Privacy Policy
Privacy Policy
Effective Date: June 6, 2023
Last Updated: August 19, 2026
At Myla Training Corp., privacy is not simply a legal requirement. It is part of what we teach.
We believe people should understand what information is being collected about them, why it is needed, how it will be used, and what choices they have.
This Privacy Policy explains how Myla Training Corp. collects, uses, discloses, protects and retains personal information when you visit our websites, purchase or use our services, participate in training, complete a form or Cybersecurity Risk Score, communicate with us, or otherwise interact with Myla.
- Our Privacy Promise
In plain language:
- We collect only the personal information reasonably needed for identified purposes.
- We tell you why we are collecting information before or at the time we collect it.
- We do not sell or rent your personal information.
- We do not secretly turn an ordinary form, survey or Cybersecurity Risk Score into participation in a research study.
- If we want to use identifiable personal information for a materially different purpose, such as a future research or benchmarking initiative, we will provide appropriate notice and obtain consent where required.
- We use service providers when necessary to operate our business, but they do not receive personal information simply so they can market their own products to you.
- We apply safeguards appropriate to the sensitivity of the information in our care.
- You may contact us to ask questions about our privacy practices or to request access to or correction of your personal information.
- You may withdraw consent where applicable, subject to legal, contractual and operational limitations.
- Who We Are
Myla Training Corp. provides privacy, cybersecurity, artificial intelligence safety, training, education, consulting and related services, primarily for dental, healthcare and other professional organizations.
For the purposes of applicable Canadian privacy law, Myla Training Corp. is responsible for personal information under its control.
Our designated Privacy Officer is responsible for overseeing our privacy program and responding to privacy questions, requests and complaints.
Privacy Officer
Myla Training Corp.
Email: [email protected]
Phone: 647-560-3726
Mail: 3600 Steeles Ave. East, Markham, Ontario L3R 9Z7, Canada
- Scope of This Policy
This Privacy Policy applies to personal information collected through:
- Myla websites and webpages
- Online training and learning services
- Purchases and customer accounts
- Cybersecurity Risk Scores and similar self evaluation tools
- Forms, questionnaires and surveys
- Webinars and events
- Consultations and professional services
- Email and other communications
- Marketing and educational communications
- Customer support
- Research initiatives where this policy is identified as applicable
Some programs or activities may have additional privacy notices or consent forms.
If an additional notice applies to a particular collection of information, that notice should be read together with this Privacy Policy.
- Provincial and Federal Privacy Laws
Myla operates across Canada, including with clients in Ontario, Alberta and British Columbia. Myla does not currently offer services to clients in Quebec.
Where the federal Personal Information Protection and Electronic Documents Act (PIPEDA) applies to our collection, use or disclosure of personal information, we comply with PIPEDA. Where Alberta's Personal Information Protection Act or British Columbia's Personal Information Protection Act applies instead of, or in addition to, PIPEDA, we comply with those laws as well.
In general, PIPEDA governs personal information handled in the course of interprovincial or international commercial activity, while Alberta's and British Columbia's provincial legislation may apply to activity conducted wholly within those provinces. Where more than one law could apply, we apply the standard that provides individuals with the greater protection.
- What Is Personal Information?
Personal information generally means information about an identifiable individual.
Depending on how you interact with Myla, personal information may include your name, contact information, professional role, organization, account activity, course activity, responses to forms or questionnaires and other information that can reasonably be associated with you.
Information that has been aggregated or deidentified so that it can no longer reasonably be associated with an identifiable individual may not be treated as personal information under applicable law.
- Information We May Collect
We limit collection to information reasonably necessary for the purposes we identify.
Information you provide directly
Depending on the service, we may collect:
- Name
- Email address
- Telephone number
- Organization or practice name
- Professional title or role
- Province, territory or geographic region
- Account and registration information
- Course enrolment information
- Training progress
- Quiz or knowledge check results
- Course completion and certificate records
- Purchase and transaction information
- Communications you send to us
- Customer support information
- Consultation requests
- Feedback
- Cybersecurity Risk Score responses
- Questionnaire or survey responses
- Preferences and communication choices
- Information voluntarily submitted through forms
Please do not provide patient records, clinical information or other sensitive personal information about another person unless Myla has specifically requested that information for an identified purpose and you are authorized to provide it.
Payment information
Payments may be processed by third party payment service providers.
Myla does not need to receive or retain your complete payment card number in order to provide most services. Payment providers may collect and process payment information under their own privacy and security practices.
