Last updated: Feb 01, 2026
This Privacy Policy (“Policy”) describes how Ennote Security Inc. ("Ennote Security", “we”, “us”, or “our”) collects, uses, discloses, processes, and protects personal information relating to individuals (“you” or “your”).
This Policy applies when you:
Ennote Security is a company based in British Columbia, Canada. We are committed to protecting your privacy in accordance with applicable privacy laws, including British Columbia's Personal Information Protection Act (PIPA).
This Policy does not apply to the extent we process personal information in the role of a service provider (or "processor") on behalf of our Customers for the content they create ("User Content"). In such cases, the Customer is the data controller.
We do not rent, sell, or trade your Personal Information.
When you deploy the Ennote Agent/Operator in your infrastructure:
ennote.io/* tags). We do not access your application code or container logs.We strictly do not use User Content (Secrets, Notes) to train Artificial Intelligence (AI) or Machine Learning (ML) models.
In Canada (PIPA), we rely on Consent (implied or express). For GDPR (EEA/UK), we process data based on:
We employ a defense-in-depth cryptosystem:
Ennote employs a Zero Persistence design for sensitive keys. Data Encryption Keys (DEKs) are encrypted by a Key Encryption Key (KEK) managed within a Hardware Security Module (HSM).
During cryptographic operations (such as wrapping/unwrapping secrets for a verified client), DEKs are processed exclusively in volatile memory (RAM).
Encrypted blobs are primarily stored on servers provided by AWS and GCP (United States).
Enterprise customers using Bring Your Own Key (BYOK) retain the Master Keys in their own cloud KMS (e.g., AWS KMS or Google Cloud KMS). In this configuration, Ennote stores encrypted data, but the Root of Trust resides within your jurisdiction and control.
Subject to local laws, you have the right to:
You have the right to lodge a complaint with a supervisory authority.
Our Services are B2B/Enterprise tools not intended for children under 13 (or 16 in EEA). We do not knowingly collect Personal Information from children.
We may update this Policy. If changes are material, we will provide prominent notice (e.g., email or website banner) prior to the change becoming effective.
If unsatisfied, you may complain to the Office of the Information and Privacy Commissioner for BC (OIPC).