Skip to content
Broadsight
  • Platform
    • Platform overview
    • Broadsight AI
    • Analytics & reporting
    • Security
  • Solutions
    • Solutions overview
    • Manage an issueIssues management
    • Handle a media requestMedia relations
    • Keep relationships on trackStakeholder engagement
    • Plan and coordinate contentContent workflows
  • Pricing
  • Resources
    • Customer stories
    • Insights & blog
    • Frequently asked questions
  • Company
    • About Broadsight
    • Contact
  • Request a demo
  • Log in

Log in

Request a demo
  1. Home
  2. Privacy Policy

Legal

Privacy Policy

Last updated September 11, 2026.

Broadsight Technology Corporation (“Broadsight,” “we,” “us,” or “our”) is a corporation incorporated under the laws of British Columbia, Canada, with its principal place of business at 800 Robson Street, Vancouver, British Columbia. Broadsight provides the Broadsight platform, a Canadian-hosted business-to-business software-as-a-service platform used by communications, media relations, stakeholder engagement and public affairs teams to record media interactions, track services and issues, manage stakeholder and partner engagement, and produce analytics and reports.

Broadsight is committed to protecting the privacy of individuals who visit our websites, individuals who access the platform under an agreement between Broadsight and their organization, and individuals whose information is recorded in the platform by our customers. This Privacy Policy (the “Policy”) describes the personal information we collect, how we use, disclose, retain and safeguard it, and the choices and rights available to you.

We handle personal information in accordance with the Personal Information Protection Act (British Columbia) (“PIPA”), the Personal Information Protection and Electronic Documents Act (“PIPEDA”) where it applies to our commercial activities, Canada’s Anti-Spam Legislation (“CASL”) in respect of our commercial electronic messages, and other privacy and data protection laws applicable to us.

1. Scope of This Policy

This Policy applies to personal information we obtain through your use of the Broadsight Properties (as defined below), and when you otherwise interact or communicate with us, including by email, by telephone, at events, and through our sales, onboarding and support processes.

For the purposes of this Policy:

  • “Websites” means our public marketing and content properties, including broadsight.ca and www.broadsight.ca, the legacy properties broadsighttracker.ca and www.broadsighttracker.ca, communications.broadsight.ca (used for our email communications), our knowledge base and resource content, forms hosted on our behalf by HubSpot, and our hosted purchase and signup page at broadsight.square.site.
  • “Platform” means the authenticated Broadsight application and its supporting services, including app.broadsight.ca, the legacy alias app.broadsighttracker.ca, the application programming interface at api.app.broadsight.ca, the protected file and attachment service at files.broadsight.ca, the hosted sign-in, password recovery and multi-factor authentication service operated for us by Amazon Cognito at broadsight.auth.ca-central-1.amazoncognito.com, and the inbound email addresses at ai.broadsight.ca used by the AutoTracker feature.
  • “Broadsight Properties” means the Websites and the Platform, together.
  • “Business Customer” means an organization that has entered into an agreement with Broadsight for access to the Platform. Broadsight is sold to organizations, and not to individual consumers.
  • “Authorized User” means an individual who accesses the Platform under a Business Customer’s agreement, using an account created for that individual by the Business Customer’s administrator or by an authorized Broadsight provisioning process. Individuals cannot self-register for the Platform.
  • “Visitor” means an individual who visits the Websites without accessing the Platform, including prospective customers who request a demonstration, contact us, subscribe to our communications or download resources.
  • “Customer Content” means the records, files and other data that a Business Customer or its Authorized Users create, upload, forward, import or otherwise submit to the Platform, and the outputs generated from that data, as further described in Section 8.
  • “Third Party Services” means websites, products and services operated by third parties that are linked from, embedded in, or integrated with the Broadsight Properties. Third Party Services are governed by their own privacy policies, which we encourage you to review, and this Policy does not apply to them.
  • “Device” means any computer used to access the Broadsight Properties, including a desktop, laptop, tablet or mobile device.

Where we make additional or product-specific privacy notices available, those notices govern to the extent they conflict with this Policy.

2. Our Role in Respect of Different Categories of Information

Our responsibilities differ depending on the information at issue, and it is important to understand the distinction.

