This Privacy and Data Protection Policy describes how RescueIT Inc. ("RescueIT", "we", "us", or "our") collects, uses, stores, protects, and discloses Personal Information and Client Data in the course of providing managed information technology services to its clients ("Client", "you"). This Policy is incorporated by reference into the Managed Services Agreement between RescueIT and the Client and forms part of the contractual commitments between the parties.
RescueIT is committed to protecting the privacy and security of all Personal Information and Client Data entrusted to us. We operate in accordance with applicable Canadian privacy legislation, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and the Alberta Personal Information Protection Act (PIPA), and align our operational controls to the CompTIA Trustmark certification framework.
1. Definitions
"Client Data" means all data and information (including Personal Information) provided by, generated by, or processed on behalf of the Client in the course of RescueIT delivering Services under the Managed Services Agreement.
"Personal Information" means information about an identifiable individual, as defined under PIPEDA and Alberta PIPA, including but not limited to names, contact information, employee identifiers, login credentials, and any other data that can be used directly or indirectly to identify a natural person.
"Processing" means any operation performed on Personal Information or Client Data, including collection, recording, storage, retrieval, use, disclosure, transfer, and destruction.
"Subprocessor" means any third party engaged by RescueIT to assist in the delivery of the Services that may access, store, or process Personal Information or Client Data.
"Data Controller" means the party that, alone or jointly, determines the purposes and means of Processing Personal Information.
"Data Processor" means the party that Processes Personal Information on behalf of, and on the documented instructions of, the Data Controller.
"Data Custodian" means the party with operational responsibility for the secure storage, handling, and protection of Personal Information and Client Data under documented instructions from the Data Controller.
2. Roles of the Parties & Data Custodianship
Client as Data Controller
The Client is, and at all times remains, the sole Data Controller of all Personal Information and Client Data Processed by RescueIT under the Managed Services Agreement. The Client is solely responsible for determining the purposes and means of Processing, establishing the lawful basis for collection and use, providing required privacy notices, obtaining required consents, and responding to data subject access, correction, and erasure requests.
RescueIT as Data Processor and Data Custodian
RescueIT acts solely as a Data Processor and Data Custodian on behalf of the Client. RescueIT Processes Personal Information and Client Data only on the documented instructions of the Client, as set out in the Managed Services Agreement, the Proposal, this Policy, and any subsequent written instructions issued by an authorized representative of the Client. RescueIT does not determine the purposes or means of Processing, does not act as Data Controller in respect of Client Data, and does not Process Client Data for any independent commercial purpose of its own.
Allocation of Liability
RescueIT's liability in respect of Personal Information and Client Data is limited to losses arising directly from RescueIT's breach of its documented obligations as a Data Processor and Data Custodian. The Client is solely responsible for losses, claims, fines, penalties, or regulatory action arising from its own determinations as Data Controller, including failure to provide required privacy notices or obtain required consents.
Notification of Unlawful Instructions
If RescueIT reasonably believes that an instruction received from the Client would result in a violation of applicable privacy or data protection law, RescueIT will promptly notify the Client's Primary Contact in writing and may suspend performance of the affected instruction until the matter is resolved, without such suspension constituting a breach of the Managed Services Agreement.
3. Compliance Framework
RescueIT operates in accordance with the following Canadian privacy laws and industry frameworks:
- Personal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 5, as amended
- Alberta Personal Information Protection Act (PIPA), S.A. 2003, c. P-6.5, as amended
- CompTIA Trustmark certification framework governing internal information security, data protection, incident response, and vendor management
- Industry-recognized cybersecurity controls aligned with the NIST Cybersecurity Framework
Where the Client is subject to additional or more stringent obligations (including PHIPA, HIPAA, GDPR, or sector-specific regulations such as law society requirements), the Client is responsible for notifying RescueIT in writing, and the parties will document any incremental obligations in a written addendum to the Managed Services Agreement.
4. Categories of Information We Process
- Authentication and access credentials, including usernames, password hashes, and MFA tokens — processed solely for administering the Client's systems
- User and device identifiers, including email addresses, device names, IP addresses, and device serial numbers
- Support ticket content, including descriptions of issues, screenshots, log files, and related communications
- System and security telemetry, including endpoint health data, antivirus and EDR alerts, patch status, configuration metadata, and audit logs
- Microsoft 365 administrative data, including mailbox configuration, SharePoint and Teams permissions, license assignments, and conditional access policies
- Backup data, including copies of files, mailboxes, and system images held in encrypted backup storage
- Strategic and operational data, including IT roadmaps, budgets, and reporting outputs
RescueIT does not deliberately collect Personal Information beyond what is necessary to deliver the Services described in the Managed Services Agreement.
