Privacy Policy
Last Updated: February 18, 2026
1. Introduction & Controller Identity
This Privacy Policy explains how NorthCode Academy Inc. ("NorthCode Academy," "we," "us," or "our") collects, uses, stores, and protects your personal data when you visit northcodeacademy.ca (the "Website") or interact with our services, including program enquiries, enrolment processes, and career support.
Data Controller: NorthCode Academy Inc., 100 King Street West, Suite 5600, Toronto, ON M5X 1C9, Canada. For any privacy-related questions or requests, contact us at [email protected] or by calling +1 416 850 7432.
This policy is effective as of February 18, 2026, and applies to all visitors regardless of geographic location. We are committed to compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA), the General Data Protection Regulation (GDPR) for visitors in the European Economic Area and United Kingdom, and applicable provincial privacy legislation in Canada.
2. Personal Data We Collect
We collect the following categories of personal data when you use our Website and services:
- Identity and contact data: full name, email address, phone number, and mailing address when you submit an enquiry form, apply for a program, or contact us directly.
- Form content: your selected program of interest, messages, questions, career background details, and any other information you voluntarily include in form submissions.
- Technical data: IP address, browser type and version, operating system, device type, screen resolution, and preferred language settings.
- Usage data: pages visited, time spent on each page, referral source (the website or search engine that directed you here), click paths through the site, and scroll depth.
- Cookies and identifiers: cookie IDs, session tokens, and advertising identifiers as described in Section 4 below and in our Cookie Policy.
- Conversion events: whether you completed a form submission, downloaded a resource, or took another measurable action on the Website.
We do not collect special-category data (such as health information, religious beliefs, or political opinions), financial account details, or government-issued identification numbers through this Website.
3. Why We Process & Legal Basis
We process your personal data for the following purposes and under the following legal bases (referencing GDPR Article 6 for EEA/UK visitors, and PIPEDA's knowledge-and-consent principle for Canadian visitors):
- Processing programme enquiries and applications: Art. 6(1)(b) — necessary for steps taken prior to entering a contract, and Art. 6(1)(a) — your consent when submitting the contact form.
- Website analytics: Art. 6(1)(a) — consent, obtained through our cookie consent mechanism before any analytics cookies are activated.
- Marketing, remarketing, and lookalike audience building: Art. 6(1)(a) — consent, obtained through our cookie consent mechanism. Marketing cookies are only activated after you expressly opt in.
- Website security and fraud prevention: Art. 6(1)(f) — legitimate interest in protecting the Website, our infrastructure, and our users from malicious activity.
- Legal and tax obligations: Art. 6(1)(c) — necessary for compliance with applicable Canadian tax law and regulatory record-keeping requirements.
Automated Decision-Making: We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on individuals.
4. Cookies & Tracking
Our Website uses cookies and similar technologies, organized into three categories. Full details, including a table of each cookie's name, purpose, and retention period, are in our Cookie Policy.
Essential Cookies (no consent required, always active):
_site_session— maintains your browsing session. Retention: session.cookie_consent— stores your cookie preference choices. Retention: 12 months.
Analytics Cookies (consent required):
- Google Analytics 4, with IP anonymization enabled. Sets
_ga(2 years) and_ga_XXXXXXXXXX(2 years, where XXXXXXXXXX is a 10-character GA4 measurement ID). Data retention is configured to 14 months.
Marketing Cookies (consent required):
_gcl_au— Google Ads conversion linker. Retention: 90 days._fbp— Meta Pixel browser identifier. Retention: 90 days._fbc— Meta Pixel click identifier, set when a click ID parameter is present. Retention: 90 days.
Beyond cookies, we may use pixel tags (gtag.js, Meta Pixel) and server-side tracking via Meta Conversion API or Google Server-Side Tag Manager, which may transmit hashed identifiers. Device identifiers may also be derived from IP address and User-Agent combinations.
5. Consent (EEA/UK Visitors)
Users in the European Economic Area and United Kingdom receive a consent notice under GDPR and UK GDPR when they first visit the Website. Marketing and analytics cookies activate only after explicit, informed, freely given consent (Art. 6(1)(a)). Your consent choice is recorded in the cookie_consent browser cookie and retained for 12 months.
You may withdraw consent at any time by clicking "Manage Cookie Preferences" in the Website footer or by clearing your browser cookies. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
6. Sharing With Advertising & Service Partners
We share personal data with the following categories of third-party service providers, strictly for the purposes outlined in this policy:
- Google LLC (Google Analytics 4, Google Ads, Google Tag Manager, Remarketing): cookie identifiers, usage data, conversion events, and remarketing list membership. Google's privacy policy: policies.google.com/privacy.
- Meta Platforms, Inc. (Meta Pixel, Custom Audiences, Lookalike Audiences, Conversion API): page views, conversion events, audience membership, and hashed identifiers. Meta's privacy policy: facebook.com/privacy/policy.
- Cloudflare, Inc. (CDN and security): IP-based threat detection and traffic routing. Cloudflare's privacy policy: cloudflare.com/privacypolicy.
We do not sell personal data. These providers are contractually prohibited from using Website data for their own independent commercial purposes.
