Legal Document

Privacy Policy

Entity: 2733420 ALBERTA INC. d/b/a "Comply+"

Last Updated: August 5, 2026

Contact: support@complyplus.ca

Previous version: 2.0 (February 12, 2026)

Current Version: 3.0

Mailing Address:

2733420 ALBERTA INC.

#204, 10359 104 Street NW

Edmonton, AB T5J 1B9

Canada

1. Purpose

This Privacy Policy explains how Comply+ ("we," "our," "us") collects, uses, and discloses personal information and information about your business, including information about your use of the service, in connection with our Services.

2. Scope

2.1 Who This Policy Applies To

This policy applies to:

  • Visitors to our website.
  • Authorized users from our client organizations.
  • Customers of our clients whose information is entered into the Services for AML compliance (including individuals who are screened against sanctions, PEP, and watchlist data).
  • Training Service (Comply+ Academy) users, including MSB and reporting entity employees, and learners administered through the portal.
  • Document reviewers — individuals invited by our clients to review or attest to documents through the Services (see Section 4.7).
  • Prospective clients.
  • Third parties referenced in compliance reports, investigations, or stored documents.
  • Former clients and users.

2.2 Where and How We Collect Information

We collect information through:

  • Our Website.
  • Email, text, and electronic communications.
  • Voice and video communications, which may be recorded and transcribed using AI-powered tools.
  • Mobile and desktop applications.
  • Third-party websites and services where we advertise.
  • Third-party data providers (for sanctions/PEP screening, see Section 4.6).
  • Document review links acted on by reviewers our clients designate.

2.3 Third-Party Websites and Services

The Website and Services may link to third-party sites with their own privacy policies. We are not responsible for third-party privacy practices.

2.4 Data Processing Agreements

We do not currently offer a separate Data Processing Agreement (DPA). Our processing of information you enter into the Service is governed by this Privacy Policy and our Terms of Service, under which we act as your service provider for your customers' data (see Section 4.1). If we execute a DPA with a client in the future, that DPA will prevail over this Privacy Policy, to the extent of any conflict, for the data it covers.

3. Information We Collect

3.1 Information You Provide

We collect personal information and your business information, including information about your use of the service, including:

  • Account details: Name, email, login credentials, organization information.
  • Customer data: Personal identifiers and AML-relevant information about your customers (names, aliases, dates of birth, addresses, occupations, countries of residence and citizenship, identification document types and numbers, bank account details, transaction details including histories, amounts, dates, counterparties, payment methods, and patterns) for compliance record-keeping, screening, risk management, reporting, and AI-powered detection.
  • Risk management records: Risk ratings you assign to your customers, business-relationship determinations, review dates and intervals, rating-change history, and free-text notes.
  • Screening queries and results: When you screen a customer, we transmit a limited identity projection (see Section 4.6) and store the query, candidate matches returned by the data provider (names, aliases, dates of birth, countries, list categories such as sanctions/PEP/adverse information, source references, and match scores), your match dispositions (confirmed / false positive), disposition notes, and the identity of the user who dispositioned each match.
  • Compliance calendar data: Obligations, due dates, recurrence settings, completion records, and free-text notes you create.
  • Documents and records: Documents you upload to the Records module (which may include compliance policies, effectiveness reviews, training records, registrations, and customer identification documents), together with version history, checksums, tags, notes, and document links.
  • Document review data: Information about review requests you initiate and outcomes provided by reviewers (see Section 4.7).
  • FINTRAC reporting details: Reporting ID, encrypted API credentials, report content and metadata.
  • Payment information: Credit card details (via third-party processors), billing addresses, transaction history.
  • Communications: Support correspondence (emails, chat, tickets).
  • Feedback: Survey and user research responses.
  • Professional information: Job title, department, role, contact details.
  • Training Service data: Email, name, industry, company name, enrollment, course progress, exam results, certificates, learning history, and training-cycle status; and, for portal-based academy administration, the learners you invite and link.
  • Managed Reporting Assistance data: Where you purchase Managed Reporting Assistance, the transaction files (e.g., CSVs) and customer information you deliver to us for report preparation. Authorized Comply+ personnel access and process this data solely to set up your account and prepare draft reports at your direction, under confidentiality obligations.