5. How We Use Personal Information & Client Data
RescueIT uses Personal Information and Client Data only for the following purposes:
- Delivering Managed Services, Onboarding Services, and Hosting Services as described in the Managed Services Agreement
- Providing helpdesk, ticketing, and incident response support
- Monitoring the security, availability, and performance of the Client's systems
- Performing backup, recovery, patching, and configuration management
- Generating reports, dashboards, and strategic reviews for the Client
- Complying with legal, regulatory, and contractual obligations
RescueIT does not sell, rent, or otherwise commercialize Personal Information or Client Data. RescueIT does not use Personal Information or Client Data to train artificial intelligence or machine learning models without the Client's express written consent.
6. Information Security & Data Protection
Encryption
Data at rest is protected using industry-standard encryption, including BitLocker for endpoint storage and provider-managed encryption for cloud and backup storage. Data in transit is protected using TLS 1.2 or higher for all external transfers.
Access Control
Role-based access control is enforced across RescueIT's internal systems, with access rights granted on a least-privilege basis. Multi-factor authentication (MFA) is enforced for all RescueIT personnel accessing Client systems or Client Data. Privileged access is subject to additional controls, including just-in-time elevation and session logging where applicable.
Endpoint & Network Security
Endpoint detection and response (EDR), antivirus, encryption enforcement, ring-fencing, and Zero Trust policies are deployed across RescueIT systems used to deliver the Services. Dark web monitoring and advanced email protection are deployed for RescueIT accounts that interact with Client environments.
Physical Security
RescueIT offices are physically secured with controlled access and visitor management. Asset management procedures track all hardware that may store or process Client Data, including assignment, return, and secure destruction.
Audit & Logging
RescueIT maintains audit and security logs for systems used to deliver the Services, including Microsoft Azure and Microsoft 365 sign-in logs and administrative actions. Logs are retained in accordance with Section 8 and reviewed for security and compliance purposes.
7. Subprocessors
RescueIT engages a limited number of trusted Subprocessors to support the delivery of the Services. Our principal Subprocessors include:
- Microsoft Corporation (including Microsoft Azure and Microsoft 365) — cloud hosting, identity and access management, productivity, and security services. Canadian region storage is provisioned by default where configurable.
- Acronis International GmbH — backup, disaster recovery, and cyber protection services
- ThreatLocker Inc. — application control, ring-fencing, and Zero Trust endpoint security
- Halo Service Solutions Ltd. — service desk, ticketing, and asset management
All Subprocessors are required to maintain security and privacy commitments substantially equivalent to those set out in this Policy. RescueIT will provide the Client with an updated list of principal Subprocessors upon written request.
8. Data Retention & Destruction
RescueIT retains Personal Information and Client Data only as long as necessary to fulfill the purposes for which it was collected. Default retention periods:
- Operational and support data (including ticket records and configuration metadata): duration of the Managed Services Agreement plus one (1) year
- Backup data: per the backup schedule and retention period specified in the Managed Services Agreement
- Audit and security logs: duration of the Managed Services Agreement plus one (1) year, or longer where required by law
On termination or expiry of the Managed Services Agreement, RescueIT will return or securely destroy Client Data in accordance with offboarding procedures. Secure destruction is performed using methods consistent with NIST SP 800-88 guidelines.
9. Incident Response & Breach Notification
RescueIT maintains a documented incident response process aligned with the CompTIA Trustmark framework. In the event of a confirmed or suspected security incident affecting Client Data, RescueIT will:
- Notify the Client's Primary Contact without undue delay, and in any event within seventy-two (72) hours of confirming a reportable incident
- Provide reasonable details regarding the nature of the incident, the categories of data affected, and the steps taken to contain and remediate
- Cooperate reasonably with the Client to support its own breach notification obligations under PIPEDA, Alberta PIPA, and other applicable laws
10. International Transfer & Data Residency
RescueIT provisions Canadian region storage for Client Data where the underlying Subprocessor makes that option available and where the Client has not requested otherwise in writing. Certain Subprocessor services may involve the transfer of Client Data outside of Canada; where such transfers occur, RescueIT relies on contractual safeguards imposed by the relevant Subprocessor that are substantially equivalent to the privacy protections set out in this Policy.
