Privacy Policy

1. Introduction and Scope

Northridge Telecom CORP. (“Northridge Telecom”, “we”, “us”, or “our”) respects your privacy. This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information in connection with: (a) our website at nrtel.ca and related web properties (the “Website”); (b) our telecommunications services, including voice-over-IP (VoIP), home phone, business phone, hosted PBX, SIP trunking, long-distance, and related services (the “Telecom Services”); (c) our cloud, web-hosting, and virtual-machine services, including shared and reseller web hosting, virtual private servers (VPS) and virtual machines, domain registration, email hosting, and related infrastructure (the “Hosting Services”); and (d) our managed information-technology and security services, including remote monitoring and management, endpoint security, backup and disaster recovery, Microsoft 365 administration, mobile device management, and related support (the “MSP Services”, and together with the Telecom Services, the Hosting Services, and the Website, the “Services”). This Privacy Policy applies to current and prospective customers, end-users of customer services, website visitors, and others whose personal information we handle.

This Privacy Policy is incorporated into, and forms part of, our Terms of Use and our Terms and Conditions of Sale. Capitalized terms used but not defined here have the meanings given in those terms.

Controller and processor roles. For our Website, Telecom Services, Hosting Services, and our own billing and account administration, Northridge Telecom generally acts as the organization that determines the purposes of processing (a “controller” or, under Quebec’s Law 25, the person carrying on an enterprise), and this Privacy Policy governs. When we deliver MSP Services (and certain Hosting Services), we may process personal information contained in Customer Data on behalf of, and under the instructions of, our business customer, who remains responsible for that information as between the parties. In that role we act as a service provider or processor; our handling of that Customer Data is governed by our agreement with the customer (including any Data Processing Addendum, available from our Privacy Officer on request), and the customer is responsible for providing any required notices to, and obtaining any required consents from, the individuals concerned.

2. Privacy Officer and Contact

Northridge Telecom has designated a Privacy Officer responsible for our compliance with applicable privacy laws. Our Privacy Officer is:
Chase Martin, Privacy Officer
Email: chase@nrtel.ca
Phone: 877-367-6005 ext 200
Address: Please contact us for address details

You may contact our Privacy Officer to request access to or correction of your personal information, to ask questions about our privacy practices, or to make a privacy-related complaint.

3. Applicable Law

Our handling of personal information is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, including Quebec’s Act respecting the protection of personal information in the private sector (commonly known as Law 25), the Personal Information Protection Act of British Columbia, and the Personal Information Protection Act of Alberta, in each case as amended. To the extent of any conflict between this Privacy Policy and a mandatory requirement of applicable law, the law prevails.

4. Categories of Personal Information We Collect

We collect only the personal information necessary to provide, bill for, secure, and support the Services, and to comply with our legal obligations. The categories of personal information we collect include:

(a) Account and Registration Data — name, business name (where applicable), address, email address, telephone number, billing and payment information, and authentication credentials.

(b) Telecom Service and Usage Data — Call Detail Records (CDRs), including calling and called numbers, date, time, duration, and routing information; calling features used; call-handling, voicemail, and call-forwarding data; and telephone numbers assigned to you (including Direct-Inward-Dialing (DID) numbers).

(c) Network and Technical Data — IP addresses, device identifiers, MAC addresses, SIP credentials and registration data, configuration data, and network traffic and security logs.

(d) Location Data — the registered service address and any address registered for 9-1-1/E911 purposes.

(e) Communications and Support Data — records of your communications with us (including by phone, email, chat, and ticket), support tickets, voicemail messages and any transcripts created, and the contents of messages you send to us.

(f) Website and Access Data — domain name, IP address, browser type, access date and time, pages visited, referring URLs, and similar information collected automatically when you visit the Website.

(g) MSP — Endpoint and Inventory Data — hostnames, operating-system and software inventory, hardware identifiers, patch status, configuration data, and performance and health metrics collected by our remote monitoring and management (RMM) platform from endpoints and servers under our management.

(h) MSP — Endpoint Security and Threat Data — security event logs, process and network telemetry, alerts, detections, and remediation records generated by our endpoint detection and response (EDR) and anti-malware tools (including Bitdefender and CrowdStrike).

(i) MSP — Identity and Productivity Tenant Data — Microsoft 365 tenant administration data, including user-account information, administrator actions, sign-in and audit logs, and mailbox, file, and message metadata accessed in the course of supporting and administering the tenant on your behalf.

(j) MSP — Mobile Device Data — enrolled device identifiers, ownership and compliance status, applied policies, and device location where enabled by you, collected through mobile device management (MDM) services such as Microsoft Intune.

(k) MSP — Backup and Recovery Data — metadata regarding protected systems, backup jobs, retention settings, and restore activity. The contents of backup sets may include documents, mailboxes, and other Customer Data; we do not access the contents of backups except as necessary to provide, support, or restore the Services at your request or as required by law.

(l) MSP — Service-Ticketing and Billing Data — contacts, ticket subjects and histories, time entries, and invoice and billing records held in our professional services automation (PSA) platform (ConnectWise) and our billing platform (WHMCS).