  • Information we determine the purposes for. We act as the organization responsible for personal information collected from Visitors through the Websites, for account and authentication information relating to Authorized Users, for technical and security logs generated by the Platform, and for information collected through our sales, billing, marketing and support activities. This Policy governs that information.
  • Information we process on behalf of our Business Customers. We act as a service provider in respect of Customer Content. Our Business Customers determine what information is entered into the Platform, for what purposes, and who may access it. We process Customer Content only to provide, secure, support, maintain and improve the contracted service, in accordance with our agreement with the Business Customer and any applicable data processing addendum. Where this Policy and that agreement differ in respect of Customer Content, the agreement governs.

If you are an Authorized User or an individual whose information appears in a Business Customer’s records, and you wish to exercise a right in respect of Customer Content, please contact the organization that maintains those records. We will assist that organization as required under our agreement with it, and will refer requests we receive directly to it where appropriate.

3. Information We Collect

“Personal information” means information about an identifiable individual. We collect the following categories of information.

Account and profile information

When a Business Customer’s administrator provisions an account, we collect the Authorized User’s name and business email address, together with the role and permissions assigned to that user and the identifier of the workspace, or tenant, to which the account belongs. We record whether multi-factor authentication is enabled. Where an Authorized User elects to use text message as a second authentication factor, we collect and store the mobile telephone number provided for that purpose, and we use it only for authentication. Passwords are managed through Amazon Cognito, our identity provider, and are not stored by Broadsight in the application.

Contact and business information

When you request a demonstration, contact us, subscribe to our communications, download a resource, submit a help or feedback form, or purchase a subscription, we collect the information you provide, which typically includes your name, business email address, telephone number, organization, job title, the content of your enquiry, and, in the case of a purchase, billing and transaction details processed through our payment provider.

Customer Content

The Platform is designed to hold records created by our Business Customers. Customer Content typically includes contact records for journalists, stakeholders, community partners, internal leads and subject matter experts, including names, email addresses, telephone numbers, organizations, titles, regions, tags and custom fields; media interaction records, service log entries, engagement records, content records and calendar entries, including topics, notes, dates and outcomes; file attachments; the body content of emails that Authorized Users intentionally forward to our AutoTracker addresses; and the reports, analytics outputs, exports and artificial intelligence conversation transcripts generated from those records.

Technical, usage and security information

We automatically record information generated by your use of the Broadsight Properties, including internet protocol addresses, timestamps, authentication and sign-in events, high-risk sign-in and account-security events recorded by our identity provider, application and system events, and user activity logs. We also record aggregate onboarding-tour telemetry describing which steps of the in-application guided tour were reached, recorded by workspace, day, tour version, event and step. That telemetry is deliberately designed to exclude individual user identifiers and Customer Content.

Cookies and local storage

We and our service providers use cookies and similar technologies on the Websites and, on a strictly necessary basis, in the Platform. Section 5 describes those technologies and your choices in respect of them.

Information we do not intentionally collect

Broadsight does not intentionally collect government identification numbers, age-verification data, student learning records, medical, therapy or wellness records, biometric identifiers or templates, precise geolocation data, or the personal information of children. We do not purchase, rent or scrape personal information for the Platform, and we do not maintain profiles of individuals for advertising purposes. Under the standard Cloud Service Agreement, Business Customers and Authorized Users must not submit Prohibited Data, including patient/medical/protected health information, financial-account numbers, government identifiers, GDPR special-category data, or similar highly sensitive information, unless expressly permitted by written agreement.

4. How We Collect Information

We collect information from the following sources.

Direct interactions

We collect information you provide when you complete a form on the Websites, request a demonstration, correspond with our sales, onboarding or support teams, attend a meeting or event, purchase a subscription, or use the Platform. Business Customer administrators provide the names and business email addresses of the individuals for whom they create accounts.

Information forwarded to AutoTracker

The AutoTracker feature operates on emails that an Authorized User deliberately forwards to a Broadsight address at ai.broadsight.ca. When an email is forwarded, we receive and scan the message, our background services parse its contents, and a draft record is prepared for review. Forwarded messages may contain the personal information of third parties who did not send the message to Broadsight, including senders, recipients and individuals named in the message. Authorized Users should forward only messages that their organization has determined are appropriate to record in the Platform.

