Entity: 2733420 ALBERTA INC. d/b/a "Comply+"
Last Updated: August 5, 2026
Contact: support@complyplus.ca
Previous version: 2.0 (February 12, 2026)
Current Version: 3.0
2733420 ALBERTA INC.
#204, 10359 104 Street NW
Edmonton, AB T5J 1B9
Canada
This Privacy Policy explains how Comply+ ("we," "our," "us") collects, uses, and discloses personal information and information about your business, including information about your use of the service, in connection with our Services.
This policy applies to:
We collect information through:
The Website and Services may link to third-party sites with their own privacy policies. We are not responsible for third-party privacy practices.
We do not currently offer a separate Data Processing Agreement (DPA). Our processing of information you enter into the Service is governed by this Privacy Policy and our Terms of Service, under which we act as your service provider for your customers' data (see Section 4.1). If we execute a DPA with a client in the future, that DPA will prevail over this Privacy Policy, to the extent of any conflict, for the data it covers.
We collect personal information and your business information, including information about your use of the service, including:
Call Recordings and AI Note-Taking: We may record and transcribe calls using AI software (e.g., Granola.ai) to improve customer support and service quality, maintain records of discussions, document technical issues, and generate internal notes. Recordings and transcripts are retained per Section 9 and may be stored on third-party platforms. For scheduled calls, we may obtain your consent at booking or call start. If you do not consent, inform us and we will disable these tools or offer alternatives.
IP addresses, browser type, and device identifiers when using our site or Service. Logs related to login attempts, API calls, submissions, exports, consent events, and system activity (which include IP address and browser user-agent) are recorded in tamper-resistant event logs for security and audit-trail purposes.
Cookies: We use cookies for authentication, preferences, and analytics. Cookies are essential for Service functionality. Disabling cookies will prevent Service access.
Cookie Consent: By using the Service, you consent to necessary cookies.
Types of Cookies We Use:
Cookie Management: Manage cookies through browser settings. Disabling cookies prevents Service use.
Analytics Opt-Out: Contact support@complyplus.ca to opt out of non-essential analytics. Strictly necessary cookies cannot be disabled.
Third-Party Analytics Providers: Our analytics providers (listed in Section 8) include Google (analytics/tag management) and PostHog (product analytics). These providers use cookies and similar technologies, are contractually obligated to protect your information, and use it only for authorized purposes. Analytics are not loaded on public document-review pages.
Behavioural Tracking and Advertising: We use analytics tools to track how users find and interact with our Website and Services, including tracking sources such as advertisements, search engines, and referral links for marketing attribution purposes. We do not use cross-site behavioral tracking for targeted advertising or sell your personal information. Our analytics tools measure marketing effectiveness and improve our Service.
Session Recording: We may use heatmaps and click tracking to improve functionality.
Geolocation Data: We derive approximate location from IP addresses for security purposes. We do not collect precise geolocation data.
Usage Data: We collect Service usage information including features accessed, time spent, navigation patterns, search queries, and report metadata.
Performance and Diagnostic Data: We collect error logs, performance metrics, browser/device diagnostics, and uptime data (via our error-monitoring provider). Error reports are scrubbed to remove screened-person data and review tokens before storage.
Some features use AI (including aiSTR™ and document data extraction) to provide decision support.
Third-Party AI Processing (OpenAI, US-based servers). The following AI features transmit data to OpenAI under data processing terms that prohibit use of your data to train general-purpose models:
AI Limitations: AI systems may produce errors, including inaccurate extractions and false positives/negatives. You must verify all AI outputs before use. AI features do not reduce your legal obligations or replace human oversight.
Data Processing for AI Training: We may use anonymized Service data to improve our AI models. We do not train AI on non-anonymized data and do not use AI training data to identify you or any individual.
Automated Decision-Making: Our AI and screening features provide decision-support only. We do not make automated decisions with legal effects about individuals. You retain full control and responsibility for compliance decisions, including screening match dispositions and risk ratings.
You are the data controller (the organization with the customer relationship and the party accountable under PIPEDA) for all customer, screening, document, and transaction data you enter into or generate through the Service. We act as a service provider/data processor on your behalf. You must obtain necessary consents, provide required notices to your customers (including regarding screening and cross-border processing), and comply with privacy laws.
