Legal
Privacy policy
How Lavawall® collects, uses, stores, and protects your information.
Effective 8 April 2025. Last reviewed 18 July 2026. Data controller: ThreeShield Information Security Corporation, Calgary, Alberta, Canada.
This policy explains what Lavawall® collects, why, where it is processed, how long it is kept, and the choices you have. Lavawall® is operated by ThreeShield Information Security Corporation ("ThreeShield", "we", "us"), a Canadian federal corporation based in Calgary, Alberta. If you have questions, contact us through our contact form with "Privacy" in the subject line.
Information we collect
We collect only what the service needs to do its job.
- Account information. Names, email addresses, company names, phone numbers, billing details, and identity data from third-party sign-in providers you choose to connect (Google, Microsoft, AWS).
- Device and endpoint security data. Operating system versions, patch status, software inventory, hardware identifiers, network configuration, running services, antivirus status, and BIOS information from endpoints where you install the agent.
- Optional feature data. File-change metadata (not file contents), user-to-directory mapping, SaaS discovery from email metadata, phishing reports (headers, metadata, and message content you submit), DMARC data, and remote-support file transfers (which are not permanently stored).
- Network and domain data. Port analysis, TLS and SSL certificates, DNS records (DMARC, SPF, DKIM), web headers, and public vulnerability indicators for the domains and addresses you ask us to scan.
- Usage logs. Console session IP addresses, timestamps, actions, and errors, kept for security, audit, and troubleshooting.
How we use it
We use personal information to provide and maintain the service, authenticate users and prevent fraud, handle billing and account administration, send transactional and (where permitted) marketing messages, meet legal and audit obligations, and produce aggregated, anonymised analytics. ThreeShield does not sell, trade, rent, or exchange any personal information or security data for commercial purposes.
How Lavawall uses Google user data (Limited Use)
If you sign in with Google or connect a Google Workspace tenant, Lavawall® requests only the access needed for the security features you turn on. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
- Google user data is used only to provide or improve the specific Lavawall® security assessment features you have enabled.
- We do not sell Google user data, and we do not use it for advertising.
- We do not transfer Google user data to others except as needed to provide the feature, to comply with the law, or as part of a merger or acquisition with equivalent protections.
- No human reads your Google user data except where you ask us for support, where you have given consent, for security purposes such as investigating abuse, or where the law requires it.
- You can withdraw access at any time from your Google Account permissions or from Lavawall® console settings.
The same principles apply to Microsoft 365, Entra ID, and Azure data you connect: it is used only for the security features you enable, is not sold, and is not used for advertising.
Phishing Reporter add-in data flow
The free Lavawall® Phishing Reporter add-in for Outlook is built so that most analysis stays close to the message. Background checks send message headers, sender, subject, recipient, the list of links, and attachment metadata to the Lavawall® console in Canada. When a user reports a message, the full body, attachment contents, and classification flags are sent so the report can be reviewed.
For link and domain reputation, only the bare domain name is sent to external reputation sources. No email contents, URL paths, query strings, attachments, user identifiers, recipient identifiers, or telemetry are sent to those sources. The legal basis for these checks is the legitimate interest of network and information security and fraud prevention under GDPR Article 6(1)(f). An organisation can disable external reputation lookups in console settings.
Where your data is processed
Databases and the console front end run on AWS in Montreal, Quebec. SIEM, log, Microsoft 365 monitoring, and reported-phishing data are held in AWS Montreal. Domain and network scanning, Tenable Nessus scanning and its results, and agent compilation run in Calgary, Alberta. Outbound notification, report, and ticket email is sent from ThreeShield's own mail server in Canada, delivered directly to the recipient's mail exchanger and DKIM-signed; no third-party email relay carries that content. Canadian storage is the default, and other geographies are available on request.
Some cross-border processing remains, and we would rather list it than leave it implied. Amazon SES in Ireland is used only to verify control of an email address and to deliver authentication codes, and carries no report or ticket content. SMS and MFA codes are delivered through Twilio in the United States. Content and agent installers are served through Cloudflare's global edge network, so a request may pass through the nearest edge location outside Canada. Meeting and call transcription tooling has no Canadian-resident option today: it is disclosed, you can opt out at any time, we never transcribe silently, and we stop transcription and delete what was captured if sensitive information is disclosed. Canada has been recognised by the European Commission as providing an adequate level of data protection for the purposes of GDPR Article 45.
Artificial intelligence and automated analysis
Lavawall® uses language models to accelerate support ticket triage, log analysis, and incident investigation. Nothing reaches a third-party model in the form you gave it to us.
