BUGSPATTER

Privacy Policy

Effective August 27, 2026

Contents

  1. 1. Introduction
  2. 2. Scope of This Policy
  3. 3. Information We Collect
  4. 4. How We Use Your Information
  5. 5. Legal Bases for Processing
  6. 6. Cookies and Similar Technologies
  7. 7. How We Share Information
  8. 8. Service Providers and Processors
  9. 9. International Data Transfers
  10. 10. Data Retention
  11. 11. Security of Your Information
  12. 12. Privacy for Children
  13. 13. Your Rights and Choices
  14. 14. California Privacy Rights
  15. 15. Additional Regional Rights
  16. 16. Email and Communication Preferences
  17. 17. Analytics and Advertising Technology
  18. 18. Third Party Links and Resources
  19. 19. Data Incident Response
  20. 20. Changes to This Privacy Policy
  21. 21. Contact Information

1 Introduction

Bug Spatter Productions Inc., operating as BugSpatter, provides computer systems design and integration services for organizations across North America. This privacy policy explains how the developer BugSpatter and its team collect, use, and protect personal information when you visit our website, contact our office, or engage our services. We are committed to handling your data with care, transparency, and respect for your privacy rights.

The company is registered at 714-40 Homewood Ave, Toronto, ON M4Y 2K2, Canada, and our products and services are developed and operated by the developer BugSpatter. Please read this policy carefully so that you understand our practices and your choices. If anything in this document is unclear, you are welcome to contact us at the address listed in the final section of this page.

2 Scope of This Policy

This policy applies to every visitor of www.bugspatter.lol, every person who contacts us by email or phone, and every client or prospective client who asks for a proposal. It covers the information we receive through our website, through our contact form, through email messages, and through conversations with our team. It also applies to information we receive during the delivery of consulting and integration projects.

The policy does not apply to third party websites that we link to, or to applications and tools that are owned by our clients. Where a client operates its own privacy rules, those rules continue to apply to the data stored inside that client system. In that situation we act as a service provider to the client, and the client acts as the controller of the data.

3 Information We Collect

We collect only the information that is needed to answer your questions and deliver our work. When you fill in the contact form we receive your name, your email address, your subject line, and the message you write. When you email us directly we receive your address, your message, and any files you attach. During a project we may collect technical details such as IP addresses, server logs, system configurations, and access credentials that are required to build or maintain your systems.

We also collect basic usage data on our website, such as pages viewed and the length of each visit, in an aggregate and anonymous form. We do not collect sensitive personal information unless you choose to share it with us for a specific purpose. Where you provide information about other people, such as the contact details of a colleague, you confirm that you have the right to share that information with us.

4 How We Use Your Information

We use your information for four purposes. First, to answer your inquiries and prepare proposals. Second, to deliver the services you have asked us to provide, including design, integration, maintenance, and support. Third, to manage our business relationships, including invoices, project records, and legal obligations. Fourth, to improve our website and our services by studying aggregate usage patterns.

We do not sell your personal information to any third party, and we do not use your data for advertising that targets you as an individual. If you work with us, your data is used only to serve the project that you authorized. We never combine project data with website analytics, and we never use one client data to benefit another client.

5 Legal Bases for Processing

We rely on several lawful bases when we process personal information. We process information to perform a contract with you, when you ask us to deliver services or prepare a proposal. We process information to comply with legal obligations, such as tax records and professional liability requirements. We also process information on the basis of our legitimate business interests, which include operating our website, protecting our systems from abuse, and improving the quality of our service.

Where a specific law requires it, we will ask for your consent before collecting particular types of data. You may withdraw consent at any time without affecting the lawfulness of processing that happened before you withdrew it. If you have questions about the basis we rely on for a particular use of your data, we will be happy to explain it to you in plain language.

6 Cookies and Similar Technologies

Our website uses a small number of cookies and similar storage technologies to make the site work properly and to understand how visitors move through our pages. We do not use advertising cookies and we do not build visitor profiles for marketing. A functional cookie may remember that you have already visited the site, and an analytics cookie may record the pages you open so that we can see which content is useful.

