1. Introduction
Black Dog Cannabis Inc. respects the privacy of every person who visits its website, requests information, or engages its professional services. The developer group known as BudsterFarm maintains the engineering methods and internal tooling used by the company, and this policy explains how the company handles personal information across all of those activities. The company is a computer systems design and integration practice working from Ottawa, Canada, and it serves clients who depend on confidentiality in the course of their own professional work.
This document describes the categories of information the company collects, the reasons it collects them, the ways it protects them, and the choices available to the people whose information it holds. It applies to the website at budsterfarm.mom and to the services the company provides. The company has written this policy in plain language so that a reader does not need legal training to understand it. Where a term has a specific meaning, the company explains that meaning in the section where the term first appears.
The company treats privacy as an engineering requirement rather than an afterthought. Just as a machine room is designed with defined limits, guards and inspection records, the company designs its information handling with clear boundaries, documented purposes and regular review. This policy is part of that discipline.
2. Who We Are
The organisation responsible for the personal information described in this policy is Black Dog Cannabis Inc., with its office at 1135 Plante Dr, Ottawa - K1V 9E5, Canada (CA). The company can be reached by email at text@budsterfarm.mom or by telephone at +17792853074. The website address is https://www.budsterfarm.mom.
The developer name BudsterFarm identifies the internal engineering group that builds and maintains the systems, tools and websites used by Black Dog Cannabis Inc. When this policy refers to the company, it means Black Dog Cannabis Inc. When it refers to the developer, it means BudsterFarm and the engineering team operating under that name. Both work under the same privacy standards, and both are accountable to the contact point above.
The company contracts with clients directly. In most engagements the client is the organisation that decides why personal information is processed, and the company acts on that organisation instruction as a service provider. In those cases the client remains the primary point of contact for the individuals whose information is involved, and the company supports the client in meeting its obligations.
3. Scope of This Policy
This policy covers personal information that Black Dog Cannabis Inc. collects through its website, through direct communications with prospective and current clients, through the delivery of its professional services, and through the ordinary operation of its business. It covers information collected in electronic form and in paper records, and it covers information held by the company itself as well as information held by service providers acting on the company behalf.
This policy does not cover the privacy practices of other organisations, including clients of the company, third party platforms that a client may operate, or external websites that a reader may reach from a link on the company site. When the company processes personal information on behalf of a client, the client privacy policy and the client instructions govern that processing, and this policy applies to the company own safeguards and internal practices.
Some services may be accompanied by additional privacy notices that describe specific handling for a particular engagement. Where such a notice conflicts with this policy, the more specific notice applies to the extent of the conflict.
4. Information We Collect
The company collects information that is necessary to respond to enquiries, deliver services, operate its business and meet its legal obligations. The categories of information are described below.
Information provided directly
- Identity and contact details such as a name, an email address, a telephone number, a job title and an organisation name.
- The content of messages sent through the contact form, by email or by telephone, including any files, diagrams or screenshots the sender chooses to provide.
- Contract and billing details for clients, such as a business address, purchase order references and invoicing contacts.
- Information shared during a project, such as system descriptions, access requests, meeting notes and approvals.
Information collected automatically
- Technical data such as an internet protocol address, browser type, device type, operating system and the pages visited on the company site.
- Approximate location derived from an internet protocol address, at the level of a city or region.
- Records of how a visitor reached the site, such as a referring link, where that information is available.
- Server logs that record requests for pages and resources, used for security and reliability.
Information from third parties
- Business contact details obtained from a professional referral, a public directory or a conference list, where the company has a legitimate reason to make contact.
- Credit or verification information for a client account, obtained from a recognised reference or repository, where applicable.
- Information supplied by a client about that client own customers or staff, where the company needs it to deliver an agreed service.
The company does not intentionally collect sensitive categories of personal information through its website, and it asks visitors not to submit such information through the contact form.
5. How We Collect Information
Most information reaches the company in one of four ways. First, a person provides it directly, for example by completing the contact form, sending an email, placing a call or signing a service agreement. Second, the company collects technical information automatically as the website serves pages to a browser. Third, a client or a colleague provides information about a person as part of a project, for instance when adding a colleague to a support request. Fourth, the company obtains business contact details from referrals or public sources.
The company does not purchase personal information from data brokers, and it does not use hidden tracking methods to build a profile of a visitor. Where the website uses measurement tools, those tools are described in the cookies section of this policy.
