1. Introduction

Black Dog Cannabis Inc. respects the privacy of every person who visits its website, requests information, or engages its professional services. The developer group known as BudsterFarm maintains the engineering methods and internal tooling used by the company, and this policy explains how the company handles personal information across all of those activities. The company is a computer systems design and integration practice working from Ottawa, Canada, and it serves clients who depend on confidentiality in the course of their own professional work.

This document describes the categories of information the company collects, the reasons it collects them, the ways it protects them, and the choices available to the people whose information it holds. It applies to the website at budsterfarm.mom and to the services the company provides. The company has written this policy in plain language so that a reader does not need legal training to understand it. Where a term has a specific meaning, the company explains that meaning in the section where the term first appears.

The company treats privacy as an engineering requirement rather than an afterthought. Just as a machine room is designed with defined limits, guards and inspection records, the company designs its information handling with clear boundaries, documented purposes and regular review. This policy is part of that discipline.

2. Who We Are

The organisation responsible for the personal information described in this policy is Black Dog Cannabis Inc., with its office at 1135 Plante Dr, Ottawa - K1V 9E5, Canada (CA). The company can be reached by email at text@budsterfarm.mom or by telephone at +17792853074. The website address is https://www.budsterfarm.mom.

The developer name BudsterFarm identifies the internal engineering group that builds and maintains the systems, tools and websites used by Black Dog Cannabis Inc. When this policy refers to the company, it means Black Dog Cannabis Inc. When it refers to the developer, it means BudsterFarm and the engineering team operating under that name. Both work under the same privacy standards, and both are accountable to the contact point above.

The company contracts with clients directly. In most engagements the client is the organisation that decides why personal information is processed, and the company acts on that organisation instruction as a service provider. In those cases the client remains the primary point of contact for the individuals whose information is involved, and the company supports the client in meeting its obligations.

3. Scope of This Policy

This policy covers personal information that Black Dog Cannabis Inc. collects through its website, through direct communications with prospective and current clients, through the delivery of its professional services, and through the ordinary operation of its business. It covers information collected in electronic form and in paper records, and it covers information held by the company itself as well as information held by service providers acting on the company behalf.

This policy does not cover the privacy practices of other organisations, including clients of the company, third party platforms that a client may operate, or external websites that a reader may reach from a link on the company site. When the company processes personal information on behalf of a client, the client privacy policy and the client instructions govern that processing, and this policy applies to the company own safeguards and internal practices.

Some services may be accompanied by additional privacy notices that describe specific handling for a particular engagement. Where such a notice conflicts with this policy, the more specific notice applies to the extent of the conflict.

4. Information We Collect

The company collects information that is necessary to respond to enquiries, deliver services, operate its business and meet its legal obligations. The categories of information are described below.

Information provided directly

Information collected automatically

Information from third parties

The company does not intentionally collect sensitive categories of personal information through its website, and it asks visitors not to submit such information through the contact form.

5. How We Collect Information

Most information reaches the company in one of four ways. First, a person provides it directly, for example by completing the contact form, sending an email, placing a call or signing a service agreement. Second, the company collects technical information automatically as the website serves pages to a browser. Third, a client or a colleague provides information about a person as part of a project, for instance when adding a colleague to a support request. Fourth, the company obtains business contact details from referrals or public sources.

The company does not purchase personal information from data brokers, and it does not use hidden tracking methods to build a profile of a visitor. Where the website uses measurement tools, those tools are described in the cookies section of this policy.

7. How We Use Information

Black Dog Cannabis Inc. uses personal information for the following purposes, and it limits each use to what is necessary for that purpose.

The company does not sell personal information, and it does not rent personal information to any third party for that third party own marketing.

8. Client Data and Service Delivery

Many of the company services involve working with systems that belong to a client and may contain personal information of the client staff, customers or partners. In those situations the client decides the purpose of the processing and the company acts on the client documented instructions. The company accesses client data only to the extent needed to perform the agreed work, and it applies the access controls, logging and confidentiality commitments described in the relevant service agreement.

The company keeps client environments separated from one another and from the company own internal systems. Where an engineer requires access to a client system, that access is granted for a defined task and a defined period, and it is reviewed afterwards. The company does not use client data for its own marketing or for any purpose unrelated to the engagement.

When an engagement ends, the company returns or deletes client data according to the terms of the agreement and the retention rules described later in this policy. The company asks clients to ensure that they have a lawful basis for any personal information they ask the company to process.

9. Cookies and Similar Technologies

A cookie is a small file that a website asks a browser to store so that the site can recognise the browser on a later visit. The company website uses a minimal set of cookies and similar storage. Strictly necessary storage supports the basic operation and security of the site. Preference storage remembers a choice that a visitor has made so the site does not ask again. Measurement storage, where used, helps the company understand which pages are useful and where visitors encounter difficulty, and it is configured to avoid identifying an individual.

A visitor can control cookies through browser settings, including deleting existing cookies and blocking future ones. Blocking strictly necessary storage may cause parts of the site to stop working. Where the law requires consent before a non essential cookie is set, the company asks for that consent first and honours a refusal.

The website does not use cookies to serve behavioural advertising, and it does not permit third parties to use its cookies for advertising networks.

10. Sharing and Disclosure

Black Dog Cannabis Inc. shares personal information only in the limited circumstances described below, and it does not disclose personal information for money.

Where a disclosure is not required by law, the company uses contractual and technical measures to limit what is shared to the minimum necessary.