11. Client Responsibilities
The Client acknowledges and agrees that it is responsible for:
- Obtaining all necessary consents and providing all required notices to data subjects in connection with the Processing of Personal Information by RescueIT
- Ensuring that Personal Information and Client Data provided to RescueIT is accurate, lawful, and provided with appropriate authority
- Complying with its own legal and regulatory obligations as a Data Controller, including obligations under PIPEDA, Alberta PIPA, and any sector-specific privacy laws
- Notifying RescueIT in writing of any sector-specific privacy obligations that require incremental safeguards beyond those set out in this Policy
12. Changes to This Policy
RescueIT may update this Policy from time to time to reflect changes in applicable law, industry frameworks, or operational practice. Material changes that affect the Client's rights or obligations will be communicated to the Client's Primary Contact in writing.
13. Governing Law
This Policy is governed by the laws of the Province of Alberta and the federal laws of Canada applicable therein, consistent with the Managed Services Agreement.
14. Contact
Questions, requests, or concerns regarding this Policy or the Processing of Personal Information by RescueIT may be directed to:
Privacy Officer — RescueIT Inc.
Email: support@rescueit.ca
Phone: 780-801-7160
1. Definitions & Interpretations
"Agreement" means the Managed Services Agreement between RescueIT and you.
"Rate Schedule" means the schedule of rates, charges, and conditions for our services, as may be varied by us from time to time.
"Response Time" means the difference between the time we are first notified of a New Service Request and the time we start providing Service. Triage, scheduling, or dispatch work is not counted when calculating Response Times.
"Services" means the provision of any support services by us including work, advice, and recommendations.
"Service Request" means any request for work that either you ask us to perform, or we perform proactively on your behalf.
2. Response Time Objective
We agree to respond to your Service Requests within the maximum time frames set out in this Policy. If the response time to an incident exceeds the times set out in this Policy — provided you reported the incident via the mandated methods — our internal tools will indicate an SLA timer breach and escalation will be triggered internally.
If the support request is lodged outside our Core Support Hours (see Section 7), the Response Time Objective does not apply. We will still work on your Service Request as fast as possible on a commercially reasonable efforts basis.
3. Service Request Priorities
We classify Service Request priorities as shown in Section 9. These priorities tie directly with our Response Time Objective to provide you with information about how quickly we will respond.
If you require a High, Medium, or Low priority request to be escalated and remediated as a Critical Priority, you can request an "Emergency Upgrade." Please see our Rate Schedule for more information.
The final decision on classifying the priority of an issue will be made by our responding technician or technical service dispatcher.
4. What's Covered
As part of this Policy, we endeavour to include the day-to-day IT support items typically required to run a business technology baseline infrastructure. Anything not included in the support list below is explicitly excluded from this Policy and will be billed at our normal rates.
- End User & Desktop Support: troubleshooting login issues, password resets, profile corruption, application crashes, printing problems, peripheral setup, wireless connectivity, file access permissions, Outlook and Microsoft 365 application support
- Onboarding & Offboarding of Users: provisioning new user accounts, licensing assignment, mailbox and OneDrive setup, MFA enrollment, hardware imaging and deployment, deactivation and license reclamation for departing staff
- Endpoint Management & Security: patch management, antivirus and EDR monitoring, encryption enforcement, ring-fencing and Zero Trust policy management, dark web monitoring, advanced email protection, phishing simulation, and security awareness training
- Microsoft 365 Management: license assignment and optimization, mailbox configuration, SharePoint and Teams permissions, OneDrive sync issues, conditional access policies, M365 admin requests, advanced backup of Email, OneDrive, SharePoint, and Teams
- Server, VM & Network Stack Support: 24/7 monitoring of servers and VMs, patching, performance optimization, backup management, ransomware protection, switch and firewall configuration management, firmware updates, Wi-Fi access point support, VPN configuration
- Mobile Device Management: device enrollment, policy enforcement, remote wipe of lost or stolen devices, app deployment, compliance reporting
- Strategic Services & Reporting: monthly customer success and strategic reviews, quarterly executive reporting, IT budget forecasting, technology roadmap planning, custom dashboards
- Helpdesk & Ticket Handling: standard ticket priority management per Section 9, response time commitments per priority table, tiered escalation through Tier 1 to Tier 4 technicians per Section 6
5. What's Not Covered
Issues or requests that produce a significant change to your systems, network, or physical setup are not included — these are considered projects and are outside the scope of the Managed Services Package. We will notify you if a project is out of scope and provide a detailed scope of work and cost estimate.