We process sensitive AML-related data under PIPEDA, including: names, dates of birth, addresses, and contact information; identification document numbers, images, and government-issued credentials; occupations, employers, and business relationships; financial transaction data, amounts, patterns, and account details; politically exposed person (PEP) status and risk classifications; sanctions screening queries, results, match scores, and dispositions; suspicious transaction indicators and risk scores; source of funds and wealth information; beneficial ownership structures and corporate relationships; transaction counterparties and related party information; and compliance documents you upload (which may contain any of the foregoing).
We process this data to provide the Services (FINTRAC reporting, screening, risk management, calendar, records, and related compliance tools) only, not for secondary purposes without consent (except anonymized data per Section 5).
Database Storage (Supabase): Your data is stored in our PostgreSQL database hosted by Supabase on Canadian servers (AWS Canada region).
Document Storage (Supabase Storage): Documents uploaded to the Records module are stored in a private storage bucket with deny-by-default access; files are served only through short-lived signed URLs issued by our backend. Uploads are verified server-side (file type, size, and checksum) before being accepted.
Application Processing (Netlify): Report preparation, screening, and related workflows run through front-end code in your browser and server-side functions hosted on Netlify that validate data, prepare reports, call our data providers, and communicate with FINTRAC's API. Functions process data temporarily in-memory; Netlify does not persistently store data beyond operational logs.
Credential Storage (AWS Secrets Manager): Your FINTRAC API credentials and any KYC-provider credentials you connect are stored encrypted in AWS Secrets Manager. This credential store is currently hosted in an AWS region in the United States.
Scheduled Jobs: Reminder digests and maintenance jobs are triggered by schedulers running within our Canadian database infrastructure and executed by our backend functions.
Draft Reports: Draft reports that have not yet been submitted to FINTRAC are stored in Supabase until you submit or delete them.
Submitted Reports: We retain records of submitted reports (including report content and FINTRAC responses) while your subscription is active, as a convenience for your reference and export. Reports transmit directly from our server-side functions to FINTRAC's API via your credentials.
Important: You are solely responsible for maintaining report copies and supporting documentation to meet PCMLTFA record-keeping obligations. Retention within the Service is a convenience, not a record-keeping service (see our Terms of Service).
Operational Logs: System logs (API calls, timestamps, status) are retained per Section 9 for troubleshooting, security monitoring, and audit-trail purposes.
While primary data is stored on Canadian servers, our sub-processors (including Supabase, Netlify, and AWS) are subject to US and/or foreign jurisdiction, and certain sub-processors process data in the United States or Europe (see Section 8). US or foreign authorities may access data under their laws, as these companies can be legally compelled to provide access.
Important: Physical location differs from legal jurisdiction. Service provider jurisdiction enables US or foreign government access despite Canadian storage.
When you screen a customer or prospect, we transmit a limited identity projection to our screening data provider, OpenSanctions Datenbanken GmbH (Germany), via its API:
The provider matches the query against datasets compiled from publicly available government sanctions lists, PEP registries, and similar sources, and returns candidate matches with scores. We store the query, results, and your dispositions as part of your compliance records. Screening data about listed persons originates from public sources; neither we nor the provider verifies its accuracy. Individuals who believe screening data about them is inaccurate should be directed by you (as the party with the customer relationship) to the underlying public source or to the data provider; we will reasonably assist.
A "preview" screening of an unsaved prospect transmits the same projection but stores no results.
Clients may use the Services to request that a person (a "reviewer") — for example, a manager or external advisor — review or attest to a document. If you are a reviewer:
Scope note: Personal information about your customers that you enter into or generate through the Services is processed only as your service provider to provide the Services, per Sections 4.1 and 4.2. The marketing, analytics, and business-operations uses below apply to information about you, your users, and your account — not to your customers' identifiable personal information (which we use only to provide the Services and, in anonymized form, per this Section and Section 12.4).
We use personal information and your business information, including information about your use of the service, to:
Service Delivery:
Account Management:
Legal Compliance:
Service Improvement:
AI and Machine Learning:
We do not use AI training data to identify you or any individual.
