Privacy Policy
01 Introduction
Yamlal Gotame ("I", "me") is committed to protecting your privacy. This policy explains how I collect, use, and safeguard personal information submitted through yamlal.gotame.com, in compliance with Quebec's Law 25 (Act respecting the protection of personal information in the private sector) and Canadian federal privacy law (PIPEDA).
This policy applies to information collected through the qualification form on this website and any direct communications related to my fractional vCTO and vCISO advisory services.
02 Information I Collect
When you submit the application form, I collect:
- Full name
- Email address
- Company name
- LinkedIn profile URL (optional)
- Qualification responses: budget range, industry, current challenges, AI maturity, and desired timeline
I do not collect payment information, government ID, health data, or information from individuals under 14 years of age.
03 Why I Collect It
- To evaluate whether there is a mutual fit for fractional advisory services
- To contact you personally to schedule a discovery conversation
- To fulfill legal obligations
I will never use your information for marketing unrelated to our engagement, and I will never sell or rent it.
04 Legal Basis for Processing
Processing is based on your explicit consent (by submitting the form) and my legitimate business interest in evaluating consulting engagements. You may withdraw consent at any time by contacting me directly.
05 Cookies & Tracking
This website uses no analytics tools, advertising pixels, or third-party tracking technologies of any kind.
Your language preference (EN/FR) is stored in your browser's local storage only — it contains no personal information and is never transmitted to any server.
No cookie consent banner is required because no non-essential cookies are set.
06 Third-Party Services
Form submissions are delivered to me via SendGrid (Twilio), a US-based email delivery provider. SendGrid acts as a data processor on my behalf and receives only the information you submit in the form. SendGrid maintains SOC 2 Type II certification and adequate data protection standards.
No other third-party services receive your personal information.
07 Data Retention
Application information is retained for up to 12 months to evaluate fit and potential future engagements. If no engagement begins, data is securely deleted at that point. If an engagement begins, data is retained only as long as necessary for the professional relationship and applicable legal obligations.
08 Security
All data submitted through this website is transmitted over HTTPS (TLS encryption in transit). I apply reasonable technical safeguards to protect data at rest. Email notifications are delivered over encrypted channels.
09 International Transfers
I am based in Canada and data is primarily processed here. Email notifications transit through SendGrid's infrastructure in the United States. SendGrid provides adequate protection through its data processing agreements and certifications.
10 Your Rights
Under Quebec's Law 25 and PIPEDA, you have the right to:
- Access the personal information I hold about you
- Correct inaccurate or incomplete information
- Withdraw your consent and request deletion
- Receive your data in a structured, portable format
- File a complaint with the Commission d'accès à l'information du Québec (CAI) at cai.gouv.qc.ca
To exercise any of these rights, contact me directly. I will respond within 30 days.
11 Policy Updates
If I make material changes to this policy, I will update this page with a revised effective date. For significant changes, I will notify individuals whose data I hold by email where reasonably practicable.