Effective Date: September 21, 2026
Legal Name: LTH CYBERSECURITY CORP.
Operating As: LTH Cybersecurity
Location: Yorkton, Saskatchewan, Canada
LTH CYBERSECURITY CORP., operating as LTH Cybersecurity ("LTH Cybersecurity", "LTH", "we", "us", or "our"), is committed to protecting the privacy, confidentiality, and security of information entrusted to us.
This Privacy Policy explains how we collect, use, disclose, retain, and protect information in connection with our website, managed security services, penetration testing, security assessments, incident response, consulting, and other cybersecurity services.
Depending on your interaction with LTH Cybersecurity, we may collect information including:
During penetration tests, security assessments, incident response engagements, managed security services, audits, and other technical work, LTH Cybersecurity may receive or encounter confidential technical information belonging to a client.
This information may include:
Such information is accessed and used only as reasonably necessary to perform the authorized service, document findings, provide remediation guidance, maintain service operations, or satisfy applicable contractual and legal obligations.
Where a client provides credentials, API keys, tokens, VPN access, administrative access, or other authentication information, LTH Cybersecurity will use that access only for the authorized purpose and within the agreed scope of the engagement.
Clients should provide temporary, restricted, or dedicated testing accounts whenever practical. Credentials and other sensitive access information are protected using reasonable security controls and should be removed or securely deleted when they are no longer reasonably required for the engagement.
Information collected by LTH Cybersecurity may be used to:
LTH Cybersecurity treats non-public information received from clients during cybersecurity engagements as confidential.
Vulnerabilities, penetration testing results, security configurations, incident information, credentials, client data, and other confidential engagement information will not be publicly disclosed by LTH Cybersecurity without authorization from the client, except where disclosure is required by law.
Where a separate Non-Disclosure Agreement (NDA), Statement of Work (SOW), Rules of Engagement (ROE), or other written agreement contains additional confidentiality requirements, those requirements will also apply.
LTH Cybersecurity may use third-party service providers and security platforms to operate our business and deliver certain services. These may include payment processors, hosting providers, communications platforms, security vendors, managed detection and response providers, and other technology providers.
Information is shared with third parties only where reasonably necessary to provide the applicable service, operate our business, comply with legal requirements, or where the client has otherwise authorized the disclosure.
Third-party providers may process information according to their own privacy policies, contractual obligations, and applicable laws.
LTH Cybersecurity does not sell personal information.
Payments may be processed through third-party payment processors or service platforms. LTH Cybersecurity generally does not directly store complete payment card information where payment information is handled by those providers.
Our website may use limited cookies and similar browser technologies for security, functionality, and advertising purposes.
Third-party services may collect information according to their own privacy policies.
LTH Cybersecurity may request documentation to verify eligibility for Indigenous organization pricing or discounts.
Verification documentation is used solely to determine eligibility and is not retained longer than necessary to complete the verification process. Verification documents are securely deleted after verification.
LTH Cybersecurity may retain a limited record indicating that eligibility was successfully verified without retaining copies of identification documents.
LTH Cybersecurity retains information only for as long as reasonably necessary for the purpose for which it was collected, to provide contracted services, maintain appropriate business records, resolve disputes, enforce agreements, or satisfy applicable legal obligations.
Security assessment evidence, reports, credentials, incident artifacts, and other engagement-specific information may have different retention periods depending on the nature of the engagement and any applicable client agreement.
Where an engagement establishes specific data deletion or retention requirements, LTH Cybersecurity will follow those requirements.
LTH Cybersecurity uses reasonable administrative, technical, and organizational safeguards appropriate to the sensitivity of the information being handled.
These safeguards may include access controls, encryption, secure authentication, restricted administrative access, system hardening, and other security measures appropriate to the applicable system or engagement.
No system or method of electronic transmission or storage can be guaranteed to be completely secure. Accordingly, LTH Cybersecurity cannot guarantee absolute security.
During cybersecurity engagements, LTH Cybersecurity seeks to collect and retain only the information reasonably necessary to demonstrate findings and complete the authorized engagement.
Where a vulnerability can be demonstrated without unnecessarily accessing, copying, or retaining sensitive client or third-party information, we seek to minimize such access and collection.
Clients may receive communications necessary to administer their accounts, provide contracted services, respond to support requests, communicate security information, or provide important service updates.
Marketing communications, where used, will be handled separately from communications reasonably necessary to provide contracted services.
Individuals may contact LTH Cybersecurity to ask questions about personal information we hold about them or to request access, correction, or deletion where applicable.
Certain information may need to be retained where required for contractual, security, accounting, legal, or other legitimate business purposes.
LTH Cybersecurity may update this Privacy Policy periodically to reflect changes to our services, business practices, technology, or legal obligations. The current effective date will be displayed at the top of this policy.
Questions or privacy-related requests may be submitted through the official LTH Cybersecurity website or through the contact information provided in your service agreement.