BrkrOps Inc.

Privacy Policy

How we treat your data.
Short version: carefully.

We're an enterprise security shop. We expect to be held to a higher standard than the average vendor — and we hold ourselves there. This page explains, in plain language, what data we collect on brkrops.ca, why, where it goes, and what you can do about it.

Effective: May 12, 2026 · Last updated: July 23, 2026

The short version

  • We don't sell data. Not to ad networks, not to data brokers, not to anyone.
  • The free browser tools (cert inspector, password generator, PEM converter) run entirely on your computer. Nothing you paste into them is sent to us.
  • The domain certificate lookup queries the public crt.sh log. Only the domain name you type is sent — to crt.sh, not to us.
  • The contact form sends your message to admin@brkrops.ca. That's it.
  • We don't use Google Analytics, Meta Pixel, or any third-party tracker. We keep our own anonymous first-party visit counts on a Canadian server — no third parties, and you can opt out with Do Not Track (see section 2.5).
  • You can ask for a copy of your data, or for it to be deleted, at any time — write to admin@brkrops.ca.
  • If you register for training, we store a student account (your name, email, course access and progress) — and you can delete all of it yourself, instantly, from your account page.
  • We're a Canadian company, hosted in Canada, and subject to PIPEDA and Alberta PIPA.

1. Who we are

BrkrOps™ Inc. is a Canadian corporation based in Edmonton, Alberta. We provide enterprise Windows Server / PKI consulting and publish the Truvald™ product. We are the "data controller" responsible for personal information collected through the brkrops.ca website.

Mailing and inquiries: admin@brkrops.ca.

2. What we collect, and why

2.1 Contact form

If you submit the contact form on the Support page, we receive: your name, email address, subject, the Truvald™ version you reported (optional), and your message. These are emailed to admin@brkrops.ca via Resend so we can reply. They are not added to any mailing list.

2.2 Free tool downloads

Each free PowerShell-tool download (CA backup, certificate notifier, etc.) is counted on the server using a small beacon containing the requested filename, a truncated IP address and your browser's User-Agent. This lets us see which tools are popular and detect abuse. We do not link these events to any identity.

Your browser also keeps a local count of your own downloads in localStorage under keys like brkrops_dl_<filename>. This information never leaves your machine — it's there only if you ever want to inspect it. Clearing your browser storage removes it.

2.3 Browser-based tools

The Tools page hosts:

  • Certificate Inspector — parses a pasted PEM certificate using JavaScript inside your browser. The certificate never leaves your browser.
  • Password / PIN Generator — uses your browser's crypto.getRandomValues(). The generated value is never sent anywhere.
  • PEM ↔ Base64 Converter — runs entirely in your browser.
  • Domain Certificate Lookup — queries the public crt.sh Certificate Transparency log. The domain name you type is sent to crt.sh, not to us. We do not log the lookup or store the result.

2.4 Language preference

Your chosen interface language (EN/FR) is stored in localStorage as pref_lang. It never leaves your browser.

2.5 First-party page analytics

We measure how visitors use brkrops.ca so we can improve it — which pages get read, which articles land, where people drop off. This is done with a small piece of our own JavaScript that reports back to a first-party analytics database on a Canadian server operated by BrkrOps Inc. No third-party analytics service is involved — no Google Analytics, no Meta Pixel, no Plausible, no Fathom, nothing else — and the data is never shared with or sold to anyone.

Per page view we record:

  • The page path you visited (e.g. /blog/the-model-has-no-answer/). Query strings are stripped.
  • A truncated (masked) IP address and your browser's User-Agent.
  • The referring URL (the page that linked you here), if any.
  • Roughly how long the page stayed open (time-on-page).
  • An anonymous visitor ID — the brkrops_vid localStorage entry, a random identifier with no link to your name, email, or anything else.

We do not record what you type, what you click beyond page-level navigation, or any form contents. There is no session replay, no heatmapping, and no mouse tracking. Known bot User-Agents are filtered out before anything is stored.

How to opt out: we honour the Do Not Track browser setting — turn it on and no page-analytics beacon is sent. You can also block first-party scripts with a browser extension, or email admin@brkrops.ca and we'll purge records matching your visitor ID or IP range, as required under PIPEDA.

Separately, and only if you accept analytics in the consent banner, your browser keeps a small local visit log in localStorage under brkrops_visit_log (last 200 entries) plus per-page counters. That log never leaves your browser; clear your site storage to remove it.

2.6 Consulting engagements

If you reach out about a consulting project, we will exchange the information needed to scope and deliver it (typically by email and, with your consent, in shared documents you control). That information is governed by the engagement contract we sign with you, not by this website privacy policy.

2.7 Student accounts and the learning platform

If you sign in to the training area, we create a student account. This is the only part of the site where we hold an ongoing personal profile, and it exists only because you chose to register.

