Skip to content
Protektant home
Cookies on Protektant
We use necessary cookies to make the site work and optional cookies to improve your experience. By clicking Accept all, you agree to our use of cookies as described in our Cookie Policy.

Privacy Policy

Protektant Privacy Policy

Privacy Policy

Effective date: [Insert publication date]

Last updated: [Insert publication date]

This Privacy Policy explains how Traditional Knowledge Inc. (“TKI,” “we,” “us,” or “our”) collects, uses, stores, discloses, and protects personal information and other covered data in connection with Protektant and related services (the “Service”).

Capitalized terms not defined in this Privacy Policy have the meanings given in the applicable Protektant terms and role-specific agreements.

1. Scope and relationship to other agreements

This Privacy Policy should be read together with the Protektant Platform Terms and User Protections, the Cookie Policy, and any Supplemental Agreement, Order Form, Rights Designation Record, data processing addendum, onboarding agreement, Nation Participation agreement, Knowledge Holder terms, Subscriber terms, or other workflow-specific terms that expressly apply to a particular relationship, role, content type, or transaction.

If a more specific agreement expressly governs the same privacy, data, rights-designation, governance, retention, or subscriber relationship issue, that more specific agreement controls for the subject matter it expressly governs.

This Privacy Policy recognizes the baseline submission license and related retention, audit, evidentiary, governance, and legal-compliance rights described below and in the relevant role-specific agreement or record.

2. Who we are

Protektant is operated by Traditional Knowledge Inc. (“TKI”), a federal corporation based in Ottawa, Ontario, Canada.

3. Children and youth participation

The Service is not directed to children under 13.

Children under 13 may not use the Service or submit information through the Service.

Users aged 13 to 17 may participate only where permitted by law and product design, and only subject to the applicable assent flow, any required parent or guardian consent, any required Nation-authorized participation approval, and any other platform controls that TKI requires.

If TKI learns that it collected information from a child under 13 without the required authorization, TKI will take appropriate corrective steps consistent with applicable law, platform integrity, and recordkeeping obligations.

4. Information we collect

Depending on your role and how you use the Service, we may collect and process the following categories of information:

4.1 Account, identity, and contact information

Name, email address, phone number, organization or Nation affiliation, role, billing contact details, and other registration or account information.

4.2 Covered Content, Indigenous Knowledge Records, and related submissions

Indigenous Knowledge Records, Traditional Knowledge, cultural or land-use information, text, audio, video, images, mapped records, transcriptions, translations, annotations, supporting materials, governance annotations, handling instructions, and other submitted or contributed content (“Covered Content”), together with contributor-supplied or content-linked metadata provided with or needed to interpret that content. “Indigenous Knowledge Record” is a user-facing label for Covered Content submitted, uploaded, entered, generated, or otherwise provided through the Service.

4.3 Payment, billing, payout, tax, and compliance information

Billing and payment details for subscribers, payout details for eligible contributors, tax forms, tax IDs, KYC or verification materials, sanctions-screening information, business information, authority documentation, and related compliance records.

4.4 Service-generated metadata and operational records

Session metadata, device metadata, IP metadata, system metadata, operational metadata, access logs, audit logs, billing records, processor records, pricing snapshots, active-user status records, storage usage records, bandwidth usage records, upload records, download records, export logs, API logs, usage logs, security events, telemetry, performance data, error logs, support logs, and administrative-action records generated by or about the Service.

4.5 Support and communications

Support tickets, onboarding communications, notices, emails, dashboard messages, implementation materials, and other communications relating to the Service.

5. How we use information

We may use information, including personal information and Covered Content where authorized, to:

  • provide, operate, secure, maintain, support, and improve the Service;
  • authenticate users, verify authority, administer accounts, subscriptions, projects, and permissions;
  • administer Rights Designation Records, Nation Governance Rules, masking, privacy status, restricted-content handling, and other governance controls;
  • maintain the Sovereign Data Treasury, canonical record, version history, audit trail, and System-of-Record integrity;
  • process subscriptions, billing, Community Continuity User Fees, Operationalization Activation Records, taxes, honoraria, royalties, refunds, storage and bandwidth limits, compliance review, collections, and fraud prevention;
  • investigate misuse, security incidents, re-identification risk, privacy complaints, access disputes, and contractual or legal violations;
  • comply with law, legal process, court orders, regulatory obligations, sanctions, anti-money-laundering obligations, tax rules, and lawful governmental requests;
  • enforce the Protektant Platform Terms and User Protections and any applicable Supplemental Agreement;
  • generate de-identified, aggregated, and statistical information for security, capacity planning, billing validation, service analytics, operational integrity, compliance, fraud prevention, and product improvement, provided that doing so does not identify you or expand any right to use restricted, Nation-governed, or rights-designated content beyond the more specific rules that apply to that content; and
  • carry out any other purpose expressly authorized by you or clearly disclosed in an applicable policy, workflow, or agreement.

Unless a Supplemental Agreement, product feature notice, or explicit consent flow clearly states otherwise, TKI will not use protected User Content to train publicly shared or general-purpose artificial intelligence models.

