Skip to main content

Privacy Policy

Last Updated: February 18, 2026

1. Introduction & Controller Identity

This Privacy Policy explains how NorthCode Academy Inc. ("NorthCode Academy," "we," "us," or "our") collects, uses, stores, and protects your personal data when you visit northcodeacademy.ca, submit an application form, or interact with our services in any capacity. We are committed to safeguarding your personal information in compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), the EU General Data Protection Regulation (GDPR), and the UK General Data Protection Regulation (UK GDPR).

Data Controller: NorthCode Academy Inc., 180 John Street, Suite 402, Toronto, ON M5T 1X5, Canada.

Contact Email: [email protected]

Effective Date: February 18, 2026

2. Personal Data We Collect

When you interact with our website and services, we may collect the following categories of personal data:

  • Identity & Contact Data: Full name, email address, phone number, and mailing address as provided through our application and contact forms.
  • Form Content: Messages, program preferences, motivational statements, and any additional information you voluntarily submit.
  • Technical Data: IP address, browser type and version, device type, operating system, preferred language, and screen resolution.
  • Usage Data: Pages visited, time spent on each page, referral source, click paths, and navigation patterns.
  • Cookies & Identifiers: Cookie data, advertising identifiers, and session tokens as detailed in Section 4 and our Cookie Policy.
  • Conversion Events: Form submissions, application completions, and program enquiry actions.

We do not collect special-category data (such as health information, religious beliefs, or political opinions), financial account details, or government-issued identification numbers unless a specific program enrolment process explicitly requires documentation for visa or regulatory purposes, in which case we will notify you separately at the point of collection.

3. Why We Process & Legal Basis

Under PIPEDA, we process personal information for purposes a reasonable person would consider appropriate. For individuals in the EEA and UK, we rely on the following legal bases under GDPR Article 6:

  • Contact & Application Forms: Processing is necessary for the performance of a contract or to take pre-contractual steps at your request (Art. 6(1)(b)), supplemented by your consent (Art. 6(1)(a)) for communications beyond the immediate enquiry.
  • Analytics: Based on your explicit consent (Art. 6(1)(a)), granted through our cookie consent mechanism.
  • Marketing & Remarketing: Based on your explicit consent (Art. 6(1)(a)), including remarketing audiences and lookalike audience creation.
  • Security & Fraud Prevention: Processing is necessary for our legitimate interests in protecting the website and its users from malicious activity (Art. 6(1)(f)).
  • Legal & Tax Obligations: Processing is necessary to comply with Canadian tax law and regulatory requirements (Art. 6(1)(c)).

Automated Decision-Making (Art. 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you. Admissions decisions are made by human staff members who review each application individually.

4. Cookies & Tracking

We use cookies and similar technologies organised into three categories. Full technical details, including cookie names and retention periods, are available in our Cookie Policy.

Essential Cookies (No Consent Required)

These cookies are strictly necessary for the website to function. They include _site_session (session continuity, expires at session end) and cookie_consent (stores your consent preferences, 12-month retention). CSRF protection tokens are also essential.

Analytics Cookies (Consent Required)

We use Google Analytics 4 with IP anonymisation enabled to understand how visitors navigate our site. Specific cookies include _ga (2-year retention) and _ga_XXXXXXXXXX (2-year retention, where XXXXXXXXXX is our GA4 measurement ID). Data retention within Google Analytics is set to 14 months.

Marketing Cookies (Consent Required)

These cookies support remarketing, conversion attribution, and custom/lookalike audience building. They include _gcl_au (Google Ads conversion linker, 90-day retention), _fbp (Meta Pixel browser identifier, 90-day retention), and _fbc (Meta Pixel click identifier, 90-day retention when a click ID is present).

Beyond cookies, we may use pixel tags (gtag.js, Meta Pixel), server-side event transmission via Meta Conversion API or Google server-side Google Tag Manager (using hashed identifiers), and device identifiers derived from IP address and User-Agent string combinations.

5. Consent (EEA/UK)

Users in the European Economic Area and the United Kingdom receive a consent notice upon their first visit under GDPR and UK GDPR. Marketing and analytics cookies activate only after you provide explicit, informed, and freely given consent (Art. 6(1)(a)). Your consent choice is recorded in the cookie_consent browser cookie, which is retained for 12 months.

You may withdraw consent at any time by clicking "Manage cookie preferences" in the website footer or by clearing your browser cookies. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

6. Sharing With Advertising & Service Partners

We share data with the following categories of third-party service providers, solely for the purposes described in this Policy:

  • Google LLC (Google Analytics 4, Google Ads, Google Tag Manager, Remarketing): Cookie identifiers, usage data, conversion events, and remarketing lists. See Google's Privacy Policy.
  • Meta Platforms, Inc. (Meta Pixel, Custom Audiences, Lookalike Audiences, Conversion API): Page views, conversion events, audience membership data, and hashed identifiers. See Meta's Privacy Policy.
  • Cloudflare, Inc. (CDN and Security): IP-based threat detection and performance optimisation. See Cloudflare's Privacy Policy.

We do not sell personal data. These providers are contractually prohibited from using data collected from our site for their own independent commercial purposes beyond the services they provide to us.

