checks on all personnel and contractors who will have access to sensitive systems or personal data, to the extent permitted by applicable employment and human rights legislation. We provide mandatory, ongoing security awareness and privacy compliance training to all employees, contractors, and third-party personnel who have access to personal information, covering topics including phishing recognition, secure data handling, incident reporting obligations, and the ethical responsibilities associated with processing personal data. We maintain detailed incident response procedures that define clear roles, responsibilities, escalation paths, communication protocols, and documentation requirements for responding to actual or suspected data security incidents, and we test these procedures through tabletop exercises at regular intervals. We also maintain business continuity and disaster recovery plans that are designed to ensure the resilience, rapid restoration, and ongoing availability of our critical systems and data in the face of disruptive events.
Physical Security Safeguards — Our corporate offices, data center facilities, and other physical locations where personal information may be stored or processed are protected by layered physical access controls, including perimeter security, monitored alarm systems, video surveillance in common areas where permitted by law, and access card authentication systems with comprehensive access logging. Server rooms, network equipment areas, and physical media storage locations are restricted to specifically authorized personnel only, with access requiring multi-factor authentication. Physical documents and removable media containing personal data are stored in locked, access-controlled cabinets or rooms when not in active use and are securely destroyed — through cross-cut shredding or certified media destruction services — when they are no longer required for business or legal purposes.
Despite the comprehensive nature of our security program, it is important to acknowledge that no method of electronic storage or transmission over the Internet or any wireless network can be guaranteed to be absolutely secure against all potential threats. While we strive to protect your personal information using commercially reasonable and industry-appropriate means, we cannot provide an unconditional guarantee of absolute security. In the unfortunate event of a data breach involving personal information that poses a real risk of significant harm to the affected individuals, we will notify those individuals and the Office of the Privacy Commissioner of Canada and any other relevant supervisory authorities in accordance with the mandatory breach notification requirements prescribed by PIPEDA and other applicable legislation, within the timeframes mandated by such laws.
10. Data Retention and Disposal
Merit Empower retains your personal information only for the duration that is reasonably necessary to fulfill the legitimate purposes for which it was originally collected, or as otherwise required or expressly permitted by applicable Canadian federal, provincial, or territorial law. The specific retention period applicable to any particular category of personal data is determined by carefully considering the following criteria, which we apply consistently and systematically to our retention scheduling decisions:
Purpose of Collection — We retain personal data for the duration necessary to provide the professional services you have requested and to fulfill the original purpose for which the data was collected at the outset of our relationship. Information that is collected for multiple purposes is retained for the longest period applicable to any of those identified purposes.
Contractual Obligations — Where you have entered into a contractual relationship with Merit Empower for the delivery of professional services, we retain your personal information for the entire duration of the contract and for a reasonable period following its conclusion — typically three to seven years, depending on the nature of the engagement and the type of data — to address any post-termination matters such as warranty claims, residual support obligations, contractual disputes, or audit requirements, and to comply with applicable statutes of limitations for potential legal claims.
Legal and Regulatory Requirements — We retain certain categories of information for periods specifically mandated by applicable federal and provincial laws and regulations in Canada. These include tax and financial record-keeping requirements under the Income Tax Act and Excise Tax Act, which typically require retention of financial records for a minimum of six years; employment standards legislation that requires retention of payroll and employment records for prescribed periods; and industry-specific regulations that may impose additional retention obligations on technology consulting firms.
Litigation and Dispute Resolution — If, at any time, we reasonably anticipate that particular information may be relevant to actual, pending, or reasonably foreseeable litigation, regulatory investigations, government inquiries, or other adversarial legal proceedings, we will preserve and retain the relevant information — through a legal hold process — until the matter is fully and finally resolved, including the expiration of all applicable appeal periods.
Security Monitoring and Incident Investigation — We retain security-related logs, audit trails, access records, and other system monitoring data for a period consistent with our security monitoring requirements, threat intelligence integration, and incident investigation needs, after which such data is securely deleted, cryptographically erased, or rendered anonymous using industry-standard techniques.
When personal information is no longer required for the purposes enumerated above and is not subject to any legal or regulatory hold, we securely and irreversibly destroy, delete, or anonymize it using methods appropriate to the sensitivity, volume, and format of the data. These methods include cryptographic erasure protocols for encrypted data at rest, secure digital deletion and overwriting for electronic records stored on magnetic or solid-state media, and cross-cut shredding, pulping, or certified incineration for paper documents and physical storage media. Where data is anonymized rather than destroyed, the anonymization process is designed to be irreversible using reasonably available technology and statistical methods.
11. Your Privacy Rights
Depending on your jurisdiction of residence and the nature of your relationship with Merit Empower, you may have certain statutory rights regarding the personal information we hold about you under applicable data protection and privacy laws. Merit Empower fully respects these rights and has established internal processes and designated personnel to facilitate their effective exercise. The rights described below represent the most commonly available data subject rights under Canadian privacy legislation, though the specific rights available to you may vary depending on the laws applicable to your place of residence and the particular circumstances of our data processing activities.
Right to Access Your Information — Under PIPEDA, you have the right to request access to the personal information that Merit Empower holds about you. You may request confirmation of whether we are processing personal information relating to you and, if so, request access to that information in a comprehensible format. We will provide you with an account of the use that has been made of your information and an account of the third parties to which it has been disclosed. We will respond to access requests within thirty calendar days, or within any extended period permitted by law with written notice of the extension and the reasons for it.
