CZENSECONSULTING LTD.
Legal & Data Governance

Privacy Policy

Commitment to privacy, data minimization, and full compliance with the Google API Services User Data Policy, including Limited Use standards.

Effective Date: September 16, 2026Entity: Czense Consulting Ltd.Domain: https://czense.ca

Privacy At A Glance

Zero Data Sale: We never sell, rent, trade, or monetize personal or Google account data.
Google Limited Use: Full adherence to Google API Services User Data Policy requirements.
Authentication Only: Google OAuth is strictly used to identify authorized administrators.
User Control: Instant revocation anytime via Google Security Permissions.

01.Introduction & Scope

This Privacy Policy applies to the website, digital intelligence portal, and administrative platforms operated by Czense Consulting Ltd. ("Czense", "we", "us", or "our") at https://czense.ca.

We are specialized technical architects providing Microsoft Dynamics 365 Finance & Operations and high-volume EDI advisory services. We handle all electronic data with enterprise-grade rigor, confidentiality, and transparency.

Google Compliance Specification

02. Google User Data & OAuth 2.0 Integration

Our website integrates Google Sign-In (OAuth 2.0) provided by Google LLC to authenticate administrative users. Here is how Google data is handled:

A. What Google Data We Access

When you authenticate through Google Sign-In, we request only basic profile scopes (openid, email, profile):

  • Your Google account email address
  • Your basic profile name
  • Your public profile avatar image (if provided)
  • A unique Google account identifier token
Notice: We do NOT request, access, or store sensitive Google scopes such as Gmail messages, Google Drive files, Calendar events, contacts, or passwords.

B. Purpose of Collecting Google User Data

Google user data is used solely to:

  • Verify the identity of the user attempting to sign in.
  • Check if the authenticated email matches our authorized administrator whitelist (ADMIN_EMAILS).
  • Grant access to administrative tools, draft reviews, and news management features.

C. Non-Permitted Uses

We explicitly do NOT use Google user data for:

  • Targeted, personalized, or behavioral advertising.
  • Marketing, commercial telemarketing, or external profiling.
  • Credit, lending, or automated risk assessments.
  • Sale, rental, or transfer to data brokers or advertising exchanges.

Google API Services User Data Policy Disclosure

"Czense Consulting Ltd.'s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements."

03.Data Sharing, Sale & Transfer Prohibition

Czense Consulting Ltd. maintains an absolute zero-sale policy:

  • No Sale of Personal Data: We do not sell, license, rent, trade, or monetize any user data, contact information, or Google account information under any circumstances.
  • No Third-Party Advertising: We do not deploy third-party advertising SDKs, behavioral trackers, or remarketing pixels on our platforms.
  • Authorized Service Providers: Personal data is processed only by essential, SOC 2 / ISO 27001 compliant cloud infrastructure providers (such as hosting and network delivery services) under strict data processing agreements.
  • Legal Compulsion: We will only disclose personal information if required by applicable law, regulation, subpoena, or lawful court order.

04.Data Retention & Security Safeguards

We apply defense-in-depth security measures to protect user data:

Cryptographic Session Tokens

Authentication sessions are managed via stateless, cryptographically signed JSON Web Tokens (JWT) stored in HTTP-only, secure, SameSite cookies. Passwords are never collected or stored.

Transit Encryption (TLS 1.3)

All communications between your browser and our servers are encrypted using modern Transport Layer Security (TLS 1.2 / TLS 1.3) with automated Let's Encrypt certificates.

Retention: Session data is retained only for the duration of your active login session. When you sign out or the session expires, the authentication token is immediately invalidated.

05. Your Rights: Revoking Permissions & Deletion

You maintain complete control over your Google user data and can exercise your rights at any time:

1. Revoke Google OAuth Access

You can instantly disconnect Czense Consulting Ltd. from your Google account via your Google Security portal:

Manage Google Account Permissions

2. Request Complete Data Deletion

To request the complete erasure of any consultation records, logs, or associated user information from our systems, simply contact our privacy desk:

dominic.lee@czense.ca

06.Cookies & Local Storage

Our website uses strictly necessary cookies solely to support secure login sessions:

  • __Secure-next-auth.session-token: Stores signed session state for authenticated administrators.
  • next-auth.csrf-token: Protects sign-in actions against Cross-Site Request Forgery (CSRF).

We do not use advertising or third-party tracking cookies.

07.Contact Information & Inquiries

If you have any questions about this Privacy Policy, our compliance with the Google API Services User Data Policy, or our data handling practices, please contact us:

Czense Consulting Ltd.

Attn: Privacy & Data Protection Officer

Email: dominic.lee@czense.ca

Jurisdiction: Canada / Global Remote