Privacy Policy
Global Assessment Corp. – Privacy Policy
Last Updated: October 30, 2025
1 Who We Are
Global Assessment Corp. is a Canadian company headquartered in Ontario, Canada. We provide raw-material pricing & trade-policy intelligence through downloadable reports and subscription services (the “Services”).
2 Scope of This Policy
This Policy explains how we collect, use, disclose, and protect “Personal Information” (information about an identifiable individual) when you:
- visit globassessment.com or related sub-domains (the “Site”);
- create an account, purchase, or download our reports;
- receive marketing or support communications; or
- interact with us on social media or at events.
3 Personal Information We Collect
Category | Examples | Source |
Account & Contact Data | name, job title, employer, email, phone | you provide |
Transaction Data | purchased products, invoice amounts, licence tier, VAT/GST number | you / payment processor |
Payment Data | last 4 digits of card, expiry, billing address (processed by [Stripe]—we never store full card numbers) | payment processor |
Usage Data | IP address, device ID, browser, pages viewed, clicks, download timestamps | cookies / analytics |
Marketing Preferences | newsletter opt-in/out, email open/click rates | you / email platform |
We do not intentionally collect data from children under 16. If you believe a minor has provided data, contact us so we can delete it.
4 How & Why We Use Personal Information
Purpose | Legal Basis (EU GDPR)* |
Process orders, deliver downloads, administer licences | Contractual necessity |
Authenticate log-ins, prevent fraud, maintain Site security | Legitimate interests |
Respond to enquiries or support tickets | Contractual necessity / legitimate interests |
Send service emails (e.g., download links, renewal notices) | Contractual necessity |
Send optional newsletters, product updates, or surveys | Consent (or CASL-compliant implied consent) |
Perform aggregated usage analytics to improve products | Legitimate interests |
Comply with tax, accounting, or legal obligations | Legal obligation |
* For residents of Canada, we rely on knowledge & consent under PIPEDA. For California users, these purposes correspond to “business purposes” under CCPA/CPRA.
5 Cookies & Similar Technologies
We use first- and third-party cookies and pixels to:
- remember session state;
- measure traffic and report performance;
- tailor marketing campaigns.
You can disable non-essential cookies via our Cookie Banner or browser settings. For more detail, see our separate Cookie Policy.
6 When We Share Personal Information
We disclose data only as needed:
- Service Providers – hosting, payment processing (Stripe Payments), email delivery, analytics.
- Professional Advisors – auditors, legal counsel.
- Authorities – if required by law or to protect rights, property, or safety.
- Corporate Transactions – in connection with a merger, acquisition, or asset sale (notice will be provided).
All vendors are bound by confidentiality and security obligations; vendors outside Canada/EU rely on Standard Contractual Clauses or equivalent safeguards for cross-border transfers.
7 International Transfers
Our primary servers are in Canada; some vendors (e.g. Stripe) operate globally. When we transfer data to jurisdictions that may have different privacy laws, we protect it as described in Section 6 and enter into appropriate data-transfer agreements.
8 How Long We Keep Data
We retain Personal Information only as long as necessary:
- Transaction records: 7 years (tax & audit).
- Marketing data: until you unsubscribe or after 24 months of inactivity.
- Analytics logs: 26 months or sooner if technically feasible.
- Support tickets: 3 years after closure.
We securely delete or anonymize data once retention limits expire.
9 Security Measures
We employ administrative, technical, and physical safeguards, including:
- TLS encryption in transit;
- Encryption at rest on database volumes;
- Least-privilege access controls & MFA for staff;
- Quarterly vulnerability scans and annual penetration tests.
No system is perfect; if a breach creates a real risk of significant harm, we will notify affected individuals and regulators as required by PIPEDA’s breach-notification rules.
10 Your Rights
Jurisdiction | Key Rights & How to Exercise |
Canada (PIPEDA) | Access, rectification, withdrawal of consent. Email [email protected] |
EU/EEA/UK (GDPR) | Access, rectification, erasure, restrict processing, data portability, object to processing, lodge complaint with supervisory authority. |
California (CCPA/CPRA) | Know, delete, correct, opt-out of “sale”/“sharing” of personal info, limit use of sensitive info, no retaliation. +1-[613-896-2175]. |
We will authenticate requests and respond within one month (GDPR) or 45 days (CCPA). Some rights may be limited by law (e.g., we can’t delete invoices we must keep for tax).
11 Marketing Communications
We send commercial emails only with express or implied consent under Canada’s Anti-Spam Law (CASL). You can unsubscribe at any time via the footer link or by emailing [email protected]
12 Third-Party Sites & Social Media
Our Site may link to external sites (e.g., LinkedIn). We are not responsible for their privacy practices. Review their policies before providing data.
13 Changes to This Policy
We will post any changes on this page with a new “Last Updated” date. Material changes become effective 30 days after posting or upon your continued use of the Services—whichever comes first.
14 Contact & Complaints
Privacy Officer
Global Assessment Corp.
Ontario, Canada
Email: [email protected]
Phone: +1 (613) 896-2175
If you are dissatisfied, you may contact:
- Office of the Privacy Commissioner of Canada – www.priv.gc.ca
- Your local data-protection authority (EU/EEA/UK)
- California Privacy Protection Agency (for CCPA matters)