7. International Transfers
Some of our service partners, including Google and Meta, are based in the United States. When personal data is transferred outside of Canada, the EEA, or the UK, we rely on the following safeguards:
- EU-US Data Privacy Framework (primary mechanism, in effect since July 2023), including the UK Extension to the DPF and the Swiss-US DPF where applicable.
- Standard Contractual Clauses (EU Commission Decision 2021/914) as a fallback mechanism.
- UK International Data Transfer Agreement (IDTA) as a fallback for UK transfers.
- For transfers from Canada, we ensure the receiving jurisdiction provides a substantially similar level of protection as required under PIPEDA, or we implement contractual safeguards.
8. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy, or as required by law:
- Contact and programme enquiry submissions: 2 years from the date of last interaction.
- Analytics data: 14 months (configured within Google Analytics 4).
- Marketing cookies: per the cookie's individual lifetime (90 days for advertising cookies, 2 years for analytics cookies).
- Email correspondence: duration of the business relationship plus 1 year.
- Server logs: 90 days.
- Cookie consent records: 3 years, retained for audit and regulatory compliance purposes.
- Legal and tax records: as required by applicable Canadian law, typically 6 to 7 years for financial records.
9. Your Rights
Depending on your jurisdiction, you may exercise the following rights regarding your personal data:
- Right of Access (GDPR Art. 15 / PIPEDA Principle 4.9): Request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to Erasure (Art. 17): Request deletion of your personal data, subject to legal retention obligations.
- Right to Restriction (Art. 18): Request that we limit how we process your data in certain circumstances.
- Right to Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent (Art. 7(3)): Withdraw previously given consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Right to Lodge a Complaint (Art. 77): File a complaint with a supervisory authority.
To exercise any of these rights, email us at [email protected] with the subject line "Privacy Rights Request." We will respond within 30 days, with the possibility of a 60-day extension for complex requests, in which case we will notify you of the delay.
Relevant supervisory authorities:
- Canada: Office of the Privacy Commissioner of Canada — priv.gc.ca
- UK: Information Commissioner's Office — ico.org.uk
- EU (general): European Data Protection Board — edpb.europa.eu
- Germany: Federal Commissioner for Data Protection — bfdi.bund.de
- France: CNIL — cnil.fr
10. Children
This Website is not directed at individuals under the age of 16. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected data from a child under 16 without verifiable parental consent, we will delete that data promptly. If you believe a minor has submitted personal data through our Website, please contact us at [email protected].
11. Do Not Track
This Website does not respond to Do Not Track (DNT) browser signals. Third-party service providers may have their own DNT handling policies. We recommend reviewing the privacy policies of Google and Meta linked in Section 6 for details on their respective approaches.
12. Account & Data Deletion
If you wish to request deletion of all personal data we hold about you, email [email protected] with the subject line "Data Deletion Request." We will complete the deletion within 30 days of verifying your identity. We may retain limited data where required by law (for example, financial records retained for Canadian tax compliance).
13. Business Transfers
In the event of a merger, acquisition, asset sale, financing, or insolvency involving NorthCode Academy Inc., personal data may be transferred to a successor entity as part of the transaction. We will notify users via a prominent notice on the Website if such a transfer materially changes how your data is used. The successor entity will be bound by this Privacy Policy until a revised policy is published with appropriate notice.
14. California Residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act and the California Privacy Rights Act provide you with specific rights regarding your personal information.
Categories of personal information disclosed in the past 12 months:
- Identifiers (name, email address, IP address, device identifiers) — disclosed to service providers and advertising partners.
- Internet or other electronic network activity (browsing history, pages viewed, referral URLs) — disclosed to analytics and advertising providers.
- Inferences (interests and preferences derived from usage patterns) — disclosed to advertising partners.
We do not sell personal information as defined by the CCPA. We do share data for cross-context behavioral advertising; California residents may opt out of this sharing via our cookie preferences panel accessible from the Website footer.
Your California rights: Right to Know, Right to Delete, Right to Correct, Right to Opt-Out of sale or sharing, and the Right to Non-Discrimination for exercising your rights. To submit a request, email [email protected] with the subject line "California Privacy Request." Identity verification is required. Authorized agents may submit requests with written proof of authorization.
15. Virginia Residents (VCDPA)
Virginia residents have the following rights under the Virginia Consumer Data Protection Act: the right to Access, Correct, Delete, obtain a copy (Portability), and Opt-Out of targeted advertising. To submit a request, email [email protected] with the subject line "Virginia Privacy Request."
We do not sell personal data or engage in profiling that produces legal or similarly significant effects. If we deny your request, you may appeal by emailing with the subject line "Appeal of Refusal — Privacy Request." We will respond to appeals within 60 days. If you are unsatisfied with the outcome, you may contact the Virginia Attorney General.
16. Nevada Residents
Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject line "Nevada Do Not Sell Request." We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. Material changes will be announced via a prominent banner on the Website homepage at least 14 days before taking effect. The "Last Updated" date at the top of this page will be revised with every update. We encourage you to review this page periodically.
18. Contact
If you have any questions about this Privacy Policy, your personal data, or your rights, you can reach us through the following channels:
- Entity: NorthCode Academy Inc.
- Address: 100 King Street West, Suite 5600, Toronto, ON M5X 1C9, Canada
- Email: [email protected]
- Phone: +1 416 850 7432
We aim to respond to all privacy-related enquiries within 5 business days.