Skip to main content

    Legal

    Privacy Policy

    Effective June 9, 2026 · Last updated June 9, 2026

    PartnerAZ Technologies Inc. ("PartnerAZ," "we," "us," or "our") is a corporation incorporated in British Columbia, with its registered office at 406-990 Broughton Street, Vancouver, BC V6G 2A5. PartnerAZ operates a platform (the "Platform") that lets public sector and private sector organizations discover vendors, submit and route vendor applications, review advisory fit scores, and schedule vendor meetings. Our website at www.partneraz.com (the "Site") supports this business.

    This Privacy Policy explains how PartnerAZ collects, uses, discloses, retains, and protects personal information, and the choices and rights available to individuals. "Personal information" means information about an identifiable individual. It does not include business contact information used solely to contact an individual in their professional capacity, to the extent excluded from applicable law, or information that has been anonymized or aggregated so that it can no longer reasonably identify an individual.

    This Policy is governed by Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and the Personal Information Protection Acts of British Columbia and Alberta, in the provinces where they apply. The Platform is offered to organizations in Canada other than Quebec. PartnerAZ does not currently offer the Platform to, or accept registrations from, users or organizations in Quebec.

    The Platform is a business tool, not a consumer service, and is not directed to children. Users must be 18 or older.

    Our two roles. For information PartnerAZ collects from its own users (account, authentication, and technical data), PartnerAZ is the organization accountable for that information. For records a Buyer organization creates through its use of the Platform (such as application review, scoring configurations, departmental authorizations, and in-platform messages), PartnerAZ acts as a service provider processing those records on the Buyer organization's instructions, and the Buyer organization remains accountable for them under the access-to-information and privacy law that applies to it. Requests about those records are directed to the Buyer organization.

    We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, where the change is material, notify registered account administrators.


    1. Personal Information We Collect and Our Sources

    We collect only what we need for the purposes described in this Policy. We collect personal information directly from users, automatically when users access the Platform or Site, and, for Buyer-created records, through Buyer organizations' use of the Platform.

    CategoryFrom BuyersFrom VendorsPrimary purpose
    Registration informationYesYesAccount creation, identity verification, Platform access
    Platform activity dataYesYesOperating the Platform, processing applications, scoring
    Meeting scheduling dataYesYesScheduling vendor meetings
    Authentication dataYesYesSecure access to the Platform
    Technical and log dataYesYesSecurity, fraud prevention, service improvement
    Marketing dataYes, with consentYes, with consentPromotional communications

    Registration information. From Buyers: name, business email, job title, organization name, and the province or territory in which the organization operates. From Vendors: name, business email, job title, company name, company province, company website, and a short company description.

    Platform activity data. From Buyers: application review decisions, scoring configuration selections, in-platform messages, and departmental authorization records. From Vendors: application submissions and responses, documents uploaded as part of an application, and in-platform messages to Buyer organizations.

    Meeting scheduling data. Proposed and confirmed meeting times, time zone, attendees, and meeting topic, used solely to schedule vendor meetings. Where a user authorizes it, the Platform connects to that user's own calendar provider (Microsoft 365 or Google Workspace) to create the meeting and its conferencing link on the user's own calendar, and the user's provider sends the invitation to attendees. PartnerAZ retains the meeting scheduling data described above and an encrypted calendar access token used to create the meeting on the user's calendar; it does not retain the user's other calendar events or availability.

    Authentication data. Authentication is managed by Auth0 by Okta in a Canadian region. PartnerAZ does not store plaintext passwords. PartnerAZ holds session tokens sufficient to confirm that a user is authenticated.

    Technical and log data. Collected automatically when users access the Platform: IP address, browser type and version, operating system, referring URL, pages accessed, date and time of access, and session identifiers. Used for security, fraud prevention, troubleshooting, and anonymized aggregate analytics. Not used to profile individuals for marketing.

    Marketing data. Collected from Buyer and Vendor users who give express consent, to send promotional communications. PartnerAZ does not send promotional communications to any user without prior express consent.