6. Covered Content, governance, rights designation, and control

6.1 Ownership retained

As between TKI and the relevant participant, Knowledge Holders retain ownership of the Covered Content and Indigenous Knowledge Records they contribute. Indigenous Governments retain their governance, stewardship, authority, and other rights and interests recognized by applicable law, custom, internal governance, and agreement. TKI does not claim ownership of Covered Content or Indigenous Knowledge Records themselves.

6.2 Submission license, consideration, and platform control

When a Knowledge Holder submits, uploads, enters, generates, or otherwise provides Covered Content or an Indigenous Knowledge Record to Protektant, the Knowledge Holder retains ownership of that content but grants TKI an exclusive, perpetual, worldwide, irrevocable, transferable, sublicensable, royalty-free license to use, process, store, host, secure, reproduce, display, transmit, format, convert, adapt, translate, transcribe, mask, normalize, classify, index, compile, annotate, govern, audit, verify, preserve, enforce, commercialize, monetize, sublicense, and otherwise administer that content within Protektant, the Sovereign Data Treasury architecture, the System of Record, and any lawful successor platform or successor operating environment.

This license supports platform operation, authorized subscriber access where applicable, Rights Designation Records, Nation Governance Rules, masking, privacy controls, restricted-content handling, honoraria facilitation where available, audit functions, System-of-Record integrity, enforcement, and audit, retention, recordkeeping, evidentiary, and legal obligations imposed on TKI by legal authorities.

The availability, operation, and use of the Service, together with TKI’s facilitation of honoraria mechanisms where such mechanisms are available or enabled, constitute full and sufficient consideration for this license.

Rights Designation Records, privacy settings, masking status, Nation Governance Rules, and restricted-content controls govern how Covered Content or Indigenous Knowledge Records are displayed, commercialized, masked, restricted, made available, or withheld within the Service. They do not negate, revoke, narrow, terminate, or make non-exclusive the baseline submission license granted to TKI unless TKI expressly agrees in writing or Non-Waivable Law requires otherwise.

6.3 Rights designation framework

The rights and handling rules that apply to Covered Content and Indigenous Knowledge Records depend on the applicable Rights Designation Record, Nation Governance Rules, Nation Participation agreement, Knowledge Holder terms, Subscriber terms, Platform Terms, Order Form, and any other applicable record or workflow.

A Full Platform Commercialization Designation records that the applicable Covered Content or Indigenous Knowledge Record is authorized for active full platform commercialization, subscriber access, sublicensing through the Service, and related commercial handling through Protektant, subject to applicable masking, privacy, Access Policies, Subscriber terms, Nation Governance Rules, restricted-content controls, and TKI administrative holds.

Some Covered Content may be governed by a Limited Commercialization / Limited Access Designation or by a Restricted / Never Commercial Handling Designation. More restrictive rights-designation, governance, or handling rules control platform handling over more permissive generic settings, but do not revoke, narrow, terminate, or make non-exclusive TKI's baseline submission license unless TKI expressly agrees in writing or Non-Waivable Law requires otherwise.

6.4 Sovereign Data Treasury and System of Record

Where applicable, the Sovereign Data Treasury operated through the Service is the canonical record and the authoritative System of Record for provenance, permissions, privacy and masking status, version history, governance annotations, access entitlements, and audit integrity for the relevant Covered Content or Indigenous Knowledge Record.

6.5 Metadata and operational data

As between you and TKI, TKI owns and may use service-generated metadata, system metadata, operational metadata, audit logs, telemetry, performance data, error logs, security events, service analytics, and other operational data generated by or about the Service, subject to applicable law, this Privacy Policy, and any applicable agreement.

For clarity, metadata attached to, submitted with, intrinsic to, or required to interpret particular Covered Content or Indigenous Knowledge Records remains part of that content or is otherwise governed by the rights designation, governance rule, Supplemental Agreement, or policy applicable to that content.

7. Sharing and disclosure

We may disclose information as follows, subject to applicable law and the more specific rules that govern the relevant content or relationship:

7.1 With Indigenous Governments and their authorized administrators

Within the applicable Sovereign Data Treasury, governance environment, and role-based permissions, and subject to Nation Governance Rules, canonical-record controls, and applicable rights designations.

7.2 With Subscribers and authorized users

Only within the scope purchased under the applicable Order Form and Access Policies, and only subject to applicable privacy settings, masking state, rights designations, Nation governance controls, export restrictions, and System-of-Record rules.

7.3 With service providers and subprocessors

With cloud providers, payment processors, communications providers, security providers, support providers, and other subprocessors acting on TKI’s behalf. TKI remains responsible for personal information processed by subprocessors on TKI’s behalf and uses contractual or other measures to require a comparable level of protection, including confidentiality obligations, security safeguards, limited-use obligations, and incident-reporting duties as appropriate to the service provided.

7.4 As required by law or legal process

To comply with law, regulation, court order, lawful governmental request, tax obligation, sanctions screening, anti-money-laundering requirements, or similar legal duties.