(m) Hosting and Cloud Data — for our Hosting Services: account and provisioning details, server and virtual-machine hostnames and identifiers, resource-usage and performance metrics (such as CPU, memory, storage, and bandwidth), access and error logs, domain-registration (WHOIS) details, and assigned IP addresses. Content that you store, host, or process using the Hosting Services (including website files, databases, and email) may itself contain personal information and other Customer Data; we do not access the contents of your hosted environments except as necessary to provide, support, secure, or restore the Services, at your request, or as required by law.

5. Purposes of Collection and Use

We use personal information for the following purposes:

(a) to establish, provision, maintain, secure, support, and troubleshoot your account and the Services;

(b) to route calls, including 9-1-1/E911 calls, to the correct destination and to maintain registered location information for emergency calling;

(c) to monitor, manage, patch, update, back up, and secure endpoints, servers, cloud tenants, and devices under our management;

(d) to detect, prevent, investigate, and respond to fraud, toll fraud, abuse, security threats, malware, and other incidents affecting you, other customers, or our network;

(e) to bill you, process payments, calculate and collect applicable taxes and surcharges, and pursue amounts owing;

(f) to communicate with you about your account, the Services, scheduled and emergency maintenance, security alerts, and important updates;

(g) to comply with applicable law, lawful requests, court orders, and regulatory obligations, including those of the CRTC, the Office of the Privacy Commissioner of Canada, the Canada Revenue Agency, and other competent authorities; and

(h) to operate, improve, and secure our business, network, and systems, including aggregated statistical and capacity analysis from which identifying details are removed where practicable.

We do not sell your personal information to third parties.

6. Consent and Legal Bases

We collect, use, and disclose your personal information with appropriate consent or other lawful basis, including: (a) your express or implied consent when you order, configure, or use the Services; (b) where collection is reasonably required to supply a product or service you have requested; (c) where necessary to comply with a legal or regulatory obligation; and (d) where permitted for our legitimate business interests (such as network security, fraud prevention, and internal operations), consistent with applicable law. You may withdraw consent to our collection, use, or disclosure of your personal information, subject to legal or contractual restrictions and reasonable notice; withdrawing consent may affect our ability to provide some or all of the Services.

7. Disclosure to Third Parties and Sub-processors

We disclose personal information only to the categories of recipients necessary to provide and operate the Services. Our recipients include:

(a) Telecommunications carriers and service providers — including Distributel (our primary voice carrier and 9-1-1/E911 service provider) and Bandwidth (used for certain United States voice routes), as well as other carriers, exchange carriers, and registration authorities used to route and connect calls;

(b) Emergency service partners — our 9-1-1/E911 service provider and the emergency response centres and national emergency calling centre partners that receive and dispatch 9-1-1 calls;

(c) Payment processors and financial institutions — used to process payments, prevent fraud, and reconcile billing;

(d) MSP and productivity platforms — including Microsoft (Microsoft 365 and Intune), ConnectWise (PSA and RMM), WHMCS (billing), Bitdefender (endpoint security), and CrowdStrike (endpoint detection and response), each acting as a sub-processor to deliver the Services;

(e) Domain registries and registrars — where we register or manage domain names on your behalf, the accredited registrars and domain-name registries (including the Canadian Internet Registration Authority (CIRA) for “.ca” domains and the applicable registry operators for other top-level domains), to which registrant contact information must be submitted as a condition of registration;

(f) Other service providers — hosting, infrastructure, and IT vendors that support our operations, bound by confidentiality and data-protection obligations; and

(g) Law enforcement, regulators, and other parties — as required by law, court order, or lawful request, including under PIPEDA, the CRTC’s powers, and other competent authority.

Recipients are permitted to use your personal information only as necessary to provide the services they supply to us and are bound by appropriate confidentiality and data-protection obligations. A current list of material sub-processors may be requested from our Privacy Officer.

8. Cross-Border Transfers

Your personal information is primarily stored and processed in Canada. However, some of our sub-processors — including Microsoft, CrowdStrike, ConnectWise, Bitdefender, and WHMCS — may process personal information in the United States or other jurisdictions outside Canada in connection with delivering their services. Where personal information is transferred outside Canada, we seek to ensure it is protected by appropriate safeguards, including written data-protection terms with the sub-processor, transfer assessments consistent with PIPEDA, and reliance on the sub-processor’s recognized security certifications (such as SOC 2 or ISO/IEC 27001) where applicable. By using the Services, you acknowledge that personal information may be processed outside Canada as described in this section.

