Personal Data Protection Policy

Replay Scout Inc.
Effective date: 3 September 2026
Last reviewed: 3 September 2026

1. Our commitment

Replay Scout Inc. ("Replay Scout", "we", "us", or "our") is committed to protecting the personal data of everyone we interact with, including our customers, their authorized users, suppliers, business partners, employees, and visitors to our website and platform. We aim to comply with the personal data protection laws that apply in the places where we operate, including the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector (as amended by Law 25), and, where applicable, the EU General Data Protection Regulation (GDPR).

This Policy sets out the principles we follow when we process personal data and the responsibilities we have taken on to honour them. It is a company-wide standard that applies to Replay Scout and any subsidiary it controls, and to every employee and contractor who works with personal data on our behalf.

This Policy describes how we protect personal data. For details about what personal data we collect from you, why we collect it, and how long we keep it, please read our Customer Privacy Notice.

2. Key definitions

Personal data means any information relating to an identified or identifiable individual, such as a name, an email address, an identification number, location data, an online identifier, or any factor specific to that person's physical, physiological, genetic, mental, economic, cultural, or social identity.

Sensitive personal data means personal data that, by its nature, merits special protection, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic or biometric data used to identify a person, and data concerning health, sex life, or sexual orientation.

Processing means any operation performed on personal data, whether automated or not, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure, or destruction.

Data controller means the organization that determines the purposes and means of processing personal data. Data processor means an organization that processes personal data on a controller's behalf. Replay Scout acts as a controller of the personal data provided to us by our customers and website visitors, and as a processor where we handle personal data on a customer's instructions.

Anonymization means irreversibly de-identifying personal data so that an individual can no longer be identified by any reasonable means. Pseudonymization means processing personal data so that it can no longer be attributed to an individual without additional information that is kept separately and protected. Pseudonymized data remains personal data and is protected under this Policy.

3. Principles we follow

We process personal data in accordance with the following principles.

Lawfulness, fairness, and transparency. We process personal data lawfully, fairly, and in a transparent manner, and we tell individuals clearly how their data is used.

Purpose limitation. We collect personal data only for specified, explicit, and legitimate purposes, and we do not further process it in a way that is incompatible with those purposes.

Data minimization. We collect and keep only the personal data that is adequate, relevant, and necessary for the purposes for which it is processed. Where practical, we anonymize or pseudonymize personal data to reduce risk to individuals.

Accuracy. We take reasonable steps to keep personal data accurate and up to date, and to correct or erase inaccurate data without delay.

Storage limitation. We keep personal data only for as long as necessary for the purposes for which it was collected, in line with our Data Retention Policy, after which it is securely destroyed in line with our Data Disposal and Destruction Policy.

Integrity and confidentiality. We apply appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

Accountability. We are responsible for, and able to demonstrate, our compliance with these principles.

4. How we build data protection into our business

Collection

We strive to collect the least amount of personal data possible. Where we obtain personal data from a third party rather than directly from the individual, our Data Protection Officer confirms that it was collected lawfully.

Notice

At or before the time we collect personal data, we inform individuals through a privacy notice of the types of personal data collected, the purposes and methods of processing, their rights, the retention period, any international transfers, any sharing with third parties, and the security measures we use to protect their data. Where sensitive personal data is collected, the notice states explicitly why it is needed. We maintain a register of our privacy notices so that they stay accurate and current.

Consent and choice

Where our processing relies on an individual's consent, we obtain that consent in a clear and unambiguous way, keep a record of it, and make it easy to withdraw at any time. If we wish to use personal data for a new purpose that is not compatible with the original one, we explain the original purpose, the new purpose, and the reason for the change, and we seek fresh consent before proceeding.

Where personal data relates to a child below the applicable age of consent in their jurisdiction (16, 14, or 13 depending on the applicable law), we obtain verifiable parental or guardian consent before collecting it.

Use, retention, and disposal

We use personal data only in the ways described in the applicable privacy notice. We maintain its accuracy, integrity, confidentiality, and relevance for the purpose it serves, protect it with appropriate security controls, and retain it only for the period set out in our Data Retention Policy. When that period ends, the data is irreversibly destroyed or anonymized.

Privacy by design and risk assessment

Before starting a new processing activity, we assess whether a Data Protection Impact Assessment is required and, where it is, we complete one before processing begins. Data protection considerations are built into the design of our systems and services.

Sharing with third parties

We do not sell personal data. We rely on service providers in the following categories: hosting and infrastructure, database hosting, transactional email delivery, file storage, address lookup and mapping, protection against automated abuse, and security monitoring, error diagnostics, and performance and usage analytics. Where we engage a supplier or partner (a "processor" or "subprocessor") to process personal data on our behalf, we assess their security and privacy practices before engaging them and bind them by written agreement to protect personal data to the same standard we apply, to process it only on our instructions and only for the purpose of providing services to us, and to pass equivalent obligations on to any subcontractor they use. Where we process personal data jointly with an independent third party, we set out our respective responsibilities in a written agreement. A current list of the subprocessors we use is available on request.

