**Privacy Policy**
**Effective Date: July 10, 2025**
**This Privacy Policy explains how personal information is collected, used, and protected on this internal employee communications platform. This platform is operated by 49th Parallel Roasters ("Company") and hosted by Open Door MSP ("Hosting Provider") for internal business communications and collaboration.**
**Shared Responsibility Model**
**Company (49th Parallel Roasters) is responsible for:**
- **Employee account management and access permissions**
- **Internal communication policies and content guidelines**
- **Workplace communication and collaboration tools**
- **Employee directory and organizational information**
- **Internal announcements and company communications**
**Hosting Provider (Open Door MSP) is responsible for:**
- **Technical infrastructure and server security**
- **Data backup and system maintenance**
- **Software updates and security patches**
- **Technical support for platform functionality**
**1. Information We Collect**
**Account Information:**
- **Name and work email address (required for employee access)**
- **Job title, department, and work location information**
- **Internal contact information and organizational hierarchy**
- **Account preferences and communication settings**
**Usage Information:**
- **Internal communications, project discussions, and work-related messages**
- **Collaboration activity and file sharing**
- **Login times and platform usage patterns**
- **Team interactions and departmental communications**
**Technical Information:**
- **IP addresses and device information**
- **Browser type and operating system**
- **Session data and authentication tokens**
- **Performance and error logs**
**2. How Your Information Is Used**
**By the Company:**
- **Manage employee access and internal communications**
- **Facilitate collaboration between teams and departments**
- **Send work-related notifications and company announcements**
- **Maintain organizational structure and employee directory**
- **Provide technical support for internal platform use**
- **Monitor usage for security and compliance purposes**
**By the Hosting Provider:**
- **Maintain technical infrastructure and platform security**
- **Monitor system performance and prevent technical issues**
- **Perform data backups and disaster recovery**
- **Apply security updates and patches**
**3. Third-Party Services**
**Firebase Cloud Messaging (Google):**
- **Used for push notifications to mobile devices and browsers**
- **Google may collect device tokens and usage data**
- **Subject to Google's Privacy Policy: [https://policies.google.com/privacy](https://policies.google.com/privacy)**
**Technical Service Providers:**
- **Server infrastructure and cloud services**
- **Security monitoring and backup services**
- **Email delivery services for system notifications**
- **Technical support and maintenance providers**
**4. Data Sharing and Disclosure**
**We do not sell your personal information.**
**Information may be shared:**
- **With your explicit consent**
- **Between Company and Hosting Provider as necessary to provide internal communication services**
- **With technical service providers under strict confidentiality agreements (backup services, security monitoring, infrastructure providers)**
- **To comply with legal obligations or court orders**
- **To protect company assets and employee safety**
- **For legitimate business purposes including internal audits and compliance reviews**
**5. Your Rights and Choices**
**You have the right to:**
- **Access your personal data stored on the platform**
- **Correct inaccurate or outdated information**
- **Delete your account and associated data**
- **Export your data (where technically feasible)**
- **Withdraw consent for optional data processing**
- **Object to certain data processing activities**
- **Lodge complaints with data protection authorities**
**How to Exercise Your Rights:**
- **Account settings: Most preferences can be managed in your user profile**
- **Platform Operator: Contact 49th Parallel Roasters at \[[customer-email@49thparallelroasters.com](mailto:customer-email@49thparallelroasters.com)\]**
- **Technical issues: Contact Open Door MSP at \[[support@opendoormsp.com](mailto:support@opendoormsp.com)\]**
- **Data deletion: Account removal typically completed within 30 days**
**6. Data Retention**
**Platform Operator Retention:**
- **Active accounts: Data retained while account is active**
- **Deleted accounts: User content anonymized or deleted within 30 days**
- **Legal compliance: Some data may be retained longer if required by law**
- **Community content: Public posts may remain for community continuity**
**Hosting Provider Retention:**
- **Technical logs: Retained for 90 days for security and performance monitoring**
- **Backup data: Maintained for disaster recovery purposes**
- **Security incidents: Logs may be retained longer for investigation**
**7. Data Security**
**Technical Safeguards:**
- **Encryption of data in transit and at rest**
- **Regular security updates and vulnerability assessments**
- **Access controls and multi-factor authentication**
- **Network security monitoring and intrusion detection**
**Organizational Safeguards:**
- **Staff training on data protection and privacy**
- **Regular security audits and compliance reviews**
- **Incident response procedures**
- **Confidentiality agreements with service providers**
**Important: No system is 100% secure. Users should use strong passwords and keep login credentials confidential.**
**8. International Data Transfers**
- **Server Location: Data is hosted on servers in Canada**
- **Cross-border transfers: May occur for technical support and maintenance**
- **Safeguards: Appropriate protections are in place for international transfers**
- **User consent: By using this service, you consent to necessary data transfers**
**9. Age Restrictions and Children's Privacy**
- **This platform is intended for current employees of 49th Parallel Roasters**
- **Access is restricted to authorized personnel only**
- **We do not knowingly allow access to individuals under 16 years of age**
- **If unauthorized access is discovered, accounts will be promptly removed**
**10. Cookies and Tracking Technologies**
**We use cookies and similar technologies for:**
- **Essential functions: Authentication and session management**
- **User preferences: Language settings and display preferences**
- **Security: Fraud prevention and unauthorized access protection**
- **Performance: Platform optimization and error monitoring**
**See our detailed Cookie Notice for more information about specific cookies used.**
**11. Push Notifications**
- **Notifications may be sent about platform activity and important updates**
- **You can manage notification preferences in your account settings**
- **Critical security notifications may be sent regardless of preferences**
- **Mobile app notifications are delivered through Firebase Cloud Messaging**
**12. Changes to This Policy**
- **We may update this privacy policy to reflect service changes or legal requirements**
- **Users will be notified of significant changes via platform notifications**
- **Continued use after changes constitutes acceptance of the updated policy**
- **Previous versions are available upon request**
**13. Legal Basis for Processing (GDPR)**
**We process personal data based on:**
- **Consent: For optional features and marketing communications**
- **Contract performance: To provide the community platform service**
- **Legitimate interests: Platform security, improvement, and community management**
- **Legal obligations: Compliance with applicable laws and regulations**
**14. Contact Information**
**For Community and Account Issues:**
**Platform Operator: 49th Parallel Roasters**
- **Email: \[[privacy@49thparallelroasters.com](mailto:privacy@49thparallelroasters.com)\]**
- **Address: \[Customer Business Address\]**
**For Technical and Hosting Issues:**
**Hosting Provider: Open Door MSP**
- **Email: [support@opendoormsp.com](mailto:support@opendoormsp.com)**
- **Address: \[MSP Business Address\]**
**15. Jurisdiction and Applicable Law**
**This privacy policy is governed by the laws of British Columbia, Canada. Any disputes will be resolved in the courts of Vancouver, British Columbia.**
---
**We are committed to protecting your privacy and handling your data responsibly through our shared responsibility approach.**
**Version: 2.0\
Last Updated: July 10, 2025**