  • Sign-in (Google or Microsoft). We use "Sign in with Google" or "Sign in with Microsoft" (OpenID Connect). From your provider we receive and store your name, email address, whether that email is verified, and an opaque provider identifier that links your future logins. We never receive your provider password.
  • Session. When you sign in we set a first-party session cookie (sid) so you stay signed in, and we record the sign-in time, the IP address, and the browser User-Agent for that session. Sessions expire after 30 days.
  • Course access. We store which course you are entitled to and any expiry date. If you redeem a student code, we record that it was used, by whom, and the email it was issued to, so a code cannot be reused.
  • Learning activity. As you work through the curriculum we store your progress through each chunk, your graded-exam attempts and scores, your hands-on lab verification results, and any in-progress lab answers you save so you can leave and resume.
  • Desktop apps. When you sign in from the Lab Builder or Lab Checker desktop apps, we issue a short-lived access token tied to your account so the app can confirm your enrollment. It is held only in the app's memory and expires quickly.

We do not sell, rent, or share any of this, and none of it is used for advertising. You can permanently erase all of it yourself at any time from your account page — see 5.1 Deleting your account below.

3. Service providers we share data with

We use a small number of service providers strictly to operate the website. Each receives only the minimum data needed for its function.

  • Resend — transactional email delivery for the contact form. Resend processes the message on its way to admin@brkrops.ca and is governed by its own privacy policy. It does not use your information for marketing.
  • crt.sh — a public Certificate Transparency log operated by Sectigo. Only the domain name you type into the lookup tool is sent. They publish CT data; we don't control their retention.
  • Google and Microsoft — identity providers for "Sign in with Google / Microsoft." When you choose to sign in, they authenticate you and return your basic profile (name, email) so we can create your student account. That sign-in is governed by their own privacy policies. We do not receive your password.
  • Stripe — payment processing for course purchases. Stripe collects and handles your card details directly on its own systems; we never see or store full card numbers. We receive only a confirmation of a completed purchase so we can issue your access.

We do not use Google Analytics, Meta Pixel, Hotjar, FullStory, or any other third-party analytics, ad, or session-replay tracker on this site. The only usage measurement we do is first-party page analytics hosted on our own Canadian server — see section 2.5 for exactly what is collected and how to opt out.

4. Where your data lives, and for how long

The brkrops.ca site is hosted on infrastructure located in Canada.

  • Contact-form emails sit in our admin inbox under our standard email-retention practice (typically 24 months).
  • Download-tracking entries are retained for 12 months for abuse-detection purposes, then aggregated into anonymous counts.
  • First-party page-analytics entries (anonymous visitor ID, page path, masked IP, referrer, time-on-page) are retained for 12 months, then aggregated into anonymous monthly totals.
  • localStorage data sits in your browser until you clear it.
  • Student-account data (profile, sessions, course access, progress, exam and lab results) is kept only for as long as your account exists. It is removed immediately and permanently when you delete your account from your account page, or when you ask us to. Sessions also expire on their own after 30 days.
  • Redeemed student codes: when an account is deleted, only the non-personal code identifier is kept on a block-list so the code can't be reused — no name, email, or other personal data is retained.
  • Resend-side records are governed by Resend's own retention policy.

5. Your rights

Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Personal Information Protection Act (PIPA), you have the right to:

  • Know what personal information we hold about you.
  • Request a copy of it.
  • Ask us to correct it if it is inaccurate.
  • Ask us to delete it, subject to legal and contractual retention requirements.
  • Withdraw consent for any optional processing.
  • File a complaint with the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner of Alberta if you believe we have mishandled your data.

Email admin@brkrops.ca. We will respond within 30 days.

5.1 Deleting your account

If you have a student account — created when you sign in with Google or Microsoft, which stores your name, email, sign-in identity, course progress and any course access — you can erase it yourself at any time from your account page using Delete my account. This immediately and permanently removes every record tied to you; nothing that could identify you is retained. If you hold active course access, deleting your account ends it at once — there are no refunds, and resuming or reviewing the course later requires a new purchase. You are welcome to register again in the future.

6. How we protect data

  • All traffic to brkrops.ca is served over HTTPS with modern TLS.
  • The contact form is rate-limited and validated server-side before forwarding to email.
  • Admin access to the host and inbox is restricted to a small number of named administrators, using SSH keys and multi-factor authentication.
  • Free tool downloads are Authenticode-signed where applicable so you can verify their origin.

No system is perfectly secure. If we ever discover a breach affecting your personal information, we will notify affected users without unreasonable delay and report it as required under PIPEDA's mandatory breach-notification rules.

7. Cookies and local storage

We don't use tracking cookies. The website uses your browser's localStorage for:

  • pref_lang — your selected interface language.
  • brkrops_vid — an anonymous random identifier used by our first-party page analytics (see section 2.5). It contains no personal information and is never shared with third parties.
  • brkrops_page_visits_*, brkrops_page_first_*, brkrops_visit_log — local-only visit counts, never transmitted.
  • brkrops_dl_*, brkrops_dl_log — local-only counts of your downloads, never transmitted.

Clearing your browser storage removes all of them. No cookies are set for advertising or cross-site tracking.

8. Children's privacy

This site is intended for IT professionals. It is not directed at, and we do not knowingly collect personal information from, anyone under 16.

9. Changes to this policy

If we make material changes to how we handle personal information, we will update the "Last updated" date at the top of this page and, where appropriate, notify affected users by email.

10. Contact

Privacy questions, access requests, complaints, or just feedback on this policy: admin@brkrops.ca.

BrkrOps™ Inc.
Edmonton, Alberta, Canada