7. International Transfers

Some of our service providers, including Google and Meta, process data outside Canada, the EEA, and the UK, including in the United States. For transfers from the EEA/UK to the US, we rely on the following safeguards:

  • EU-US Data Privacy Framework (primary mechanism, in effect since July 2023)
  • UK Extension to the Data Privacy Framework
  • Swiss-US Data Privacy Framework
  • Standard Contractual Clauses (EU Commission Implementing Decision 2021/914) as a fallback mechanism
  • UK International Data Transfer Agreement (IDTA) as a fallback for UK transfers

8. Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:

  • Contact and application submissions: 2 years from last interaction
  • Analytics data: 14 months (Google Analytics retention setting)
  • Marketing cookies: Per individual cookie lifetime (maximum 2 years for _ga; 90 days for _gcl_au, _fbp, and _fbc)
  • Email correspondence: Duration of the relationship plus 1 year
  • Server logs: 90 days
  • Cookie consent records: 3 years for audit purposes
  • Legal and tax records: As required by applicable Canadian law (typically 6–7 years for financial records under the Canada Revenue Agency requirements)

9. Your Rights (GDPR & UK GDPR)

If you are located in the EEA or UK, you have the following rights under the GDPR and UK GDPR:

  • Right of Access (Art. 15): Obtain confirmation of whether your personal data is being processed and request a copy of that data.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
  • Right to Erasure (Art. 17): Request deletion of your personal data when it is no longer necessary for the purposes it was collected, or if you withdraw consent.
  • Right to Restriction of Processing (Art. 18): Request that we limit the processing of your data in certain circumstances.
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests, including direct marketing.
  • Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint (Art. 77): File a complaint with a supervisory authority.

To exercise any of these rights, email us at [email protected] with the subject line "Privacy Rights Request." We will respond within 30 calendar days. In complex cases, this may be extended by up to 60 additional days, and we will notify you of the extension within the initial 30-day period.

Canadian residents also have the right to access and correct their personal information under PIPEDA. Contact us at the email above, and we will respond within 30 days.

Lead Supervisory Authorities: UK — Information Commissioner's Office (ico.org.uk); EU (general) — European Data Protection Board (edpb.europa.eu); France — CNIL (cnil.fr); Germany — BfDI (bfdi.bund.de).

10. Children

Our website and programs are not directed at individuals under the age of 16. We do not knowingly collect personal data from minors. If we discover that data has been collected from a child under 16 without verifiable parental consent, we will delete that data promptly. If you believe we have inadvertently collected information from a minor, please contact us immediately at [email protected].

11. Do Not Track

This website does not currently respond to "Do Not Track" (DNT) browser signals. Third-party providers integrated with our site may have their own DNT handling policies, which are governed by their respective privacy policies linked in Section 6 above.

12. Account & Data Deletion

To request deletion of all personal data we hold about you, email [email protected] with the subject line "Data Deletion Request." We will verify your identity and complete the deletion within 30 calendar days. We may retain limited data where Canadian tax law or other regulatory obligations require it, and we will inform you of any such exceptions.

13. Business Transfers

In the event of a merger, acquisition, asset sale, corporate restructuring, financing, or insolvency proceeding, personal data held by NorthCode Academy Inc. may be transferred to a successor entity as part of the transaction. If such a transfer materially changes how your data is used, we will notify you via a prominent notice on our website at least 14 days before the change takes effect, and you will have the opportunity to request deletion of your data before the transfer.

14. California (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you additional rights regarding your personal information.

Categories disclosed in the past 12 months:

  • Identifiers (name, email, IP address, device identifiers) → disclosed to service providers and advertising partners
  • Internet or other electronic network activity (browsing history, page interactions, referral URLs) → disclosed to analytics and advertising providers
  • Inferences (interests, preferences derived from browsing behaviour) → disclosed to advertising partners

We do not sell personal information as defined by the CCPA. We do share data for cross-context behavioural advertising. California residents may opt out of this sharing via our cookie preferences panel accessible from the website footer.

Your California Rights: Right to Know, Right to Delete, Right to Correct, Right to Opt-Out of sale or sharing, and Right to Non-Discrimination. To submit a request, email us at [email protected] with the subject line "California Privacy Request." Identity verification is required. Authorized agents must provide written proof of authorisation.

15. Virginia (VCDPA)

Virginia residents have additional rights under the Virginia Consumer Data Protection Act (VCDPA), including the rights to Access, Correct, Delete, obtain a copy of personal data in a Portable format, and Opt-Out of targeted advertising.

To submit a request, email [email protected] with the subject line "Virginia Privacy Request." We do not sell personal data or engage in profiling that produces legal or similarly significant effects.

If we refuse your request, you may appeal by emailing us with the subject line "Appeal of Refusal — Privacy Request." We will respond to appeals within 60 days. If the appeal is unresolved, you may contact the Virginia Attorney General.

16. Nevada

Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject line "Nevada Do Not Sell Request." We do not currently sell personal information as defined under Nevada Revised Statutes Chapter 603A.

17. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be announced via a prominent banner on our homepage at least 14 days before taking effect. The "Last Updated" date at the top of this page will be refreshed with every revision. We encourage you to review this page periodically.

18. Contact

If you have questions about this Privacy Policy, your personal data, or wish to exercise any of your rights, please contact us:

For privacy-specific enquiries, please use the subject line "Privacy Enquiry" so we can route your message to the appropriate team member promptly.