top of page

Privacy Policy

A Legal Disclaimer

Lunima Cybersecurity Inc. ("Lunima," "we," "our," or "us") is committed to protecting the privacy of every person and business that interacts with our website, services, and team. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and your rights under Canadian law — specifically the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. Please read this document carefully. If you have questions, contact us at Lunima.ca

Privacy Policy

Lunima Cybersecurity Inc. is a Toronto-based cybersecurity consulting firm incorporated under the laws of the Province of Ontario, Canada. We provide cybersecurity assessments, email security configuration, compliance documentation, continuous security monitoring, staff training, and incident response services to Canadian businesses.

What Information We Collect

We collect only the personal information that is necessary to provide our services, respond to enquiries, and comply with legal obligations. We do not collect information "just in case."

2.1 Information You Give Us Directly

  • Contact information: Your name, business name, email address, and phone number when you complete a contact form, book a service, or email us directly.

  • Business and technical information: Your business domain name, website URL, industry, and a description of your security concerns — provided when you request a free security scan or book an engagement.

  • Communications content: The content of emails, messages, and calls you send to us, including any documents or files you share.

  • Suspicious email submissions: If you forward a suspicious email to scan@lunima.ca for threat triage, we receive the content and metadata of that email for analysis purposes only.

  • Payment information: If you pay for a Lunima service, payment is processed by a third-party provider (Stripe or Wave). We do not receive or store your full credit card number. We receive a transaction confirmation and basic billing details.



    2.2 Information We Collect Automatically
     

  • Website analytics: Pages visited, time on page, referral source, device type, and browser type — collected through standard analytics tools. This data is aggregated and does not identify you personally.

  • Technical log data: IP address, timestamp, and request data collected automatically by our web hosting provider 



    2.3 Information We Collect as Part of Service Delivery

  • Domain scan data: When we perform a security assessment, we scan publicly available technical records for your domain — including DNS records (DMARC, SPF, DKIM), SSL certificate information, security headers, and publicly indexed breach databases (HaveIBeenPwned). This information is publicly accessible and does not require us to access any of your internal systems.

  • Assessment findings: Technical vulnerabilities, compliance gaps, and remediation records created during an engagement are retained as part of your client record for service continuity.

  • Incident response records: If you engage Lunima for incident response, we may collect information about the breach — including affected systems, dates, and the nature of data involved — solely to assist in containment, regulatory reporting, and documentation.



    Legal Basis for Collection
     

  • Under PIPEDA, Lunima collects and uses personal information based on the following grounds:

  • Consent: By submitting a contact form, requesting a service, or emailing us, you consent to the collection and use of your information as described in this policy. You may withdraw consent at any time (see Section 10).

  • Contractual necessity: When you hire Lunima for a service engagement, processing your contact details and technical information is necessary to deliver the service you have requested.

  • Legitimate business interest: We process aggregated website analytics data to understand how our site is used and how to improve it.

  • Legal obligation: We may retain certain records as required by applicable Canadian law, including tax records and engagement documentation.







    © 2025 Lunima Cybersecurity Inc. All rights reserved.

    This Privacy Policy was prepared specifically for Lunima Cybersecurity Inc. and reflects the requirements of the Personal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 5, and other applicable Canadian privacy legislation as of the effective date above. This document does not constitute legal advice. If you have specific legal questions about your own privacy obligations, consult a qualified Canadian privacy lawyer.

bottom of page