Privacy Policy

Last updated: 2026-08-15

Who we are

CoMotion.Solutions is operated by CoMotion Solutions Agency Inc., a corporation incorporated under the Canada Business Corporations Act, with its mailing address at 354 Guelph St, Unit 23-450, Georgetown, ON L7G 4B5. In this policy, “we”, “us”, and “our” mean CoMotion Solutions Agency Inc., and “CoMotion.Solutions” is the brand name under which we operate comotion.solutions.

Definitions

In this policy:

  • Personal Information means information about an identifiable individual. This is the meaning the federal privacy statute, the Personal Information Protection and Electronic Documents Act (PIPEDA), gives the term, and we use it the same way throughout.
  • Site means the comotion.solutions website and everything we publish on it.
  • Service Provider means a third party that processes Personal Information on our behalf. Every Service Provider we use is listed in Who we share it with.

What we collect and why

This is a short list, because the Site does very little. You cannot create an account on it, and you cannot buy anything on it. We collect the following, and only for the purposes stated:

  • Booking a call. Your name, email address, time zone, and anything you write in the booking form. Purpose: schedule and hold the call you booked, and follow up about it. The booking is handled by our scheduling provider, not by a form we run.
  • Emailing us. Your email address, your name if you give it, and what you write. Purpose: answer you, and follow up about it.
  • Visiting the Site. Our hosting provider records your IP address, your browser type, and basic details of the request. Purpose: serve the Site, and keep it secure and available.
  • Measuring how the Site is used. The page you opened, the site you came from, the country you are in, your browser and operating system, and how quickly the page loaded. Purpose: see which pages people actually read and how quickly the Site loads, so we know what to keep and what to fix. Our analytics provider collects this on every page. It sets no cookie, and you can turn it off, as Cookies and analytics explains.
  • Opening the booking tool. Your IP address, your browser type, and any cookies our scheduling provider sets. Purpose: load the booking tool, once you press the button that opens it. This is not the same as booking a call: it covers opening the tool and then changing your mind. Nothing is sent to that company, and no cookie is set, unless you press the button. Cookies and analytics sets out exactly what appears when you do.

We collect only what we need for these purposes. We do not ask you for anything else, and the Site has no forms of its own.

How we use your information

We use Personal Information only for the purposes listed in What we collect and why. If we want to use it for a new purpose, we will tell you what that purpose is and ask for your consent before we start. We disclose Personal Information only as described in Who we share it with.

We keep Personal Information as accurate, complete and up to date as its purposes require. Your access and correction rights explains how to have it corrected.

You give us consent through the action that provides the Personal Information: booking a call with us, or sending us an email.

Two things happen the moment you open any page. The provider that hosts the Site records the request, including your IP address, so that the page can be sent to you and kept secure, and you cannot turn that off. Every website works that way, and it is the one thing on this list that withdrawing consent cannot stop, because there is no way to send you a page without it. The second is our website analytics, which counts the page view. You can turn that one off, and Cookies and analytics says how. Beyond those two, nothing goes to another company and no cookie is set unless you press the button that opens the booking tool.

We do not send marketing email. We do not have a mailing list, and we do not add you to one when you contact us. If we ever start sending marketing messages, we will ask for your consent first, as Canada’s anti-spam law requires, and we will update this policy before we do.

You can withdraw any consent at any time, subject to legal and contractual restrictions and reasonable notice, by contacting our privacy officer (Privacy officer and complaints). If you withdraw consent, we may not be able to do the thing you asked us to do, such as hold a call you booked. How long we keep it identifies the records a legal or contractual restriction requires us to keep after withdrawal.

Who we share it with

We do not sell Personal Information. We share it only with the Service Providers below, under contract, and only the data each one needs for its role:

  • Cal.com, our scheduling provider, whose booking tool opens inside the page when you ask for it. Shared: your name, email, time zone, and anything you write when booking, and, because the tool then loads in your browser, your IP address and browser type from the moment you open it. Region: the United States.
  • Google, which hosts the calendar your booking is written into. Shared: your name, email, the time you chose, and anything you write in the booking notes. Region: the United States and other countries where Google operates.
  • Migadu, which hosts the email addresses we publish. Shared: your email address, your name if you give it, and whatever you write to us. Region: Switzerland and France.
  • Cloudflare, which hosts the Site, provides its network edge and security, and provides our website analytics. Shared: your IP address, request metadata, and page-view details. Region: global edge network.

