PRIVACY POLICY
This Privacy Policy explains how TGMT-Systems Inc. ("TGMT", "Kohezion", "we", "us", or "our") collects, uses, discloses, protects, retains, and otherwise processes Personal Information in connection with the Kohezion website, platform, services, support, professional services, and related business activities.
This Policy replaces the prior Kohezion privacy policy. It should be read together with the Kohezion License Agreement, applicable Order Forms, Data Processing Addenda (DPAs), Business Associate Agreements (BAAs), and the Kohezion Security Statement. If a DPA or BAA applies and expressly conflicts with this Policy for the processing it governs, the DPA or BAA controls to the extent of that conflict.
Contents
2. Personal Information we collect
3. How we use Personal Information
4. Consent and lawful processing
5. Customer Content and customer-controlled data
6. Artificial intelligence and Karla
7. When we disclose Personal Information
8. Hosting, data residency, and cross-border processing
9. Security safeguards
10. Retention, deletion, and anonymization
11. Privacy and security incidents
12. Cookies and similar technologies
13. Marketing communications
14. Your privacy rights and choices
15. Children and minors
16. Third-party websites and integrations
17. Business transactions
18. Changes to this Privacy Policy
19. Privacy Officer and contact information
1. Scope and our role
This Policy applies to Personal Information that TGMT handles in connection with:
- the public Kohezion websites, including www.kohezion.com and related pages operated by TGMT;
- Kohezion accounts, free trials, subscriptions, and administrative or billing relationships;
- the Kohezion platform and related hosted services;
- customer support, training, implementation, migration, customization, and other Professional Services;
- Karla and other optional artificial intelligence or automated features;
- sales, marketing, events, newsletters, and business communications; and
- job applications, vendor relationships, and other direct interactions with TGMT.
TGMT may act in different roles depending on the information involved. For Personal Information that we collect for our own business purposes, such as website inquiries, billing contacts, account administration, security logs, or marketing preferences, TGMT generally determines the purposes for which that information is processed. For Customer Content that a customer submits to Kohezion, the customer generally determines why the information is collected and how it is used, and TGMT processes that information on the customer's behalf as described in Section 5.
This Policy is intended to describe our practices under applicable privacy laws, which may include the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Act respecting the protection of personal information in the private sector, as applicable. Other laws may provide additional rights depending on where an individual is located.
2. Personal Information we collect
2.1 Information you provide directly
Depending on how you interact with TGMT, we may collect information such as:
- name, business email address, telephone number, organization, title, and other business contact information;
- account registration information, username, administrator information, authentication and security settings;
- subscription, billing, invoice, purchasing, and transaction information;
- information contained in requests for information, sales inquiries, meeting bookings, support requests, surveys, feedback, or other communications;
- information provided in connection with implementation, configuration, training, migration, or other Professional Services;
- job application and recruitment information if you apply to work with TGMT; and
- marketing and communication preferences.
2.2 Customer Content
Customers and Users may submit data, records, documents, files, images, forms, application data, workflow information, and other content to the Kohezion platform ("Customer Content"). Customer Content may include Personal Information about employees, customers, patients, clients, suppliers, applicants, members, or other individuals. TGMT does not determine the content a customer chooses to submit, subject to the restrictions in the Kohezion License Agreement and any applicable DPA or BAA.
2.3 Usage, device, and security information
When you use our websites or Services, we may automatically collect technical and usage information, including:
- IP address, browser and device type, operating system, language, time zone, referring and exit pages, and similar device information;
- login times, account activity, feature usage, page or application interactions, and diagnostic information;
- audit, authentication, access, security, API, error, and system logs; and
- cookie identifiers and analytics information, subject to your cookie choices where required.
2.4 Information from other sources
We may receive Personal Information from a customer administrator, an authorized User, a payment processor, an identity provider, a customer-requested integration, a referral source, a business partner, or another person where permitted by law. If a customer provides Personal Information about another individual, the customer is responsible for having the authority to provide that information to TGMT.
2.5 Payment information
TGMT may use third-party payment processors or billing providers. Payment providers may collect payment card or banking information directly under their own terms and privacy practices. Unless TGMT expressly states otherwise, TGMT does not intentionally collect or store full payment card numbers through the Kohezion platform. We may receive limited transaction information, such as billing contact information, payment status, invoice details, transaction identifiers, and limited payment-method information needed for accounting, fraud prevention, and customer support.
