
Privacy and Information Security
Infinite Gravity Data Services is well-versed
in privacy issues, particularly in Canada, and we follow the
guidelines and principles spelled out in the Personal
Information Protection and Electronic Documents Act as well as
the BC Personal Information Protection Act.
We do not
maintain any sensitive information about individuals. When we work with customer data, we
ensure that our contracts clearly spell out each party's
obligations with respect to privacy and the use of personal
information.
Data is maintained on our files only so long as required to
perform the service we are asked to provide. After we have
finished a job and our client signs off on the work, all
unnecessary data is permanently deleted. Only data required to
fulfill auditing or legal requirements is maintained. An example
of data that may be retained would be data which were modified or
corrected and which we may need for auditing, to support our
invoices, or for quality assurance purposes.
All data that we work with is stored, in encrypted form, on
physically secure servers. Access to database is permitted only to
specific employees on a need-to-know basis. No visitors or
non-employees are permitted in our server room.
Encryption
Encryption is used extensively in our organization to protect
information. We have standardized on PGP as our encryption
tool of choice, and we encourage all of our clients to use PGP
when transferring data to us for processing. Our
PGP Public Key is available on our web site
here.
Secure Communications
All sensitive information provided to Infinite Gravity Data
Services is transmitted using 128-bit Secure Socket Layer (SSL)
encryption. SSL
is a proven encryption system that lets your browser automatically
encrypt data before you send it to us.
Canadian Operations
We are a 100% Canadian company and we do not outsource any data to
any company not located in Canada. In fact, except for National
Change of Address work, we do not outsource any work at all. We
will not permit the application of non-Canadian laws (read: the US
Patriot Act, et al) to our business or to our customers' data.
|