9. Data Retention

We retain personal information only as long as necessary to fulfil the purposes for which it was collected and to comply with our legal, regulatory, and record-keeping obligations. Applicable requirements include: (i) the CRTC’s call-traceback framework under CRTC 2026-52 (effective June 25, 2026), which requires telecommunications service providers offering voice services to retain call data sufficient to support traceback for a minimum of ten (10) calendar days and to respond to traceback requests within two (2) business days; (ii) the record-keeping requirements of the Canada Revenue Agency under section 230 of the Income Tax Act and the Excise Tax Act (generally six (6) years from the end of the relevant tax year, subject to provincial variation, and longer where the CRA’s written permission to destroy earlier has not been obtained); and (iii) PIPEDA’s principle that personal information not be retained longer than necessary for the identified purposes. Unless a longer or shorter period is required or permitted by law, our standard retention periods are:

(a) Call Detail Records (CDRs) supporting billing, revenue, or tax — seven (7) years, which satisfies the CRA’s six-year minimum and applicable provincial requirements;

(b) Technical and non-billing CDRs (such as failed-call or purely operational logs not tied to billing) — thirteen (13) months;

(c) Billing and payment records — seven (7) years;

(d) Account and Registration Data — for the duration of your relationship with us, plus a reasonable period thereafter to permit account close-out and dispute resolution;

(e) 9-1-1/E911 registered address — kept current for the duration of service and retained thereafter as required to support emergency-call investigations;

(f) Network and security logs — thirteen (13) months;

(g) Support records and Website access logs — two (2) years;

(h) MSP — RMM inventory and agent data — for the duration of the managed-services engagement, plus ninety (90) days thereafter;

(i) MSP — MDM device data — for the duration of device enrollment, plus ninety (90) days thereafter;

(j) MSP — EDR and security telemetry, and Microsoft 365 administrator and audit logs — thirteen (13) months;

(k) MSP — PSA / ticketing records — two (2) years following ticket closure; and

(l) MSP — Backup contents — in accordance with the retention schedule set out in the customer’s agreement with us; and

(m) Hosting Services — provisioning and account records for the duration of the hosting engagement, plus a reasonable close-out period; server, access, and security logs for the Hosting Services — thirteen (13) months; hosted content and Customer Data in accordance with Section 17 (Customer Data) of our Terms and any applicable order or invoice.

Our CDR retention periods well exceed the ten-day call-traceback minimum required by CRTC 2026-52; we retain that minimum only as a floor and not as a target. Information that is no longer required is destroyed, erased, or de-identified in accordance with our retention schedule.

10. Data Security

We protect personal information with safeguards appropriate to the sensitivity of the information, including physical, technical, and administrative measures such as access controls, encryption in transit, network monitoring, endpoint protection, secure configuration management, and secure destruction. Access to personal information is limited to personnel and sub-processors who require it to perform their duties and who are bound by confidentiality obligations. No method of transmission or electronic storage is completely secure, but we use commercially reasonable measures designed to protect your personal information.

11. Breach of Security Safeguards

In the event of a breach of security safeguards involving your personal information that creates a real risk of significant harm, Northridge Telecom will notify affected individuals and the Office of the Privacy Commissioner of Canada (OPC) of the breach as soon as feasible after determining that a breach has occurred, and will keep and maintain a record of such breaches, in each case as required by PIPEDA and the associated Breach of Security Safeguards Regulations.

12. Automated Decision-Making and Profiling

We use automated processing in connection with fraud detection, toll-fraud prevention, network and endpoint security alerting, spam and malware filtering, and capacity and performance monitoring. We do not use automated processing to make decisions that produce juridical effects for you (such as decisions about eligibility for a service, pricing, or termination of service) based solely on automated means. Any material adverse action with respect to your account or the Services is subject to human review before it is taken.

13. Your Privacy Rights

Subject to applicable law, you have the right to:

(a) be informed about how we collect, use, and disclose your personal information, as set out in this Privacy Policy;

(b) request access to the personal information we hold about you;

(c) request correction of inaccurate or incomplete personal information;

(d) withdraw consent to our collection, use, or disclosure of your personal information, subject to legal or contractual restrictions;

(e) in certain circumstances and where required by applicable law (including Law 25), request that we cease using or disclosing your personal information, or request other measures available under that law; and

(f) file a complaint with our Privacy Officer and, if not satisfied, with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.

To exercise any of these rights, contact our Privacy Officer using the details in Section 2. We will respond to verified requests within the time frames required by applicable law and may require sufficient information to confirm your identity before acting on a request.

14. Cookies and Tracking Technologies

The Website uses first-party cookies and similar technologies to operate the site, remember your preferences, and understand how the site is used (for example, by counting visitors and pages visited in aggregate). The Website does not use cookies or similar technologies for third-party advertising and does not sell your personal information. You can control or delete cookies through your browser settings; some features of the Website may not function properly if cookies are disabled. Where applicable law requires consent for non-essential cookies, we will seek that consent before deploying them.

15. Children’s Information

The Services are not directed to individuals under the age of consent applicable in their province of residence (for example, fourteen (14) years in Quebec), and we do not knowingly collect personal information from children except as may be necessary to provide a service ordered by a parent or guardian. If you believe we have collected personal information from a child in a manner inconsistent with applicable law, please contact our Privacy Officer.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the policy on this page and, where appropriate, provide notice through the Website or by other means. Your continued use of the Services after a change takes effect constitutes acceptance of the updated Privacy Policy, to the extent permitted by applicable law.

17. Contact

If you have any questions or requests regarding this Privacy Policy or our privacy practices, please contact our Privacy Officer:
Chase Martin, Privacy Officer
Email: chase@nrtel.ca
Phone: 877-367-6005 ext 200

General inquiries may also be directed to admin@nrtel.ca.