7.5 For security, integrity, and enforcement

To prevent fraud, contain security incidents, investigate misuse, preserve audit integrity, protect the rights stack, enforce contractual restrictions, or respond to re-identification, circumvention, competing-repository conduct, or other threatened harm.

We do not sell personal information for advertising or profiling.

8. International processing and subprocessors

Personal information may be processed or stored outside Canada. While information is processed in another jurisdiction, it may be accessible to courts, regulators, law-enforcement authorities, or national-security authorities in that jurisdiction.

TKI may change subprocessors on notice through this Privacy Policy, a published subprocessor list, in-product notice, direct notice, or another process required by an applicable data processing addendum.

9. Security

TKI uses administrative, technical, physical, and organizational safeguards appropriate to the nature and sensitivity of the information processed through the Service.

These safeguards may include encryption in transit and at rest where appropriate, role-based access controls, strong authentication, audit logging, monitoring, backup and recovery controls, credential controls, token-rotation practices, access reviews, and incident-response procedures.

No system is perfectly secure, and TKI does not guarantee that the Service will be free from all security incidents, but TKI uses commercially reasonable measures to protect the Service and the information it processes.

10. Your rights and requests

Subject to applicable law, role-specific agreements, and verification of identity and authority, you may have rights to:

  • request access to personal information about you;
  • request correction of inaccurate personal information;
  • withdraw consent for non-essential processing where withdrawal is legally available;
  • request deletion, removal from active access, or redesignation of particular content or records, subject to legal, contractual, governance, evidentiary, and record-integrity limits; and
  • request information about how your personal information is processed.

Requests may be submitted to privacy@protektant.com.

TKI may require reasonable verification of identity, role, and authority before acting on a request.

For Covered Content, Indigenous Knowledge Records, and related records, deletion, removal, or redesignation requests generally operate prospectively only. Unless required by law or otherwise expressly agreed, such requests do not require TKI to unwind prior lawful access, prior lawful analyses, completed outputs, subscriber reliance, Nation reliance, prior analytics, transaction history, payout records, royalty records, audit records, canonical history, compliance archives, retained System-of-Record copies, or legal obligations imposed on TKI by legal authorities.

If a Knowledge Holder’s account is deleted and TKI confirms the deletion as effective, the submission license for that Knowledge Holder’s Covered Content or Indigenous Knowledge Records is shortened from perpetual duration to the greater of seven years from the effective date of account deletion or the duration of any outstanding reliance by any party for the purposes of the platform.

During that shortened license period, TKI may continue to use, retain, process, disclose, preserve, audit, enforce, and administer the applicable Covered Content, Indigenous Knowledge Records, metadata, logs, snapshots, audit trails, transaction records, System-of-Record copies, and related records as reasonably necessary for platform operation, audit, evidentiary integrity, historical reliance, dispute resolution, fraud prevention, payout or royalty administration, enforcement, and legal obligations imposed on TKI by legal authorities.

11. Retention

TKI retains personal information and related records only for as long as reasonably necessary for the purposes for which they were collected and processed, or as otherwise required or permitted by law and applicable agreements.

Retention periods may vary depending on role, content type, payment status, audit requirements, legal obligations, dispute risk, and platform integrity requirements.

Without limiting the foregoing, TKI may retain:

  • account, billing, payout, tax, sanctions, and compliance records for the periods required by law or reasonably necessary for audit and enforcement;
  • audit logs, system logs, access records, processor records, security events, pricing snapshots, and administrative records for security, billing validation, dispute resolution, and legal compliance;
  • canonical records, snapshots, transaction history, payout records, system-of-record copies, and compliance archives to the extent reasonably necessary for record integrity, historical reliance, fraud prevention, dispute resolution, legal compliance, payout or royalty administration, and preservation of System-of-Record integrity.

After the shortened license period following confirmed account deletion ends, TKI will not authorize new active subscriber access to the applicable Covered Content or Indigenous Knowledge Record unless a new authorization, surviving legal basis, or legal requirement applies. This does not require TKI to delete or alter records that must be retained for audit, evidentiary, compliance, or legal purposes.

12. Changes to this Privacy Policy

TKI may update this Privacy Policy from time to time to reflect changes to the Service, security practices, law, business operations, or risk-management requirements.

If TKI makes a material change, TKI may provide notice by posting the updated Policy on the Service, by email, through an in-product notice, or by another reasonable method. Unless a shorter period is required for legal, security, fraud-prevention, or operational reasons, material changes should take effect no sooner than thirty days after notice.

Continued access to or use of the Service after the effective date of an updated Privacy Policy constitutes acceptance of the updated version, to the extent permitted by applicable law.

13. Dispute resolution and governing law

Privacy-related disputes are governed by the dispute-resolution, governing-law, venue, and arbitration provisions stated in the Protektant Platform Terms and User Protections or in the more specific agreement that applies to the relevant relationship, role, or transaction.

14. Contact us

Traditional Knowledge Inc.

Attn: Privacy / Legal

Ottawa, Ontario, Canada

Email: privacy@protektant.com

General contact: contact@protektant.com

Back to top ↑