PRIVACY POLICY
Canadian-built. Canadian-operated. Fix First Security is operated by 1001549742 Ontario Inc., incorporated in Ontario, Canada. All personal information is collected and processed in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). Our privacy officer can be reached at info@fixfirstsecurity.com.
Who We Are
Fix First Security is an exposure validation platform operated by 1001549742 Ontario Inc., a corporation incorporated under the laws of Ontario, Canada. We are the "organization" responsible for the personal information you provide to us under PIPEDA. Our privacy officer can be reached at: info@fixfirstsecurity.com
Information We Collect
We collect the following categories of information: Account information: Your name, company name, email address, and role when you register. Scan targets: Domain names, IP addresses, URLs, and container images you submit for scanning. We do not access or store the internal content of your systems — only the security-relevant exposure data returned by our scanning tools. Scan results: Vulnerability findings, severity ratings, Fix First Scores, MITRE ATT&CK mappings, CISA KEV flags, and remediation recommendations generated from your submitted targets. Assessment answers: Responses to optional questionnaires about your security environment. Usage data: Log files, API calls, and feature usage to improve the service and detect abuse. Payment information: Processed by Stripe — we do not store your credit card numbers.
How We Use Your Information
We use your information to: • Provide and operate the Fix First Security scanning and reporting service • Generate vulnerability findings, Fix First Scores, and executive, technical, and compliance reports • Send alerts when CISA KEV or critical findings are detected on your targets • Process your subscription payments through Stripe • Respond to your support and sales requests • Improve our scanning engine, intelligence feeds, and report quality • Comply with legal obligations under Canadian law We do not sell your personal information or scan data to third parties. We do not use your vulnerability data for advertising purposes.
Scan Data and Confidentiality
Your scan targets and results are confidential. We treat all vulnerability findings, security posture data, and remediation information as sensitive business information. Scan data is accessible only to: (a) your authorized account users, (b) Fix First Security personnel for support and service improvement purposes, and (c) MSP partners if you are a client of a Managed Service Provider using our MSP portal. We do not share your scan results with third parties, government agencies, or other customers except as required by law.
Legal Basis for Processing
Under PIPEDA, we collect and use your personal information based on your consent, which you provide when you create an account and submit scan targets. You may withdraw consent at any time by cancelling your account. Withdrawal of consent will result in deletion of your data as described in Section 9.
Data Storage and Security
Your data is stored on servers operated by Hetzner Online GmbH in the United States under a data processing agreement that requires equivalent privacy protections to Canadian law. We protect your data using: • AES-256 encryption for sensitive credentials and tokens • TLS encryption for all data in transit • JWT authentication with expiring tokens • Role-based access controls • Regular security reviews of our own platform Fix First practices what it validates. Our platform undergoes the same exposure assessment we provide to customers.
Information Sharing
We share your information only with: Service providers: Hetzner (hosting), Stripe (payments), Resend (email) — each under data processing agreements requiring them to protect your data. Intelligence feeds: We query public threat intelligence APIs (CISA KEV, VirusTotal, AbuseIPDB, HIBP) with your submitted targets to enrich findings. These services receive only the target identifier — not your account information. MSP partners: If you are a client of a Managed Service Provider using our MSP portal, your scan results and findings are visible to your MSP under their client agreement. Legal requirements: We may disclose information if required by Canadian law, court order, or to protect the rights and safety of our users. We will never sell your data.
Your Rights Under PIPEDA
As a Canadian resident, you have the right to: Access: Request a copy of the personal information we hold about you. Correction: Ask us to correct inaccurate information. Withdrawal of consent: Stop us from using your personal information, subject to legal or contractual restrictions. Complaint: File a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca if you believe we have violated PIPEDA. To exercise these rights, email us at info@fixfirstsecurity.com. We will respond within 30 days.
Data Retention and Deletion
We retain your data for as long as your account is active. Specifically: Account and scan data: Retained while your subscription is active and for 30 days after cancellation. Scan results and findings: Retained for 24 months to allow you to track your security posture over time. Payment records: Retained for 7 years as required by Canadian tax law. Upon account deletion, we permanently delete your personal information within 30 days, except where retention is required by law. To request deletion of your data, email info@fixfirstsecurity.com.
Authorized Scanning Policy
Fix First Security is an authorized scanning platform. By submitting a target for scanning, you confirm that you have explicit authorization to scan that target — either as the owner or as an authorized representative. Submitting targets you do not have authorization to scan is a violation of these terms and may constitute a violation of applicable Canadian and international law. We maintain authorization records for all scans and cooperate with law enforcement investigations of unauthorized scanning activity.
Breach Notification
In the event of a breach of security safeguards involving your personal information that creates a real risk of significant harm, we will notify you and the Office of the Privacy Commissioner of Canada as required by PIPEDA. We maintain an incident response plan and will notify affected users as quickly as possible with information about what happened, what data was involved, and what steps we are taking.
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of material changes by email at least 14 days before they take effect. The current version is always available at fixfirstsecurity.com/privacy.html.
Contact Our Privacy Officer
For any privacy questions, requests, or concerns: Fix First Security 1001549742 Ontario Inc. Toronto, Ontario, Canada Email: info@fixfirstsecurity.com Phone: 647 848 0182 Office of the Privacy Commissioner of Canada www.priv.gc.ca · 1-800-282-1376
Privacy questions? Email us at info@fixfirstsecurity.com — we respond within 2 business days.