3. How we use Personal Information
We may use Personal Information for the following purposes, as appropriate to the relationship and permitted by law:
- to create, authenticate, administer, secure, and support Kohezion accounts;
- to provide, operate, maintain, troubleshoot, and improve the Services and Professional Services;
- to process subscriptions, invoices, payments, renewals, plan changes, and other commercial transactions;
- to respond to inquiries, provide technical support, communicate about service changes, and manage customer relationships;
- to configure and provide customer-requested features, integrations, exports, workflows, and automations;
- to prevent, detect, investigate, and respond to fraud, abuse, unauthorized access, security events, and violations of our agreements;
- to maintain audit trails, service logs, backups, business continuity, and operational records;
- to perform analytics, measure website and product usage, and improve usability, performance, security, and reliability;
- to send newsletters, product information, event information, or other marketing communications where permitted, subject to applicable opt-out rights;
- to comply with legal, regulatory, contractual, tax, accounting, insurance, and law-enforcement obligations; and
- to establish, exercise, or defend legal rights and claims.
We may also create and use aggregated or de-identified information that does not identify and cannot reasonably be used to identify a customer, User, or individual. We may use such information for security, analytics, benchmarking, service development, and business improvement, subject to applicable law and any applicable BAA.
4. Consent and lawful processing
We collect, use, and disclose Personal Information only where we have a lawful basis to do so under applicable law. Depending on the circumstances, this may include consent, performance of a contract, compliance with a legal obligation, protection of legitimate business or security interests, or another basis permitted by law.
Where consent is required, we seek consent in a manner appropriate to the sensitivity of the information and the context. Consent may be withdrawn where permitted by law, subject to legal or contractual restrictions and reasonable notice. Withdrawal of consent may affect our ability to provide a requested feature or service when the information is necessary for that purpose.
We limit collection to information reasonably necessary for identified purposes and do not require Personal Information that is not necessary to provide a requested product or service, except as permitted by law.
5. Customer Content and customer-controlled data
Customer Content is governed primarily by the customer's instructions and the Kohezion License Agreement. As between TGMT and the customer, the customer owns Customer Content, subject to the limited rights TGMT needs to provide, secure, maintain, and support the Services.
When TGMT processes Personal Information contained in Customer Content on behalf of a customer:
- the customer is responsible for determining the purposes and lawful basis for collecting and using that information;
- the customer is responsible for providing required notices and obtaining required consents or other authority;
- TGMT processes the information to provide the Services, perform customer-requested Professional Services, maintain security and reliability, comply with law, and otherwise follow authorized customer instructions;
- where applicable law requires contractual data-processing terms, the customer must execute TGMT's applicable DPA before submitting the affected Personal Information; and
- individuals seeking access, correction, deletion, or another right concerning information controlled by a Kohezion customer should generally contact that customer first. TGMT will reasonably assist the customer as required by applicable law, a DPA, or a BAA.
Regulated Data. Customers must comply with the Regulated Data restrictions in the Kohezion License Agreement. Protected health information (PHI) under HIPAA may be processed only through an eligible Kohezion plan or environment after a BAA has been executed. Other specialized categories of regulated data may require a particular plan, configuration, DPA, BAA, or written approval from TGMT.
6. Artificial intelligence and Karla
Certain optional Kohezion features, including Karla, may use third-party artificial intelligence providers acting as TGMT subprocessors to process Customer Content for the feature requested by the customer.
- TGMT does not use Customer Content to train TGMT or third-party artificial intelligence or machine-learning models.
- TGMT engages AI providers under terms that do not permit Customer Content submitted through the Services to be used to train their models.
- AI features are optional and may be enabled or disabled subject to the customer's plan and account settings.
- Customers are responsible for deciding what information to submit to an AI feature and for ensuring they have the legal authority to do so.
- For Accounts subject to a BAA, AI use involving PHI is limited to providers and configurations permitted under the applicable BAA and TGMT's HIPAA program.
AI-generated output may contain or reflect Personal Information included in the input. Customers should independently review AI output before relying on it and should not use AI features for prohibited or unsupported categories of data.
7. When we disclose Personal Information
We do not sell Customer Content or Personal Information as a data product. We may disclose Personal Information in the following circumstances:
7.1 Service providers and subprocessors
We may use Affiliates, contractors, and service providers to help operate our business and provide Kohezion. These may include cloud hosting providers such as Amazon Web Services (AWS), communications and email providers, payment processors, analytics providers, security and monitoring providers, support tools, AI providers, professional advisers, and other technology vendors. We limit their access to what is reasonably necessary for the applicable service and impose contractual confidentiality and data-protection obligations where required by law, a DPA, or a BAA.
7.2 Customer-requested integrations
If a customer connects or requests a third-party service or integration, the customer authorizes TGMT to exchange the information necessary to provide that integration. Once information is provided to an independent third party at the customer's direction, that third party's terms and privacy practices may apply.