Analytics:
Such data may be used without restriction.
Security and Fraud Prevention:
Communications and Updates:
Marketing Communications:
Opt out anytime via email links, account settings, or support@complyplus.ca. Transactional communications remain unaffected.
Business Operations:
Other Purposes: For purposes disclosed at collection; for purposes with your consent; and as otherwise permitted or required by applicable law. We will not use personal information or your business information for materially different purposes without consent or as permitted by law.
We process personal information and your business information on the following legal bases:
Data Storage and Location:
We store primary data on Canadian servers where feasible. Service providers may be subject to the laws of the US or foreign jurisdictions per Section 13.
Security Measures: We implement reasonable administrative, technical, and organizational measures, including encryption in transit and at rest, role-based access controls, row-level security, tamper-resistant audit logging, server-side file validation and checksums for uploaded documents, hashed single-use review tokens, rate limiting on public endpoints, and error-report scrubbing. Access to customer data by Comply+ personnel (including for support and Managed Reporting Assistance) is limited to authorized staff on a need-to-know basis, under confidentiality obligations.
Security Limitations and Disclaimers: While we implement reasonable security measures to protect personal information, you acknowledge and agree that: no system is completely secure and we cannot guarantee absolute security of your information; transmission of information is at your own risk outside our direct control; the security of your information also depends on you (maintain the confidentiality of your login credentials, use strong passwords, enable multi-factor authentication, and do not share account access); and we cannot control third-party security practices.
Security Incident Response: If we become aware of a security breach affecting your personal information, we will: conduct a prompt investigation to assess the nature and scope of the incident; take reasonable steps to contain and remediate the incident; notify you without undue delay in accordance with applicable law; notify the Office of the Privacy Commissioner of Canada and/or affected individuals if required by PIPEDA or other applicable privacy legislation; provide information about the incident, affected data, our response, and mitigation recommendations; and cooperate with you in any investigation or remediation efforts. Notification may be delayed if required by law enforcement or regulatory authorities.
Operational Logs and Retention: Operational and audit logs are retained per Section 9.
We engage third-party service providers ("sub-processors") to deliver, support, and improve the Service.
Jurisdiction and Data Location: Sub-processors use Canadian infrastructure where indicated but may be subject to US or other foreign jurisdiction.
Current Sub-Processors:
| Sub-Processor | Purpose | Data Processed | Location / Jurisdiction |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, document storage, backend infrastructure, scheduled jobs | All company-specific data: user accounts, customer records, risk ratings, screening results, calendar data, uploaded documents, reports, audit logs | Canada (AWS Canada) — US jurisdiction |
| Netlify, Inc. | Web application hosting, serverless functions, CDN | Operational data (IP addresses, request logs); temporarily processes report, screening, and document data during workflows | Canada (AWS Canada); global CDN — US jurisdiction |
| Amazon Web Services (AWS) | Cloud infrastructure underlying Supabase; encrypted credential storage (Secrets Manager) | Underlying storage/processing; encrypted FINTRAC and KYC-provider API credentials | Canada (ca-central-1); credential store currently in a US region — US jurisdiction |
| OpenSanctions Datenbanken GmbH | Sanctions, PEP, and watchlist screening data (API) | Screening queries: names, aliases, dates of birth, countries (see Section 4.6) | Germany / EU-hosted — German jurisdiction |
| OpenAI, L.L.C. | AI document extraction, KYC data structuring, STR narrative drafting (anonymized), transaction analysis (aiSTR™) | Uploaded ID/entity documents; transaction data, patterns, and risk indicators; narrative data (anonymized before transmission as described in Section 3.3) | United States |
| Resend, Inc. | Transactional email delivery (all Service email: invitations, calendar reminders, weekly digests, review requests and outcomes, training invitations) | Recipient names and email addresses, email content (which may include compliance status summaries and secure review links) | United States |
| Stripe, Inc. | Payment processing and subscription billing | Billing identity, payment card details, subscription and transaction history | United States |
| Functional Software, Inc. (Sentry) | Error and performance monitoring | Error reports, stack traces, performance telemetry (scrubbed of screened-person data and review tokens) | United States |
| PostHog, Inc. | Product analytics | User ID, usage events; email only after policy acceptance | United States / EU |
| Google LLC (Analytics / Tag Manager) | Website analytics, marketing attribution, conversion tracking | IP addresses, cookies, browser information, page views, referral source, user journey data | United States |
| Atlassian Pty Ltd (Jira) | Support ticketing | Ticket content, your name and email, attachments you submit with support requests | United States / Australia |
| Granola Labs, Inc. (Granola.ai) | AI-powered note-taking and call transcription | Call audio, transcripts, meeting summaries, participant names | United States |
| Internal alerting tools (Slack Technologies / Discord Inc.) | Internal operational alerts to Comply+ staff (e.g., submission success/failure monitoring, new signups) | Limited metadata: organization name, report type/status, error text | United States |
Customer-Connected Services (your contracts, not sub-processors): If you connect your own accounts with KYC/identity-verification providers (e.g., SumSub, Persona) or use your own FINTRAC enrollment, data exchanged with those providers is governed by your agreements with them. We transmit to and receive data from them at your direction using the credentials you supply.