Cross-border transfers

Our primary database is hosted in a data-centre region located in Canada. Some of the service providers we rely on — for email delivery, file storage, address lookup, and performance monitoring — process limited personal data in the United States. Where personal data is transferred to a country outside the jurisdiction in which it was collected, we do so only where appropriate safeguards are in place, such as a data transfer agreement incorporating recognized contractual clauses, and, where the applicable law requires it, only after completing a transfer risk assessment. Our privacy notices state where and to whom such transfers are made.

5. Your rights

Depending on where you live and the law that applies, you may have the following rights in relation to the personal data we hold about you.

Access. You may ask us to confirm whether we process your personal data and to provide a copy of it, along with information about how we use it.

Rectification. You may ask us to correct personal data that is inaccurate or incomplete.

Erasure ("right to be forgotten"). You may ask us to delete your personal data. Where we are acting as a controller and have shared the data with third parties, we take reasonable steps, including technical measures, to inform them of your request.

Data portability. You may ask to receive a copy of the personal data you provided to us in a structured, commonly used, machine-readable format, free of charge, and to have it transmitted to another organization where technically feasible.

Restriction and objection. You may ask us to restrict the processing of your personal data in certain circumstances, and you may object to processing that is based on our legitimate interests or that is carried out for direct marketing.

Withdrawal of consent. Where our processing relies on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.

Complaint. You may lodge a complaint with us or with the privacy regulator in your jurisdiction (see Section 9).

To exercise any of these rights, please submit a request using our Data Subject Access Request Form or contact our Data Protection Officer using the details in Section 9. We will respond within one month of receiving your request, or within any shorter period required by applicable law, and we will tell you if we need more time to deal with a complex request. We may need to verify your identity before acting on a request, and we may decline requests that are manifestly unfounded or excessive or that would adversely affect the rights of others. We keep a log of the requests we receive and how they were handled.

6. How we protect personal data

We maintain an information security program, documented in our Information Security Policy, that is designed to protect the confidentiality, integrity, and availability of the personal data we process. Our measures include access controls that limit personal data to those who need it for their role, authentication requirements for all systems that hold personal data, encryption of personal data where appropriate, logging and monitoring of access to our systems, regular checks and scans to confirm that security controls are working as intended, and secure disposal of data and equipment at the end of their life.

Every employee and contractor who handles personal data receives data protection awareness training, and employees working directly with personal data receive additional role-specific training.

7. Responding to personal data breaches

If we learn of a suspected or actual personal data breach, we investigate promptly and take appropriate remedial action in accordance with our Data Breach Response and Notification Procedure. Where a breach creates a real risk of significant harm to individuals, or a risk to their rights and freedoms, we notify the relevant privacy regulator without undue delay and, where the GDPR applies, within 72 hours of becoming aware of the breach. We also notify affected individuals where required by law, and we keep a record of every breach, its effects, and the action we took.

8. Governance and accountability

Responsibility for protecting personal data is shared by everyone who works for or with Replay Scout. In addition:

Our Chief Executive Officer sets and approves our overall personal data protection strategy.

Our Data Protection Officer (DPO), a function held by our Chief Technology Officer or their designate, manages our personal data protection program, develops and promotes our data protection policies and procedures, oversees supplier due diligence and contractual data protection commitments, delivers employee training and awareness, and handles requests and complaints from individuals.

Our Legal Counsel, together with the DPO, monitors changes in personal data protection law and translates them into compliance requirements for the business.

Our DPO and IT function together ensure that all systems, services, and equipment used to store personal data meet acceptable security standards.

Compliance with this Policy is audited regularly. Employees who breach this Policy are subject to disciplinary action and may also be subject to civil or criminal liability where their conduct breaks the law.

9. How to contact us

If you have a question about this Policy, wish to exercise your rights, or want to make a complaint about how we have handled your personal data, please contact our Data Protection Officer:

Email: privacy@replayscout.com
Post: Data Protection Officer, Replay Scout Inc., Suite 5100, Bay Adelaide – West Tower, 333 Bay Street, Toronto, Ontario, M5H 2R2, Canada

If you are not satisfied with our response, you have the right to complain to the privacy regulator in your jurisdiction, including the Office of the Privacy Commissioner of Canada, the Commission d'accès à l'information du Québec, or, if you are in the European Economic Area, the supervisory authority in your member state.

10. Conflicts of law

This Policy is intended to comply with the laws and regulations of the places where Replay Scout Inc. is established and operates. If there is any conflict between this Policy and applicable law, the applicable law prevails.

11. Changes to this Policy

We review this Policy at least annually and whenever there is a significant change in the law or in our business. When we make material changes, we will update the effective date above and, where appropriate, notify affected individuals.

Related documents