Call Recordings and AI Note-Taking: We may record and transcribe calls using AI software (e.g., Granola.ai) to improve customer support and service quality, maintain records of discussions, document technical issues, and generate internal notes. Recordings and transcripts are retained per Section 9 and may be stored on third-party platforms. For scheduled calls, we may obtain your consent at booking or call start. If you do not consent, inform us and we will disable these tools or offer alternatives.

3.2 Automatically Collected Information

IP addresses, browser type, and device identifiers when using our site or Service. Logs related to login attempts, API calls, submissions, exports, consent events, and system activity (which include IP address and browser user-agent) are recorded in tamper-resistant event logs for security and audit-trail purposes.

Cookies: We use cookies for authentication, preferences, and analytics. Cookies are essential for Service functionality. Disabling cookies will prevent Service access.

Cookie Consent: By using the Service, you consent to necessary cookies.

Types of Cookies We Use:

  • Strictly Necessary Cookies: Required for authentication, security, and core Service functionality. These cannot be disabled.
  • Functional Cookies: Remember your preferences and settings.
  • Analytics Cookies: Help us understand how the Service is used and identify areas for improvement.

Cookie Management: Manage cookies through browser settings. Disabling cookies prevents Service use.

Analytics Opt-Out: Contact support@complyplus.ca to opt out of non-essential analytics. Strictly necessary cookies cannot be disabled.

Third-Party Analytics Providers: Our analytics providers (listed in Section 8) include Google (analytics/tag management) and PostHog (product analytics). These providers use cookies and similar technologies, are contractually obligated to protect your information, and use it only for authorized purposes. Analytics are not loaded on public document-review pages.

Behavioural Tracking and Advertising: We use analytics tools to track how users find and interact with our Website and Services, including tracking sources such as advertisements, search engines, and referral links for marketing attribution purposes. We do not use cross-site behavioral tracking for targeted advertising or sell your personal information. Our analytics tools measure marketing effectiveness and improve our Service.

Session Recording: We may use heatmaps and click tracking to improve functionality.

Geolocation Data: We derive approximate location from IP addresses for security purposes. We do not collect precise geolocation data.

Usage Data: We collect Service usage information including features accessed, time spent, navigation patterns, search queries, and report metadata.

Performance and Diagnostic Data: We collect error logs, performance metrics, browser/device diagnostics, and uptime data (via our error-monitoring provider). Error reports are scrubbed to remove screened-person data and review tokens before storage.

3.3 AI Features and Automated Processing

Some features use AI (including aiSTR™ and document data extraction) to provide decision support.

Third-Party AI Processing (OpenAI, US-based servers). The following AI features transmit data to OpenAI under data processing terms that prohibit use of your data to train general-purpose models:

  • Document extraction: When you use AI extraction to prefill customer or entity records, the identification or entity documents you upload (which may include government-issued ID images) are transmitted to OpenAI for text extraction.
  • KYC data structuring: Where you connect a KYC provider, leftover unstructured applicant data may be processed by OpenAI to prefill fields, which are flagged for your review.
  • STR narrative drafting (aiSTR™): Before transmission, data is anonymized — names are replaced with neutral labels, dates of birth are converted to age bands, and identifiers are truncated. Names are re-inserted only on your device.
  • Transaction analysis: Transaction data, patterns, and risk indicators processed for suspicious-activity detection features.

AI Limitations: AI systems may produce errors, including inaccurate extractions and false positives/negatives. You must verify all AI outputs before use. AI features do not reduce your legal obligations or replace human oversight.

Data Processing for AI Training: We may use anonymized Service data to improve our AI models. We do not train AI on non-anonymized data and do not use AI training data to identify you or any individual.

