Privacy Policy

We are committed to protecting your personal information — called “personal data” in European law — and to being clear about what we hold and why. This policy is written in plain language on purpose.

This policy, together with our Cookies Policy, applies to every visitor and user of our websites at esafetyfirst.com (the “sites”) and our online services. It explains how we use your personal information and the rights you have over it. It also covers personal information you give us by phone, SMS, email, letter or in person.

We handle your personal information under the laws that actually apply to you and to us: Canada’s federal private-sector privacy law (PIPEDA) and the substantially similar provincial laws of British Columbia, Alberta and Quebec — including Quebec’s strengthened requirements under Law 25 — Canada’s anti-spam law (CASL) for commercial email, and, because our company is established in Romania, the EU General Data Protection Regulation (GDPR). Nothing in this policy limits any right the law gives you.

1. Who holds your information?

eSafetyFirst Canada (“eSafetyFirst”, “we”) is responsible for your personal information — the “data controller”, in European terms. Our Privacy Officer oversees how we handle it; you can reach them through the contact details in section 14.

2. What information do we collect, and how?

2.1. We may collect, store and use the following kinds of personal information:

Identity Data: your name, username or another identifier;

Contact Data: billing address, email address and telephone numbers;

Transaction Data: details of payments to and from you, and of the training you have purchased from us;

Technical Data: internet protocol (IP) address, login data, browser type and version, time-zone setting and location, operating system, and other details of the devices you use to access the sites;

Profile Data: your username and password, the courses on your account, your preferences, feedback and survey responses;

Usage Data: how you use our sites and services;

Marketing and Communications Data: your marketing and communication preferences;

Other: anything else you choose to send us or make available to us.

2.2. We collect personal information in three ways:

Direct interactions: you give it to us by filling in forms on our sites or by writing to us, calling us or emailing us. That includes the personal information you provide when you:

Create an account on our sites;

Subscribe to our newsletter or other updates;

Ask us to send you marketing material;

Enter a competition, promotion or survey;

Give us feedback, report a problem with our sites, or otherwise contact us.

Automated technologies: as you use the sites, we automatically collect Technical Data about your device, browser and browsing patterns. We collect it through cookies and similar technologies — and no non-essential tracking runs until you consent through our cookie banner. Our Cookies Policy has the details.

Third parties and public sources: we may receive personal information about you from the third parties and public sources set out below.

Technical Data, for example from:

Our analytics providers;

Advertising platforms that measure our campaigns;

Search providers that bring visitors to our sites.

Contact, Financial and Transaction Data from the providers of our technical and payment services, such as our card payment processors.

Identity and Contact Data from publicly available sources, such as government business registries — for example, when we work with your employer.

2.3. We do not collect any sensitive (“special category”) personal information: details of race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade-union membership, health, or genetic and biometric data. Nor do we collect information about criminal convictions or offences.

2.4. If you contact us, we may keep a record of the correspondence, call or chat.

2.5. We may monitor or record your communications with us to develop our sites and services, to train our team, and where a court, regulator or law-enforcement body orders it.

3. How do we use your personal information?

3.1. We use your personal information only for the purposes set out in this policy or in the relevant part of the sites, and only as the law permits.

3.2. We may use your personal information to:

Verify your identity;

Manage our relationship with you — registering your account, telling you about changes to this policy, or inviting you to leave a review or take a survey;

Provide and administer the sites and our services, keep them running properly — troubleshooting, data analysis, testing and research — and improve your experience;

Perform our contract with you: providing the training you have purchased, managing payments, fees and charges, and collecting money owed to us;

Send you service messages (not marketing) about safety training you have purchased;

Send you email notifications you have specifically requested;

Send you our newsletter and marketing about our training and, only where you have expressly agreed, offers from selected partners;

Handle your enquiries and complaints;

If you buy training from us, you will be asked for payment card details. All card transactions are handled by third-party payment providers through a secure online payment gateway; we keep no record of your card details ourselves. Your card information is used only to process your payment and to prevent and detect fraud. Review the providers’ privacy policies, available on their websites, before providing your details.

