BiosecurityAG Inc. — Biosecurity Agriculture Platform

Privacy policy

Last Updated: July 22, 2026

Introduction

  • BiosecurityAG Inc. ("BiosecurityAG", "we", "us", "our") operates the Biosecurity Agriculture Platform — a livestock farm operations and biosecurity system. This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you access or use the Platform.
  • This Policy applies to two distinct groups of individuals, and the legal basis for processing differs between them. Please read the section that applies to you carefully.
  • This Policy is governed by Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Ontario's Employment Standards Act, 2000 (ESA), and applicable provincial privacy legislation including Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25), Alberta's Personal Information Protection Act (PIPA), and British Columbia's Personal Information Protection Act (BC PIPA), as relevant to where the Platform is used.
  • By using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree with any part of it, please do not use the Platform.

1. Who This Policy Applies To

  • The Platform is used by two groups, and the way we handle personal information differs between them.

1.1 Platform Customers (Producers and Veterinarians)

  • Producers are farm owners, operators, and corporate organizations that subscribe to Biosecurity Agriculture to manage their operations.
  • Veterinarians are licensed animal health professionals using the Platform to support Producers.
  • When you sign up for a Platform account, register your organization, or interact with us as a customer, BiosecurityAG is the data controller for your personal information. We decide what information to collect about you and why.

1.2 Personnel of Producers (Employees, Supervisors, Managers, Visitors)

  • Personnel are individuals associated with a Producer's organization — including farm employees, unit supervisors, on-farm managers, owners, veterinary visitors, technical advisors, and other workforce members — who use the Platform to perform their duties.
  • When Personnel use the Platform, the Producer (their employer) is the data controller for that personal information.
  • The Producer decides what information to collect about its Personnel, why it is collected, and how it is used.
  • BiosecurityAG acts only as the data processor — we store and process the information on the Producer's behalf, under our contract with that Producer.
  • This distinction matters legally. If you are an employee whose employer uses Biosecurity Agriculture, your privacy rights regarding your employment data are exercised through your employer in the first instance.
  • We will support your employer in responding to your requests, and we will respond to you directly when required by applicable law.

2. Information We Collect

2.1 Information We Collect Directly From Customers

  • When a Producer or Veterinarian creates and uses an account, we collect:
  • Identification: name, business name, role, mailing address, email address, phone number.
  • Professional credentials: licenses, diplomas, certifications, regulatory registration numbers (where applicable).
  • Account credentials: username, encrypted passwords, multi-factor authentication settings.
  • Billing information: payment method tokens, billing address, invoice records (we do not store full payment card numbers — these are tokenized and held by our payment processor).
  • Communications: emails, support tickets, chat messages, and survey responses you send to us.

2.2 Information We Process on Behalf of Producers (About Their Personnel)

  • Producers configure the Platform to record specific operational data about their Personnel.
  • This includes:
  • Identification: name, role, employee identifier assigned by the Producer.
  • Account access: username, encrypted password, role-based permissions.
  • Shift records: shift start time, end time, pause periods (lunch, breaks, meetings), total worked time, net worked time.
  • Unit visit logs: which farm units were entered, check-in time, check-out time, duration of each visit.
  • Critical step completion: tasks performed, time of completion, evidence captured (photos, numerical readings, electronic signatures) when the Producer requires evidence as part of a critical step.
  • Issue reports submitted by Personnel during their shifts.
  • Audit metadata: device identifier, IP address, application version, timestamp of each action — used to verify the integrity of the operational record.
  • BiosecurityAG processes this information only as instructed by the Producer and only for the purposes set out in our agreement with that Producer.

2.3 Information Collected Automatically

  • Platform usage data: pages viewed, features used, time spent, click events.
  • Device and connection data: device type, operating system, browser type, IP address, language, time zone.
  • Diagnostic data: crash logs, error reports, performance metrics.
  • Cookies and similar technologies: as described in Section 9.

2.4 What We Do Not Collect

  • We do not collect GPS or geo-fenced location data unless a specific feature is explicitly enabled by the Producer and disclosed to Personnel.
  • We do not perform keystroke logging, screen recording, or productivity surveillance.
  • We do not collect biometric data.
  • We do not collect health information about Personnel except where the Producer has configured the Platform to track work-related leave for ESA compliance, and only to the minimum extent required.
  • We do not knowingly collect personal information from individuals under 18. The Platform is not designed for, marketed to, or intended for use by minors. If we become aware that we have collected such information, we will delete it promptly.

