Privacy Policy
LAST UPDATED: JULY 1, 2026
This Privacy Policy describes how ML arteka, a brand of mobileLIVE Inc. (“ML arteka”, “mobileLIVE”, “we”, “us”, or “our”), collects, uses, discloses, and protects your personal information when you visit our websites, engage our services, or interact with us in any capacity.
1. Introduction
- ML arteka is the market-facing brand of mobileLIVE Inc., a technology consultancy serving enterprise clients across financial services, telecom, and retail in North America. Our capabilities span Data & AI, Cloud & Engineering, Experience, Enterprise Platforms, and Spec-Driven Delivery. We are committed to protecting the privacy and security of your personal information.
- This policy applies to information collected through our website at mlarteka.com and mlarteka.ca (the “Websites”), our marketing and sales activities, our client engagements and related services (the “Services”), and any other interactions you have with us.
- ML arteka is headquartered in Canada and serves enterprise clients across North America. We comply with applicable data protection laws in the jurisdictions where we operate, including the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, the European Union General Data Protection Regulation (GDPR) and UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and other applicable state and national data protection laws.
- By using our Websites or Services, you acknowledge that you have read and understood this policy. If you do not agree with the practices described here, please do not use our Websites or Services.
2. Data Controller Information
For the purposes of applicable data protection legislation, the party responsible for your personal information is:
| Entity | ML Arteka | mobileLIVE Inc. |
| Address | 207 Queens Quay W, Unit 320, Toronto, ON M5J 1A7 |
| privacy@mlarteka.com | |
| Websites | mlarteka.com / mlarteka.ca |
| May evolve during discussion | Must be validated before build |
| Answers “why” | Answers “what” and “how success is measured” |
Where we process personal information on behalf of a client as part of a services engagement, we act as a service provider and data processor. In those cases, the client remains responsible as the controller for having the appropriate lawful basis and consent for the data shared with us. Such processing is governed by the applicable services agreement and, where relevant, a data processing agreement.
3. Information We Collect
We collect personal information in several ways, depending on how you interact with us. The categories are set out below.
3.1 Information you provide directly
| Category | Details |
|---|---|
| Contact information | Name, email, phone, company, job title, and mailing address, for example when you complete a form, request a consultation, subscribe, or contact us. |
| Account credentials | Username and password, if you create an account to access a client portal or resource. |
| Communication data | The content of emails, messages, chat transcripts, and form submissions you send us. |
| Professional information | Company, industry, role, department, and business requirements shared during sales, onboarding, or delivery. |
| Payment information | Billing details, only where applicable to a paid engagement. |
3.2 Information collected automatically
When you visit our Websites, we automatically collect technical and usage information through cookies and similar technologies, including some provided by third parties.
| Category | Details |
|---|---|
| Device information | Browser type and version, operating system, device type, and identifiers. |
| Usage & behavioral data | Pages visited, time on page, referring URLs, navigation paths, and content interactions, used to understand and improve the site. |
| Network information | IP address, approximate (city or country) location, and connection details. |
| Cookie & tracking data | Session identifiers, preferences, and analytics data from first- and third-party cookies and pixels. See Section 9. |
| Third-party analytics and advertising | We use tag management and analytics tools on our Websites. GA4, Google Ads, Meta, Pixel, LinkedIn Insights Tag, HubSpot Tracking, RB2B, Expertsie.ai |
3.3 Information from third parties and lead generation
We may receive personal information from business partners and referral sources, publicly available business directories, social and advertising platforms (such as LinkedIn), and marketing or lead-generation partners. When you engage with our ads, sponsored content, events, or downloadable resources, we may collect the professional details you submit through those platforms’ lead forms. That information is handled under this policy and the relevant platform’s own policy.
3.4 Client information processed during engagements
When delivering consulting, engineering, or managed services, we may process information that resides in or originates from a client’s systems, which can include personal information about the client’s employees, customers, or vendors. We process such information solely as a service provider, on the client’s instructions, for the purpose of delivering the contracted Services, governed by the applicable services agreement and data processing agreement. We do not own, sell, or repurpose client data.
3.5 Anonymized case studies
We may use anonymized, aggregated descriptions of engagements and outcomes for marketing. These do not identify a client unless the client has given explicit written permission, and any named disclosure is limited to what that client has approved.