We will update this list as sub-processors change. Material changes will be communicated per Section 15.
We retain personal information only as long as necessary for collection purposes, legal compliance, dispute resolution, and agreement enforcement.
Active Subscription Data:
Training Service Data: Training service data (user codes, progress, exam results, certificates, training cycles) may be deleted at any time without notice. You are responsible for exporting and maintaining training completion records.
Sandbox and Test Environments: Accounts without paid subscriptions are sandbox/test environments for evaluation only, not for production use or long-term storage. Sandbox accounts have no data persistence guarantee; data may be purged at any time without notice. You must not use sandbox environments for production compliance or live customer data.
Terminated or Expired Subscriptions: Upon termination or expiration of your subscription:
Service Discontinuation: If we discontinue the Services entirely, we will use commercially reasonable efforts to provide at least ninety (90) days' notice so you can export your data (see the wind-down provisions of our Terms of Service), after which remaining data may be permanently deleted or anonymized, subject to the exceptions above.
Anonymization: Anonymized data is not considered personal information nor your business information and may be used indefinitely for business purposes without restriction.
Legal Holds and Exceptions: We may retain information longer where: required or permitted by applicable law or regulation; subject to a legal hold, litigation, government investigation, or regulatory inquiry; necessary to establish, exercise, or defend legal claims; required to comply with audit, accounting, or tax obligations; or you have specifically requested retention.
Your Retention Obligations: You remain responsible for PCMLTFA and FINTRAC record-retention requirements (generally at least five years for prescribed records). The Service does not substitute for your record-keeping system; you must maintain your own copies.
Requesting Deletion: To delete data before termination, use the Service interface or contact support@complyplus.ca. Deletion may affect Service functionality and your regulatory compliance.
By using the Service, you acknowledge and agree to the following responsibilities:
Data Controller Obligations:
Compliance Obligations: You are the reporting entity under PCMLTFA and must: determine reportable transactions; ensure accurate and timely FINTRAC reports; maintain an independent AML compliance program; train personnel; conduct ongoing monitoring and risk assessments; determine screening cadence and disposition matches; meet PCMLTFA record-keeping requirements; and comply with all applicable laws. The Service assists your compliance but does not replace your obligations.
Record-Keeping: Export and maintain all required reports, documents, attestation registers, screening records, training certificates, and supporting documentation outside the Service. Export all required data before termination — data may be permanently deleted within 30 days (subject to the exceptions in Section 9).
Security: Safeguard login credentials, passwords, and API keys; use strong, unique passwords; enable MFA; restrict access to authorized personnel and promptly remove departed users; keep devices and networks secure; report unauthorized access to support@complyplus.ca; log out on shared computers. Treat document review links as sensitive — anyone with an unexpired link can access the document.
Verification and Review Obligations: Independently verify all AI outputs and screening results before use; review all reports before FINTRAC submission; validate data accuracy. You are responsible for all content submitted under your FINTRAC reporting entity identifier.