7.3 Legal requirements and protection of rights
We may disclose Personal Information where required or permitted by applicable law, regulation, subpoena, court order, governmental request, or legal process, or where reasonably necessary to protect the rights, security, property, or safety of TGMT, our customers, Users, or others. Where legally permitted and commercially practicable, we may notify an affected customer before a compelled disclosure of Customer Content.
7.4 Professional advisers
We may disclose information to legal counsel, auditors, accountants, insurers, financial advisers, and other professional advisers where reasonably necessary for legitimate business, compliance, or legal purposes and subject to appropriate confidentiality obligations.
7.5 No sale of Personal Information
TGMT does not sell Personal Information for money. Some analytics, advertising, or embedded-content technologies used on the public website may be treated as "sharing," targeted advertising, or a similar concept under certain privacy laws even when no money changes hands. Where required, we provide cookie or consent controls that allow users to manage non-essential technologies.
8. Hosting, data residency, and cross-border processing
For Customer Content, Canada is the default Hosting Region unless an applicable Enterprise Order Form specifies another Hosting Region. Eligible Enterprise customers may request an alternative region made available by TGMT, including a United States region where available, including for eligible Accounts operating under a BAA.
Data residency refers primarily to the location of Customer Content at rest in primary production data stores and routine backups maintained by TGMT. Unless an Order Form, DPA, or BAA expressly provides otherwise, information may be transmitted through, accessed from, or transiently processed in other jurisdictions by TGMT personnel, Affiliates, subprocessors, or third-party providers as reasonably necessary for support, security, communications, integrations, AI features, disaster recovery, or other customer-requested functionality.
Personal Information collected through our public website or for our own business operations may also be processed in Canada, the United States, or other jurisdictions where our service providers operate. Information processed in another jurisdiction may be subject to the laws of that jurisdiction and may be accessible to courts, law-enforcement, or governmental authorities in accordance with applicable law.
Where applicable law requires an assessment or contractual safeguards before Personal Information is communicated or entrusted for processing outside Quebec or another jurisdiction, TGMT will implement the required measures before the applicable transfer.
9. Security safeguards
TGMT maintains administrative, technical, and physical safeguards designed to protect Personal Information against loss, theft, unauthorized access, use, disclosure, modification, or destruction. Safeguards are selected having regard to the sensitivity, quantity, distribution, purpose, and format of the information and may include:
- authentication, authorization, and role-based access controls;
- encrypted network communications using Transport Layer Security (TLS/HTTPS);
- logging, monitoring, audit trails, security reviews, vulnerability management, and incident response procedures;
- backup, recovery, business-continuity, and disaster-recovery measures;
- access restrictions for personnel and contractors based on business need;
- confidentiality obligations and security/privacy training for personnel; and
- physical and environmental safeguards provided through our hosting infrastructure and service providers.
No method of transmission, storage, or security control is completely risk-free. Customers are also responsible for protecting credentials, configuring permissions and security settings appropriately, managing Users, and using the security controls made available for their plan.
Additional information about Kohezion security practices is available in our Security Statement: https://www.kohezion.com/security-statement
10. Retention, deletion, and anonymization
We retain Personal Information only for as long as reasonably necessary for the purposes for which it was collected or as required or permitted by applicable law, contract, accounting requirements, dispute-resolution needs, security requirements, or legitimate business needs.
Retention periods vary depending on the type of information. For example:
- account, billing, contract, and transaction records may be retained as required for administration, tax, accounting, audit, legal, and dispute-resolution purposes;
- security, access, fraud-prevention, and diagnostic records may be retained for periods reasonably necessary to protect the Services and investigate incidents;
- marketing contact information may be retained while there is an active business relationship or legitimate marketing purpose, subject to opt-out rights and applicable law; and
- Customer Content is retained according to the customer's subscription, the Kohezion License Agreement, applicable Order Forms, DPAs, BAAs, and TGMT's then-current retention and deletion procedures.
Following termination or expiration of a Kohezion subscription, customers generally have a limited post-termination export period as described in the License Agreement. After the applicable period, TGMT may delete Customer Content from active systems. Residual copies may remain in routine backups, security records, or legally required archives until overwritten or deleted in the ordinary course.
Where permitted by law, we may anonymize information instead of destroying it when the information is no longer required in identifiable form and the anonymized information will be used for a serious and legitimate purpose.
11. Privacy and security incidents
TGMT maintains procedures to respond to suspected or confirmed confidentiality and security incidents involving Personal Information. We assess incidents, take reasonable measures to contain and reduce risk, investigate causes, and take steps intended to prevent recurrence.