4. How We Use Your Information
We use personal information for the following purposes:
| Purpose | Details |
|---|---|
| Service delivery | To scope, deliver, and support our consulting and engineering Services; manage your account; and, where applicable, process payments. |
| Communications | To respond to inquiries and requests; send service and security notices; and send marketing about our Services and events, with consent where required. |
| Analytics & improvement | To understand site usage and improve experience, conduct internal research, and produce aggregated, de-identified insights. |
| Case studies & marketing | Creating anonymized examples of our work. Client names are never disclosed without written permission. |
| Legal & compliance | To meet legal obligations, enforce agreements, protect rights and safety, and prevent fraud and security incidents. |
| Business operations | To manage client and partner relationships, support a possible merger, acquisition, or asset sale (under confidentiality), and maintain records. |
5. Legal Bases for Processing
If you are located in the European Economic Area (EEA), the United Kingdom, or another jurisdiction that requires a lawful basis for processing, we rely on the following bases under the GDPR:
| Legal basis | Applicable processing |
|---|---|
| Contractual necessity (Art. 6(1)(b)) | Processing necessary to deliver Services, manage accounts, process payments, and provide support. |
| Legitimate interests (Art. 6(1)(f)) | Site analytics, service improvement, security, fraud prevention, and direct marketing to existing business contacts, balanced against your rights and freedoms. |
| Consent (Art. 6(1)(a)) | Marketing to new contacts and placing non-essential cookies. You may withdraw consent at any time, without affecting the lawfulness of prior processing. |
| Legal obligation (Art. 6(1)(c)) | Tax and accounting records, responding to lawful requests, and cooperating with regulators. |
We do not intentionally collect special-category or sensitive personal data (such as health, biometric, racial, religious, or political data).
6. Data Sharing and Disclosure
We do not sell your personal information, and we do not rent, trade, or otherwise make it available to third parties for their own marketing without your consent. We share it only in these limited cases.
Service providers and subprocessors
We engage trusted vendors who process data on our behalf under contract, bound to security and data-protection obligations and permitted to process data only on our instructions. Our current providers include:
| Provider | Category | Purpose |
|---|---|---|
| HubSpot | CRM & email marketing | Lead tracking, sales pipeline, and marketing or transactional email. |
| GA4 | Analytics | Website analytics and tag management. |
| Google Ads, Meta Pixel, Linkedin Insight Tag | Advertising | Advertising and lead generation. |
| WordPress, Godaddy | Hosting / CDN | Website hosting, DNS, and content delivery. |
This list may be updated from time to time. Material changes to our subprocessor list will be communicated to affected clients in accordance with the applicable data processing agreement.
- Clients (as processor): where we process client data, we share it with that client per the data processing agreement and their instructions.
- Legal requirements: where required by law or legal process, or to protect rights, property, or safety.
- Business transfers: in a merger, acquisition, reorganization, or asset sale, with notice to affected individuals.
- With your consent: where you have explicitly agreed.
7. International Data Transfers
Your information may be stored or processed by providers located outside your country of residence, including in the United States, which may have different data-protection laws. Before transferring personal information across borders, we put appropriate contractual and security safeguards in place.
For transfers from Canada, we apply PIPEDA’s accountability requirements so the information receives a comparable level of protection through contractual and other measures. For transfers of personal information from the EEA or UK, we rely on Standard Contractual Clauses, an applicable adequacy decision (such as the EU adequacy framework for Canada), or another lawful transfer mechanism, together with a transfer impact assessment and supplementary measures where required.
You may request details of the safeguards we use by contacting us at privacy@mlarteka.com
8. Data Security
- We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information we hold. ML arteka operates a SOC 2 program, and our measures include:
- Technical safeguards: access controls on a least-privilege basis, encryption in transit, and monitoring for anomalous activity.
- Organizational safeguards: staff security practices and training, documented incident-response procedures, and security review of third-party vendors.
- No method of transmission or storage is completely secure, but we work continuously to protect personal information and to respond promptly to incidents. For more on our security and governance practices, see our Trust Center at https://www.mlarteka.com/trust-center
9. Cookies and Tracking Technologies
Our Websites use cookies, pixels, and similar technologies, including some from third parties, to enable functionality, understand usage, and support marketing.
| Cookie type | Purpose |
|---|---|
| Strictly necessary (required) | Essential for site function, security, and sessions. Cannot be disabled. |
| Performance / analytics (optional) | Help us understand how visitors use the site. |
| Functional (optional) | Remember preferences, language, and settings. |
| Marketing / targeting (optional) | Support advertising, retargeting, and campaign measurement. |
You can manage non-essential cookies through our consent banner and your browser settings. Optional technologies do not load before you make a choice, and you can reopen cookie settings from the Website footer to change your consent at any time. A geo-aware banner serves the correct consent model based on visitor location, and where required by law we obtain consent before placing non-essential cookies.
Global Privacy Control: we honor Global Privacy Control (GPC) signals as an opt-out of the sale or sharing of personal information where applicable.
Do Not Track: because there is no common industry standard for “Do Not Track” browser signals, our Websites do not currently respond to them. You can still control tracking through your cookie preferences or browser settings.
10. Data Retention
We keep personal information only as long as necessary for the purposes described, to meet legal and regulatory obligations, resolve disputes, and enforce agreements. When information is no longer needed, we securely delete or anonymize it.
| Data category | Retention Period |
|---|---|
| Client / account data | Duration of the relationship plus a defined tail. [Indicative: + 3 years, confirm] |
| Prospect / lead data | From last meaningful interaction, unless consent is renewed. [Indicative: 24 months, confirm] |
| Website analytics | Aggregated analytics retained on an ongoing basis; identifiable session data limited. [Indicative: up to 26 months, confirm] |
| Financial / billing records | As required by tax and accounting rules.[Indicative: 6 to 7 years, confirm] |
| Communication records | As required by tax and accounting rules. [Indicative: 6 to 7 years, confirm] |
| Financial / billing records | From date of communication, or longer if tied to an ongoing relationship or legal matter. [Indicative: up to 3 years, confirm] |
Retention periods marked indicative are proposed defaults pending confirmation by ML arteka | mobileLIVE and counsel.
