Privacy Policy
Last Updated: March 14, 2026
1. Introduction & Controller Identity
This Privacy Policy explains how Northbridge IT School (“we”, “us”, or “our”) collects, uses, and protects your personal data when you visit our website and when you contact us about our programs, admissions, tuition, and related services. This policy is written to be practical and readable. If anything is unclear, you can contact us using the details in Section 18.
Data Controller: Northbridge IT School Inc.
Registered address: 200 Bay St, Royal Bank Plaza, South Tower, Toronto, ON M5J 2J2, Canada
Contact email: [email protected]
Effective Date: March 14, 2026. We do not appoint a Data Protection Officer for ordinary business operations. If you have a privacy question, email us and we will route it to the appropriate person.
2. Personal Data We Collect
We collect personal data that you choose to provide and limited technical data that helps the website function and helps us understand usage. The categories below describe what we may collect depending on how you interact with the site.
- Identity and contact details: name, email address, and phone number (if you provide it).
- Form content: the message you send to admissions, including program interests, background information you choose to share, preferred start timing, and other details you include.
- Technical data: IP address, browser type and version, device type, operating system, language settings, approximate location inferred from IP (city/region level), and diagnostic data needed for security and performance.
- Usage data: pages viewed, time spent on pages, referring/exit pages, and basic interaction signals (such as clicks on navigation links).
- Cookies and identifiers: cookie values and similar identifiers stored in your browser (see Section 4).
- Conversion events: events such as submitting a contact form or clicking key navigation items, measured to understand what content is useful and how marketing performs (only where consent applies).
We do not intentionally collect special-category data (such as health data, political opinions, religious beliefs), financial account details, or government identification numbers through this website. Please do not include sensitive information in a message to admissions.
3. Why We Process Personal Data & Legal Basis
Where GDPR or UK GDPR applies, we process personal data only when we have a legal basis. The most common reasons are responding to admissions inquiries, operating the website, and measuring site performance. The legal bases below align with GDPR Article 6.
- Admissions contact form and communications: to respond to your request and provide information about programs and tuition. Legal basis: Article 6(1)(b) (steps prior to entering a contract) and, where required, Article 6(1)(a) (consent).
- Analytics: to understand how visitors use our pages and improve content and navigation. Legal basis: Article 6(1)(a) (consent), where applicable.
- Marketing and remarketing: to measure advertising performance and show relevant ads to people who have visited our site. Legal basis: Article 6(1)(a) (consent), where applicable.
- Security, abuse prevention, and troubleshooting: to protect the site and users, reduce fraud and malicious activity, and maintain availability. Legal basis: Article 6(1)(f) (legitimate interests).
- Legal obligations: to comply with applicable laws, respond to lawful requests, and maintain required records. Legal basis: Article 6(1)(c) (legal obligation).
Automated Decision-Making (GDPR Article 22): we do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you.
4. Cookies & Tracking
Cookies are small text files stored on your device. We also use similar technologies such as pixel tags and server-side event forwarding where configured. Our cookie categories match our Cookie Policy at /cookie-policy/.
Essential (always active)
Essential cookies are required to make the site work and to store your consent preferences. These do not require consent in many jurisdictions because they are strictly necessary.
- _site_session: supports basic session continuity. Retention: session.
- cookie_consent: stores your consent choice. Retention: 12 months.
Analytics (consent-based)
Analytics cookies help us understand site usage, such as which pages are viewed most and how visitors move through the site. When enabled, we use Google Analytics 4 (GA4) with IP anonymization configurations. Typical cookie examples include _ga and _ga_XXXXXXXXXX. Analytics data retention is typically configured for 14 months.
Marketing (consent-based)
Marketing cookies help measure advertising performance and support remarketing (showing ads to people who previously visited the site). When enabled, typical cookies include Google Ads conversion linker cookies (such as _gcl_au) and Meta Pixel cookies (such as _fbp and _fbc where click IDs exist). These cookies are commonly retained for around 90 days, depending on the provider.
In addition to cookies, marketing and analytics may involve pixel tags (for example, tags loaded via Google Tag Manager) and may include server-side processing (for example, forwarding conversion events with hashed identifiers when configured). We do not attempt to identify you by name through these technologies unless you provide your details to us directly.
5. Consent (EEA/UK)
Users in the EEA and UK receive a consent notice under GDPR/UK GDPR. Marketing and analytics cookies activate only after explicit, informed, freely given consent (GDPR Article 6(1)(a)). Your consent choice is recorded in the cookie_consent browser cookie for 12 months. You may withdraw consent at any time using the “Manage cookie preferences” link in the footer or by clearing your browser cookies.
Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it. Essential cookies remain active because the site cannot operate correctly without them.
6. Sharing With Advertising & Service Partners
We use carefully selected service providers to host and secure the site, respond to requests, and measure performance. Depending on your cookie choices, we may share limited data with advertising and analytics partners. We do not sell personal data.