That is the list of companies we give your information to directly, and it is short because the Site does very little. Some of them use their own providers to run their services, and the booking scheduler is one: its booking tool reports its own errors to Sentry, an error-tracking service in the United States, which Cookies and analytics explains. Our analytics comes from Cloudflare, which is already on the list above because it hosts the Site. We use no advertising network, no customer relationship system, and no email marketing platform.

We may also disclose Personal Information where a law, court order, or other lawful authority requires us to.

Where your information is processed

Some Service Providers process or store Personal Information outside Canada:

  • Cal.com, scheduling. United States.
  • Google, calendar. United States and other countries where Google operates.
  • Migadu, email hosting. Switzerland and France.
  • Cloudflare, hosting, network edge, and website analytics. Global.

One of these providers brings another with it. When you open the booking tool, it reports its own errors to Sentry, an error-tracking service in the United States. That is Cal.com’s arrangement rather than ours, and we cannot switch it off, which is why the booking tool now waits for you to open it.

While your Personal Information is in another country, it is subject to the laws of that jurisdiction and may be accessible to the courts, law enforcement and national security authorities there. We remain accountable for it. We use each of these providers under the terms and privacy commitments they publish, and we chose them partly on that basis. We have not negotiated separate data-protection agreements with them, and we do not control how they run their own services.

Cookies and analytics

We use a small number of cookies and similar technologies. This is the complete list:

  • Cookies set by our booking scheduler, Cal.com, and only if you open it. The booking tool sits behind a button: nothing is asked of Cal.com, and none of these cookies are set, until you press it. Once you do, as at 13 August 2026 they are: __cf_bm, which Cal.com’s network uses to tell real visitors from bots; and __Secure-next-auth.csrf-token and __Secure-next-auth.callback-url, which the scheduler uses to keep its own booking form working safely. These are Cal.com’s cookies, set on Cal.com’s domain, and they are governed by Cal.com’s privacy policy, not this one. Opening the tool also lets it report its own errors to Sentry, an error-tracking service in the United States that Cal.com chose and we do not control.
  • Website analytics, from Cloudflare, the company that also hosts this site. It runs on every page and it does not use cookies. It counts page views and records the page you were on, the site you came from, the country you are in, your browser and operating system, and how quickly the page loaded. It does not follow you to other websites, it does not build a profile of you, and it stores nothing in your browser. We use it to see which pages are worth keeping and which are not.
  • You can turn the analytics off. There is a button on this page, under Your analytics choice, and it takes effect on the next page you open. Turning it off saves one small preference in your browser so we remember your choice on this device, and that preference is the only thing this site stores in your browser. Nothing else you do here is remembered.
  • Nothing else. We run no advertising pixels, no session or screen recording, and no cross-site tracking of any kind. If you never open the booking tool, the analytics described above is the only thing running, and this site sets no cookies at all. Our fonts are served from our own site rather than a third party.

We do not show a cookie consent banner; this section is our complete cookies disclosure.

Analytics is not necessary to show you this Site, so you have a choice about it. Under Your analytics choice on this page there is a button that turns it off, and your choice is remembered on the device you set it on. The analytics itself sets no cookie, and we do not ask you to accept anything before you read the Site.

One of these companies, our booking scheduler, is not somewhere we send you: its booking tool opens inside our page. It stays dormant until you press the button to open it, and only then does your browser load it from that company and take its cookies. Anything we merely link you to is different again: it runs on its own site, with its own cookies and its own privacy policy, and when you go there you are dealing with that company.

Information we handle for our clients

Information we handle for our clients. This policy is about information we collect through our website. We also handle information that belongs to our clients, and that is different, so we set it out here plainly.

When we deliver services, an Operations Blueprint, a build, or a managed AI agent we operate, we handle information belonging to the client organization, which can include Personal Information about that organization’s own staff and customers. In that work we act for the client and under the client’s instructions.