Automated interactions

As is the case when you visit most websites, we receive information as part of the communication connection itself, including network routing information, browser and device characteristics, your internet protocol address (which may indicate your general geographic location or your organization), and the date and time of your request. We also record information about your interaction with the Broadsight Properties, such as which pages were visited and when, using the technologies described in Section 5.

Aggregate and de-identified information

We generate aggregated and anonymized statistics about the use, performance and reliability of the Platform. These statistics are derived from usage data and, in some cases, from queries run across the platform database. They are used to understand usage patterns, to monitor performance and to improve the service. Aggregated and anonymized statistics do not identify any individual or any Business Customer, and we do not attempt to re-identify individuals from them. Where our work with aggregate data brings us into incidental contact with Customer Content, that is a by-product of understanding broader patterns and not a deliberate examination of any particular customer’s records.

5. Cookies, Analytics and Similar Technologies

A cookie is a small file placed on your Device by a web server, which can later be read back by that server. Cookies and comparable technologies, including tags, pixels and browser storage, may record a unique identifier, your preferences, and general usage and volume statistics. Some cookies expire when you close your browser; others persist for a period set by the party that placed them.

The Websites

Our public Websites use analytics, advertising measurement, form, statistics and embedded media technologies provided by third parties. The following table describes them.

Technology or providerPurposeCategory
Google Analytics 4 and Google Tag ManagerMeasures traffic and use of the Websites, and manages the deployment of measurement tags.Analytics and performance
Google Ads conversion trackingMeasures the effectiveness of our advertising and attributes enquiries to campaigns.Advertising and attribution
LinkedIn Insight TagMeasures campaign performance and supports advertising and audience reporting on LinkedIn.Advertising and attribution
HubSpot analytics, forms and cookie bannerHosts our demonstration, contact, resource, help and feedback forms, records form submissions and communication preferences, measures site engagement, and presents our cookie banner.Functional, analytics and marketing
WordPress.com and Jetpack statisticsProvides content management and site statistics for our public content and knowledge base.Functional and analytics
Vimeo and Loom embedded videoDelivers embedded video content on our pages.Functional; may be set by the provider for its own analytics
WordPress and Gravatar assetsDelivers images, avatars and other assets used in our content.Functional

Our cookie banner allows you to accept or decline non-essential cookies on the Websites. You may also control cookies through your browser, which can be set to notify you when a cookie is offered, to reject cookies, or to accept only cookies returned to the originating server. You can generally disable cookies without losing access to the Websites, although some features may not function as intended. Google and LinkedIn each offer their own opt-out mechanisms and advertising controls, which operate independently of our banner.

The Platform

The authenticated Platform does not use advertising pixels, and does not include Google Analytics, Google Tag Manager, LinkedIn, HubSpot or conventional third-party product-analytics software development kits. It uses only the following technologies:

  • a secure, HTTP-only refresh-token cookie, which maintains your authenticated session;
  • three signed content-delivery cookies, which authorize your browser to retrieve the file attachments your permissions allow you to access;
  • limited first-party browser storage, which holds your post-sign-in return address, your selected calendar or log month and comparable display preferences, a short-lived recovery marker, and, where the artificial intelligence assistant is enabled, in-progress job and thread identifiers, a timestamp and pending prompt text; and
  • aggregate onboarding-tour telemetry and authentication and security logging, as described in Section 3.

Local and session storage in the Platform is cleared when you sign out. Because these technologies are strictly necessary to authenticate you, to protect files, to operate features you have requested and to secure the service, they are not subject to a consent banner and cannot be disabled while continuing to use the Platform.

6. How We Use Information

We use the information described in this Policy for the following purposes.