Where required by applicable law, a DPA, or a BAA, TGMT will provide required notifications to customers, affected individuals, regulators, or other authorities. Notification timing, content, and responsibility may depend on TGMT's role in relation to the affected information and on the applicable contractual and legal requirements.
12. Cookies and similar technologies
Our public websites use cookies and similar technologies for functionality, security, preferences, analytics, and embedded content. Some non-essential cookies may be placed only after consent where required.
Examples of cookie categories that may be used include:
- Necessary cookies – required for core website functionality, security, session management, or requested features;
- Analytics cookies – used to understand how visitors use our websites and to improve performance and content, including analytics services such as Google Analytics where enabled;
- Embedded-content cookies – used by third-party content such as embedded video services, including YouTube where enabled; and
- Advertising or marketing cookies – used where enabled to measure campaigns or provide more relevant marketing, subject to applicable consent requirements.
You can manage non-essential cookies through the cookie settings or consent controls presented on the Kohezion website. Browser settings may also allow you to block or delete cookies, although disabling certain cookies may affect website functionality.
For additional information about website cookies and available controls, see: https://www.kohezion.com/online-data-privacy
13. Marketing communications
We may send product information, newsletters, event information, educational materials, or other commercial communications where permitted by law. Marketing emails include an unsubscribe mechanism where required. You may opt out of promotional communications at any time. We may still send non-promotional communications that are necessary to administer an account, provide requested Services, address security matters, issue invoices, or communicate important contractual or operational information.
14. Your privacy rights and choices
Depending on applicable law and the nature of our relationship with you, you may have rights concerning your Personal Information, including the right to:
- request information about the existence, use, and disclosure of your Personal Information;
- request access to Personal Information we hold about you;
- request correction of inaccurate or incomplete Personal Information;
- withdraw consent where processing is based on consent and withdrawal is legally available;
- request deletion, de-indexing, restriction, or cessation of certain processing where applicable;
- request a copy or transfer of eligible computerized Personal Information in a structured, commonly used technological format where a portability right applies;
- object to or opt out of certain marketing, analytics, advertising, profiling, or automated processing where applicable; and
- submit a complaint about our privacy practices.
These rights are not absolute. We may need to verify identity before responding and may deny or limit a request where permitted or required by law, including where disclosure would reveal information about another person, compromise security, violate privilege, interfere with legal obligations, or concern information we are required to retain.
Customer-controlled information. If your request concerns Personal Information contained in a Kohezion customer's Customer Content, please contact that customer first because the customer generally controls that information. If appropriate, TGMT will assist the customer with the request in accordance with applicable law and contractual obligations.
You may submit a privacy request or complaint using the contact information in Section 19. If you are not satisfied with our response, you may have the right to contact the privacy regulator with jurisdiction over the matter.
15. Children and minors
Kohezion is a business software platform and TGMT does not intentionally market the Services directly to children. Our public website and account-registration processes are not intended for children acting on their own behalf. Customers that use Kohezion to process Personal Information relating to minors are responsible for complying with applicable consent, notice, authorization, and other legal requirements. Where applicable law requires parental or guardian consent for collection directly from a minor, TGMT will follow that requirement for information TGMT collects for its own purposes.
16. Third-party websites and integrations
Our websites and Services may link to or integrate with third-party websites, applications, identity providers, payment services, analytics tools, communication tools, AI providers, or other services. TGMT does not control the independent privacy practices of third parties. We encourage you to review the applicable privacy notice before providing information directly to an independent third party.
17. Business transactions
Personal Information and Customer Content may be disclosed or transferred as permitted by law in connection with a proposed or completed merger, acquisition, financing, corporate reorganization, sale of assets, change of control, or similar business transaction. TGMT will use appropriate contractual or legal safeguards for Personal Information in connection with such a transaction and will provide notice where required by applicable law or contract.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, technologies, legal requirements, or privacy practices. The current version will be posted on the Kohezion website with its effective date. Where required by applicable law, we will provide additional notice of material changes and obtain consent if a new use or disclosure requires consent.
19. Privacy Officer and contact information
TGMT is responsible for Personal Information under its control. Questions, privacy requests, complaints, or concerns may be directed to:
| Organization | TGMT-Systems Inc. |
| Privacy contact | Privacy Officer / Person in Charge of the Protection of Personal Information |
| Address | 1205 Queens Park, Gatineau, Quebec, Canada, J9J 2Z2 |
| Web contact | https://www.kohezion.com/contactus |
| Website | https://www.kohezion.com |
If an applicable law requires a request to be submitted in a particular manner or requires additional information to process the request, we will provide reasonable instructions after receiving the request.
Related Kohezion documents: License Agreement | Security Statement | Data Privacy / Cookies