Official site: www.bezalink.com — not affiliated with bezalink.ca, bealink.com, beelink.com, or similarly named childcare, waitlist, hardware, education, or third-party domains.
Sunlit institutional atrium with glass walls, elevated walkways, and a clear public-facing interior.

Privacy Policy

BezaLink protects personal information across its public website, qualified brief intake, adaptive learning infrastructure, evidence records, credential services only where separately authorized and enabled, and related account or consent paths.

Public scope

This is the public Privacy Policy for BezaLink Technologies Inc. Version v1.1 is the statutory-hardened release candidate for publication.

Article 1

Who We Are

BezaLink Technologies Inc. is an Alberta corporation building human-centred mastery infrastructure for adaptive learning, evidence-based competency, and reviewable workforce trust.

BezaLink is built for how humans actually learn. The platform is designed to help learners master their craft by adapting learning to the way each person processes, understands, practices, and retains knowledge.

Only where separately authorized, scoped, and enabled, BezaLink may also support evidence records, competency attestations, credential records, and employer verification through the BezaLink Verifiable Attestation System, or BVAS. These capabilities are not activated by the public website.

Some BezaLink features may be in preview, pilot, demonstration, controlled rollout, or future release. This Privacy Policy applies to features when they are available, enabled, piloted, or used. It does not mean every described feature is live for every user at all times.

Article 2

Contact Information

Privacy Contact: Mark Sanchez, Founding Architect. Company: BezaLink Technologies Inc. Location: Edmonton, Alberta, Canada.

For privacy requests, access requests, correction requests, consent withdrawal, or complaints, email privacy@bezalink.com. For security matters, email security@bezalink.com. For support, email support@bezalink.com.

Article 3

Scope Of This Policy

This Privacy Policy applies to personal information we collect, use, disclose, retain, protect, or otherwise process through bezalink.com, the BezaLink web application and portal only where separately authorized and enabled, BezaLink learning and mastery features only where separately authorized and enabled, BVAS credential and verification services only where separately authorized and enabled, API integrations only where separately authorized and enabled, customer support, billing, communications, pilots, demonstrations, and related services.

This Policy does not apply to anonymized or aggregated information that cannot reasonably identify an individual, third-party websites or services not controlled by BezaLink, or information processed by third parties under their own privacy policies.

Article 4

Personal Information We Collect

We collect only the personal information reasonably necessary for identified business, legal, security, learning, mastery, credentialing, verification, support, and platform purposes.

  • Account and identity information such as name, email, account identifier, authentication status, organization context, role type, and account settings.
  • Learning, mastery, assessment, and evidence information such as program enrollment, progress, attempts, scores, practice records, submissions, reflections, feedback, competency milestones, and readiness indicators.
  • Credential, attestation, and verification information only where BVAS or related features are separately authorized, scoped, and enabled, including credential identifiers, attested competency claims, issuance or revocation status, verification timestamps, and audit metadata.
  • Technical, usage, and security information such as IP address, device type, browser, session identifiers, authentication timestamps, feature usage, error logs, API metadata, and security event logs.

Article 5

How We Use Personal Information

We use personal information to create and manage accounts, authenticate users, deliver adaptive learning, support mastery development, administer assessments and evidence records, issue or verify BVAS records only where separately authorized and enabled, process payment-related information only where a payment feature is separately authorized and enabled, provide support, send service notices, maintain audit logs, detect abuse, protect security, improve the platform, and comply with legal obligations.

We do not use personal information for materially different purposes unless we provide additional notice and obtain consent where required by law.

Article 6

Consent And Permitted Purposes

BezaLink collects, uses, and discloses personal information with consent where consent is required, and for reasonable purposes permitted by applicable privacy law.

Consent may be express or implied depending on context, sensitivity, reasonable expectations, and applicable law. You may withdraw consent at any time, subject to legal, contractual, technical, security, credential-integrity, and retention limitations.

Article 7

Learning, Evidence, And BVAS Attestation Records

BezaLink treats credentials as downstream from human cognition, mastery, and evidence. The purpose of an attestation record is to reflect meaningful evidence of skill, not merely platform activity.

Where credential sharing is enabled, learners control whether eligible attestation records are shareable, private, active, expired, revoked, or otherwise restricted according to platform settings, program rules, and applicable law.

When an authorized employer or verifier checks a shared credential, they may see only verification-relevant information such as credential identifier, attested competency claims, issuing context, issuance date, expiry date where applicable, credential status, and verification result.

Article 8

Credential Retention And Cryptographic Severability

BVAS attestation records and related evidence records may be retained longer than ordinary account records where necessary for credential integrity, learner portability, employer verification, auditability, fraud prevention, dispute resolution, legal compliance, or preservation of learner-controlled credential history.

Where deletion is requested, BezaLink may anonymize, revoke, restrict, archive, or append correction records instead of deleting records where deletion would compromise credential integrity, legal obligations, audit trails, security, fraud prevention, dispute resolution, or the rights of another party.

