Privacy Policy
Introduction
This Privacy Policy explains how Tsenawt Technologies Inc. ("Tsen'awt", "we", "us") handles personal information in connection with the Tsen'awt platform (the "platform") deployed for an organization, most often a First Nation, a Tribal Council, a First Nations Policy or Technical Organization, a First Nations Provincial or Territorial Organization, or a First Nations National Advocacy Organization (the "Customer"). We are based in British Columbia, Canada, and we handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA).
The platform is built to keep the Customer's records on dedicated hardware rather than in a public cloud. That design shapes this whole policy. Read section 2 first: it explains the two layers of information involved, because your rights and our commitments differ between them.
Section 1. Who this policy covers
This policy applies to the people who administer and use the platform on behalf of the Customer and its designated organizations. It does not govern how the Customer collects or uses personal information about its own members, clients, or community within the platform: in that relationship the Customer is the party responsible for the information, governed by its own laws, policies, and, where it applies, the First Nations Information Governance Centre's principles of OCAP. We act only as the operator of the software that holds those records on the Customer's behalf.
Section 2. Two layers of information
Layer one: the Customer's records and content. The documents, spreadsheets, files, tags, and other records created on the platform are stored on the EdgePod, a self-contained device that runs the software. The pod serving a deployment sits on the Customer's own premises or, where the Customer chooses, is operated by Tsen'awt in Canada under a hosting arrangement; in every case the records on it are owned and controlled by the Customer at all times. We do not copy this content to any third-party cloud. We do not sell it, mine it, use it for advertising, or use it to train artificial-intelligence models. No analytics vendor or off-pod service sits in the path of this content. We process it only as needed to run the software the Customer asked us to run.
Layer two: account information. To operate the deployment we hold a small amount of information about the people who use it: names, usernames, work email addresses, roles and group memberships, securely hashed sign-in credentials, and support correspondence. This layer is the subject of most of the rest of this policy.
Section 3. Information we collect
Account information: your name, username, work email address, organization, role, and group memberships, provisioned by your administrator.
Authentication information: a securely hashed password and, where enabled, your two-factor authentication configuration. There is no third-party sign-in on this deployment.
Platform content: the records described in section 2, layer one, held on the EdgePod.
Usage and technical information: actions recorded in the platform's activity and audit logs, and basic server logs such as IP address and timestamps needed to operate and secure the service. Access to a deployment is over the Customer's private network connection where one is configured.
Communications: the content of messages you send us for support.
Section 4. How we use personal information
We use personal information to provide, maintain, and support the platform; to create and secure accounts and authenticate sign-in; to respond to support requests and communicate about the service; to keep the service secure, investigate misuse, and maintain the audit trail; and to meet our legal obligations.
We do not use your information for advertising, we do not sell it, and we do not use platform content to train AI models. There is no billing information on the platform: fees are handled by invoice under the services agreement between Tsen'awt and the Customer, outside the platform.
Section 5. Consent
Under PIPEDA and BC PIPA we rely on consent to collect, use, and disclose personal information, except where the law permits or requires us to act without it. Accounts are created by the Customer through its administrators; by using your account you consent to the handling described in this policy. You may withdraw consent, subject to legal and contractual limits, by contacting us as set out in section 11; withdrawing consent may mean we can no longer provide part or all of the service to you.
Section 6. Service providers and disclosure
Deployments are designed to involve no outside processors in the path of the Customer's content. Account emails (such as password resets and notifications) are delivered through the deployment's mail service. No payment processor, analytics vendor, advertising network, or data broker is used. We may disclose personal information where the law requires it, to enforce our agreements, or to protect the rights and safety of people and the service, and where a demand concerns the Customer's records we will direct the requester to the Customer and notify the Customer unless the law prevents it.
Section 7. Support access
Tsen'awt support staff do not browse the Customer's content. Administrative access used to provide support is limited to what the Customer requests, is logged in the platform's audit trail, and, where it involves acting within a user's account, occurs only with consent under the deployment's support access policy.
Section 8. Where information is stored
All platform content and account information is held on the EdgePod in Canada. Because this content is not held in a foreign public cloud, it is outside the reach of foreign disclosure orders such as the United States CLOUD Act, and requests for it are directed to the Customer rather than to a cloud vendor.
Section 9. How long we keep information
Account information is kept for as long as the account is active and afterward only as long as needed for the purposes in this policy and to meet legal requirements. Platform content is retained under the Customer's control and its own retention rules; on termination of the deployment, the Customer may export or take possession of all of its records as set out in the services agreement.
Section 10. Security and breach notification
We protect information with encryption in transit between users and the pod, access controls and role-based permissions, two-factor authentication where enabled, and audit logging of administrative actions. Access to a deployment requires the Customer's private network connection where one is configured. No system is perfectly secure, but we take measures appropriate to the sensitivity of the information.
If a breach of security safeguards creates a real risk of significant harm to affected individuals, we will notify the Customer without unreasonable delay and will report and notify as required by PIPEDA and BC PIPA, including to the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia and to affected individuals, and we will keep records of breaches as the law requires.
Section 11. Your rights and contact
Subject to the law, you may ask what personal information we hold about you, request access to it, ask us to correct it, withdraw your consent, and make a complaint to us or to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca). If your request concerns records the Customer holds about you on the platform, we will direct you to the Customer, which is responsible for those records.
Privacy Officer, Tsenawt Technologies Inc., 6-2020 Vine Street, Vancouver, British Columbia, Canada V6K 3K1. Email: privacy@tsenawt.io.
Section 12. Indigenous data sovereignty and OCAP
The platform is designed around the First Nations principles of OCAP, a registered trademark of the First Nations Information Governance Centre. Ownership: the Customer owns its records; they belong to the Customer, not to Tsen'awt. Control: the Customer controls who can reach its records and on what terms. Access: the Customer decides how its records are accessed and can reach, export, or take possession of them at any time. Possession: the records sit on a dedicated pod rather than a shared public cloud, and the Customer holds or may take physical possession of its data, including on its own EdgePod, at any time.
Section 13. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new effective date and, for material changes, give the Customer reasonable notice.