Usage Compliance: Use the Service lawfully and per our Terms; no illegal activities or rights violations; respect IP rights.
Cooperation Obligations: Cooperate with security and regulatory investigations; review and comply with policy changes.
Third-Party Services and Integrations: Maintain your FINTRAC registration, API credentials, and compliance with FINTRAC requirements; manage your own provider relationships (e.g., KYC providers) and comply with their terms.
Accuracy of Information Provided to Us: Provide accurate contact, billing, and account details; maintain a valid email address (reminders and notices depend on it); accurately represent your organization, binding authority, and authorized users.
Subject to applicable privacy laws, you have rights regarding your personal information.
You may request access to your personal information: what personal information we have collected; how we have used and disclosed it; to whom we have disclosed it; and the source (if not collected directly from you). We will respond within 30 days. We may charge reasonable fees with advance notice. Users may access personal information through their account profile.
Access may be limited where: information is protected by legal privilege; providing access would impose unreasonable cost or disproportionate effort; it would reveal others' personal or confidential commercial information; it is part of formal proceedings or investigations; access is prohibited by law or court order; it would compromise security or reveal proprietary information; or the request is frivolous, vexatious, or in bad faith. If we cannot provide access, we will notify you of the reasons (subject to legal or regulatory restrictions) and your right to challenge our decision.
You have the right to request correction of inaccurate or incomplete personal information we hold about you. Contact support@complyplus.ca with details of the inaccurate information and requested corrections. Note: append-only compliance records (e.g., screening run history, review outcomes, audit logs) are corrected by annotation rather than alteration, to preserve audit-trail integrity. Where appropriate, we will transmit corrected information to third parties who received the inaccurate information from us. Screening data about listed persons originates from public sources; see Section 4.6.
You may withdraw consent for processing based on consent under certain circumstances. Contact support@complyplus.ca or use the address in Section 17. Upon withdrawal: we may not be able to provide the Service or features; your subscription may need to be terminated; and we may retain personal information where we have another legal basis. You cannot withdraw consent for: contract performance; legal requirements; completed transactions/services; or processing previously relied upon (irreversible).
You may request deletion of personal information in certain circumstances. Contact support@complyplus.ca for specific or full deletion. We will delete personal information if: it is no longer necessary for its collection purposes; you have withdrawn consent and we have no other legal basis to retain it; you have successfully objected to processing; it was unlawfully collected or processed; or deletion is required by applicable law. We may be unable to delete where retention is necessary for: legal obligations or court orders; establishment, exercise, or defense of legal claims; fulfilling our contractual obligations to you; legitimate business purposes (e.g., fraud prevention); or record retention requirements under applicable law. Terminate your subscription to delete personal information; data may be deleted within 30 days, subject to the exceptions in Section 9. You must export needed data first.
We require accurate, current personal information and business information to provide the Service and contact you. Update contact information, organization details, billing information, and authorized user lists through your account profile or support@complyplus.ca.
We verify identity before responding to privacy requests. We may request information to confirm identity and rights. For third-party requests, we require authorization proof and may verify identity.
We will acknowledge receipt of your request within five (5) business days and respond within 30 days or as required by law. If we need more time (typically up to 30 additional days), we will notify you with the reason and new timeline. Most requests are free, except where they require significant resources or law permits a fee.
Opt out by: clicking the "unsubscribe" link in marketing emails; adjusting your communication preferences in your account profile; or contacting support@complyplus.ca. Opting out will not affect transactional or Service-related communications (e.g., account notifications, security alerts, system updates, billing notices), communications necessary to provide the Service, or communications required by law. Note that calendar reminders and digests are Service communications controlled by your notification settings in the product. Opt-outs are processed within 10 business days.
If your information was entered into the Service by one of our clients (as your service provider, financial services provider, or counterparty), that client controls your information. Direct access, correction, or deletion requests to them. You may also contact us at support@complyplus.ca; we will verify your request and coordinate with the client, and respond directly where the law requires us to.
If you have privacy concerns: Step 1: Contact our Privacy Officer at support@complyplus.ca or the mailing address in Section 17. We will investigate and respond. Step 2 — Escalation: If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada or your Provincial Privacy Commissioner. Step 3 — Legal Remedies: You may pursue legal remedies through the courts as applicable.