Information collected automatically
When you use our website or online services, certain information may be collected automatically, including:
- Internet Protocol address
- Browser type
- Device information
- Operating system
- Pages visited
- Date and time of visits
- Referring pages or links
- General interaction information
- Cookie and similar technology information
We use this information for purposes such as website operation, security, troubleshooting, understanding service use and improving user experience.
- Why We Collect and Use Personal Information
We may collect and use personal information for purposes including:
- Providing requested products and services
- Creating and managing accounts
- Delivering training
- Recording course progress and completion
- Issuing certificates
- Calculating and delivering Cybersecurity Risk Scores
- Responding to inquiries and customer support requests
- Providing consultations and professional services
- Processing transactions
- Maintaining business and accounting records
- Administering events and webinars
- Improving our services and educational content
- Maintaining website and system security
- Preventing misuse and fraud
- Communicating operational or service information
- Sending educational or marketing communications where permitted
- Meeting legal and regulatory obligations
- Investigating and responding to privacy or security incidents
- Establishing, exercising or defending legal rights
- Other purposes that are clearly identified when information is collected
We will not collect, use or disclose personal information for purposes that a reasonable person would consider inappropriate in the circumstances.
- Identifying Purposes and Consent
We aim to identify the purposes for collecting personal information before or at the time it is collected.
The form of consent required depends on factors such as:
- The sensitivity of the information
- The reasonable expectations of the individual
- The purpose for which the information is being collected
- Applicable legal requirements
Consent may be express or implied where permitted by law.
When a purpose is not necessary to provide the product or service you requested, we will provide an appropriate choice where required.
You may withdraw consent to future collection, use or disclosure where applicable, subject to legal or contractual restrictions and reasonable notice.
Withdrawal of consent may affect our ability to provide certain services.
- Cybersecurity Risk Scores, Forms and Questionnaires
Myla may offer Cybersecurity Risk Scores, questionnaires, checklists, self evaluation tools or similar resources.
When you complete one of these tools, we use the information for the purposes identified when the information is collected. For example, information submitted through a Cybersecurity Risk Score may be used to calculate or communicate your score, provide related educational information and administer the service you requested.
Completing a Cybersecurity Risk Score does not automatically enroll you in a research study.
Unless we have clearly told you otherwise before collection and obtained any consent required by law, identifiable responses submitted for a Cybersecurity Risk Score will not be treated as participant data in a separate national benchmarking or research study.
We will not represent you as a research participant merely because you completed a Risk Score or another general Myla form.
- Surveys
Myla may conduct surveys for different purposes.
Some surveys may be used to:
- Collect feedback
- Improve training
- Understand customer needs
- Evaluate educational programs
- Measure user experience
- Gather opinions
- Support specifically identified research
The purpose of a survey will be identified when appropriate.
A general feedback survey does not automatically become a research study.
If information is collected specifically for research, benchmarking or another materially different purpose, additional information or consent may be provided.
- Research and Benchmarking
Myla may conduct or participate in research, industry measurement or benchmarking initiatives.
When we invite individuals to participate in a research or benchmarking initiative that involves the collection or use of identifiable personal information, we will provide information appropriate to the initiative.
Depending on the nature of the project, this may include:
- The purpose of the study
- Who is conducting or sponsoring it
- What information will be collected
- How information will be used
- Whether participation is voluntary
- Whether information will be aggregated or deidentified
- How findings may be published
- Whether third parties will receive or process information
- How long information may be retained
- How participants may withdraw where applicable
- Who to contact with questions
Where appropriate or required, we will obtain specific consent for participation.
New purposes
Personal information collected for one purpose will not simply be repurposed for an unrelated research or benchmarking initiative without appropriate notice and consent where required.
- Aggregated and Deidentified Information
Where appropriate, Myla may create statistics or insights using information that has been aggregated or deidentified.
We take reasonable steps intended to prevent aggregated or deidentified information from identifying an individual.
We may use appropriately aggregated or deidentified information for purposes such as:
- Service evaluation
- Trend analysis
- Program improvement
- Educational insights
- Business planning
- Reporting
- Research where legally appropriate
We will not use aggregation or deidentification as a means of avoiding consent requirements that apply to the original collection or use of identifiable personal information.
- Artificial Intelligence
Myla provides education about responsible artificial intelligence use and recognizes that AI systems can create significant privacy considerations.