11. Service Providers and Subprocessors

The company uses a small number of external providers to operate its business and deliver its services. These providers may include web hosting, cloud infrastructure, email transmission, data backup, accounting and customer records systems. Before engaging a provider that will handle personal information, the company reviews the provider security posture and enters a written agreement that requires confidentiality, appropriate safeguards and a clear limit on the use of the information.

A client that has specific requirements about where data may be stored or which providers may be used can raise those requirements at the start of an engagement. Where the company uses a subcontractor for a client project, the company remains responsible for the subcontractor work and informs the client as required by the applicable agreement.

A current list of the categories of service providers is available on request from the contact point in this policy.

12. International Transfers

The company is based in Canada and generally stores its records in Canada. Some providers used by the company may process information in other countries, particularly where cloud infrastructure is involved in a client project. When personal information is transferred across a border, the company takes steps to ensure that the information continues to receive a comparable level of protection, whether through contractual commitments, provider safeguards or the law of the receiving country.

A person who wishes to know whether their information may be processed outside Canada can contact the company and receive an explanation of the relevant arrangements. Where a client engagement requires information to remain in a particular jurisdiction, the company plans the architecture accordingly and documents that choice.

13. Data Retention

The company keeps personal information only for as long as it is needed for the purpose for which it was collected, for a related legitimate purpose, or to satisfy a legal, tax or contractual requirement. Retention periods vary with the type of record. Business enquiries that do not lead to an engagement are normally kept for a modest period so that a follow up conversation remains possible, and are then removed. Client contract and billing records are kept for the period required by tax and business law. Support and project records are kept for the life of the client relationship and for a reasonable period afterwards to allow continuity of service.

When a retention period ends, the company deletes the information or renders it anonymous so that it can no longer be linked to an individual. Where deletion is not immediately possible, for example because information sits in a protected backup, the company isolates the information and removes it when the backup cycle allows.

14. Security Measures

Black Dog Cannabis Inc. applies administrative, technical and physical safeguards to protect personal information against loss, misuse and unauthorised access. These safeguards reflect the sensitivity of the information and the risk of harm that could follow a breach.

No security programme can promise absolute protection. The company therefore focuses on reducing likelihood, limiting impact and responding quickly, and it reviews its safeguards each quarter alongside its client system reviews.

15. Your Privacy Rights

Subject to applicable law, a person may exercise the following rights in relation to personal information held by the company. The company responds to a verified request within the period required by law and does not charge a fee unless the request is manifestly unfounded or repetitive.

To exercise a right, contact the company using the details in the final section of this policy. The company may ask for information that confirms identity before acting, so that one person cannot obtain another person records. Where a request concerns information that the company holds on behalf of a client, the company will refer the request to that client, which decides how the request should be handled.

16. Privacy for Children

The services of Black Dog Cannabis Inc. are intended for organisations and for adults acting in a professional capacity. The website is not directed to children, and the company does not knowingly collect personal information from a child. If the company learns that it has collected such information without appropriate consent, it will take reasonable steps to delete it promptly. A parent or guardian who believes that a child has provided personal information to the company is encouraged to contact the company so that the matter can be resolved.

Where a client engagement happens to involve information about young people, the client is responsible for obtaining any consent required and for giving the company lawful instructions about that information.

17. Marketing and Communications

The company may send business communications such as service updates, invitations to a review session or a seasonal notice about the quarterly review programme. These communications are sent where a person has asked to receive them or where the company has a permitted reason to contact a business contact. Every marketing message includes a simple way to opt out, and an opt out request is honoured promptly.

The company does not share contact details with advertising networks, and it does not sell a mailing list. Transactional and service communications, such as a response to a support request or an invoice notice, are not marketing and continue for as long as the relationship requires.

19. Automated Decision Making

The company does not use personal information to make automated decisions that produce legal effects or similarly significant effects for an individual. Monitoring tools used to protect the website and the company systems may apply automated rules to detect abuse or a security event, but any decision that materially affects a person is reviewed by a human member of the team.

Where a client project involves analytics or automation that could affect individuals, the company works within the client instructions, documents the logic at an appropriate level and supports the client in providing any explanation that the law requires. The company does not build systems whose behaviour cannot be explained to the people affected by them.

20. Breach Notification

The company maintains a documented procedure for responding to a suspected or confirmed breach of personal information. The procedure covers containment, assessment, notification and remediation. When an incident occurs, the company acts first to stop the loss, then determines what information was involved, what harm could result and who needs to be told.

Where the law requires notification to a regulator or to affected individuals, the company provides that notice without undue delay and includes the information those parties need to protect themselves. Where the company is acting for a client, the company notifies the client promptly so that the client can meet its own notification duties. After every significant incident the company produces a review that records the cause, the response and the changes made to prevent recurrence.

21. Changes to This Policy

The company reviews this policy regularly and updates it when its practices, its services or the law change. When an update is material, the company changes the effective date at the top of the page and, where appropriate, provides additional notice on the website or by direct communication to active clients. Continued use of the website after an update indicates acceptance of the revised policy for future interactions.

The company keeps earlier versions of this policy so that a person can understand how practices have evolved. A request for a previous version can be made through the contact point below.

22. How to Contact Us

Questions, requests and concerns about this policy or about the handling of personal information should be directed to Black Dog Cannabis Inc. using the details below. The company aims to acknowledge a privacy enquiry within one business day and to resolve it as quickly as the circumstances allow.

A person who is not satisfied with the company response may have the right to complain to the privacy regulator in the relevant jurisdiction. The company will cooperate fully with any such review.