Privacy Policy

Effective Date: 20 February 2026

This Privacy Policy describes how GroupFractal (“GroupFractal”, “we”, “our”, or “us”) collects, uses, processes, stores, discloses, and safeguards personal information and client business data in accordance with:

  • Canada Personal Information Protection and Electronic Documents Act (PIPEDA)
  • European Union General Data Protection Regulation (GDPR)
  • Applicable United States privacy laws

By using our website or engaging our services, you acknowledge and agree to this Privacy Policy.

1. Roles And Legal Capacity

For purposes of data protection laws:

  • GroupFractal acts as a Data Controller for information collected through its website and marketing activities.
  • GroupFractal acts as a Data Processor when processing personal data on behalf of clients under a service agreement.

Clients remain the Data Controller of their own customer data.

2. Categories Of Information Collected

2.1 Website And Lead Data

When individuals submit forms, book consultations, download resources, or contact GroupFractal, we may collect:

  • Name
  • Email address
  • Phone number
  • Company name
  • Website URL
  • Industry
  • Budget information
  • Marketing objectives
  • Business challenges
  • IP address
  • Browser data
  • Referral source
  • Any additional voluntarily submitted information

2.2 Client Provided Business Data

During service delivery, GroupFractal may access or process:

  • Analytics data
  • Google Ads and Meta Ads account data
  • CRM data
  • Ecommerce transaction data
  • Conversion tracking data
  • Sales funnel data
  • Attribution data
  • Call tracking data
  • Customer segmentation data
  • Email marketing platform data
  • Search Console data
  • Marketing strategy documents
  • Reports and dashboards
  • Confidential internal business documents

This data is processed strictly for contractual service delivery.

2.3 Automatically Collected Data

Through cookies and tracking technologies:

  • IP address
  • Device identifiers
  • Operating system
  • Browser type
  • Page interactions
  • Session duration
  • Engagement metrics

3. Lawful Basis For Processing Under GDPR

Where GDPR applies, processing is based on:

  • Article 6 1 b Contractual necessity
  • Article 6 1 f Legitimate interest
  • Article 6 1 a Consent
  • Article 6 1 c Legal obligation

4. Purpose Of Processing

GroupFractal processes information to:

  • Provide SEO and PPC services
  • Perform audits and analysis
  • Manage advertising accounts
  • Improve marketing performance
  • Deliver reporting and insights
  • Respond to inquiries
  • Improve website functionality
  • Maintain business records
  • Comply with regulatory obligations

We do not sell personal information.

5. Confidentiality And Data Protection Commitments

GroupFractal implements strict safeguards including:

  • Role based access control
  • Secure authentication
  • Encrypted data transmission
  • Contractual confidentiality obligations
  • Limited access to authorized personnel
  • Vendor due diligence

Client data is never used for unrelated commercial purposes.

6. Data Sharing And Subprocessors

We may share information with:

  • Cloud hosting providers
  • Advertising platforms
  • Analytics platforms
  • CRM systems
  • Payment processors
  • Professional advisors
  • Legal authorities if required

Where acting as a Data Processor, we engage subprocessors under written agreements ensuring compliance with GDPR Article 28 and PIPEDA safeguards.

7. International Data Transfers

Because digital advertising platforms operate globally, data may be transferred outside Canada or the European Economic Area.

Where required, we implement:

  • Standard Contractual Clauses
  • Adequacy mechanisms
  • Contractual safeguards
  • Technical security measures

8. Data Retention

We retain data only as long as necessary for:

  • Contract fulfillment
  • Legal obligations
  • Dispute resolution
  • Tax and accounting requirements

Client data may be deleted upon written request after termination, subject to legal retention requirements.

9. Individual Rights Under GDPR

Where GDPR applies, individuals have the right to:

  • Access their personal data
  • Rectification
  • Erasure
  • Restriction of processing
  • Data portability
  • Objection to processing
  • Withdraw consent

Requests may be submitted using the contact information below.

10. Rights Under Canadian PIPEDA

  • Access personal information held by us
  • Request correction of inaccurate information
  • Withdraw consent where applicable
  • File complaints with the Office of the Privacy Commissioner of Canada

11. Security Measures

GroupFractal maintains appropriate administrative, technical, and physical safeguards to protect personal and business data against:

  • Unauthorized access
  • Loss
  • Misuse
  • Alteration
  • Disclosure

No method of transmission is completely secure. However, we maintain commercially reasonable security standards consistent with industry best practices.

12. Breach Notification

  • We will assess material risk
  • Notify affected clients where required
  • Comply with GDPR Articles 33 and 34 where applicable
  • Comply with Canadian breach reporting requirements

13. Children

Our services are not directed toward individuals under 18 years of age.

14. Changes To This Policy

We reserve the right to modify this Privacy Policy. Updates will be posted with a revised effective date.

15. Contact Information

GroupFractal

Email: info@groupfractal.com

Website: https://groupfractal.com

If you are located in the European Union and wish to exercise GDPR rights, please contact us using the email above.