We may use technology, including AI enabled tools, to support limited business or administrative activities where appropriate.
When considering AI enabled services, we aim to minimize the amount of personal information involved and evaluate privacy and security risks appropriate to the circumstances.
We do not sell personal information for AI training.
Myla does not intentionally provide personal information to third parties for the purpose of training their general purpose artificial intelligence models unless we have clearly disclosed that purpose and have an appropriate legal basis and consent where required.
We do not use a person's Cybersecurity Risk Score responses to train a public or general purpose AI model.
We will not use AI to make consequential decisions about an individual without appropriate safeguards and transparency where applicable.
Because AI technologies and service provider practices evolve rapidly, we may update this section as our use of AI changes.
- Service Providers
Myla relies on service providers to operate parts of our business.
Depending on the services you use, service providers may assist with:
- Website hosting
- Learning management
- Payment processing
- Email delivery
- Customer communication
- Cloud hosting or storage
- Analytics
- Scheduling
- Video conferencing
- Technical support
- Accounting or business administration
We provide service providers with information only as reasonably necessary for the services they perform for us.
We expect service providers handling personal information on our behalf to protect that information through contractual, technical, organizational or other appropriate safeguards.
Service providers may use subcontractors as part of delivering their services.
Myla remains responsible for personal information under its control in accordance with applicable law.
- Cross Border Processing
Some service providers may store or process personal information outside your province or outside Canada.
This means personal information may be subject to the laws of another jurisdiction and may be accessible to courts, law enforcement, national security authorities or other government bodies in that jurisdiction where legally permitted.
Myla takes reasonable steps appropriate to the circumstances to assess and protect personal information processed by service providers.
If you have questions about cross border processing, contact our Privacy Officer.
- We Do Not Sell Personal Information
Myla does not sell or rent personal information.
We do not provide personal information to unrelated third parties so that they can independently market products or services to you.
This does not prevent us from using service providers that process information on our behalf or from making disclosures permitted or required by law.
- When We May Disclose Personal Information
We may disclose personal information:
- To service providers acting on our behalf
- With your consent
- Where necessary to complete a transaction or provide a requested service
- To professional advisers where appropriate
- To comply with law, regulation, subpoena, court order or lawful government request
- To investigate suspected fraud, misuse, security incidents or unlawful activity
- To protect the rights, safety or property of Myla, our users or others
- In connection with a proposed or completed corporate transaction, subject to applicable privacy requirements
- In other circumstances permitted or required by law
We limit disclosure to what is reasonably necessary in the circumstances.
- Email, Educational Communications and CASL
Myla may send different types of email.
Service communications
We may send communications necessary to provide a service you requested, including:
- Account information
- Purchase confirmations
- Course information
- Certificate information
- Cybersecurity Risk Score results
- Responses to inquiries
- Security or privacy notices
- Other transactional or operational messages
Commercial or promotional communications
Where Canada's Anti Spam Legislation applies, Myla sends commercial electronic messages in accordance with applicable consent, identification and unsubscribe requirements.
Consent may be express or, in circumstances permitted by law, implied.
Submitting a form or completing a Cybersecurity Risk Score should not be interpreted as unlimited consent to receive unrelated marketing communications.
Commercial electronic messages include an unsubscribe mechanism where required.
You may unsubscribe from marketing communications at any time. Unsubscribing from marketing does not necessarily prevent us from sending transactional, security, privacy or other noncommercial communications associated with services you use.
- Cookies and Similar Technologies
Our websites and service providers may use cookies and similar technologies.
These technologies may be used to:
- Enable website functionality
- Maintain sessions or logins
- Remember preferences
- Support security
- Understand website use
- Improve performance
- Measure engagement
Some cookies may be necessary for the website to function.
Other technologies may be provided by third party services.
You may be able to control certain cookies through your browser settings or other tools made available on our website.
Blocking some cookies may affect website functionality.
- Security Safeguards
Myla uses administrative, technical and organizational safeguards appropriate to the sensitivity, amount, format and use of personal information under our control.
Safeguards may include measures relating to:
- Access control
- Authentication
- System security
- Secure transmission or storage where appropriate
- Staff awareness
- Service provider management
- Security monitoring
- Incident response
- Secure disposal
Access to personal information is limited to individuals who require it for legitimate business purposes.
No organization or technology can guarantee absolute security. We therefore continually assess risks and adjust safeguards where appropriate.
- Privacy and Security Incidents
If Myla becomes aware of a privacy or security incident involving personal information, we will investigate and respond according to the circumstances and applicable law.
