Home/Privacy Policy

Privacy Policy

Intrv is a security company. We think it would be poor form to ask for your data without explaining plainly what we do with it. This page sets out what we collect through this website, why, how long we keep it, and what you can ask us to do about it.

Last updated: 01 SEP 2026

Who we are

This site is operated by INTRV. In this policy, "we" and "us" mean that entity. Questions about this policy or about your personal information should go to our privacy contact at privacy@intrv.ca.

Information you give us

We collect personal information only when you choose to send it to us. Nothing on this site collects identifying information silently. Where you complete a form, we collect the fields you fill in:

  • Get a Quote — your name, job title, email, phone, company details, the systems you want tested, your region and hosting environment, your budget and timeline indications, and your confirmation that you are authorised to request security testing.
  • Contact enquiry — your name, job title, email, phone, company details, region, the nature and urgency of your enquiry, the services you are interested in, and your message.

Scoping information tells us what you need and whether we are the right firm for it. You can decline to provide any of it, though incomplete scoping information may mean we cannot quote accurately.

Information collected automatically

Like most websites, this site records limited technical information that does not identify you personally: browser type and version, device type, approximate region, referring page, pages viewed, and the date and time of your visit. We use this to understand which pages are useful and to keep the site working.

Our current analytics and hosting providers are Webflow, Google Inc., Zoho Inc. Our site is hosted by Webflow, and form submissions are processed and stored on Webflow's infrastructure.

How we use your information

We use what you send us to reply to your enquiry, scope and quote engagements, deliver work you have engaged us for, and keep the records a professional services firm is expected to keep. We do not use enquiry information to build advertising profiles.

We will send you marketing email only if you have asked us to. Where we do, every message carries a working unsubscribe link, as Canada's anti-spam legislation requires.

Who we share it with

We do not sell your personal information, and we do not share it with third parties for their own marketing. We share it only with service providers who help us run the business — our website host, email provider and analytics provider — and only to the extent they need it to perform that service. Those providers are bound to protect it and may not use it for their own purposes.

We may also disclose information where the law requires it, such as under a court order or a lawful request from a regulator or law enforcement.

Confidentiality of engagement information

Information you share while scoping or during an engagement — architecture details, IP ranges, application inventories, findings and reports — is treated as confidential and handled under the engagement agreement and any non-disclosure agreement between us. Testing findings are shared only with the people you name. We do not publish client names, reports or findings as case studies without written permission.

How long we keep it

We keep enquiry and scoping information for 36 months from our last contact with you, unless it becomes part of a client record. Client engagement records, including reports, are retained for 7 years to meet professional, contractual and tax obligations, and are then securely destroyed.

How we protect it

We apply access controls, encryption in transit, and the principle of least privilege, so that only the people who need access to your information have it. No system is perfectly secure, and we will not claim otherwise — but we hold our own environment to the standard we test our clients against.

Cookies

Cookies are small files a site stores in your browser. Session cookies expire when you close the browser; persistent cookies remain until they expire or you delete them. We use them to keep the site functioning and to understand aggregate usage.

You can refuse or delete cookies in your browser settings. Some parts of the site may not work as intended if you do.

Your rights

Under Canadian privacy law, and under the GDPR if you are in the UK or European Economic Area, you can ask us to:

  • confirm whether we hold personal information about you, and give you a copy;
  • correct information that is inaccurate or incomplete;
  • delete information we no longer have a lawful reason to keep;
  • withdraw a consent you previously gave, including consent to marketing;
  • explain what we do with your information and who we share it with.

Write to privacy@intrv.ca and we will respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, or to your local supervisory authority if you are in the UK or EEA.

Information held outside Canada

Some of our service providers store data outside Canada, including in the United States. Where that happens, your information may be accessible to courts and authorities in those jurisdictions under their local law. We choose providers that offer protection comparable to what we are required to provide.

Links to other sites

Where we link to external sites — advisories, standards bodies, or research — we do so because the material is useful, not as an endorsement. We do not control those sites and are not responsible for their content or their privacy practices.

Changes to this policy

We may update this policy as our practices or the law change. The date at the top of this page shows when it was last revised. Where a change materially affects how we handle information you have already given us, we will tell you directly rather than rely on you noticing.