4. Marketing and consent

4.1. We may use your personal information to work out which of our courses and offers are likely to interest you (“marketing”).

4.2. We send marketing email only with your consent, as Canada’s anti-spam law (CASL) requires. Consent can be express — you asked for our updates — or implied for a limited time after you deal with us: a purchase counts as implied consent for up to two years, an enquiry for six months. Implied consent lapses on its own after that.

4.3. We will always get your express consent before sharing your personal information with any third party for its own marketing.

4.4. You can stop marketing at any time: every message we send includes an unsubscribe link, and you can also simply ask us. Unsubscribing is free and takes effect within ten business days at the latest — usually much sooner.

5. Our legal grounds for using your personal information

5.1. Canadian privacy law rests on your consent; the GDPR, which applies to us as a company established in Romania, lists specific legal bases. In practice we rely on the grounds below, and sometimes on more than one at once.

Contract: to enter into a contract with you and honour it. This covers providing the training you have purchased, registering and managing your account, and sending you service updates.

Consent: where you have agreed to a use of your personal information — for example, opting in to marketing email. You can withdraw your consent at any time; section 10 explains how.

Legal Obligation: where processing is necessary to meet a legal or statutory requirement — tax and accounting rules, for example, or cooperating with a police investigation.

Legitimate Interest: where processing is necessary for our legitimate interests (a GDPR basis) and your rights do not override them: improving our sites and services, understanding how they are used, market research, running our business, and keeping the sites secure for everyone. For Canadian customers we hold every such use to Canadian law’s own test — a purpose a reasonable person would consider appropriate in the circumstances.

6. Who we share your personal information with

6.1. We do not give your personal information to third parties except as set out in this policy.

6.2. We may share it with our employees, officers, agents, suppliers or subcontractors where reasonably necessary for the purposes in this policy.

6.3. We may share it within our corporate group: our subsidiaries, our ultimate holding company and its subsidiaries.

6.4. We may also use or share your personal information as follows:

To give third parties statistical information about our users — never in a form that identifies you personally;

With the service providers that support our sites and services from time to time, including our live-chat provider.

6.5. In addition, we may share your personal information:

Where the law requires it, or in connection with legal proceedings;

To establish, exercise or defend our legal rights, including for fraud prevention;

If we ever sell or buy a business or assets — with the prospective buyer or seller and their advisers. If our business is sold, your details pass to the new owner so that your training and certificates continue without interruption; we notify you of the change, and the disclosure stays within what privacy law allows. Your personal information is never itself the thing being sold.

6.6. We use Microsoft Advertising and its Universal Event Tracking (UET) tag to measure advertising performance and conversions. Microsoft collects or receives personal information from our sites and from us to provide Microsoft Advertising, including reporting, measurement and, where enabled, audience features. For information about how Microsoft processes this information, read the Microsoft Privacy Statement.

6.7. We may also share information with our legal and professional advisers and, in line with the relevant legislation, with the police and other public or governmental bodies for the prevention or detection of offences and the prosecution of offenders.

7. Where your information is stored, and international transfers

7.1. We operate in Canada and in the European Union, so your personal information may be processed in both. Depending on where you live, that can mean a transfer outside Canada or outside the European Economic Area (EEA).

7.2. Some of our service providers are also based outside Canada or the EEA, so their processing can involve an international transfer too.

7.3. Whenever your personal information leaves the EEA, we make sure it keeps an equivalent level of protection through at least one of these safeguards:

It goes to a country the European Commission has recognised as providing adequate protection — Canada holds that recognition for commercial organisations. For further details see How the EU decides whether a non-EU country protects personal data adequately ;

Or the transfer is covered by contracts approved by the European Commission that give personal data the same protection it has in Europe. For further details, see Standard contractual clauses for data transfers between EU and non-EU countries .