We may disclose personal information or your business information, including information about your use of the service, in the following circumstances:
We disclose information to FINTRAC when reports are submitted through the Service: at your direction as the reporting entity; using your FINTRAC reporting entity identifier and API credentials; and in accordance with PCMLTFA obligations. You are solely responsible for reports submitted to FINTRAC.
We disclose personal information and your business information to service providers who support the Service, as listed in Section 8, including database and document hosting, application hosting and serverless computing, cloud infrastructure, screening data providers, AI processing, email delivery, analytics providers, payment processors, customer support and communication tools, and security and monitoring services.
When you use review/attestation workflows, we send the document link and related context to the reviewers you designate. When you invite learners to training, we send invitation emails to the addresses you provide. You are responsible for the accuracy and appropriateness of these recipients.
We may use and disclose aggregated, de-identified, or anonymized information without restriction, including: to industry organizations or regulatory bodies for benchmarking or research purposes; in whitepapers, case studies, or educational content about AML compliance trends (in aggregate form only); to potential investors, partners, or acquirers for business development purposes; and in academic or policy research about financial crime compliance. Aggregated or anonymized data cannot reasonably identify you or your organization.
We may disclose personal information or your business information for purposes disclosed at collection or with your express consent. Withdraw consent at support@complyplus.ca, subject to legal/contractual restrictions.
We may disclose personal information or your business information as required/permitted by law: to comply with court orders, laws, subpoenas, warrants, or government/regulatory requests; to cooperate with privacy commissioners or regulatory authorities; and to comply with lawful requests for national security, public safety, or criminal enforcement. We notify you of requests where legally permissible.
We may disclose personal information or your business information to enforce our rights and agreements, including for billing, collections, investigating violations, enforcing IP rights, breach claims, and recovering amounts owed.
We may disclose personal information or your business information to: protect the rights, property, or safety of Comply+, our employees, our customers, or the public; prevent or address fraud, security threats, or technical issues; protect against legal liability or harm to our business operations; detect, prevent, or respond to criminal activity, including money laundering or terrorist financing; and respond to emergencies involving danger of death or serious physical injury.
We may disclose personal information or your business information to a buyer, investor, or successor in the event of: a merger, acquisition, or consolidation; a sale of all or substantially all of Comply+'s assets or business; a restructuring or reorganization; dissolution of the business; or bankruptcy, receivership, liquidation, or similar proceeding. The acquiring party will honor this Privacy Policy or provide notice and opt-out rights as required.
We may disclose personal information or your business information to our professional advisors, who are bound by confidentiality obligations.
We may share personal information or your business information with affiliates for purposes in this Privacy Policy, subject to the same commitments.
We may disclose personal information or your business information where: we provide you with notice at the time of collection; the disclosure is required or authorized by law; or you have provided consent to the disclosure.
Primary data is stored in Canada, but our service providers are subject to US and other foreign jurisdictions, and certain processing (screening, AI, email, payments, support, and encrypted credential storage) occurs in the United States or Europe. Foreign authorities may compel access under their laws.
You must inform your customers about foreign processing and government-access risks and assess whether this is acceptable for your use case. US and other foreign legal processes may not provide the same privacy protections, procedural safeguards, or judicial oversight as Canadian law. You are responsible for determining whether your use of the Service complies with applicable privacy laws, including requirements related to cross-border data transfers.
We implement the following safeguards despite foreign jurisdiction risks: Canadian primary data storage where feasible; contractual protections requiring service providers to meet PIPEDA-level standards, implement safeguards, notify us of legal demands where permitted, challenge unlawful requests, and limit disclosure; minimization (e.g., screening queries send only the limited projection in Section 4.6; STR narrative drafting anonymizes before transmission); encryption in transit and at rest; and transparency through this policy. These safeguards cannot prevent lawful foreign government access, which service providers must honor regardless of contractual requirements.