You can disable cookies through your browser settings at any time. Disabling cookies will not prevent you from reading any page on our website, although some interactive features may behave differently. We keep the cookie list short and review it regularly. Our cookie table is available on request, and we will tell you exactly what each cookie does.

7 How We Share Information

We share personal information only where it is necessary to deliver our services or to meet the law. We share project details with subcontractors who perform work under our direction, and we require those parties to protect the data with the same care that we do. We may share information with professional advisors such as lawyers and accountants, with payment processors when you pay us, and with our hosting and software vendors.

We may also disclose information when we are required to do so by a court order, a regulator, or another legal process. If we are asked to hand over data, we will review the request and challenge it where the law allows. We never sell your data and we never trade it with marketing brokers. Our sharing list is short, and we are always willing to tell you who has access to your information.

8 Service Providers and Processors

From time to time we use third party providers for specific technical tasks. These providers include cloud hosting companies, code repositories, monitoring tools, email services, and productivity software. Each provider processes personal information only for the purposes we direct and under a written agreement. We choose providers that offer strong security, clear data handling rules, and records of their own compliance.

We review our provider list whenever we change tools, and we maintain a register of every provider that touches client data. If a provider is located in another country, we take care to keep the transfer lawful under the rules described in the international transfers section of this policy. Providers do not get broader access than their task requires.

9 International Data Transfers

Our company is based in Canada and our primary systems are hosted in North America. When data moves to a service provider in another region, we make sure the transfer is protected by an appropriate legal mechanism, such as a standard contractual clause or an equivalent safeguard recognized by applicable law. We will not move your data to a country simply to avoid a legal duty.

Where you ask us to host your systems in a specific region for compliance reasons, we will honour that request as part of the project agreement. We will update this policy if our hosting locations change in a material way. You can ask us at any time for a list of the countries where your data is stored.

10 Data Retention

We keep personal information only as long as we need it. Website contact submissions are retained for as long as an inquiry stays relevant and are removed when the matter is closed. Project documents and business records are kept for the periods required by tax law and professional standards, which is typically several years. Support tickets and access logs are kept for security and troubleshooting and are deleted on a rolling schedule.

When data is no longer needed, we delete it or convert it to a form that cannot identify a person. Our retention schedule is reviewed each year and adjusted when the law changes. If you would like a copy of the retention schedule that applies to your engagement, we will provide one on request.

11 Security of Your Information

We protect your information with administrative, technical, and physical safeguards. Access to your data is limited to the people who need it for their work. Accounts use strong passwords and multi factor authentication where the platform supports it. Data in transit is protected by encryption, and data at rest is encrypted on our primary systems. We run regular backups, apply security patches promptly, and review access logs for unusual activity.

No method of transmission or storage is completely secure, and we cannot guarantee absolute safety, but we take reasonable measures that meet industry practice for a firm of our size. Our team receives regular security training, and our access list is reviewed every quarter. If you notice anything suspicious in your dealings with us, please report it to the contact address below immediately.

12 Privacy for Children

Our website and services are directed at adults and at business organizations. We do not knowingly collect personal information from children, and we do not design our services for children to use. If you believe that a child has provided personal information to us without parental consent, please contact us at talk@bugspatter.lol so that we can review and delete the information promptly.

If we learn that we have collected personal data from a child, we will remove it as soon as we can. Parents and guardians may contact us at any time to ask for the removal of information that a child has shared with us. We take this responsibility seriously and we respond to such requests without delay.

13 Your Rights and Choices

Depending on where you live, you may have the right to access the personal information we hold about you, to correct mistakes in it, to delete it, and to restrict or object to particular processing. You may also have the right to receive your data in a portable format and to ask us not to make automated decisions about you. To exercise any of these rights, contact us at talk@bugspatter.lol with a clear description of your request.

We will respond within the period required by applicable law and we will never punish you for making a request. We may ask you to verify your identity before we act, to make sure that we do not hand your data to the wrong person. Most requests are completed within a week, and we will keep you informed if any request takes longer.