6. Legal Bases for Processing
Where the law requires a legal basis for processing personal information, the company relies on one or more of the following foundations. Consent applies where a person has clearly agreed to a specific use, such as subscribing to a business update. Contract applies where processing is needed to take a step requested by a person or to perform an agreement with a client. Legal obligation applies where a law or a regulator requires the company to keep or disclose information. Legitimate interests apply where the company has a genuine business reason that does not override the rights of the individual, such as protecting the site against abuse or responding to a sincere business enquiry.
Where consent is the basis, a person may withdraw it at any time by contacting the company. Withdrawal does not affect processing that already took place lawfully, and it does not affect processing that rests on another basis.
7. How We Use Information
Black Dog Cannabis Inc. uses personal information for the following purposes, and it limits each use to what is necessary for that purpose.
- To respond to enquiries and provide the information or quotation that a person has requested.
- To plan, deliver, support and review the professional services described on the services page.
- To manage client relationships, including scheduling quarterly system reviews and handling support requests.
- To issue invoices, manage accounts and keep accurate business records.
- To protect the website, the company systems and the company clients against fraud, abuse and security threats.
- To meet legal, tax, insurance and regulatory obligations.
- To improve the website and the company services by understanding how visitors use the site in aggregate.
- To send business communications where a person has asked to receive them or where the company has a permitted reason to make contact.
The company does not sell personal information, and it does not rent personal information to any third party for that third party own marketing.
8. Client Data and Service Delivery
Many of the company services involve working with systems that belong to a client and may contain personal information of the client staff, customers or partners. In those situations the client decides the purpose of the processing and the company acts on the client documented instructions. The company accesses client data only to the extent needed to perform the agreed work, and it applies the access controls, logging and confidentiality commitments described in the relevant service agreement.
The company keeps client environments separated from one another and from the company own internal systems. Where an engineer requires access to a client system, that access is granted for a defined task and a defined period, and it is reviewed afterwards. The company does not use client data for its own marketing or for any purpose unrelated to the engagement.
When an engagement ends, the company returns or deletes client data according to the terms of the agreement and the retention rules described later in this policy. The company asks clients to ensure that they have a lawful basis for any personal information they ask the company to process.
11. Service Providers and Subprocessors
The company uses a small number of external providers to operate its business and deliver its services. These providers may include web hosting, cloud infrastructure, email transmission, data backup, accounting and customer records systems. Before engaging a provider that will handle personal information, the company reviews the provider security posture and enters a written agreement that requires confidentiality, appropriate safeguards and a clear limit on the use of the information.
A client that has specific requirements about where data may be stored or which providers may be used can raise those requirements at the start of an engagement. Where the company uses a subcontractor for a client project, the company remains responsible for the subcontractor work and informs the client as required by the applicable agreement.
A current list of the categories of service providers is available on request from the contact point in this policy.
12. International Transfers
The company is based in Canada and generally stores its records in Canada. Some providers used by the company may process information in other countries, particularly where cloud infrastructure is involved in a client project. When personal information is transferred across a border, the company takes steps to ensure that the information continues to receive a comparable level of protection, whether through contractual commitments, provider safeguards or the law of the receiving country.
A person who wishes to know whether their information may be processed outside Canada can contact the company and receive an explanation of the relevant arrangements. Where a client engagement requires information to remain in a particular jurisdiction, the company plans the architecture accordingly and documents that choice.
13. Data Retention
The company keeps personal information only for as long as it is needed for the purpose for which it was collected, for a related legitimate purpose, or to satisfy a legal, tax or contractual requirement. Retention periods vary with the type of record. Business enquiries that do not lead to an engagement are normally kept for a modest period so that a follow up conversation remains possible, and are then removed. Client contract and billing records are kept for the period required by tax and business law. Support and project records are kept for the life of the client relationship and for a reasonable period afterwards to allow continuity of service.
When a retention period ends, the company deletes the information or renders it anonymous so that it can no longer be linked to an individual. Where deletion is not immediately possible, for example because information sits in a protected backup, the company isolates the information and removes it when the backup cycle allows.
14. Security Measures
Black Dog Cannabis Inc. applies administrative, technical and physical safeguards to protect personal information against loss, misuse and unauthorised access. These safeguards reflect the sensitivity of the information and the risk of harm that could follow a breach.
- Access to systems is limited to personnel who need it for a defined task, and access is reviewed periodically.
- Authentication uses strong credentials and, where available, additional verification for remote access and administrative functions.
- Information in transit is protected with encryption, and sensitive information at rest is encrypted where the platform supports it.
- Systems are patched on a scheduled cycle, and changes are tested before they reach a production environment.
- Backups are taken regularly and restore procedures are tested, because a backup that has never been restored is not yet a safeguard.
- Personnel are bound by confidentiality obligations and receive privacy and security training appropriate to their role.
- Incidents are logged, investigated and reviewed so that lessons are turned into concrete improvements.