For credential-integrity purposes, BezaLink may retain detached cryptographic hashes, integrity proofs, event fingerprints, revocation markers, or other non-content verification artifacts after underlying directly identifying records are deleted, anonymized, or restricted.

BezaLink treats such artifacts as personal information for as long as they can reasonably identify, be linked to, or be re-associated with an individual, whether alone or in combination with other information under BezaLink control.

Where a retained BVAS hash or verification artifact has been cryptographically and operationally severed from identifying records so BezaLink no longer holds the lookup table, secret, mapping, metadata, or other reasonably available means to identify the individual, BezaLink will treat the severed artifact as anonymized or non-identifying integrity data to the extent permitted by applicable law.

Article 9

Sharing And Service Providers

BezaLink does not sell personal information and does not share personal information with advertising networks for third-party behavioural advertising.

BezaLink may use current or anticipated material service providers including Supabase, Stripe, Twilio SendGrid, Sentry, Intercom or similar support tooling, and Cloudflare. Some providers process personal information only if the relevant feature is separately authorized and enabled.

Material service providers that process personal information on BezaLink behalf must be governed by contractual, technical, and organizational safeguards appropriate to the nature of the processing. Where applicable, this includes Data Processing Agreements, processor terms, confidentiality obligations, access restrictions, security requirements, incident-notification duties, retention and deletion controls, and audit or review rights.

BezaLink remains accountable for personal information transferred to a service provider for processing. Service providers may process personal information only for purposes authorized by BezaLink and may not use it for their own unrelated purposes.

Article 10

Data Residency And Cross-Border Processing

BezaLink is based in Alberta, Canada. Where technically and commercially feasible, BezaLink seeks to store core Canadian learner platform data in Canada. Some service providers may process personal information outside Canada, including in the United States or other jurisdictions.

Cross-border processing does not remove BezaLink accountability for personal information under its control. BezaLink uses contractual, technical, organizational, and vendor-management safeguards designed to provide a comparable level of protection for personal information processed by service providers, including binding processor terms or Data Processing Agreements where applicable.

Article 11

Retention And Privacy Rights

We retain personal information only as long as reasonably necessary for the purposes described in this Policy or as required or permitted by law.

Depending on applicable law and your relationship with BezaLink, you may have privacy rights including access, correction, consent withdrawal, complaint, and where legally or technically available, deletion, anonymization, restriction, or export.

Where PIPEDA applies, we will generally respond to access requests within 30 calendar days unless a lawful extension applies. Where Alberta PIPA applies, we will respond no later than 45 days after receiving a written request unless the time period is lawfully extended.

To exercise privacy rights, email privacy@bezalink.com with your full name, the email address associated with your account or request, the nature of your request, and enough detail for us to identify the relevant records.

Article 12

Security And Breach Records

BezaLink uses technical, administrative, and organizational safeguards appropriate to the sensitivity of the personal information we process.

If BezaLink becomes aware of a privacy breach or breach of security safeguards involving personal information, we will take steps to contain, investigate, assess, and remediate the incident.

Where a breach creates a real risk of significant harm or otherwise requires notification under applicable law, BezaLink will notify applicable privacy regulators and affected individuals as required.

BezaLink also maintains an internal breach record for breaches of security safeguards involving personal information under its control, including breaches that do not meet the real-risk-of-significant-harm reporting threshold. Where PIPEDA applies, BezaLink will keep and maintain breach records for at least 24 months, or longer where required or appropriate for legal, audit, security, dispute-resolution, or governance purposes.

Article 13

Children, CASL, And Cookies

The BezaLink platform is intended for users who are at least 18 years old unless a specific institutional, apprenticeship, school, youth, or supervised program is launched with appropriate consent, authority, and safeguards. We do not knowingly collect personal information from children under 13.

We will send commercial electronic messages, newsletters, promotional updates, or marketing communications only where permitted by Canada Anti-Spam Legislation or other applicable law. Where BezaLink relies on implied consent from an existing business relationship, that implied consent generally lasts for up to 24 months after a relevant purchase, subscription, contract, or transaction, or up to 6 months after an inquiry or application, unless withdrawn earlier or another lawful basis applies.

We will process unsubscribe requests without delay and no later than 10 business days after receiving the request.

BezaLink uses cookies and similar technologies for authentication, security, fraud prevention, platform functionality, preferences, diagnostics, and analytics. We do not use cookies for third-party behavioural advertising or cross-site advertising retargeting.

Article 14

Changes, Accountability, And Complaints

We may update this Privacy Policy from time to time to reflect changes in our platform, data practices, service providers, legal obligations, security practices, learning services, credentialing or verification services, and business operations.

BezaLink privacy program is built around accountability, data minimization, consent, purpose limitation, safeguards, individual access, correction, retention control, complaint handling, and governance discipline.

If your complaint is not resolved to your satisfaction, you may contact the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada.