Privacy Policy
Effective date: September 3, 2026
Last updated: September 3, 2026
This Privacy Policy explains how Ciber Media (“Ciber Media”, “we”, “us”, “our”) collects, uses, discloses, retains and protects personal information when you visit or interact with ciber-media.com (the “Site”).
Ciber Media is operated from Toronto, Ontario, Canada. We handle personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. Depending on where you live, additional laws may give you further rights — the European Union’s General Data Protection Regulation (GDPR), the UK GDPR, Quebec’s Law 25, and the California Consumer Privacy Act as amended by the CPRA. Sections 11 to 14 set out those additional rights.
Please read this policy together with our Terms & Conditions, our Disclaimer and our DMCA Policy.
1. Who is responsible for your information
Ciber Media is the “organization” under PIPEDA and the “controller” under the GDPR and UK GDPR in respect of the personal information described in this policy. That means we decide why and how it is processed, and we are accountable for it.
We have designated an individual responsible for privacy compliance, reachable at [email protected]. All privacy enquiries, access requests, correction requests, deletion requests and complaints should be sent to that address.
Postal correspondence: Ciber Media, Privacy Officer, Toronto, Ontario, Canada.
2. Scope of this policy
This policy applies to personal information we collect through the Site, through email correspondence with us, and through the comment and subscription features of the Site.
It does not apply to:
- Third-party websites we link to. Following an external link takes you outside the scope of this policy — see section 9.
- Content embedded from third parties, such as video players and social media posts, which behave as though you had visited the third party’s own site — see section 7.
- Information you make public yourself, for example the display name and comment text you choose to publish in a comment thread.
3. Categories of personal information we collect
3.1 Information you provide to us directly
| Where it comes from | What we receive |
|---|---|
| Comments on articles | The display name you enter, your email address, your website URL if you supply one, the content of your comment, your IP address, and your browser user-agent string. This is standard WordPress comment data. |
| Email correspondence | Your name and email address, any information in your message and attachments, and routing metadata contained in the email headers. |
| Newsletter or update subscriptions, where offered | Your email address, the date and source of your subscription, and — where the mailing tool records it — whether messages were opened or links clicked. |
| Story tips and source correspondence | Whatever you choose to send. We ask that you do not send sensitive personal information you are not comfortable disclosing by ordinary email. |
| Correction, privacy and copyright requests | Your name, contact details, the substance of your request, and any identity-verification information we reasonably need to act on it. |
3.2 Information collected automatically
When you request a page, our servers and infrastructure providers record technical information as part of delivering it. This typically includes:
- Your IP address, and the approximate geographic region derived from it;
- The date and time of the request;
- The URL requested, the HTTP status returned, and the number of bytes sent;
- The referring page, where your browser sends one;
- Your browser type and version, operating system, device type and screen characteristics;
- Language preferences sent by your browser.
Where analytics are enabled, we may also record which pages were viewed in a session, how long a page was open, scroll depth, and outbound link clicks, in aggregated or pseudonymized form.
3.3 Information we do not collect
We do not ask for and do not knowingly collect: government identifiers, financial account or payment card numbers, health information, biometric data, precise GPS location, or information about your racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation. Please do not send us such information.
4. Why we use personal information, and our lawful basis
Under PIPEDA we identify the purposes for which personal information is collected at or before the time of collection, and we limit collection to what is necessary for those purposes. For readers protected by the GDPR or UK GDPR, the table below also identifies our lawful basis.
| Purpose | Information used | Lawful basis (GDPR / UK GDPR) |
|---|---|---|
| Delivering the Site and its pages to you | Technical request data | Legitimate interests — operating a website that works |
| Security, abuse prevention, spam filtering, rate limiting and fraud detection | Technical request data, comment metadata | Legitimate interests — protecting the Site and its readers; legal obligation where applicable |
| Publishing and moderating comments | Comment data | Consent, given when you submit a comment |
| Responding to your enquiries, tips, corrections and requests | Correspondence data | Legitimate interests — answering people who contact us; legal obligation for statutory requests |
| Sending a newsletter or update emails, where offered | Email address, engagement data | Consent, withdrawable at any time |
| Understanding audience and article performance in aggregate | Analytics data | Consent where required by local law; otherwise legitimate interests |
| Measuring and reporting on advertising, where advertising is carried | Advertising identifiers and interaction data | Consent |
| Complying with legal obligations and responding to lawful requests | Any relevant information | Legal obligation |
| Establishing, exercising or defending legal claims | Any relevant information | Legitimate interests; legal claims exemption |
New purposes. If we ever wish to use personal information for a purpose not identified above, we will identify that purpose and, where the law requires it, obtain your consent before doing so.
5. What we do not do with your information
- We do not sell personal information, and we have not sold or shared personal information for cross-context behavioural advertising in the preceding twelve months.
- We do not rent, trade or otherwise commercialize mailing lists.
- We do not use your personal information, your comments or your correspondence to train machine-learning or artificial-intelligence models, and we do not license it to others for that purpose.
- We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not carry out profiling of that kind.
- We do not disclose the identity of a confidential source without that source’s agreement, other than where compelled by a binding court order after we have exhausted reasonable means of resisting it.
6. Cookies and similar technologies
A cookie is a small text file stored by your browser. We use cookies and similar technologies (local storage, pixels) in the limited categories below.
| Category | Purpose | Examples | Can you refuse? |
|---|---|---|---|
| Strictly necessary | Keeping the Site functional and secure | WordPress session and authentication cookies for logged-in users; wordpress_test_cookie, which checks whether your browser accepts cookies; security and load-balancing cookies set by our host |
No — the Site cannot work without them |
| Functional | Remembering choices you make | comment_author, comment_author_email and comment_author_url, which WordPress sets for about one year so you do not have to retype your details when commenting again |
Yes — decline the option when commenting, or clear them in your browser |
| Analytics | Understanding which articles are read and how readers arrive | Cookies or identifiers set by our analytics provider, where analytics are enabled | Yes — via your browser, our cookie banner where shown, or provider opt-outs |
| Advertising | Serving and measuring advertising, where the Site carries advertising | Cookies set by an advertising partner | Yes — consent is requested before non-essential advertising cookies are set in jurisdictions that require it |
Managing cookies. Every major browser lets you view, block and delete cookies, and offers a private-browsing mode that discards them at the end of a session. Blocking strictly necessary cookies will break parts of the Site. Instructions are available in the help pages of Chrome, Firefox, Safari and Edge.
Do Not Track. Browsers can send a “Do Not Track” header. Because no common industry standard has emerged for interpreting it, we do not currently alter our behaviour in response to that signal. Where a jurisdiction recognizes a legally binding opt-out preference signal, such as Global Privacy Control, we honour it as an opt-out request.
7. Embedded content from other sites
Articles may embed material hosted by third parties — for example video players, social media posts, code snippets, document viewers or charts. Embedded content behaves exactly as though you had visited the third party’s own website. The third party may collect data about you, set and read its own cookies, embed additional tracking, and monitor your interaction with the embedded content, including if you have an account and are logged in with them.
We do not control that processing and it is governed by the third party’s own privacy policy, not by this one. If you would prefer to avoid it, most browsers and content-blocking extensions can prevent third-party embeds from loading.
8. Disclosure of personal information
8.1 Service providers
We disclose personal information to service providers who process it on our behalf, on our instructions and for no independent purpose of their own. The categories are:
- Web hosting and content delivery — serving the Site, storing its database, absorbing malicious traffic;
- Email — sending and receiving our correspondence;
- Comment spam filtering — evaluating submitted comments for spam, which involves sending comment metadata to the provider;
- Analytics — measuring aggregate readership, where enabled;
- Newsletter delivery — sending subscription emails, where offered;
- Advertising — serving and measuring advertisements, where the Site carries advertising;
- Professional advisers — legal and accounting advisers, bound by professional confidentiality.
We use contractual means to require a comparable level of protection while the information is being processed by a service provider, as PIPEDA requires.
8.2 Legal and protective disclosures
We may disclose personal information without your consent where PIPEDA or other applicable law permits or requires it, including: in response to a subpoena, warrant, court order or other binding legal demand; to comply with the rules of a court or tribunal; to investigate a breach of an agreement or a contravention of law; where necessary to protect the life, health or security of an identifiable person; and to establish, exercise or defend a legal claim.
Where we are legally permitted to do so, we will make reasonable efforts to notify you before disclosing your information in response to a legal demand, so that you may seek to challenge it.
8.3 Business transfers
If Ciber Media is involved in a merger, acquisition, financing, reorganization or sale of assets, personal information may be disclosed to the parties to that transaction and transferred as part of it. Where such information is disclosed before the transaction closes, it will be limited to what is necessary to evaluate the transaction and will be subject to an agreement restricting its use to that purpose. We will notify you of any change in control that materially affects how your personal information is handled.
9. Links to other websites
The Site links extensively to primary sources — company announcements, regulator pages, court documents, vendor advisories and other publications. We provide these links so you can verify our reporting. We do not control those sites, are not responsible for their content or their privacy practices, and a link is not an endorsement. Review the privacy policy of any site you visit through a link from ours.
10. International transfers and storage
Our service providers may store and process personal information in Canada, the United States, the European Union or the United Kingdom. Where information is transferred outside your country of residence:
- It remains subject to this policy and to the contractual protections we have in place with the relevant provider;
- It may be accessible to the courts, law-enforcement bodies and national-security authorities of the receiving jurisdiction under that jurisdiction’s laws;
- For transfers of personal data out of the EEA or the UK, we rely on the European Commission’s adequacy decision in respect of Canada for commercial organizations subject to PIPEDA, or, where an adequacy decision does not apply, on Standard Contractual Clauses or the UK International Data Transfer Addendum together with a transfer risk assessment.
You may contact [email protected] for information about our policies and practices regarding service providers located outside Canada.
11. Your rights under Canadian law
Under PIPEDA, and under provincial legislation where it applies, you have the right to:
- Know what personal information we hold about you, how it is used, and to whom it has been disclosed;
- Access that information, subject to the limited exceptions PIPEDA permits — for example where disclosure would reveal personal information about a third party, would compromise a confidential journalistic source, or is subject to solicitor-client privilege;
- Challenge the accuracy of the information and have it corrected, completed or annotated;
- Withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice; and
- Complain about our handling of your personal information.
If you are a Quebec resident, Law 25 additionally gives you the right to request that personal information be de-indexed or that its dissemination cease in defined circumstances, and the right to receive computerized personal information you provided in a structured, commonly used technological format.
12. Your rights under the GDPR and UK GDPR
If you are in the European Economic Area, Switzerland or the United Kingdom, you additionally have the rights to: access your personal data; have inaccurate data rectified; have data erased in defined circumstances; restrict processing; object to processing carried out on the basis of legitimate interests, and to object at any time to processing for direct marketing; receive data you provided in a portable format; and withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
You also have the right to lodge a complaint with a supervisory authority in your country of residence, place of work, or the place of an alleged infringement.
13. Your rights under California law
California residents have the right to know the categories and specific pieces of personal information collected, the categories of sources, the business purposes for collection, and the categories of third parties to whom it is disclosed; the right to delete personal information, subject to exceptions; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information; and the right not to be discriminated against for exercising these rights.
As stated in section 5, we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit.
14. How to exercise your rights
Send your request to [email protected]. Please describe what you are asking for and give us enough detail to locate the information — for example, the email address you used when commenting, or the date and subject of the correspondence.
Verification. Before acting on a request we will take reasonable steps to verify that it comes from you or an authorized agent, proportionate to the sensitivity of the information. We may ask you to confirm the request from the email address associated with the information. We will not use verification information for any other purpose.