Who is accountable for what. For that work, the client organization decides what is collected and why, and we act on its instructions. The client remains accountable to the people its information is about. We remain accountable for handling it properly, and we cannot contract out of that.

What governs it. That handling is governed by the signed client service agreement and its statement of work, not this website policy. That agreement, not this policy, sets out what we may do with the information, how long we keep it, how it is protected, who else may process it, and what happens to it when the engagement ends.

Third parties in delivery. Some services we operate for clients rely on third-party providers that process information as part of doing the work. Third-party model providers act as sub-processors when a managed agent runs. They are disclosed and kept current per engagement under the service agreement.

If your information was given to us by an organization we work for, we are not the right first contact. Ask that organization, because it holds the relationship with you and decides how its information is handled. If you cannot reach them, contact our privacy officer (Privacy officer and complaints) and we will help you get to the right place.

How long we keep it

We keep Personal Information only as long as its purpose, or a legal requirement, needs it, and then we delete it:

  • Booking records and email enquiries: 24 months after we last hear from you, then deleted.
  • Site visit records: we do not keep server request logs. Our hosting provider processes each request in order to serve and secure the Site, and we have not turned on any request logging.
  • Website analytics: we do not keep these records ourselves. Our analytics provider holds the page-view measurements, and we cannot set how long it keeps them.
  • Email server logs held by our email provider: at most 30 days. Those logs record sender and recipient addresses and the time of connection, but not your IP address.
  • Records held by the scheduler for someone who opens the booking tool without booking: If you open the booking tool but do not book, anything the scheduler keeps is held under its own policy, not ours. We do not receive those records and we cannot set how long they are kept.
  • Information we handle for a client: for as long as that client’s agreement says, not on the schedule above.

How we protect it

We protect Personal Information with safeguards appropriate to its sensitivity: the Site is served over an encrypted connection, it has no database and no accounts, it carries a policy that allows scripts and network connections only from our own site, from the booking scheduler, and from our analytics provider, and blocks everything else on our own pages, it stops the Site being framed by another site, it sends only our origin, not the full address of the page you were on, when you follow a link away from the Site, and the booking tool runs inside a window belonging to the scheduler that our settings cannot reach, with Cookies and analytics setting out what it loads. Because the Site collects so little, there is very little held about you in the first place.

No system is perfectly secure, and we do not promise that. We notify you and the regulator when the law requires it (If there is a breach).

Your access and correction rights

You can ask us:

  • what Personal Information we hold about you, how we use it, and who we have shared it with. We will give you access to it;
  • to correct it if it is inaccurate or incomplete; and
  • to delete it. We will delete what we are not required to keep.

To exercise any of these, contact our privacy officer (Privacy officer and complaints). We may need to verify your identity first, and we will respond within the time PIPEDA allows.

If the information you are asking about was given to us by an organization we work for, see Information we handle for our clients for who to ask first.

Privacy officer and complaints

Privacy officer and complaints. The Privacy Officer, CoMotion Solutions Agency Inc. is accountable for how CoMotion Solutions Agency Inc. handles Personal Information. We will tell you who currently holds that role if you ask. Reach them at:

If you have a complaint about our handling of your Personal Information, contact our privacy officer first. We investigate every complaint and tell you what we found and what we changed. If you are not satisfied with our response, you can complain in writing to the Office of the Privacy Commissioner of Canada (priv.gc.ca), which oversees PIPEDA.

If there is a breach

If a breach of our security safeguards creates a real risk of significant harm to you, we will notify you, and report to the Office of the Privacy Commissioner of Canada, as soon as feasible after we determine the breach occurred. We also notify any other organization or government institution that can reduce the risk of harm, and we keep a record of every breach of security safeguards, whatever its size, for at least 24 months.

Changes to this policy

When we change this policy, we post the new version at comotion.solutions/privacy and update the “Last updated” date at the top. If a change expands what we collect or how we use it, we will tell you before it takes effect, by posting a notice on the Site (we have no mailing list, so we cannot email you), and, where the change needs your consent, we will ask for it.