Examples of services not included:
- Physically moving equipment between locations
- Net new software installation (e.g., new CRM, ERP, or EHR software)
- Major hardware repair (unless covered by warranty)
- Major software installation or upgrades for more than 5 workstations
- Major data restoration (e.g., complete server restores or multiple folder recoveries due to client error)
- Disaster recovery due to hardware failure, water/fire damage, or theft
- Microsoft 365 migrations
- Offboarding documentation and collaboration
6. Tiered Support Structure
To understand how we respond to your support requests, here is how our support team is structured:
- Tier 1 — Desktop Support: First level of support. Answers all initial requests and resolves approximately 85% of issues. All end users will work with Tier 1 technicians for at least 1 hour unless our management team determines otherwise.
- Tier 2 — Advanced Support: Handles requests that have taken Tier 1 technicians more than one hour to resolve. Dealt with on a first in, first out basis determined by urgency. Tier 2 technicians can also schedule calls at a time convenient for the end user.
- Tier 3 — Network Operations Centre (NOC): Server and network support engineers who spend most of their time proactively monitoring and resolving backend issues on your network. Support Tier 1 and Tier 2 technicians as needed.
- Tier 4 — Field Engineers: Highest level of training and skill. Handle all requests that the first three tiers are unable to resolve, plus all requests involving onsite work.
7. Support Hours
8. How to Submit a Support Request
Client Portal — The best and fastest way to submit a ticket. Allows us to log device information so our technicians can begin troubleshooting prior to calling you.
Email: support@rescueit.ca — Automatically creates a ticket in our ticketing system. Best suited for low- to medium-priority issues. Processed in the order received.
Phone: 780-801-7160 — Calls answered in the order received. Use for critical requests only. If our dispatcher is unavailable, leave a detailed voicemail including: Company Name, Your Full Name, Your Phone Number, and details on the problem. Critical Priority Service Requests must be lodged via phone or the Response Time Guarantee will only apply at High/Medium priority level.
9. Priority Levels & Anticipated Response Times
| Priority | Examples | Response Time |
|---|---|---|
| 🔴 Critical | Main server offline — all users unable to work. Network switch failure stopping half the company. VPN link between offices offline causing one office to be unable to work. | 1 Hour |
| 🟡 High | Internet connection offline (users can still work locally). CEO's computer stopped working. Main accounting software stopped working. | 2 Hours |
| 🔵 Medium | A user's desktop will not turn on. Main printer not working but users can print to another. User having problems connecting to wireless network. | 4 – 6 Hours |
| 🟢 Low | Printing is slower than normal. Single user unable to scan. User needs a program installed on their PC. | 8 Hours |
| — No Priority | Proactive maintenance of systems. | N/A |
Response Time Exclusions
Our Response Time commitments do not apply to:
- Additions, moves, or changes to users, devices, configurations, or network
- Issues lodged in any manner other than as specified in this Policy and our Agreement
- Issues lodged outside our Core Support Hours
- Items caused by hardware or software not meeting our Minimum Standards
- Service Requests related to software not on our Approved Software List
- Issues caused by you not acting on advice or recommendations given by us
- Issues caused by you or third parties modifying any hardware or software configuration
- Issues related to user-initiated virus and malware infections
- Service Requests involving the sourcing of hardware or software
- Hardware and software issues for items not under current warranty or maintenance coverage
Support does not include training for supported software or hardware, use case or business process development, application development, system design, implementation, or data recovery. This Support Policy does not apply to issues caused by accident, abuse, misuse, liquid contact, fire, earthquake, or other external causes, or to issues arising from service performed by anyone who is not an authorized service provider.
This Policy is subject to the Agreement.
Questions about your support coverage? Contact us at support@rescueit.ca or call 780-801-7160.