No security programme can promise absolute protection. The company therefore focuses on reducing likelihood, limiting impact and responding quickly, and it reviews its safeguards each quarter alongside its client system reviews.
15. Your Privacy Rights
Subject to applicable law, a person may exercise the following rights in relation to personal information held by the company. The company responds to a verified request within the period required by law and does not charge a fee unless the request is manifestly unfounded or repetitive.
- Access: to learn whether the company holds personal information about you and to receive a copy of it.
- Correction: to ask that inaccurate or incomplete information be corrected.
- Deletion: to ask that information be deleted where there is no remaining lawful reason to keep it.
- Restriction: to ask that processing be limited while a concern is examined.
- Objection: to object to processing that rests on legitimate interests or on direct marketing.
- Portability: to receive information in a structured, commonly used format where the law provides that right.
- Withdrawal of consent: to withdraw consent at any time where consent is the basis for processing.
To exercise a right, contact the company using the details in the final section of this policy. The company may ask for information that confirms identity before acting, so that one person cannot obtain another person records. Where a request concerns information that the company holds on behalf of a client, the company will refer the request to that client, which decides how the request should be handled.
16. Privacy for Children
The services of Black Dog Cannabis Inc. are intended for organisations and for adults acting in a professional capacity. The website is not directed to children, and the company does not knowingly collect personal information from a child. If the company learns that it has collected such information without appropriate consent, it will take reasonable steps to delete it promptly. A parent or guardian who believes that a child has provided personal information to the company is encouraged to contact the company so that the matter can be resolved.
Where a client engagement happens to involve information about young people, the client is responsible for obtaining any consent required and for giving the company lawful instructions about that information.
17. Marketing and Communications
The company may send business communications such as service updates, invitations to a review session or a seasonal notice about the quarterly review programme. These communications are sent where a person has asked to receive them or where the company has a permitted reason to contact a business contact. Every marketing message includes a simple way to opt out, and an opt out request is honoured promptly.
The company does not share contact details with advertising networks, and it does not sell a mailing list. Transactional and service communications, such as a response to a support request or an invoice notice, are not marketing and continue for as long as the relationship requires.
18. Third Party Links
The company website may link to resources operated by other organisations, for example a standards body, a software vendor or a professional association. The company does not control those sites and is not responsible for the way they handle personal information. A visitor who follows such a link should read the privacy notice of the destination site before providing any information.
Where the company embeds a third party tool in one of its own pages, the company selects the tool with care and limits the information the tool can access, but the tool provider may still set its own storage or collect technical data under its own policy.
19. Automated Decision Making
The company does not use personal information to make automated decisions that produce legal effects or similarly significant effects for an individual. Monitoring tools used to protect the website and the company systems may apply automated rules to detect abuse or a security event, but any decision that materially affects a person is reviewed by a human member of the team.
Where a client project involves analytics or automation that could affect individuals, the company works within the client instructions, documents the logic at an appropriate level and supports the client in providing any explanation that the law requires. The company does not build systems whose behaviour cannot be explained to the people affected by them.
20. Breach Notification
The company maintains a documented procedure for responding to a suspected or confirmed breach of personal information. The procedure covers containment, assessment, notification and remediation. When an incident occurs, the company acts first to stop the loss, then determines what information was involved, what harm could result and who needs to be told.
Where the law requires notification to a regulator or to affected individuals, the company provides that notice without undue delay and includes the information those parties need to protect themselves. Where the company is acting for a client, the company notifies the client promptly so that the client can meet its own notification duties. After every significant incident the company produces a review that records the cause, the response and the changes made to prevent recurrence.
21. Changes to This Policy
The company reviews this policy regularly and updates it when its practices, its services or the law change. When an update is material, the company changes the effective date at the top of the page and, where appropriate, provides additional notice on the website or by direct communication to active clients. Continued use of the website after an update indicates acceptance of the revised policy for future interactions.
The company keeps earlier versions of this policy so that a person can understand how practices have evolved. A request for a previous version can be made through the contact point below.
22. How to Contact Us
Questions, requests and concerns about this policy or about the handling of personal information should be directed to Black Dog Cannabis Inc. using the details below. The company aims to acknowledge a privacy enquiry within one business day and to resolve it as quickly as the circumstances allow.
Black Dog Cannabis Inc.
1135 Plante Dr, Ottawa - K1V 9E5, Canada (CA)
Email: text@budsterfarm.mom
Phone: +17792853074
Website: https://www.budsterfarm.mom
A person who is not satisfied with the company response may have the right to complain to the privacy regulator in the relevant jurisdiction. The company will cooperate fully with any such review.