3. Purposes of Processing

3.1 Purposes for Customer Information

  • To provide, maintain, and improve the Platform.
  • To create and manage user accounts and verify customer identity and credentials.
  • To process payments and issue invoices.
  • To communicate about service updates, security notices, and account matters.
  • To diagnose technical issues and support customers.
  • To detect, prevent, and investigate fraud, security incidents, and breaches of our Terms of Service.
  • To comply with legal obligations and respond to legal requests.
  • To produce aggregated, de-identified analytics about Platform use that does not identify any individual.

3.2 Purposes for Personnel Information

  • Personnel information is processed only for the purposes determined by the Producer and authorized in our contract with that Producer.
  • Typical authorized purposes include:
  • Recording shift start and end times for compliance with the Ontario Employment Standards Act and equivalent provincial legislation.
  • Tracking which Personnel were in which farm units, when, and for how long, to support biosecurity protection and outbreak traceability.
  • Recording completion of critical biosecurity steps and the evidence captured for each completion.
  • Producing operational reports for the Producer's management and for regulatory or audit purposes.
  • Supporting the Producer's payroll, scheduling, and human resources functions.
  • Investigating and responding to operational incidents flagged by Personnel.
  • BiosecurityAG will not use Personnel information for any purpose beyond providing the Platform to the Producer.
  • We do not use Personnel information to train artificial intelligence models, profile individuals, or build datasets for sale or secondary use.

4. Legal Basis for Processing

4.1 For Customer Information

  • We process Customer information based on:
  • Performance of our contract with you.
  • Your consent, where required.
  • Our legitimate interests in operating, securing, and improving the Platform, where consent is not required by law.
  • Compliance with our legal obligations.

4.2 For Personnel Information

  • The legal basis for processing Personnel information rests with the Producer (the data controller) and depends on the Producer's jurisdiction:
  • JurisdictionTypical legal basis
    Ontario (provincially regulated)Common-law right to manage employment, supplemented by the ESA's electronic monitoring policy requirement for employers with 25+ employees.
    Federal employers in any provincePIPEDA — necessary for establishing, managing, or terminating the employment relationship; with notice to employees.
    Alberta and British ColumbiaProvincial PIPA — reasonable for establishing, managing, or terminating employment; with notice to employees.
    QuebecLaw 25 — legitimate purpose with proportionality, with notice to and consent of employees.
    United StatesDetermined by applicable state law (e.g., NY, CA) and federal labor regulations; Producer responsible for compliance.
  • Each Producer is contractually required to confirm that it has provided required notices and obtained any required consents from its Personnel before configuring the Platform to record their information.

5. How We Share Information

  • We do not sell personal information.
  • We share information only as described below.

5.1 With Producers

  • All Personnel information is shared with — and accessible to — the Producer that employs or contracts with that individual.
  • The Producer determines who within its organization can see what data, through the Platform's role-based access controls.

5.2 With Service Providers (Sub-Processors)

  • We engage trusted third parties to provide infrastructure and operational support.
  • Each is bound by contract to use information only for the services we have engaged them to provide and to maintain confidentiality and security at least equivalent to our own.
  • Our current sub-processors include:
  • Cloud hosting and infrastructure: Amazon Web Services (AWS), Canadian region (ca-central-1).
  • Payment processing: a regulated payment processor (Stripe or equivalent).
  • Email and communication delivery.
  • Analytics and error monitoring (configured to exclude personal information where possible).
  • A current list of sub-processors is available on request to our Privacy Officer.
  • We will provide reasonable advance notice of material changes to our sub-processor list.

5.3 With Veterinarians and Service Providers Engaged by the Producer

  • If a Producer engages a Veterinarian, technical advisor, feed company, or auditor through the Platform, the Producer may grant that party access to specified Personnel and operational information.
  • Such access is configured by the Producer.

5.4 In Legal and Safety Situations

  • In response to a valid legal process such as a court order, subpoena, or government investigation.
  • To enforce our agreements or protect our legal rights.
  • To protect the rights, safety, or property of any individual.
  • In connection with a merger, acquisition, financing, or sale of assets, in which case we will give notice to affected customers.

5.5 With Consent

  • We may share information for any other purpose with the appropriate consent of the data subject.

6. International Data Transfers

  • Personal information is primarily stored and processed in Canada (AWS Canadian region).
  • In certain circumstances — including support, backup, and disaster recovery — information may be transferred to or accessed from other jurisdictions including the United States and the European Union.
  • Where information is transferred outside the jurisdiction in which it was collected, we use contractual and technical safeguards designed to maintain a level of protection comparable to that required by applicable law in the originating jurisdiction.
  • By using the Platform, you acknowledge that personal information may be processed in jurisdictions whose laws differ from those of your home jurisdiction.