Where required by law, this may include:
- Taking steps to contain and remediate the incident
- Assessing potential harm
- Maintaining required records
- Reporting the incident to a privacy regulator
- Notifying affected individuals
- Notifying other organizations where appropriate to reduce the risk of harm
- Retention
We retain personal information only for as long as reasonably necessary to:
- Fulfil the purposes for which it was collected
- Provide requested services
- Maintain appropriate business records
- Maintain training or certification records where appropriate
- Meet contractual obligations
- Meet tax, accounting, regulatory or legal requirements
- Resolve disputes
- Protect legal rights
- Meet other legitimate and lawful requirements
Retention periods differ depending on the type of information and the purpose for which it is held.
When personal information is no longer reasonably required, we take appropriate steps to securely destroy, delete or deidentify it, subject to technical, legal and operational limitations.
- Accuracy
We take reasonable steps to keep personal information sufficiently accurate, complete and current for the purposes for which it is used.
You are encouraged to contact us if information we hold about you needs to be corrected.
- Access and Correction
Subject to applicable law, you may request:
- Confirmation of whether Myla holds personal information about you
- Access to personal information under our control
- Information about how it has been used or disclosed
- Correction of inaccurate or incomplete information
We may need to verify your identity before processing a request.
Certain information may be withheld where permitted or required by law.
We will respond within the period required by applicable law.
To make a request, contact:
- Withdrawal of Consent
Where Myla relies on consent, you may withdraw that consent subject to legal or contractual restrictions and reasonable notice.
We will explain relevant consequences of withdrawal where appropriate.
Withdrawal generally applies prospectively and does not invalidate lawful handling of information that occurred before consent was withdrawn.
- Deletion Requests
You may ask us to delete personal information.
We will consider deletion requests in accordance with applicable law and our legal, regulatory, contractual and operational obligations.
We may need to retain certain information even after a deletion request, for example where required for:
- Tax or accounting purposes
- Legal obligations
- Fraud prevention
- Establishing or defending legal rights
- Maintaining required business records
Where deletion is appropriate, we will take reasonable steps to complete it.
- Children and Minors
Myla's services are intended primarily for adults and professionals.
We do not knowingly design our general training and professional services for children.
If you believe a minor has provided personal information to us inappropriately, please contact our Privacy Officer so we can investigate.
- Links to Other Websites
Our websites may contain links to third party websites or services.
Myla is not responsible for the privacy practices of independent third parties.
We encourage you to review the privacy information provided by those organizations before submitting personal information to them.
- Changes to This Privacy Policy
We may update this Privacy Policy as:
- Our services change
- Technology changes
- Our privacy practices evolve
- Laws or regulatory guidance change
The current version will be posted on our website with a revised Last Updated date.
If we make a material change that significantly affects how we handle personal information, we will provide additional notice where appropriate or required.
A change to this policy does not itself authorize Myla to use personal information for an unrelated new purpose where consent is required.
- Questions, Requests and Complaints
We welcome questions about our privacy practices.
If you have a question, access request, correction request, complaint or concern, contact:
Privacy Officer
Myla Training Corp.
Email: [email protected]
Phone: 647-560-3726
Mail: 3600 Steeles Ave. East, Markham, Ontario L3R 9Z7, Canada
We will review privacy complaints fairly and take appropriate steps where a concern is substantiated.
You may also have the right to contact the privacy regulator responsible for your jurisdiction.
For matters governed by the federal Personal Information Protection and Electronic Documents Act, information about privacy rights and complaints is available from the Office of the Privacy Commissioner of Canada at priv.gc.ca. Alberta residents may also contact the Office of the Information and Privacy Commissioner of Alberta, and British Columbia residents may also contact the Office of the Information and Privacy Commissioner for British Columbia.
- Our Accountability Commitment
Privacy is an ongoing responsibility.
Myla maintains and continues to develop policies, procedures, training and oversight intended to ensure that personal information is handled responsibly throughout its lifecycle.
New initiatives that materially change how Myla collects, uses or discloses personal information should receive appropriate privacy review before implementation.
This includes new:
- Forms and surveys
- Cybersecurity Risk Scores
- Research projects
- Benchmark studies
- Marketing automations
- Artificial intelligence tools
- Technology platforms
- Service providers
- Data uses
Our goal is simple: if we would expect another organization to be transparent with our information, we should be equally transparent with yours.