Redaction happens before anything is sent
A redaction system runs over every payload before it leaves our systems. It removes IP addresses, company names, usernames, email addresses, and sensitive personally-identifiable information (SPII) that may appear in a ticket — including the free text a person typed, not just structured fields. A third-party model never receives those values. What it receives is the redacted remainder, which is what makes the analysis useful without making it identifying.
Email that our internal scans indicate may contain medical information is never sent to a third-party model at all. It is excluded from model processing entirely and handled by a person.
Every model we use is contractually configured so that your information is not used to train it.
Where each kind of analysis is processed
- Redacted ticket and breach information is processed in Canada. If you would prefer your information processed in another country, contact support and we will arrange it.
- Redacted context around suspected breach indicators, and threat intelligence, may be processed in the United States. That processing contains no IP address, no company name, no user, no email address, and no ticket information — it is the indicator and the technical context around it, nothing that identifies you or your client.
Please still keep sensitive detail out of tickets
Redaction is thorough, but the free text of a support request is written by a person under pressure and we would rather not rely on a filter alone. Please do not put health information, personal information about a patient, client or customer, clinical detail, identifiers such as a personal health number or account number, credentials, or a screenshot or forwarded message containing any of that, into a ticket. If a problem cannot be described without it, telephone support instead and we will handle it without model processing.
Subprocessors
We rely on a small set of service providers, each bound to protect the data they handle:
- Amazon Web Services — cloud hosting and databases, hosted in Canada (Montreal and Calgary), and email address verification through SES in Ireland.
- Amazon Web Services AI services — hosted in Canada, for redacted analysis.
- Anthropic — models hosted in Canada through AWS for anything relating to your tickets and breaches. Anthropic models hosted in the United States are used for some other tasks, which do not involve your ticket or breach information.
- OpenAI — verification purposes only, with no access to your tickets or breach information.
- Tenable for the Nessus vulnerability scanning engine, with results held by ThreeShield in Calgary.
- Meeting and call transcription tooling in the United States, where the client has not opted out.
- Cloudflare for content delivery, web application firewall, and bot protection.
- Twilio for SMS and MFA delivery.
- MaxMind for IP enrichment, processed locally.
- Domain and URL reputation sources that receive only bare domain names, including malware-blocking DNS resolvers and public malicious-URL feeds.
- Public TLD registries for RDAP lookups.
Contact forms and support were previously handled by external providers and have since moved in-house to Lavawall®.
Cookies and analytics
The Lavawall® console uses only essential session cookies required for authentication and security. The public marketing website may use analytics and tag-management cookies on marketing pages only. We honour browser Do Not Track signals, and analytics opt-out tools are available. See our cookie choices on any consent banner shown to you.
How long we keep it
- Account and subscription data: for the life of the account plus 7 years.
- Security telemetry and scan results: for the life of the account plus 90 days, subject to your chosen retention tier (see the data retention page).
- Server and access logs: up to 12 months.
- Support tickets: 7 years from closure.
- Public website analytics: per provider defaults, typically 26 months.
How we protect it
We use TLS 1.2 or higher in transit, encryption of sensitive data at rest, enforced multi-factor authentication, Cloudflare WAF and DDoS protection, least-privilege access, regular vulnerability assessments, and staff security awareness training. If a breach affects your personal information, we notify as required: within 72 hours under GDPR, and as soon as feasible under PIPEDA and provincial law.
Your rights and choices
Everyone, in every jurisdiction, can ask us to access their personal information, correct inaccurate data, delete their account and associated information, withdraw consent, unsubscribe from marketing, and revoke third-party integrations.
- Canada (PIPEDA, Alberta PIPA, BC PIPA). You can challenge the accuracy and completeness of your data and complain to the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada.
- EU and EEA (GDPR). You can restrict processing (Article 18), request portability (Article 20), object to processing (Article 21), and complain to your national supervisory authority.
- United States (CCPA/CPRA and similar state laws). You can know, delete, correct, and copy your personal information. ThreeShield does not sell or share personal information for cross-context behavioural advertising.
To make a request, use our contact form with "Privacy Request" in the subject line. We verify your identity and respond within 30 days. We do not make automated decisions that produce legal or similarly significant effects without human review.
Children's privacy
Lavawall® is intended for businesses and IT professionals and is not directed at anyone under the age of 18. We do not knowingly collect personal information from children.
Changes to this policy
If we make a material change, we will give at least 30 days' notice by email before it takes effect. Continued use of the service after the effective date means you accept the updated policy.
Contact
For any privacy question or request, use our contact form with "Privacy" in the subject line. EU and EEA residents can reach our GDPR representative by marking the subject "GDPR Representative". You can also complain to the Office of the Information and Privacy Commissioner of Alberta (oipc.ab.ca), the Office of the Privacy Commissioner of Canada (priv.gc.ca), or your national supervisory authority in the EU.