Privacy Policy

1. Personal data we collect

When you purchase a license, we collect (via our payment processor, Paddle) your first name, last name, billing address, email, and payment information. When you create a client-portal account, we collect your email, used for magic-link sign-in; the portal also records your download activity (which version, when) for support and audit purposes. If you contact us for support, we collect the content of your message, your reply email, and any screenshot you choose to attach. A screenshot may contain details of your environment (VM names, IP addresses): it is stored securely with restricted access, used only for your support case, handled as a support record (section 4), reachable through a link that expires, and automatically deleted no later than 90 days after it is sent. Beyond what you choose to share voluntarily, no technical data from your VMware environment is collected by MB Conseil TI Inc.

2. Data VIA collects at the customer site

No data from your environment is transmitted to us automatically. VIA runs locally, in the appliance installed in your network. By default (L1 depth), it reads your vCenter metadata read-only (inventory, configuration, and performance of VMs, hosts, datastores, and networks), with no guest credentials. If you enable the optional guest passes, VIA also reads metadata inside the VMs. With the L2 pass, through the VMware Tools Guest Operations channel and without running any command: installed software and packages, running process names, services, scheduled tasks, listening ports and active TCP connections (Linux), local accounts and groups and domain membership (Linux), as well as excerpts of certain system and application configuration files, read from a fixed list, with secret-shaped values masked. With the L3 pass, VIA also runs a fixed list of read-only commands that complete this data: active network connections, services, scheduled tasks and, on Windows, local accounts and groups with their security identifiers (SIDs), domain membership, Windows license state (partial key, KMS host), drivers, and volumes. At L3 only, and only if you enable it, VIA can collect a subset of this data over a direct connection to the VMs (SSH or WinRM over HTTPS) when the VMware Tools channel is unavailable: operating system, host name, installed software and packages, running services, listening ports and, on Linux, the last boot time. The L2 and L3 passes require guest credentials that you provide; they are used only for the scan and stay in the appliance. VIA collects no disk content, no application data, no passwords stored in the VMs, and no network traffic. All of this data is processed locally in the appliance, and the resulting report is a file on your machine. The software does not communicate with any server of MB Conseil TI Inc. or of a third party and performs no telemetry; internet access is denied by default. The license file is validated locally, offline, without transmitting anything to MB Conseil TI Inc. The only technical data that can reach us is what you choose to share yourself, voluntarily (see section 8).

3. Data usage

We use the personal data collected to: deliver the license file, validate purchase authenticity, provide technical support, respond to user requests, and comply with legal obligations (billing, taxes). We do not send marketing emails without explicit opt-in consent.

4. Data retention

We keep personal data for the following periods, then delete it. A portal sign-in link expires one (1) hour after it is sent. A portal session expires after seven (7) days without activity. A portal account inactive for twenty-four (24) months is deleted, except for paid license and payment records and the terms acceptance history. Paid license and payment (billing) records, as well as the terms acceptance history, are retained for seven (7) years per Quebec and Canadian tax requirements, then deleted. In the portal, a license obtained without payment (for example a free beta license) is deleted with the account. The license issuance server, hosted in Quebec, keeps the delivered license file, which contains your email address, and a technical reference (issue date, vCenter identifier), for issuance, preventing reissuance, and support. This copy is not deleted with the portal account. Support requests are retained for twenty-four (24) months after the last interaction, then deleted. Screenshots attached to a support request are automatically deleted no later than ninety (90) days after they are sent, independently of how long the textual support request is kept. Mailing-list addresses (confirmed subscription only) are retained until you withdraw your consent. Every mailing-list email includes an unsubscribe link. The link in our welcome email leads to our unsubscribe page: your address is removed from the list immediately; its deletion at our sending provider is requested at the same time and, if a technical failure occurs, retried automatically for at most thirty (30) days. The link in our broadcasts is our sending provider's own: it stops further sends as soon as you click; our provider then notifies us, and we delete your address at the provider and remove it from our list; if a technical failure occurs, that notice is redelivered to us automatically. We then keep, for twenty-four (24) months, a pseudonymous record of your withdrawal, which does not contain your address and is used only to honor that withdrawal. Discount-eligibility data (survey or mailing-list signup) is retained for at most twenty-four (24) months after the last interaction, or as long as you stay subscribed to the list, then automatically deleted; if you completed the survey, your discount eligibility is therefore kept until that term even after you unsubscribe from the list.

