NoGrid Generator Services Legal
NoGrid Services Privacy Policy
Effective date: 2026-06-23 ยท Privacy
# NoGrid Services Privacy Policy
Effective date: 2026-06-23
This Privacy Policy explains how NoGrid Services ("NoGrid", "we", "us", or
"our"), a Nova Scotia, Canada service provider, collects, uses, discloses,
protects, and retains personal information when we provide generator
monitoring, connectivity, portal access, device management, support, and
related services (the "Services").
This policy applies to clients, client personnel, authorized users, site
contacts, and other individuals whose information is handled through the
Services in Nova Scotia, elsewhere in Canada, or where the Services otherwise
apply. If a signed service agreement, order form, data processing agreement, or
similar contract applies to a client account, that agreement also applies.
NoGrid's privacy practices are intended to align with Canadian private-sector
privacy requirements, including the Personal Information Protection and
Electronic Documents Act (PIPEDA), and with applicable Nova Scotia laws,
contracts, and service obligations. Some Nova Scotia public bodies,
municipalities, health custodians, or regulated clients may have additional
privacy, access, records, residency, procurement, or breach-response
requirements. Those requirements should be addressed in the applicable client
agreement before the Services are used for that client data.
## 1. Information We Collect
We collect only the information reasonably needed to provide, secure, support,
bill for, and improve the Services.
### Account and contact information
We may collect names, business names, job titles, email addresses, phone
numbers, mailing addresses, billing contacts, account roles, authorization
records, and communication preferences.
### Service and device information
We may collect information about generators, monitored equipment, EdgeBox or
other gateway devices, cellular or network configuration, firmware versions,
device identifiers, device status, connectivity state, telemetry, event logs,
alerts, support notes, and service history.
Device and generator data may include site names, approximate or precise site
locations, equipment identifiers, operational status, runtime, voltage,
temperature, network signal quality, SIM or modem identifiers, and other
diagnostic information needed to monitor and support the Services.
### Portal and authentication information
When users access the portal, we may collect login events, session information,
IP addresses, browser or device information, role and permission records, audit
logs, and security events. We may use an identity provider or authentication
service to manage sign-in.
### Support and communications
We may collect information submitted through email, phone calls, support
requests, onboarding forms, service tickets, field notes, or other client
communications.
### Payment and billing information
We may collect billing details, invoices, payment status, tax information, and
related account records. If a third-party payment processor is used, payment
card or bank information may be collected and processed by that provider under
its own terms and privacy practices.
## 2. How We Use Information
We use personal information for the following purposes:
- providing, operating, and maintaining the Services;
- creating and managing client accounts and authorized users;
- monitoring generator, device, and connectivity status;
- delivering alerts, reports, service notifications, and support responses;
- provisioning, updating, securing, and troubleshooting devices;
- performing billing, account administration, and contract management;
- preventing misuse, unauthorized access, fraud, service abuse, or unsafe
operation;
- maintaining audit logs and operational records;
- complying with legal, regulatory, insurance, tax, accounting, or safety
obligations;
- improving service reliability, security, and support processes.
We do not sell personal information. We do not use client generator telemetry
for unrelated advertising or third-party marketing.
## 3. Consent and Client Authority
By using the Services, clients confirm that they have the authority to provide
personal information and site, equipment, or operational information to NoGrid
for the purposes described in this policy.
Clients are responsible for ensuring that their authorized users, employees,
contractors, site owners, tenants, and other affected individuals receive any
required notices and provide any required consents before their information is
submitted to or processed through the Services.
Where consent is required, it may be express or implied depending on the
context and the sensitivity of the information. Individuals may withdraw consent
where permitted by law, subject to contractual, legal, technical, safety, or
service limitations.
## 4. Information Sharing
We may share information only as reasonably required for the purposes described
in this policy, including with:
- authorized client administrators and users;
- NoGrid personnel, contractors, and service providers who need access to
operate or support the Services;
- hosting, database, authentication, email, SMS, connectivity, monitoring,
payment, accounting, and support providers;
- equipment vendors, installers, maintainers, or field-service partners when
needed to support a client site or device;
- insurers, professional advisors, auditors, or legal representatives;
- government, law enforcement, regulatory, or emergency authorities where
required or permitted by law;
- another organization in connection with a merger, financing, sale,
restructuring, or transfer of all or part of the business, subject to
appropriate confidentiality protections.
Service providers are expected to use information only for the services they
provide to us or to the client, and to protect it using appropriate safeguards.
## 5. Cross-Border Processing
NoGrid is based in Nova Scotia, Canada. Information may be stored or processed
in Canada or in other jurisdictions where NoGrid, its clients, or its service
providers operate. Information processed in another jurisdiction may be
accessible to courts, law enforcement, or regulators in that jurisdiction.
If a Nova Scotia client requires Canada-only storage, Canada-only access, public
body handling requirements, or other data-residency controls, those requirements
must be stated in the applicable written agreement before the Services are used
for that data.
## 6. Retention
We retain personal information and operational records only as long as
reasonably required for the purposes described in this policy, unless a longer
period is required or permitted by law, contract, warranty, insurance, safety,
tax, accounting, audit, dispute-resolution, or backup obligations.
Telemetry, audit logs, security logs, and support records may be retained for
different periods depending on service configuration, client contract terms, and
operational need. Where practical, information that is no longer needed will be
deleted, anonymized, aggregated, or isolated from active use.
## 7. Safeguards
We use administrative, technical, and physical safeguards appropriate to the
sensitivity of the information, which may include access controls, role-based
permissions, authentication controls, encryption in transit where supported,
logging, backups, network segmentation, device authorization, and operational
security procedures.
No system is perfectly secure. Clients are responsible for protecting their own
accounts, credentials, local networks, devices, and authorized-user access.
Clients must notify NoGrid promptly if they suspect unauthorized access,
credential compromise, device tampering, or a security incident affecting the
Services.
## 8. Cookies and Similar Technologies
The portal may use cookies or similar technologies that are necessary for login,
session management, security, CSRF protection, user preferences, and basic site
operation. We do not use these technologies for third-party behavioural
advertising unless a separate notice and consent process is provided.
## 9. Access, Correction, and Privacy Requests
Individuals may request access to personal information we hold about them, ask
for corrections, or ask questions about our privacy practices. We may need to
verify identity and account authority before responding.
Some information may not be released or changed if doing so would reveal
another person's information, compromise security, interfere with an
investigation, conflict with legal or contractual obligations, or be otherwise
restricted by law.
Privacy requests should be sent to:
NoGrid Services Privacy Contact
Email: privacy@nogrid.ca
Mailing address: [insert legal mailing address]
## 10. Incident Response
If we determine that a privacy or security incident creates a real risk of
significant harm to an individual, we will take steps required by applicable
Canadian and Nova Scotia law, which may include notifying affected individuals,
clients, regulators, or other parties as appropriate.
## 11. Children
The Services are intended for business, operational, and site-management use.
They are not directed to children, and children should not create portal
accounts or submit personal information through the Services.
## 12. Changes to This Policy
We may update this Privacy Policy from time to time. The updated policy will be
posted with a new effective date. If we make material changes that require
additional notice or consent, we will provide notice as required by applicable
law or contract.
## 13. Contact
Questions about this Privacy Policy or NoGrid's privacy practices can be sent
to privacy@nogrid.ca or to the mailing address listed above.