Right to Challenge Accuracy and Request Correction — You have the right to challenge the accuracy and completeness of your personal information and to request that we amend or correct it as appropriate. If we have disclosed inaccurate or incomplete information to third parties, we will, where appropriate and feasible, transmit the corrected information to those third parties. If we refuse to correct information following a challenge to its accuracy, we will annotate the information with a notation indicating that a correction was requested but not made, and we will provide the reasons for our refusal.
Right to Withdraw Consent — Where we rely on your consent as the legal basis for the collection, use, or disclosure of your personal information, you have the right to withdraw that consent at any time, subject to legal or contractual restrictions and upon providing us with reasonable notice. We will inform you of the implications of withdrawing consent, which may include our inability to provide certain services that depend on the processing of the relevant information. Withdrawal of consent does not have retroactive effect and does not affect the lawfulness of any processing conducted prior to the withdrawal.
Right to File a Complaint — If you believe that Merit Empower has not adequately addressed your privacy concerns or has failed to comply with its obligations under applicable privacy legislation, you have the right to file a formal complaint with the Office of the Privacy Commissioner of Canada. The Commissioner has the authority to investigate complaints, make findings, issue recommendations, and, in certain circumstances, initiate court proceedings. We encourage you to contact us directly through the channels provided in this policy before filing a complaint, to give us the opportunity to understand and resolve your concern promptly and amicably.
12. Children's Privacy
Our website and professional services are designed, developed, and marketed exclusively for business professionals, organizational decision-makers, and corporate entities. They are not designed, intended, or configured to attract, solicit, or collect information from children under the age of thirteen, nor do we knowingly collect, maintain, process, or disclose personal information from individuals we have actual knowledge are under the age of thirteen. For purposes of this section, the term children refers to individuals under the age of thirteen as defined under the United States Children's Online Privacy Protection Act (COPPA), and by analogous reference to applicable age thresholds under the privacy legislation of other jurisdictions where we may have a presence or where our website may be accessible.
If we become aware that we have inadvertently collected personal information from a child under the applicable age threshold without verifiable parental consent, we will take immediate and documented steps to permanently delete such information from all of our systems, records, and backup repositories. We strongly encourage parents, guardians, and educators to actively monitor and guide children's internet activities and to instruct children never to provide personal information through websites, forms, or applications without the explicit knowledge and permission of a responsible adult. If you are a parent or legal guardian and you believe that your child has provided us with personal information without your knowledge and consent, please contact us immediately using the contact details set forth in Section 14 of this policy. Upon satisfactory verification of your identity and your relationship to the child, we will promptly and permanently delete the relevant data and provide you with written confirmation that the deletion has been completed.
13. Changes to This Privacy Policy
Merit Empower reserves the unilateral right to update, modify, amend, supplement, or replace this Privacy Policy at any time and at our sole discretion, to accurately reflect changes in our personal information handling practices, operational requirements, service offerings, legal and regulatory obligations, privacy frameworks, and technological capabilities. When we make changes to this policy, we will revise the Effective Date displayed at the top of the document and post the updated version on this publicly accessible page without delay. The updated policy will become effective on the date specified in the accompanying notice, which will not be fewer than thirty calendar days after the date of posting for material changes that significantly affect your privacy rights or our data processing operations.
For material changes — defined as changes that expand the categories of personal information we collect, introduce new purposes for processing that are incompatible with those originally disclosed, materially alter how we share personal information with third parties, change the legal bases on which we rely for processing, significantly curtail the rights available to you under this policy, or otherwise result in processing that a reasonable person would find unexpected or objectionable — we will provide additional, prominent notification through our website, such as a banner notification displayed on our homepage or a pop-up message during your initial visit following the change. Where we maintain your contact information and where consistent with applicable privacy law, we will also endeavor to notify you directly through electronic mail at least thirty calendar days before the material changes take effect.
Changes that are purely editorial, typographical, organizational, or intended solely to improve clarity are not classified as material and do not require the advanced notification described above. We recommend that you review this Privacy Policy each time you visit our website or engage our services to ensure that you remain informed about our current data handling practices and the comprehensive measures we take to protect your privacy and personal information. Your continued use of our website or services following the posting of any revised policy constitutes your acknowledgment of the revised terms and your acceptance of the updated policy. If you do not agree with any provision of the revised policy, you should immediately discontinue use of our website and services. You may also request deletion of your personal data, subject to the lawful limitations and exceptions described in Sections 10 and 11 of this policy.
14. Contact Information
If you have any questions, concerns, requests, or complaints regarding this Privacy Policy, our personal information handling practices, our compliance with PIPEDA or other applicable privacy legislation, or the exercise of your privacy rights, please do not hesitate to contact us using any of the methods provided below. We are genuinely committed to addressing your inquiries promptly, thoroughly, and transparently, and we will endeavor to respond to all privacy-related communications within ten business days of receipt.
Merit Empowering You (Operating as Merit Empower)
Registered Office Address
206-7880 Keele Street
Vaughan, Ontario L4K 4G7
Canada
Electronic Mail
Privacy Inquiries: info@meritempower.lol
Telephone
Main Office: +1 (608) 431-3578
Website
www.meritempower.lol
Designated Privacy Officer
Merit Empower has designated an individual responsible for overseeing organizational compliance with this Privacy Policy and applicable data protection legislation. All communications addressed to the attention of the Privacy Officer at the above contact details will be directed to the responsible individual without delay. If you believe that your privacy concern has not been satisfactorily addressed after engaging with us directly, you retain the right to lodge a formal complaint with the Office of the Privacy Commissioner of Canada at 30 Victoria Street, Gatineau, Quebec K1A 1H3, or through the Commissioner's website at www.priv.gc.ca.