7. Data Retention

  • We retain personal information only as long as necessary for the purposes described in this Policy or as required by law.
  • Data typeRetention period
    Customer account informationFor the duration of the customer relationship plus seven (7) years for tax, contractual, and legal record requirements.
    Shift records, unit visit logs, time recordsThree (3) years from creation, in compliance with Ontario ESA section 15. Producer may instruct longer retention for its own compliance needs.
    Critical step completion records and evidenceThree (3) years minimum, longer where the Producer requires for traceability or audit purposes.
    Billing and invoice recordsSeven (7) years for tax compliance.
    Communications with supportTwo (2) years from last contact.
    Backup dataUp to ninety (90) days after deletion from production systems.
    Anonymized and aggregated dataIndefinitely — does not identify any individual.
  • On termination of a customer agreement, we provide the Producer with a thirty (30) day window to export their data. After that window, we delete the data within ninety (90) days, except where retention is required by law.

8. Your Privacy Rights

  • Subject to applicable law, you have the following rights with respect to your personal information.

8.1 Rights Available to All Individuals

  • Right to be informed — to know what information we hold and how it is used.
  • Right of access — to obtain a copy of your personal information.
  • Right to rectification — to correct inaccurate or incomplete information.
  • Right to erasure — to request deletion in certain circumstances.
  • Right to withdraw consent — where consent is the basis for processing.
  • Right to challenge compliance — to file a complaint with our Privacy Officer or with the relevant regulator.

8.2 How Personnel Exercise Their Rights

  • If you are Personnel of a Producer (an employee, supervisor, or other workforce member of a customer organization):
  • Your first point of contact for privacy requests is your employer.
  • The employer is the data controller and holds primary obligations to respond to you.
  • You may also contact our Privacy Officer directly.
  • We will work with your employer to respond to your request and will respond to you directly when required by law.
  • In Quebec, individuals have direct rights against the Producer under Law 25 and may also contact the Commission d'accès à l'information.

8.3 How to Make a Request

  • To exercise any of these rights, contact our Privacy Officer using the details in Section 12.
  • We will respond within thirty (30) days.
  • Complex requests may take longer, but we will keep you informed.
  • We may charge a minimal fee where permitted by law for access requests, and will inform you in advance of any cost.
  • If we deny a request, we will explain why and inform you of your recourse, including the right to file a complaint with the Office of the Privacy Commissioner of Canada or the relevant provincial regulator.

9. Cookies and Similar Technologies

  • The Platform uses cookies and closely related technologies (such as browser local storage) to authenticate users, secure sessions, remember preferences, and understand how the Platform is used.
  • This Section explains what we set, why, and what choices are available to you.

9.1 Authentication and Session Cookies

  • Access to the Platform requires signing in.
  • When you sign in, we set one or more HTTP cookies that identify your authenticated session.
  • These cookies are essential: without them, the Platform cannot verify who you are and cannot keep you signed in as you move between pages.
  • Our authentication cookies are configured with the following protections:
  • HttpOnly — the cookie cannot be read by scripts running in your browser, which materially reduces the risk of session theft through cross-site scripting.
  • Secure — the cookie is transmitted only over encrypted HTTPS connections and is never sent in clear text.
  • SameSite — the cookie is restricted from being sent on cross-site requests, which protects against cross-site request forgery.
  • Scoped and time-limited — session cookies are scoped to the Platform domain and expire after a defined period of inactivity or on sign-out.
  • Persistent sign-in cookies, where offered, expire after a fixed maximum period.
  • Authentication cookies contain a session identifier or an encrypted token.
  • They do not contain your password, and they do not contain operational or employment data.
  • When you sign out, the session is invalidated on our servers and the corresponding cookie is cleared.

9.2 Categories of Cookies We Use

  • Strictly necessary — authentication, session integrity, security (including cross-site request forgery protection), load balancing, and core Platform function.
  • These cannot be disabled while you are using the Platform, because the Platform cannot operate securely without them.
  • Under PIPEDA and applicable provincial legislation, these are set on the basis of necessity for delivering a service you have requested.
  • Functional — remember interface preferences such as language, time zone, and display settings, so you do not need to reset them at each sign-in.
  • These may be declined without preventing you from signing in, although some conveniences will be lost.
  • Analytics — measure aggregate Platform usage, feature adoption, and performance so that we can improve reliability and usability.
  • Analytics data is used in aggregate and is configured to exclude personal information where technically possible.
  • These may be declined.

9.3 What We Do Not Use

  • The Platform does not use advertising cookies, cross-site behavioural tracking cookies, advertising identifiers, or third-party marketing pixels.
  • We do not participate in advertising networks, and we do not sell or share cookie-derived information with advertisers or data brokers.
  • Cookies are not used to monitor individual worker productivity.