    PartnerAZ does not collect Social Insurance Numbers, other government-issued identification numbers, financial account numbers, health information, biometric data, or genetic information, and asks users not to submit them through the Platform.


    2. Purposes for Collecting and Using Personal Information

    We identify the purposes for collection at or before the time we collect, and we use personal information only for those purposes or a consistent purpose.

    • Operate and support the Platform: create and manage accounts, route and process applications, enable in-platform review and communication within each Buyer's authorized scope, schedule meetings, and provide support.
    • Generate advisory fit scores: the fit score is a deterministic, weighted calculation of Vendor application responses against criteria the Buyer configures. It does not use machine learning or artificial intelligence. Buyers set all criteria; PartnerAZ does not set or influence them, does not make recommendations, and does not make procurement decisions. Scores are advisory inputs for the Buyer's human decision.
    • Security and fraud prevention: protect the Platform, detect and prevent unauthorized access, and investigate misuse.
    • Service communications: account, security, application-status, meeting, and policy-change notices.
    • Marketing communications: only to users who have given express consent, and only until consent is withdrawn.
    • Legal compliance: meet legal, regulatory, tax-record, and breach-notification obligations.
    • Anonymized aggregate analytics: improve the Platform using data that has been anonymized so it cannot reasonably identify any individual or organization.

    PartnerAZ does not use personal information to train, develop, or fine-tune any artificial intelligence or machine-learning model. PartnerAZ may develop and improve Platform models, including matching and ranking, using only anonymized or aggregated data, which is not personal information. If PartnerAZ ever proposes a materially new purpose, it will give notice and obtain any consent required by law before using existing personal information for it.


    3. How We Disclose Personal Information

    We do not sell, rent, or trade personal information.

    • Within the Platform. Vendor profile and application content is shown to Buyer users as the core discovery and review function, within each Buyer's authorized scope. Buyer personnel information is not disclosed to Vendors, except that a Buyer contact's name and organization may be shown to a Vendor for a scheduled meeting or an authorized in-platform message.
    • Service providers (sub-processors). PartnerAZ uses Amazon Web Services (hosting and storage), Amazon Simple Email Service (transactional email), Amazon CloudWatch (logging and monitoring), and Auth0 by Okta (authentication and brokering the user-authorized connection to the user's calendar provider), each processing in Canada. Sub-processors are bound by written data-protection agreements and may use personal information only to perform their function. The current list is available to the Organization on request, and PartnerAZ gives at least 30 days' notice before adding or replacing a sub-processor that processes personal information.
    • User-connected calendar providers. When a user authorizes calendar scheduling, the Platform connects to that user's own Microsoft or Google account at the user's direction. For that calendar, Microsoft and Google act as the user's own service providers, not as PartnerAZ sub-processors, and the meeting and attendee data created there reside in the user's own account.
    • Legal and regulatory. We may disclose personal information where required or permitted by law, including in response to a valid court order or lawful authority demand. We notify affected individuals where the law permits.
    • Business transfer. In a merger, acquisition, or sale of assets, personal information may transfer to the successor, which must commit to protections substantially equivalent to this Policy. We give registered users at least 30 days' notice before any such transfer.

    4. Cookies and Website Analytics

    The Platform uses strictly necessary cookies to log users in and maintain sessions. The Site uses analytics cookies (Apollo, Google Analytics, and HubSpot) that load only after you accept them through our cookie banner. Site analytics do not access Platform data. You can manage cookies through your browser and as described in our Cookie Policy.


    5. Your Choices

    • Marketing: users who have given marketing consent can withdraw it at any time, through account settings or by emailing privacy@partneraz.com, without affecting Platform access.
    • Cookies: manage cookies through your browser and the Cookie Policy.
    • Access and correction: exercise the rights described in Section 9.

    6. Data Retention

    We keep personal information only as long as necessary for the purposes in this Policy or as required by law, then securely destroy or anonymize it.