By using the Service, you acknowledge and consent to: service providers being subject to US or foreign jurisdiction despite Canadian storage; US or foreign authorities potentially accessing your data; our inability to prevent, challenge, or always be notified of such access; storage by US companies (even when physically in Canada) being subject to US laws and government access; processing of specified data categories in the United States and Europe as described in Sections 4.6, 8, and 13.1; and data transmission through US-controlled infrastructure. If you do not consent, do not use the Service.
You are responsible for: informing your customers that their data will be processed by service providers subject to foreign jurisdiction (including that screening queries are processed in Europe and AI/email/credential processing occurs in the United States) and may be accessible to foreign authorities; and obtaining necessary consents and ensuring PIPEDA compliance.
We may change data locations when modifying sub-processors or infrastructure, with material changes communicated per Section 15.
We cannot prevent lawful foreign government access to data held by our service providers but will use providers with strong privacy practices and challenge inappropriate requests where possible.
A "data breach" means unauthorized access to or loss of personal information posing real risk of significant harm.
Upon becoming aware of a data breach, we will contain it, secure systems, and investigate to determine affected information, impacted individuals, and remediation steps.
If a data breach poses a real risk of significant harm to you or affected individuals, we will notify you without undue delay by email to your primary contact. Our notification will include: breach description, affected data types, remediation steps, and mitigation recommendations. We will provide updates as we learn more.
If legally required, we will notify relevant privacy commissioners and regulatory authorities within applicable timelines. FINTRAC Breaches: You are solely responsible for assessing and fulfilling any FINTRAC reporting obligations. Consult legal counsel.
If individuals are at risk, we will coordinate with you on notification approach and timing. As data controller, you may have independent notification obligations (including to your customers and to reviewers you designated). We will provide breach details and assistance to support your notification obligations.
We may delay notification if required by authorities or court order, if notification would impede a criminal investigation or threaten national security, if notification would cause additional harm, or if we are prohibited by court order. We will notify you when legally permissible.
Upon notification, you agree to: review the notification and assess your obligations; take recommended steps to mitigate potential harm; notify your customers if legally required or if you control the affected data; cooperate with us in investigating and responding to the breach; preserve any evidence of suspicious activity in your account; and not publicly disclose breach details without coordinating with us (except as legally required).
If you discover a security incident involving the Service or your account, you must: immediately notify us at support@complyplus.ca; provide incident details including what occurred, when discovered, and what data was affected; cooperate with our investigation; and immediately secure your account (e.g., change passwords, revoke compromised access).
While we make reasonable efforts to notify you of breaches and respond to incidents, you acknowledge: we cannot guarantee security or prevent all breaches; transmission is at your own risk; we are not responsible for breaches affecting third-party systems (including FINTRAC's systems after reports are submitted; your own systems, networks, or devices; internet service providers; reviewers' email accounts or systems; or sub-processors, except as provided in our contracts with them); you are responsible for securing your credentials, devices, and networks; and our liability for security breaches is limited as set forth in our Terms of Service.
Email: support@complyplus.ca (Subject: SECURITY INCIDENT)
We may update this Privacy Policy. Website-only changes are effective upon posting without separate notice. Service-related changes will be notified by:
(a) website or in-Service notice;
(b) email to your account;
(c) displaying notice upon login; or
(d) providing notice through other reasonable means. Continued use after changes constitutes acceptance. If you disagree, discontinue use and terminate per the Terms of Service. You must maintain a current email address with us and periodically review this policy for changes.
This Privacy Policy is governed by Alberta and Canadian federal law. Disputes are subject to Terms of Service provisions.
For privacy complaints and inquiries, contact:
Privacy Officer:
The following provisions survive termination of your use of the Service: Sections 4.6 (Screening Data), 4.7 (Document Reviewers), 5 (Information Use, to the extent related to anonymized data), 8 (Sub-Processors), 9 (Data Retention), 10 (Your Responsibilities), 11 (Your Rights, as applicable), 12 (Disclosures of Your Information), 13 (International Transfers), 14.9 (Security Limitations and Disclaimers), 16 (Governing Law), and 17 (Contact).
This privacy policy was last updated on August 5, 2026 (Version 3.0).
This privacy policy was last updated on August 5, 2026 (Version 3.0)