For Quebec customers: before communicating personal information outside Quebec, we assess that it will receive adequate protection there, as Quebec law requires. Please if you want details of the specific safeguard used for any transfer.

8. Security of your personal information

8.1. No transmission over the internet is completely secure. We protect data in transit, but we cannot promise absolute security for information travelling over the internet.

8.2. We use appropriate security measures to prevent your personal information from being accidentally lost, altered, disclosed, or accessed without authorisation. We limit access to the people who need it for their work — employees, agents, contractors and service providers — and they process it only on our instructions, under a duty of confidentiality.

8.3. We have procedures for any suspected breach. If a breach creates a real risk of significant harm, we notify you and the appropriate regulator, and we keep a record of the incident — as Canadian and Quebec law require.

8.4. Keep your password and login details confidential. We will never ask you for your password.

9. How long we keep your information

9.1. We keep personal information only as long as we need it for the purpose we collected it, including legal, accounting and reporting requirements. If you have an account, we keep your information while the account is live. The platform also cleans up after itself: a certificate that expires and is not renewed within three months is removed from your account, and an account left holding nothing — no credit and no certificate — is removed automatically.

9.2. In some circumstances you can ask us to delete information sooner — see Deletion under “Your rights” below.

9.3. We may anonymise information so it can no longer be linked to you, and use it for research or statistics indefinitely.

10. Your rights

10.1. You have rights over your personal information while we hold it. Exactly which law grants each right depends on where you live — PIPEDA and provincial law in Canada, Law 25 in Quebec, the GDPR in the EEA — and we honour requests under all of them:

Right of access - you can ask for a copy of the personal information we hold about you. Under Canadian federal law we respond within thirty days. If we ever have to refuse a request, we tell you why.

Right of correction - you can have inaccurate or incomplete information about you corrected.

Deletion - you can ask us to delete information we hold about you. In the EEA this is the GDPR’s “right to be forgotten”; in Quebec it includes asking us to de-index content. Elsewhere in Canada there is no blanket erasure right — but you can withdraw consent at any time, and when you ask, we delete whatever we have no legal reason to keep.

Right to restriction of processing - in certain circumstances you can ask us to limit what we do with your information while a question about it is resolved.

Right of portability - you can ask for personal information you gave us in a structured, commonly used electronic format, to take to another organisation. The GDPR provides this in the EEA; Quebec’s Law 25 has provided it since September 2024.

Right to object - you can object to certain uses of your information — above all direct marketing. Object to marketing and we stop.

Right to complain - you can complain to a privacy regulator; section 14 tells you who that is where you live.

Please with any question about your rights, or to exercise any of them. If a third party named in this policy is involved in processing your information, we forward your request to them as well.

11. Updating your information

11.1. Tell us if any personal information we hold about you needs to be corrected or updated.

12. Changes to this policy

12.1. When we change this policy, we post the new version on our sites. Check this page occasionally so you know the terms you are on.

12.2. For significant changes, we may also notify you by email.

13. Third-party websites

13.1. Our sites link to third-party websites, plug-ins and applications. Following those links may allow third parties to collect or share information about you. We do not control those websites and are not responsible for their privacy practices — read the privacy policy of every site you visit.

14. Contact and complaints

14.1. If you are unhappy with how eSafetyFirst Canada — or a third party described in this policy — has handled your personal information, or with how a complaint has been dealt with, please first, and our Privacy Officer will look into it. If you are not satisfied with our answer, you can complain to the privacy regulator where you live: in Canada, the Office of the Privacy Commissioner of Canada; in Quebec, the Commission d’accès à l’information; in the EEA, your national supervisory authority — for Romania, where we are established, the National Supervisory Authority for Personal Data Processing (ANSPDCP).

If you have any other question about this policy or how we treat your personal information, please visit the ‘’ section of our website.