14 California Privacy Rights

If you live in California, the California Consumer Privacy Act and related rules give you specific rights. You have the right to know what personal information we collect, use, and share. You have the right to request deletion of your personal information. You have the right to opt out of the sale of your personal information, and we confirm that we do not sell personal information at all. You have the right to be free from discrimination for exercising these rights.

To make a request, email talk@bugspatter.lol or call +14127032658. We will verify your identity and respond within the time allowed by law, and we will provide the requested information free of charge. We may ask for a little more detail when a request involves large volumes of data, so that we can locate the right records efficiently.

15 Additional Regional Rights

Residents of other regions have rights under their local laws as well. If you are in the European Union or the United Kingdom, you may lodge a complaint with your local data protection authority at any time. If you are in Canada, you may contact the Office of the Privacy Commissioner about our handling of your data. If you are in another jurisdiction, please review the rights available under the privacy law of your home country.

We will honour any valid request that comes to us from any region, even where a local law does not require it, and we will cooperate with the relevant authorities in good faith. Nothing in this policy limits the mandatory rights that the law of your country grants you.

16 Email and Communication Preferences

We send email for three reasons: to reply to your inquiries, to manage an active project, and to share occasional updates about our company with people who have chosen to receive them. Every marketing message we send includes a simple way to opt out, and we honour every opt out without delay. We do not send commercial email to people we do not know.

If you receive a message from us that you did not expect, forward it to talk@bugspatter.lol and we will investigate. Project related messages continue as long as the engagement is active, because they are part of the service we owe you. Once a project ends, we send only the messages that the law or our retention duties require.

17 Analytics and Advertising Technology

Our website uses a privacy friendly analytics setup that records aggregate numbers rather than individual profiles. We look at totals such as the number of visitors per month, the most popular pages, and the countries where visitors are located. We do not run retargeting campaigns and we do not place tracking pixels from advertising networks. When we link to our social media profiles, those platforms may collect their own data under their own policies, and we encourage you to review them.

If you prefer not to be counted in our analytics, you may disable JavaScript or use a private browsing window. The aggregate numbers we see are used only to decide which content to improve. We never sell those numbers and we never connect them to your identity.

18 Third Party Links and Resources

Our website may link to external resources such as government guides, industry standards, client sites, and partner tools. These third party sites have their own privacy practices and their own terms, which are not controlled by us. When you leave our website, the information you share is subject to the policy of the site you are visiting.

We recommend that you review the privacy policy of any external site before you provide personal data. We are not responsible for the content or the privacy practices of any third party resource that we do not operate. A link from our site is not an endorsement of the linked service.

19 Data Incident Response

If a security incident affects the personal information we hold, we will respond quickly and honestly. We maintain an incident response plan that assigns roles, defines containment steps, and preserves evidence. We will investigate the cause, fix the underlying weakness, and document what happened. Where the law requires it, we will notify the affected people and the relevant authorities within the required timeframes.

We will also review our controls to reduce the chance of a repeat event. We treat incidents as learning opportunities and we share the lessons with our team through updated procedures. You will always be told what happened, what we changed, and how to protect yourself if there is anything you need to do.

20 Changes to This Privacy Policy

We may update this privacy policy from time to time to reflect changes in our services, our technology, or the law. When we make a material change, we will post the updated policy on this page and change the effective date at the top of the document. If a change affects your existing rights in a meaningful way, we will contact you directly where we have your contact details.

The version that applies to you is the one that is in force at the time you engage our services. You are welcome to review this page at any time to see the latest version. The date at the top of the page always reflects the most recent revision.

21 Contact Information

Questions and requests about this privacy policy are welcome at any time. You can reach the developer BugSpatter by email at talk@bugspatter.lol or by telephone at +14127032658. You can also write to Bug Spatter Productions Inc., 714-40 Homewood Ave, Toronto, ON M4Y 2K2, Canada.

We aim to answer every privacy message within two business days. If you feel that we have not resolved a concern, you may contact the privacy authority in your region. Thank you for trusting us with your information.

Bug Spatter Productions Inc. · 714-40 Homewood Ave, Toronto, ON M4Y 2K2, Canada · talk@bugspatter.lol · +14127032658

Return to the BugSpatter homepage