Privacy Policy

Effective Date: October 2, 2025
Last Updated: October 2, 2025

Introduction

Spearstone Inc. and it subsidiary IAXOV Inc. ("Spearstone", "IAXOV," "we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard information collected through the phone, web, or other interfaces and related services.

1. Information We Collect

1.1 Information You Provide

We collect information you voluntarily provide when you:

  • Request a Demo: Name, email address, phone number, company name, company size, industry, role, and optional message
  • Download Resources: Name, email address, company name, and role
  • Contact Us: Name, email address, company, subject, and message content
  • Subscribe to Newsletter: Email address
  • SMS Messaging Consent: Spearstone and its subsidiaries will collect your explicit consent for SMS messaging including the explicit purposes in which you authorize us to contact you using SMS services.

1.2 Automatically Collected Information

When you visit our website, we automatically collect:

  • Usage Data: Pages visited, time spent, click patterns, scroll depth
  • Device Information: Browser type, operating system, device type, screen resolution
  • Log Data: IP address, access times, referrer URLs, error logs
  • Analytics Data: Session recordings, heatmaps, conversion events (via PostHog)

1.3 Information from Third Parties

We may receive information about you from third-party services if you connect your account (e.g., LinkedIn for profile enrichment) or if you arrive at our site through marketing campaigns.

2. How We Use Your Information

We use collected information for:

  • Service Delivery: Responding to demo requests, providing requested content, delivering newsletters
  • Communication: Sending follow-up information, product updates, and relevant research
  • Analytics: Understanding website usage, improving user experience, optimizing conversion rates
  • Marketing: Delivering targeted content, measuring campaign effectiveness, lead qualification
  • Compliance: Meeting legal obligations, enforcing terms, protecting rights and safety
  • Development: Improving our website, developing new features, testing functionality
  • SMS Messaging: Spearstone and its subsidiaries will never contact you via SMS messaging for marketing purposes. Additionally, we will only contact for you for purposes which you have explicitly granted us consent to do so. Example purposes are for identity security, password reset confirmation, and alerts, all of which you must to explicitly consent to individually.

3. Data Sharing and Disclosure

3.1 We Share Information With:

  • Service Providers: PostHog (analytics), email service providers, CRM systems, hosting providers
  • Business Partners: Only with your explicit consent for partnership opportunities
  • Legal Requirements: When required by law, court order, or government request
  • Business Transfers: In connection with merger, acquisition, or asset sale (with notice)

3.2 We Do NOT:

  • Sell your personal information to third parties
  • Share your information for third-party marketing without consent
  • Use your data for purposes unrelated to Spearstone or its subsidiaries services

4. Data Sovereignty and Security

4.1 Data Storage

Marketing website data is stored on secure servers with encryption at rest (AES-256) and in transit (TLS 1.3). Data location depends on deployment region and can be configured for specific geographic requirements.

4.2 Security Measures

  • Multi-factor authentication for administrative access
  • Regular security audits and penetration testing
  • Automated vulnerability scanning and patching
  • Encryption of all sensitive data (at rest and in transit)
  • Access controls with principle of least privilege
  • Comprehensive audit logging of all data access

4.3 Data Retention

We retain your information for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by law. Marketing contacts: 7 years. Analytics data: 2 years. You may request deletion at any time (see Your Privacy Rights below).

5. Your Privacy Rights

5.1 Rights Under GDPR (EU/UK Users)

  • Right to Access: Request copies of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restriction: Limit how we use your data
  • Right to Data Portability: Receive your data in a structured format
  • Right to Object: Object to processing for marketing purposes
  • Rights Related to Automated Decision-Making: Opt-out of automated processing

5.2 Rights Under CCPA (California Users)

  • Right to Know: What personal information we collect and how it's used
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt-out of sale of personal information (we don't sell data)
  • Right to Non-Discrimination: Equal service regardless of privacy choices

5.3 Rights Under PIPEDA (Canadian Users)

  • Right to Access: Access your personal information we hold
  • Right to Challenge: Challenge the accuracy and completeness of your information
  • Right to Withdraw Consent: Withdraw consent at any time

5.4 Exercising Your Rights

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. To protect your privacy, we may need to verify your identity before fulfilling your request.

6. Cookies and Tracking Technologies

6.1 Cookies We Use

  • Essential Cookies: Required for website functionality (session management, security)
  • Analytics Cookies: PostHog for usage analytics and user behavior tracking
  • Preference Cookies: Remember your settings and preferences

6.2 Managing Cookies

You can control cookies through your browser settings. Note that disabling cookies may limit website functionality. To opt-out of PostHog analytics, visit your browser's privacy settings.

7. International Data Transfers

Spearstone operates globally. If you access our website from outside Canada, your information may be transferred to, stored, and processed in Canada or other countries where our service providers operate.

We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses (SCCs) compliant with the European Commission for EU data transfers.

8. Children's Privacy

STRATEVITA marketing services are intended for business professionals and organizations. We do not knowingly collect personal information from individuals under 16 years of age. If you believe we have collected information from a minor, please contact us immediately at [email protected].

9. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify you of material changes by:

  • Posting the updated policy on this page with a new "Last Updated" date
  • Sending email notification to registered users
  • Displaying a prominent notice on our website

Your continued use of our services after such modifications constitutes acceptance of the updated policy.

10. Contact Information

Data Protection Officer

Email: [email protected]
Address:Spearstone Inc. C/O IAXOV, 330 5th Avenue SW, Suite 1800, Calgary, Alberta, T2P 0L4, Canada

General Inquiries

Email: [email protected]

Regulatory Authorities

If you are located in the EU/UK, you have the right to lodge a complaint with your local data protection authority. For Canadian residents, you may contact the Privacy Commissioner of Canada. California residents may contact the California Attorney General's office.