11. Your Privacy Rights
Depending on your jurisdiction, you may have certain rights regarding your personal information. We respect these rights and respond to valid requests in accordance with applicable law.
11.1 Canada (PIPEDA)
Canadian residents may access the personal information we hold, request correction of inaccuracies, and withdraw consent (subject to legal or contractual limits), and may file a complaint with the Office of the Privacy Commissioner of Canada. We respond to access and correction requests within the timeframe required by law (generally 30 days).
11.2 United States (CCPA/CPRA and comparable state laws)
California residents have the right to know and access, delete, and correct their personal information; to opt out of the sale or sharing of personal information; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights. We do not sell personal information. To exercise rights, contact privacy@mlarteka.com or use “Your Privacy Choices.” We verify requests and respond within 45 days (extendable once by an additional 45 days, with notice). Residents of other US states with comprehensive privacy laws have comparable rights, including to opt out of targeted advertising and to appeal a denied request.
11.3 EEA and UK (GDPR)
If you are in the EEA or UK, you have the following rights under the GDPR and UK GDPR:
| Right | Description |
|---|---|
| Access | Essential for site function, security, and sessions. Cannot be disabled. |
| Rectification | Help us understand how visitors use the site. |
| Erasure | Remember preferences, language, and settings. |
| Restriction | Request that we limit processing in certain circumstances. |
| Portability | Receive your data in a structured, commonly used, machine-readable format. |
| Objection | Object to processing based on legitimate interests or to direct marketing at any time. |
| Withdraw consent | Withdraw consent at any time where processing is based on consent. |
| Lodge a complaint | Complain to your local supervisory authority if you believe your rights have been violated. |
We respond within 30 days of receipt, extendable by up to 60 days for complex requests, with notice. Contact privacy@mlarteka.ai to exercise any of these rights.
11.4 Other frameworks
If you are located in another jurisdiction with applicable data-protection law (for example Brazil under the LGPD or Australia under the Privacy Act 1988), you may have comparable rights. We honor valid requests in accordance with local law. Contact privacy@mlarteka.com to exercise them.
12. Children’s Privacy
Our Websites and Services are not directed to individuals under 18 (or the age of majority in your jurisdiction), and we do not knowingly collect their personal information. If we learn we have done so without appropriate consent, we will delete it promptly. Parents or guardians may contact privacy@mlarteka.com.
13. Third-Party Links and Services
Our Websites may link to third-party sites, services, or platforms we do not operate or control. This policy does not apply to them, and we are not responsible for their practices or content. Please review their privacy policies before sharing information with them.
14. Automated Decision-Making and Profiling
We do not use automated processing that produces legal or similarly significant effects on our Website visitors or marketing contacts. We may use automated lead-scoring (for example within HubSpot) purely to prioritize sales outreach; this does not affect service eligibility, pricing, or terms. If this changes, we will update this policy and, where required, provide notice, obtain consent, or offer human review.
15. Data Breach Notification
If a breach of security safeguards creates a real risk of significant harm, we will notify the Office of the Privacy Commissioner of Canada and affected individuals as required under PIPEDA, and keep records of incidents. Where a breach affects personal information subject to the GDPR, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and notify affected individuals where required. For breaches involving client data we process, we notify the affected client within the timelines in the applicable data processing agreement.
16. Contact Us
If you have questions, concerns, or requests regarding this policy or our data-protection practices, you may contact us using the following information:
| privacy@mlarteka.com | |
| Mailing address | ML arteka | mobileLIVE Inc., 207 Queens Quay W, Unit 320, Toronto, ON M5J 1A7 |
| Websites | www.mlarteka.com |
Privacy inquiries, including access and rights requests, are handled by our privacy team at privacy@mlarteka.com.
If you are not satisfied with our response, Canadian residents may contact the Office of the Privacy Commissioner of Canada (priv.gc.ca); California residents may contact the California Privacy Protection Agency or the California Attorney General’s office; EEA and UK residents may contact their local supervisory authority.
17. Changes to This Privacy Policy
We may update this policy to reflect changes in our practices, technology, or legal requirements. For material changes we will post the updated policy with a revised effective date and, where appropriate, notify clients and registered contacts. Continued use of our Websites or Services after changes take effect constitutes acceptance.
18. Supplementary Provisions
18.1 GDPR representative
ML arteka | mobileLIVE does not currently maintain an establishment in the EEA or UK. If we begin targeting the EEA or UK market such that a representative is required, we will appoint one under Article 27 of the GDPR and publish their contact details here. In the interim, EEA and UK residents may direct privacy inquiries to privacy@mlarteka.com.
18.2 CCPA metrics
Where required by the CCPA, we will make available annual metrics on the number of consumer requests received, complied with, and denied, and the median response time.
18.3 Accessibility
This policy is available in accessible formats on request. Contact privacy@mlarteka.com.
18.4 Governing law
This policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, except where superseded by mandatory data-protection law in your jurisdiction.