  • To provide and administer the Platform. To provision workspaces and accounts, authenticate Authorized Users, enforce role-based permissions and separation between workspaces, store and process Customer Content, operate the modules and features enabled for a Business Customer, generate reports, analytics, exports and downloadable outputs, and deliver requested reports by email to the address given by the requesting user.
  • To secure the service. To authenticate and re-authenticate users, detect and respond to high-risk sign-ins and suspected account compromise, monitor for unauthorized access, investigate suspected misuse, maintain audit and activity logs, and maintain backups.
  • To support and maintain the service. To respond to help and feedback submissions, troubleshoot faults reported to us, deliver onboarding and customer success services, communicate service and maintenance notices, and administer our agreement with the Business Customer.
  • To improve the service. To understand how features are used, to identify defects and usability problems, and to plan improvements, principally using aggregated and anonymized statistics and the aggregate onboarding telemetry described above.
  • To transact with you. To respond to enquiries, prepare quotations and agreements, process purchases and payments, issue invoices and receipts, and maintain accounting, tax and financial records.
  • To communicate with you about our products. To send newsletters, resources, product announcements and other commercial electronic messages, where you have consented to receive them or where we are otherwise permitted to send them, and to measure the effectiveness of those communications and of our advertising.
  • To comply with legal obligations. To satisfy record-keeping, tax and reporting obligations, to respond to lawful requests from courts, regulators, law enforcement and other public authorities, to establish, exercise or defend legal claims, and to enforce our agreements.

We do not use personal information to make decisions about individuals that produce legal or similarly significant effects, and we do not construct behavioural profiles, risk scores or eligibility assessments about individuals.

7. Artificial Intelligence Features

The Platform includes the following features that use artificial intelligence or automated processing. Each is identified as such in the interface.

  • AutoTracker. AutoTracker creates a draft interaction or service record from an email that an Authorized User has intentionally forwarded to a Broadsight address. The body content of the forwarded message is processed to prepare the draft, which may include suggested classifications and extracted details such as names, email addresses, dates and topics. Internal application header identifiers used to attribute the message to the correct workspace and user are not sent to the model. Every draft is presented to a person for review, and is saved to a log only when an Authorized User accepts it. AutoTracker does not take account actions and does not provide advice or recommendations to individuals.
  • Broadsight AI assistant. Where a Business Customer has enabled the assistant, the assistant responds to prompts submitted within the Platform. Prompts, in-progress job and thread identifiers, timestamps and the resulting conversation transcripts are processed to deliver the feature, and transcripts may be exported by the user.
  • Analytics and Reports. Analytics and reporting features generate visual summaries, dashboards, images and reports from the records in a Business Customer’s workspace. They summarize existing records and do not draw inferences about individuals.

Artificial intelligence processing is performed through the managed artificial intelligence service of our cloud infrastructure provider, under enterprise terms. Inputs are used transiently to generate the requested output. Broadsight does not currently use customer or user data, including aggregated or de-identified Customer Content or Usage Data, to train or improve Broadsight-owned AI/ML models, and does not use Customer Content to train public or third-party artificial intelligence models. We do not permit our providers to use Customer Content, prompts or outputs to train or improve their models. A Business Customer may ask to have one or more artificial intelligence features available in its workspace disabled; the remainder of the Platform continues to function normally if an AI feature is disabled.

Artificial intelligence output can be incomplete or inaccurate. Drafts and generated summaries are working material intended for human review, and should be verified before they are relied upon.

8. Customer Content, Business Customers and Authorized Users

A central function of the Platform is to allow our Business Customers to record and manage information about the individuals with whom they engage, including journalists, stakeholders, community partners, public officials, colleagues and other contacts. We hold that information on behalf of the Business Customer.

While Broadsight is committed to keeping Customer Content secure and confidential, and treats it as confidential information under our agreement with the Business Customer, responsibility for the collection, accuracy, lawfulness, retention and appropriate use of the personal information recorded in a workspace rests with the Business Customer. A Business Customer that submits personal information to the Platform is responsible for providing any notice and obtaining any consent required for Broadsight to receive, host, process and retain that information as described in this Policy and in the applicable agreement.

Access to Customer Content within a workspace is controlled by the Business Customer through role-based permissions. Workspace administrators can create, configure and disable users, manage permissions and workspace settings, view the multi-factor authentication status of users, and access the records, logs, reports and outputs within their workspace. Authorized Users should understand that their activity within the Platform is visible to their organization’s administrators.

Data is separated by workspace, and records in one workspace are not visible to another, with one exception. Where a Business Customer enables the Collaborate feature, it may share defined categories of records with a partner organization that has also opted in. Sharing is configured by the Business Customer, is limited to the categories it approves, and can be revoked by it. Broadsight does not share records between workspaces except where a Business Customer has enabled that feature.

Broadsight personnel access Customer Content only where required for support, maintenance, troubleshooting, security or incident response, on a least-privilege basis, and subject to confidentiality obligations.