- Google LLC (Google Analytics 4, Google Ads, Tag Manager, remarketing): cookie identifiers, usage data, conversion events, and related technical signals. Privacy policy: https://policies.google.com/privacy
- Meta Platforms, Inc. (Meta Pixel, custom/lookalike audiences, conversion measurement): page view events, conversion events, audience membership signals, and hashed identifiers where configured. Privacy policy: https://www.facebook.com/privacy/policy
- Cloudflare (CDN and security): IP-based signals and request metadata to protect the site from abuse and improve reliability. Privacy policy: https://www.cloudflare.com/privacypolicy/
We do not permit these providers to use site data for their own independent commercial purposes. They process data on our behalf to deliver the services described, subject to their contractual and technical controls.
7. International Transfers
Some service providers process data in countries outside the EEA/UK, including the United States. Where required, we rely on recognized transfer mechanisms and safeguards, which may include: the EU–US Data Privacy Framework (and the UK Extension where applicable), the Swiss–US Data Privacy Framework, and Standard Contractual Clauses (EU 2021/914) as a fallback. For UK transfers, we may also rely on the UK International Data Transfer Addendum/IDTA where appropriate.
We take a practical approach: we limit what we share, use consent controls where required, and work with providers that publish security and privacy documentation.
8. Retention
We keep personal data only as long as necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law. Typical retention periods are:
- Admissions inquiries and contact submissions: up to 2 years from the last interaction, to support follow-ups and maintain context.
- Analytics data: typically 14 months (as configured in the analytics platform).
- Marketing cookies: for the cookie lifetime set by the provider (commonly around 90 days for certain identifiers).
- Email correspondence: for the duration of the relationship, plus up to 1 additional year for continuity and recordkeeping.
- Server/security logs: typically up to 90 days, unless needed longer to investigate abuse or security incidents.
- Cookie consent record: up to 3 years for audit purposes, where applicable.
- Legal and tax records: retained as required by applicable law (often 6 to 10 years depending on record type and jurisdiction).
9. Your Rights (GDPR & UK GDPR)
If GDPR or UK GDPR applies to you, you may have rights including: access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), objection (Article 21), and the right to withdraw consent at any time (Article 7(3)). You also have the right to lodge a complaint with a supervisory authority (Article 77).
To exercise your rights, email [email protected]. We typically respond within 30 days. For complex requests, the response period may be extended by up to 60 additional days as permitted by law. We may ask for information to verify identity before completing a request.
Supervisory authorities include (depending on your location): the European Data Protection Board directory (https://edpb.europa.eu) and the UK Information Commissioner’s Office (https://ico.org.uk).
10. Children
This site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If we learn that we have collected personal data from a child under 16 without verifiable parental consent, we will delete it promptly.
11. Do Not Track
This website does not respond to Do Not Track (DNT) browser signals. Third-party providers may have their own DNT handling and opt-out mechanisms.
12. Data Deletion Requests
To request deletion of personal data, email us at [email protected] with the subject line “Data Deletion Request”. We will confirm what we can delete and what we must retain for legal, security, or operational reasons. Requests are typically completed within 30 days after identity verification.
13. Business Transfers
In a merger, acquisition, asset sale, financing, or insolvency, personal data may be transferred to a successor entity as part of the transaction. If a transfer would materially change how personal data is used, we will provide notice on the website.
14. California (CCPA / CPRA)
This section applies to California residents where the California Consumer Privacy Act (as amended by the CPRA) applies. In the past 12 months, we may have collected the following categories of personal information: identifiers (such as name, email address, IP address, and cookie identifiers), internet/network activity (such as browsing interactions on our site), and inferences (such as interests based on visited pages).
We do not sell personal information as defined by CCPA. We may share personal information for cross-context behavioral advertising when marketing cookies are enabled. California residents may opt out via our cookie preferences panel (Manage cookie preferences in the footer).
Your rights may include the right to know, delete, correct, and opt out of sale/sharing, and the right to non-discrimination. To submit a request, email [email protected] with the subject “California Privacy Request”. We will verify your identity before fulfilling the request. Authorized agents may submit requests with proof of authorization.
15. Virginia (VCDPA)
For Virginia residents where the Virginia Consumer Data Protection Act applies, rights may include access, correction, deletion, data portability, and the ability to opt out of targeted advertising. We do not sell personal data and do not engage in profiling that produces legal or similarly significant effects.
To submit a request, email [email protected] with the subject “Virginia Privacy Request”. If we deny a request, you may appeal by emailing with the subject “Appeal of Refusal — Privacy Request”. We will respond to appeals within 60 days as required by law. If the appeal is denied, you may contact the Virginia Attorney General.
16. Nevada
Nevada residents may submit a verified opt-out request by emailing us with the subject “Nevada Do Not Sell Request”. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.
17. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be announced via a notice on our homepage at least 14 days before taking effect when required. The “Last Updated” date at the top of this page changes whenever we publish a new version.
18. Contact
If you have questions about this Privacy Policy or want to exercise a privacy right, contact:
Northbridge IT School Inc.
200 Bay St, Royal Bank Plaza, South Tower, Toronto, ON M5J 2J2, Canada
Email: [email protected]
Phone: +1 416 340 3131