5. Third-party processors

We use the following sub-processors, each bound by data protection agreements: Paddle (payment processing, invoicing); Vercel (website and portal hosting, anonymized audience analytics, United States); Upstash (portal account data storage, Montreal region, Quebec, Canada); Resend (sending of transactional email, including internal notices that carry the content of your support requests, beta access requests, and survey answers; hosting of the mailing list, only for addresses whose subscription was confirmed through the emailed link, and sending of its broadcasts, with unsubscribe possible at any time; Resend keeps a copy of sent emails, including their content; United States); Microsoft 365 (hosting of our mailbox, where your support requests, beta program access requests, survey answers, and the support bundles you send us are received); Cloudflare, including R2 (DNS and website protection globally; encrypted relay of license issuance requests to our issuance server, which are readable by Cloudflare while relayed: name, email, vCenter identifier, chosen license name, tier and VM cap, language, request reference and license file; routing of incoming email sent to our mbtools.ca addresses; file storage in North America). These processors receive only the minimum data required for their function. Several of them process or store information outside Quebec, notably in the United States. Before such processing, we assess privacy factors and govern those providers through written agreements, as required by applicable law.

6. Your rights (applicable data protection laws)

You have the following rights, under applicable data protection laws: access to your personal data, correction of inaccurate data, deletion (right to be forgotten) subject to legal retention obligations, portability of data in a structured format, withdrawal of consent at any time, and objection to processing. To exercise these rights, write to privacy@mbtools.ca. You can also delete your portal account yourself from the Account page. We respond within 30 days.

7. Breach notification

When a confidentiality incident involves personal information, we take reasonable measures to reduce the risk of harm and prevent similar incidents. If it presents a risk of serious injury, we promptly notify the Commission d'accès à l'information and affected individuals as required by applicable law.

8. Voluntary sharing of a bundle (support or contribution)

As part of the beta program, you may choose to share a bundle generated from the appliance. This sharing is always at your initiative: nothing is sent without an explicit action on your part. The available support bundle (Debug package) contains the real identifiers of your environment; it is produced only at your explicit request, and you choose to send it to us. An anonymized version will be offered as soon as the completeness of the anonymization is proven. This bundle is for diagnosing a specific case you report: it contains the log and metadata of the run concerned, with no report and no inventory data, and you email it to support@mbtools.ca when support asks you to. The information it contains is handled under sections 4, 6, and 7: it is used only for that support case, stored securely with restricted access, never reused for any other purpose, and deleted no later than 30 days after the case is resolved. A contribution bundle, intended only to improve the accuracy of the product's rules, is planned; it does not exist in the product yet. You may share nothing at all, with no impact on your use of VIA.

9. Beta program access requests

When you submit a beta program access request, we collect the form information (name, email, role, VMware situation, estate size, and your message content) and use it to assess the fit of your organization and environment, communicate with you, plan your beta participation if you are selected, and document our decision. Access is limited to the people and processors who need it for these purposes. Access requests (accepted, declined, or incomplete) are retained for twelve (12) months after the decision, then destroyed, unless a legal retention obligation applies. Submitting an access request triggers no marketing communication: that requires separate consent, through an optional checkbox.

10. Contact

Personal Information Protection Officer: MB Conseil TI Inc., Quebec, Canada. For any question relating to this policy, your personal data, or to reach the officer: privacy@mbtools.ca.

11. Cookies

The site sets only cookies that are strictly necessary for it to work, and no advertising or audience measurement cookies: audience measurement on the public site uses none. Client portal: a session cookie (authjs.session-token) keeps you signed in; it expires after seven (7) days without activity or when you sign out. An anti-forgery token (authjs.csrf-token) protects sign-in against requests from other sites, and a cookie remembers the page to return to after sign-in (authjs.callback-url); both are deleted when you close your browser. When you request a sign-in link, a portal-signin-lang cookie keeps the language you chose, so that a new account opens in that language; it holds no identifier and expires after one (1) hour. The language choice of some pages is also kept in your browser's local storage, without being transmitted to us.