Legal
Privacy Policy
Effective date: January 28, 2026
At Petrichor Labs, privacy isn’t a checkbox — it’s the foundation of everything we build. This policy explains how we handle your personal information with the same care we ask of our clients.
1. Overview
Petrichor Labs (“we”, “us”, or “our”) is committed to protecting the privacy of individuals who visit our website, inquire about our services, or engage with us in any capacity. This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and your rights with respect to it.
We operate in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia’s Personal Information Protection Act (PIPA), and, where applicable, the EU’s General Data Protection Regulation (GDPR) and Canada’s proposed Bill C-27.
2. Who We Are
Petrichor Labs is a privacy-first technology consultancy headquartered in Vancouver, British Columbia, Canada. We help organizations design, build, and operate software that respects data sovereignty, meets regulatory requirements, and keeps personal data under their control.
For the purposes of this policy, Petrichor Labs is the data controller for personal information collected through this website.
3. Information We Collect
We collect personal information only when you voluntarily provide it or when it is generated by your use of our website. This may include:
- Contact information: Name, email address, company name, and any message content you submit through our contact form.
- Usage data: Pages visited, time spent, referring URLs, browser type, and device information — collected via privacy-respecting analytics.
- Cookies and similar technologies: Session cookies required for site functionality, and optional analytics cookies if you consent.
- Job application data: If you apply for a position, we collect the information you submit (CV, cover letter, contact details).
We do not collect sensitive personal information (e.g., health data, financial account numbers, government ID numbers) through this website.
4. How We Use Your Information
We use personal information for the following purposes:
- To respond to your inquiries and provide the services you request.
- To send you relevant updates, newsletters, or service announcements — only with your consent.
- To improve our website and understand how visitors use it.
- To evaluate job applications and communicate with candidates.
- To comply with legal obligations and enforce our terms.
We rely on the following legal bases for processing (where GDPR applies): consent, legitimate interests (e.g., responding to inquiries, improving the site), and legal obligation.
6. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share it only in the following limited circumstances:
- Service providers: Trusted vendors who help us operate the site (e.g., hosting, email delivery) under strict confidentiality obligations.
- Legal requirements: If required by law, court order, or to protect the rights and safety of our users or the public.
- Business transfers: In the event of a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction, subject to equivalent privacy protections.
7. Data Residency and Transfers
We are a Canadian company and, wherever possible, store and process data within Canada. If any personal information is transferred outside Canada (e.g., through a third-party service provider), we ensure appropriate safeguards are in place — such as contractual clauses or adequacy decisions — consistent with PIPEDA and, where applicable, GDPR requirements.
8. Data Retention
We retain personal information only as long as necessary to fulfill the purposes for which it was collected, or as required by law. Contact form submissions are retained for up to 24 months. Analytics data is aggregated and anonymized. Job application data is retained for up to 12 months after the position is filled, unless you ask us to delete it sooner.
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Ask us to correct inaccurate or incomplete information.
- Deletion: Request that we delete your personal information, subject to legal retention obligations.
- Withdrawal of consent: Withdraw consent for any processing based on consent, at any time.
- Portability: Receive your data in a structured, machine-readable format (where applicable under GDPR).
- Objection: Object to processing based on legitimate interests (where applicable under GDPR).
To exercise any of these rights, contact us at support@petrichorlabs.ca. We will respond within 30 days.
10. Security
We implement industry-standard technical and organizational measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These include encrypted data transmission (TLS), access controls, and regular security reviews. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
11. Children's Privacy
Our website and services are not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.
12. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies before providing any personal information.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we do, we will revise the “Effective Date” at the top of this page. We encourage you to review this policy periodically. Continued use of the website after changes are posted constitutes your acceptance of the updated policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy Officer:
If you are located in the EU and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.