9. Disclosure of Information and Service Providers

Broadsight does not sell, rent, license or trade personal information or Customer Content, and does not disclose personal information to third parties for their own advertising, cross-context behavioural advertising or sponsorship purposes. We do not use Customer Content for advertising, and we do not upload customer or prospect lists to advertising platforms for audience building, matching or enhanced conversions. We disclose information only as described below.

Infrastructure and database service providers

The following service providers process Customer Content and other Platform data on our behalf, under contract, and are permitted to use it only to provide services to us:

  • Amazon Web Services, which provides hosting, storage, computing, identity and authentication services through Amazon Cognito, content delivery and protected file access, monitoring and logging, and the receipt and scanning of emails forwarded to AutoTracker; and
  • MongoDB Atlas, which provides managed database hosting, administration and database backups.

Website, marketing, support, payment and administrative service providers

We also use service providers in connection with the Websites and our business operations, including HubSpot for our forms, marketing communications, and help and feedback submissions; Square for our hosted purchase and signup page and payment processing; Xero for invoicing, accounting and financial records; Google, LinkedIn, WordPress.com and Jetpack for website analytics, statistics and advertising measurement; and Vimeo, Loom and Gravatar for embedded media and assets. Payment card details entered on our hosted purchase page are collected and processed by Square and are not stored by Broadsight.

Other disclosures

  • Partner organizations designated by a Business Customer, where the Business Customer has enabled the Collaborate feature, and only for the categories of records it has approved for sharing.
  • Legal and regulatory recipients, where we believe in good faith that disclosure is required or permitted by law; to comply with a subpoena, warrant, court order or other lawful process; to respond to a request from a public authority; to enforce our agreements; to establish, exercise or defend legal claims; to obtain legal, accounting or insurance advice; or to protect the rights, property or safety of Broadsight, our customers or others.
  • Professional advisors, including our legal counsel, auditors and insurers, subject to professional obligations of confidentiality.
  • A successor entity, in connection with a proposed or completed financing, merger, acquisition, reorganization or sale of all or part of our business or assets, subject to appropriate confidentiality protections and to the requirements of applicable privacy legislation.

We require our service providers to protect personal information with safeguards comparable to our own, and to use it only for the purposes for which we engaged them. A current list of the service providers that process Customer Content is available to Business Customers on request.

10. Data Residency, Hosting and Cross-Border Processing

Production Customer Content is stored in Canadian regions of Amazon Web Services. Core production services use AWS Canada (Central), with AWS Canada (West) used where applicable for redundancy and disaster recovery. Broadsight does not relocate production Customer Content outside the Canadian hosting model unless expressly agreed with the Business Customer or required by law. Limited authorized access from outside Canada may occur as described below.

Broadsight is based in Canada, and our personnel are located in Canada. Authorized personnel and contractors may access data from Canada and, in limited circumstances, from the United States. Certain of our website, marketing, support, payment and administrative service providers described in Section 9 process information outside Canada, including in the United States. Information processed in another country is subject to the laws of that country, and may be accessible to its courts, law enforcement and national security authorities under those laws. This paragraph does not qualify our commitments regarding the residency of production Customer Content.

Broadsight does not currently target or offer its services to individuals in the European Economic Area or the United Kingdom. Before Personal Data governed by the General Data Protection Regulation is submitted, applicable contractual terms, including a data processing addendum where required, must be in place with the Business Customer.

11. Retention and Deletion of Information

We retain personal information only as long as reasonably necessary to fulfil the purposes for which it was collected, to provide the service, and to satisfy legal, contractual, accounting and reporting requirements.

Access to the Platform ends when the Business Customer’s agreement expires or is terminated. Individual accounts are disabled in accordance with that agreement and at the Business Customer’s request. On request, we will delete Customer Content within 60 days in accordance with the applicable agreement, and will confirm deletion. Copies of deleted information may remain in backups until the applicable backup lifecycle expires, and in logs and records retained for the periods set out above. Backup copies are protected by the same safeguards as production data, are not used for any other purpose, and are overwritten or destroyed in the ordinary course. We may also retain information where required by law, where necessary to establish, exercise or defend legal claims, or where necessary for security and incident response.