9.4 Your Choices

  • Most browsers allow you to view, block, or delete cookies through their settings, and to be notified before a cookie is set.
  • Where the Platform presents a cookie preference control, you may accept or decline non-essential categories at any time, and change your choice later.
  • Blocking strictly necessary cookies will prevent you from signing in and will make the Platform unusable.
  • This is a technical consequence of secure authentication, not a commercial choice on our part.
  • Blocking functional or analytics cookies does not prevent access to the Platform.

9.5 Cookies and Personnel

  • Where you access the Platform as Personnel of a Producer, authentication cookies establish that you are signed in and are set by BiosecurityAG as part of delivering the Platform.
  • Cookies are not used to record your location, monitor your activity outside the Platform, or generate employment-related assessments of you.
  • Information about your shifts, unit visits, and task completions is recorded through the Platform features described in Section 2.2 — configured by your employer — and not through cookies.

10. Security

  • We protect personal information against unauthorized access, use, disclosure, alteration, and destruction using a combination of technical, administrative, and physical safeguards.
  • These include:
  • Encryption in transit (TLS 1.2 or higher) and at rest.
  • Role-based access controls and the principle of least privilege.
  • Multi-factor authentication for administrative access.
  • Audit logging of access to and changes in personal information.
  • Regular security testing and vulnerability management.
  • Confidentiality and security obligations on all employees and contractors.
  • Sub-processor due diligence and contractual safeguards.
  • Backup, disaster recovery, and incident response capabilities.
  • No system can be guaranteed to be completely secure.
  • If a security incident affects your personal information, we will notify you and any required regulator without unreasonable delay, in accordance with PIPEDA, applicable provincial legislation, and the Producer's contract.

10.1 Breach Reporting

  • Under PIPEDA and applicable provincial laws, BiosecurityAG must report a breach of security safeguards involving personal information to the relevant regulator and to affected individuals if the breach is likely to result in significant harm.
  • We assess this based on the sensitivity of the information, the likelihood of misuse, and other relevant factors.
  • We maintain records of all breaches involving personal information for at least twenty-four (24) months and provide them to the Office of the Privacy Commissioner on request.
  • Where the affected information was processed on behalf of a Producer, we will notify the Producer without undue delay so the Producer can fulfill its own breach notification obligations to its Personnel.

11. Children and Minors

  • The Platform is intended for use only by individuals 18 years of age or older.
  • We do not knowingly collect personal information from children under 18.
  • If we learn that we have collected information from a child under 18, we will delete it promptly.
  • If you believe a child has provided us with personal information, contact our Privacy Officer.

12. Privacy Officer and Contact

  • BiosecurityAG has appointed a Privacy Officer to oversee our compliance with applicable privacy laws and to respond to privacy questions, requests, and complaints.
  • Privacy Officer: Ihor Levchyshyn
  • BiosecurityAG Inc.
  • 375 Barber Avenue North, Listowel, Ontario, Canada N4W 1R8
  • Email: igor@biosecurity.ag
  • Phone: +1 226-622-2799
  • If you are not satisfied with our response, you may file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca), or the relevant provincial privacy regulator including the Information and Privacy Commissioner of Ontario (ipc.on.ca), the Commission d'accès à l'information du Québec (cai.gouv.qc.ca), the Office of the Information and Privacy Commissioner of Alberta (oipc.ab.ca), or the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca).

13. Changes to This Policy

  • We may update this Policy from time to time to reflect changes in law, business practice, or the Platform itself.
  • We will post the updated Policy on our website with a new "Last Updated" date.
  • For material changes, we will provide reasonable advance notice through the Platform or by email.
  • Your continued use of the Platform after the effective date of the updated Policy constitutes acknowledgment of the updates.

14. PIPEDA Fair Information Principles

  • This Policy is designed to align with the ten Fair Information Principles set out in PIPEDA Schedule 1:
  • PrincipleHow we comply
    1. AccountabilityOur Privacy Officer (Section 12) is accountable for our privacy program. We hold sub-processors to equivalent standards by contract.
    2. Identifying PurposesSection 3 identifies all purposes for which we process personal information.
    3. ConsentWe obtain consent where required and rely on contractual or legal exemptions where the law permits (Section 4).
    4. Limiting CollectionWe collect only what is necessary for the purposes identified (Section 2.4 lists what we explicitly do not collect).
    5. Limiting Use, Disclosure, RetentionWe use information only for stated purposes and retain it only as long as necessary (Sections 3, 5, and 7).
    6. AccuracyPersonal information is kept accurate and up-to-date as reasonably possible (Section 8).
    7. SafeguardsSection 10 describes our technical, administrative, and physical safeguards.
    8. OpennessThis Policy is publicly available on our website. Sub-processor lists and additional details are available on request.
    9. Individual AccessSection 8 describes how individuals access their information and challenge accuracy.
    10. Challenging ComplianceSection 12 describes how to file a complaint with us or with regulators.