    CategoryRetention
    Account, registration, and Platform activity data (Buyers and Vendors)Duration of the active account, plus a minimum of two years after closure for potential claims
    In-platform messagesSix years from the end of the relevant taxation year, as required by the Income Tax Act
    Meeting scheduling dataBooking records for the duration of the meeting relationship; scheduling preferences and any calendar access token deleted on disconnection or within 90 days after account closure
    Authentication session dataDuration of the session; expired sessions purged on a rolling basis
    Technical and log dataAs long as necessary for security, fraud prevention, and audit, then deleted
    Express marketing consent recordsThree years from withdrawal of consent, consistent with CASL
    Security breach recordsAt least 24 months from the date the breach is determined

    7. Security and Data Location

    PartnerAZ maintains appropriate technical and organizational safeguards, including encryption of personal information in transit and at rest, access controls on a least-privilege basis, and logging. No safeguard is perfect, and we cannot guarantee absolute security.

    Personal information collected through the Platform is stored and processed in Canada, in the Amazon Web Services Canada. The full calendar event created through the scheduler resides in the user's own calendar account; for this feature PartnerAZ retains the meeting scheduling data and an encrypted access token, in Canada, and does not retain the user's other calendar events or availability. Some of our service providers are incorporated outside Canada even though they process this information in Canada, which can in limited circumstances expose that information to lawful-access requests under the laws of the provider's home country. PartnerAZ manages this through vendor selection and written data-protection commitments, and remains accountable for personal information that service providers process on its behalf.

    If PartnerAZ becomes aware of a breach of security safeguards that creates a real risk of significant harm, it will notify affected individuals and the Office of the Privacy Commissioner of Canada (and any other authority required by law) as soon as feasible, and it maintains a record of breaches as required by law.

    Public sector Buyers with specific data-residency or due-diligence requirements, including written confirmation of Canadian data residency or support for a privacy impact assessment, may contact legal@partneraz.com.


    8. Children

    The Platform and Site are intended for business users aged 18 and older and are not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided personal information to us, contact privacy@partneraz.com and we will delete it, except where retention is required by law.


    9. Your Rights, Consent, and Accountability

    Privacy Officer. PartnerAZ has designated a Privacy Officer accountable for compliance with PIPEDA and applicable provincial privacy law, reachable at privacy@partneraz.com or 406-990 Broughton Street, Vancouver, BC V6G 2A5.

    Consent. We collect, use, and disclose personal information with consent, except where the law permits or requires otherwise. Users provide consent at registration; Vendor marketing requires separate express consent. You may withdraw consent at any time, subject to legal and contractual limits, which may affect our ability to provide certain features.

    Your rights. Subject to applicable law, you may: (a) ask whether we hold personal information about you and request access to it, along with an account of how it has been used and disclosed; (b) request correction of inaccurate or incomplete information; and (c) withdraw consent. We respond to written access requests within 30 days, and will tell you if we need a permitted extension. Where we cannot provide full access or make a requested correction, we will explain why and note your disagreement on file. Send requests to privacy@partneraz.com.

    Records held for a Buyer organization. Where your request concerns records a Buyer organization created through the Platform, we will refer the request to that organization, which is accountable for those records.

    Complaints. If we have not resolved your concern, you may contact the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the privacy or information commissioner in your province, including the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca) or of Alberta (oipc.ab.ca).


    10. Links to Third-Party Websites

    The Platform or Site may link to websites we do not control. This Policy does not apply to those sites, and we are not responsible for their practices. Review their privacy policies before providing personal information.


    11. Changes to This Policy

    We may update this Policy to reflect changes in our practices or the law. We will post the updated Policy with a new "Last updated" date and, for material changes, notify registered account administrators. Continued use of the Platform after an update takes effect constitutes acceptance of the updated Policy, subject to any consent the law requires.


    12. Contact Us

    Questions, requests, or complaints about this Policy or your personal information:

    PartnerAZ Technologies Inc.

    Email: privacy@partneraz.com

    Mail: 406-990 Broughton Street, Vancouver, BC V6G 2A5