Timing. We respond to PIPEDA access requests within 30 days, and to GDPR/UK GDPR requests within one month, extendable by a further two months for complex or numerous requests, in which case we will tell you within the first month. There is no charge for a request unless it is manifestly unfounded or excessive, in which case we will tell you the cost in advance and give you the opportunity to withdraw the request.
If we refuse. Where we decline a request in whole or in part, we will tell you why, identify the provision relied on, and explain how you may complain.
15. Retention
| Information | Retention period |
|---|---|
| Published comments and their metadata | Retained while the article remains published, so that threads stay intact and repeat commenters can be recognized — deleted on request |
| Comments held as spam or rejected in moderation | Deleted automatically, typically within 30 days |
| Email correspondence | For as long as needed to handle the matter, and normally no more than 24 months afterwards |
| Newsletter subscription data | Until you unsubscribe, plus a minimal suppression record so we do not email you again |
| Server and security logs | Typically 30 to 90 days, then deleted or aggregated into non-identifying statistics |
| Analytics data | Aggregated or pseudonymized; retained no longer than 26 months in identifiable form |
| Records of privacy and copyright requests | Retained as long as necessary to demonstrate compliance, ordinarily up to 6 years |
| Records subject to a legal hold | Retained until the hold is lifted |
When personal information is no longer required for the purposes it was collected for, or for legal or business purposes, we delete it or render it anonymous.
16. Security safeguards
We apply safeguards appropriate to the sensitivity of the information, including:
- Encryption of all traffic to and from the Site in transit (HTTPS/TLS);
- Access controls on the publishing system, with accounts limited to those who need them and multi-factor authentication on administrative accounts;
- Prompt application of security updates to the platform and its components;
- Restriction of personal information to the smallest number of people who require it;
- Contractual security obligations imposed on service providers.
No method of transmission over the internet or of electronic storage is completely secure, and we cannot guarantee absolute security. Ordinary email in particular is not a secure channel; please do not send us information by email that would harm you if it were intercepted.
17. Breach notification
If a breach of security safeguards involving personal information under our control creates a real risk of significant harm to an individual, we will report the breach to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, as PIPEDA requires, and we will maintain records of breaches as required by law. Where the GDPR or UK GDPR applies, we will notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk to individuals’ rights and freedoms, and notify affected individuals without undue delay where the risk is high.
18. Children
The Site is intended for a professional adult readership. It is not directed at children, and we do not knowingly collect personal information from anyone under 13, or under the age of digital consent in their jurisdiction where that age is higher. If you believe a child has provided us with personal information, contact [email protected] and we will delete it.
19. Journalistic purposes
Ciber Media collects, uses and discloses some personal information exclusively for journalistic purposes. PIPEDA does not apply to the collection, use or disclosure of personal information for journalistic, artistic or literary purposes and no other purpose, and comparable exemptions exist under the GDPR and UK GDPR for processing carried out for journalism. Where information falls within that exemption — for example material relating to a person who is the subject of an article, or communications with a confidential source — the rights described in sections 11 to 14 may be limited to the extent necessary to protect our journalistic activity and our sources. We apply such limits narrowly, only where genuinely necessary, and we will tell you when we rely on this section.
20. Changes to this policy
We may update this policy to reflect changes in our practices, our providers or the law. When we do, we will change the “last updated” date above. For changes that materially affect how we handle personal information, we will post a prominent notice on the Site and, where the law requires it, obtain your consent before applying the change to information already collected. Previous versions are available on request.
21. Complaints
If you are concerned about how we have handled your personal information, please raise it with us first at [email protected]. We will investigate, respond in writing, and where a complaint is justified, take appropriate measures including amending our practices.
If you are not satisfied with our response, you may complain to:
- The Office of the Privacy Commissioner of Canada;
- The Commission d’accès à l’information du Québec, if you are a Quebec resident;
- Your national data protection authority, if you are in the EEA;
- The Information Commissioner’s Office, if you are in the UK.
22. Contact
Privacy Officer
Ciber Media
Toronto, Ontario, Canada
[email protected]
General enquiries: [email protected] — see our Contact Us page.