Business Customers should export any records they require before their agreement ends. Authorized Users may export records from the Service Log, Media Interactions, Engagement Log, Content Log and Contacts modules, together with analytics images, artificial intelligence conversation transcripts and generated reports, subject to their permissions. File-attachment export or transfer can be coordinated through assisted offboarding support.

12. Security Safeguards

Broadsight maintains technical, physical and administrative safeguards designed to protect personal information against loss and unauthorized access, collection, use, disclosure, copying, modification and disposal, appropriate to the sensitivity of the information. Our safeguards include:

  • hosting in Canadian regions of Amazon Web Services, with managed database services provided by MongoDB Atlas;
  • separation of data by workspace, and role-based access controls governing what each user may see and do;
  • authentication through Amazon Cognito, with support for multi-factor authentication, controls for high-risk sign-in events, and a minimum password length of twelve characters with complexity requirements;
  • encryption of data in transit and at rest, and encrypted storage of file attachments, with access to attachments authorized through signed, time-limited credentials;
  • continuous monitoring and logging, with alerting for account-takeover and high-risk sign-in indicators;
  • least-privilege internal access, granted on the basis of role and responsibility, and subject to confidentiality obligations;
  • automated dependency scanning, static code analysis and a controlled build and deployment pipeline, which does not process Customer Content;
  • managed backups and disaster recovery arrangements; and
  • a documented incident response plan, reviewed and exercised by our team.

Broadsight does not currently hold a SOC 2 Type I or Type II report. Broadsight is preparing for both SOC 2 Type I and Type II, with current readiness and remediation work focused on Type I as the first milestone and the control/evidence program being designed to support a subsequent Type II audit period. Broadsight does not currently hold ISO/IEC 27001 certification. We have completed external security and vulnerability reviews, summaries of which are available to Business Customers and prospective customers under a non-disclosure agreement where appropriate, and we are establishing a regular independent penetration-testing cadence. No method of transmission or storage is completely secure, and while we take our obligations seriously, we cannot guarantee absolute security. Security also depends on you. Authorized Users should keep credentials confidential, enable multi-factor authentication where their organization permits it, and notify their administrator or Broadsight promptly if they suspect unauthorized access.

13. Privacy Incidents and Notification

We maintain a documented incident response plan that provides for identification, severity classification, containment, eradication, recovery, post-incident review and documentation of incidents in an incident log. We evaluate and respond promptly to events that suggest unauthorized access to or handling of personal information or Customer Content.

Where we determine that personal information or Customer Content has been subject to unauthorized access, use or disclosure, we will notify the affected Business Customer without undue delay, and will notify affected individuals, regulators and other parties where required by applicable law or by our agreement with the Business Customer. Notification will describe the nature of the incident, the information involved, the steps taken and the steps affected parties may wish to take, to the extent that information is available.

14. Your Rights and Choices

Subject to the limits and exceptions in applicable law, you may exercise the following rights in respect of personal information for which Broadsight is responsible:

  • Access. Request confirmation of whether we hold personal information about you, a copy of that information, and information about how it has been used and to whom it has been disclosed.
  • Correction. Request correction of inaccurate or incomplete personal information.
  • Deletion. Request deletion of personal information, where we are not required or entitled to retain it.
  • Withdrawal of consent. Withdraw consent to a collection, use or disclosure that relies on your consent, on reasonable notice. Withdrawing consent may mean that we can no longer provide part or all of the service to you; we will explain the consequences before giving effect to a withdrawal.
  • Communication preferences. Unsubscribe from our marketing communications and update your preferences, as described in Section 15.
  • Complaint. Raise a concern with our Privacy Officer, and escalate it to the Office of the Information and Privacy Commissioner for British Columbia or another supervisory authority with jurisdiction.

To make a request, contact our Privacy Officer using the details in Section 19. We will respond within 30 days, or will notify you within that period of any permitted extension and the reason for it. We will take reasonable steps to verify your identity before responding, generally by confirming the request through the authenticated account or the Business Customer administrator associated with it, and we will not collect more information than necessary for that purpose. We do not charge a fee for access requests, although a minimal fee may apply where a request is unusually voluminous, in which case we will provide an estimate before proceeding.

Where your request concerns Customer Content, the Business Customer that maintains those records is responsible for responding, and we will refer your request to it and assist as our agreement requires. Authorized Users can update their own name, email address and multi-factor authentication settings, including a mobile number provided for text-message authentication, within the Platform; role and workspace assignments are controlled by the Business Customer’s administrator.

15. Marketing Communications and Preferences

Where you have consented or we are otherwise permitted to contact you, we may send newsletters, resources, product announcements, event invitations and other commercial electronic messages. Every marketing message we send identifies Broadsight, provides our mailing address and contact information, and includes an unsubscribe mechanism that operates without charge. Unsubscribe requests are given effect promptly and are recorded on a suppression list so that they continue to be honoured. We may engage service providers to enrich or verify business contact information used for our outbound sales activities.

Certain communications are necessary to the service and are not subject to unsubscribe. These include account invitations, password and authentication messages, service and maintenance notices, security notifications, support correspondence, billing and contractual communications, reports you have asked the Platform to send you, and notices required by law. Text messages are sent only in connection with multi-factor authentication, where an Authorized User has chosen that method, and are never used for marketing.

16. Your United States Privacy Rights

A proportion of our customers and prospective customers are located in the United States. Broadsight does not sell personal information, does not share personal information for cross-context behavioural advertising, and does not process sensitive personal information for the purposes regulated by United States state privacy statutes. Our public Websites use the advertising measurement and analytics technologies described in Section 5, and those technologies may be treated as “sharing” under some state statutes; you may decline non-essential cookies through our banner, through your browser, and through the opt-out mechanisms offered by the relevant providers.

Residents of United States states with comprehensive privacy legislation may, subject to the applicable statute, request access to, correction of, deletion of, or a portable copy of personal information we hold about them, and may appeal a decision on such a request. We will honour these requests, and treat an appeal as a request for reconsideration by our Privacy Officer, whether or not we meet a statutory threshold in the relevant state. We do not discriminate against individuals who exercise privacy rights. Requests may be submitted using the contact details in Section 19, and may be made by an authorized agent who provides evidence of authority.

17. Children and Sensitive Information

The Broadsight Properties are business tools directed to organizations and their staff. They are not directed to children, we do not knowingly collect personal information from children, and accounts are created only for individuals designated by a Business Customer in the course of that organization’s work. If we become aware that we have received the personal information of a child other than through a Business Customer’s deliberate record-keeping, we will delete it.

The Platform is not designed as a repository for Prohibited Data. Under Broadsight’s standard Cloud Service Agreement, Business Customers and Authorized Users must not submit patient, medical or protected health information, financial-account details, government identifiers, GDPR special-category data, or similar highly sensitive information unless expressly permitted by written agreement.

18. Changes to This Policy

We may amend this Policy from time to time to reflect changes to our practices, our service, our service providers or applicable law. The date at the top of this Policy indicates when it was last revised. Where a change is material, we will provide notice before it takes effect, by posting a prominent notice on the Broadsight Properties, by email, or through the Platform. Prior versions are archived and are available on request. Your continued use of the Broadsight Properties after a change takes effect constitutes acceptance of the amended Policy; if you do not accept it, you should discontinue use of the Broadsight Properties, and Authorized Users should raise the matter with their organization.

19. How to Contact Us

Broadsight has designated a Privacy Officer who is accountable for our compliance with this Policy and with applicable privacy legislation. Questions, requests and complaints about this Policy or about our handling of personal information should be directed to:

Kurt Heinrich, Founder and Chief Strategy Officer

Broadsight Technology Corporation

Email: info@broadsight.ca

We will acknowledge your enquiry, investigate it, and advise you of the outcome. If you are not satisfied with our response, you may contact the Office of the Information and Privacy Commissioner for British Columbia, or the privacy regulator with jurisdiction in your province, territory or state.

Broadsight

System of record for corporate communications and public affairs. Built for the people behind the message.

Request a demo

Platform

  • Platform overview
  • Broadsight AI
  • Analytics & reporting
  • Security
  • Pricing

Solutions

  • Solutions overview
  • Issues management
  • Media relations
  • Stakeholder engagement
  • Content workflows

Resources

  • Customer stories
  • Insights & blog
  • Frequently asked questions

Company

  • About Broadsight
  • Contact
  • Log in

© 2026 Broadsight Technology Corporation. All rights reserved.

Privacy·Terms·Accessibility

Made in Canada