Automated Decision-Making: Our AI and screening features provide decision-support only. We do not make automated decisions with legal effects about individuals. You retain full control and responsibility for compliance decisions, including screening match dispositions and risk ratings.

4. Sensitive Data Handling

4.1 Your Role as Data Controller

You are the data controller (the organization with the customer relationship and the party accountable under PIPEDA) for all customer, screening, document, and transaction data you enter into or generate through the Service. We act as a service provider/data processor on your behalf. You must obtain necessary consents, provide required notices to your customers (including regarding screening and cross-border processing), and comply with privacy laws.

4.2 Nature of Data We Process

We process sensitive AML-related data under PIPEDA, including: names, dates of birth, addresses, and contact information; identification document numbers, images, and government-issued credentials; occupations, employers, and business relationships; financial transaction data, amounts, patterns, and account details; politically exposed person (PEP) status and risk classifications; sanctions screening queries, results, match scores, and dispositions; suspicious transaction indicators and risk scores; source of funds and wealth information; beneficial ownership structures and corporate relationships; transaction counterparties and related party information; and compliance documents you upload (which may contain any of the foregoing).

We process this data to provide the Services (FINTRAC reporting, screening, risk management, calendar, records, and related compliance tools) only, not for secondary purposes without consent (except anonymized data per Section 5).

4.3 Data Storage and Processing Architecture

Database Storage (Supabase): Your data is stored in our PostgreSQL database hosted by Supabase on Canadian servers (AWS Canada region).

Document Storage (Supabase Storage): Documents uploaded to the Records module are stored in a private storage bucket with deny-by-default access; files are served only through short-lived signed URLs issued by our backend. Uploads are verified server-side (file type, size, and checksum) before being accepted.

Application Processing (Netlify): Report preparation, screening, and related workflows run through front-end code in your browser and server-side functions hosted on Netlify that validate data, prepare reports, call our data providers, and communicate with FINTRAC's API. Functions process data temporarily in-memory; Netlify does not persistently store data beyond operational logs.

Credential Storage (AWS Secrets Manager): Your FINTRAC API credentials and any KYC-provider credentials you connect are stored encrypted in AWS Secrets Manager. This credential store is currently hosted in an AWS region in the United States.

Scheduled Jobs: Reminder digests and maintenance jobs are triggered by schedulers running within our Canadian database infrastructure and executed by our backend functions.

4.4 Report Handling

Draft Reports: Draft reports that have not yet been submitted to FINTRAC are stored in Supabase until you submit or delete them.

Submitted Reports: We retain records of submitted reports (including report content and FINTRAC responses) while your subscription is active, as a convenience for your reference and export. Reports transmit directly from our server-side functions to FINTRAC's API via your credentials.

Important: You are solely responsible for maintaining report copies and supporting documentation to meet PCMLTFA record-keeping obligations. Retention within the Service is a convenience, not a record-keeping service (see our Terms of Service).

Operational Logs: System logs (API calls, timestamps, status) are retained per Section 9 for troubleshooting, security monitoring, and audit-trail purposes.

4.5 Data Processing and Foreign Jurisdiction Access

While primary data is stored on Canadian servers, our sub-processors (including Supabase, Netlify, and AWS) are subject to US and/or foreign jurisdiction, and certain sub-processors process data in the United States or Europe (see Section 8). US or foreign authorities may access data under their laws, as these companies can be legally compelled to provide access.

Important: Physical location differs from legal jurisdiction. Service provider jurisdiction enables US or foreign government access despite Canadian storage.

4.6 Sanctions & PEP Screening Data

When you screen a customer or prospect, we transmit a limited identity projection to our screening data provider, OpenSanctions Datenbanken GmbH (Germany), via its API:

  • For individuals: name, alias (if recorded), date of birth, and country (citizenship or residence).
  • For entities: name and country.
  • We do not transmit addresses, identification numbers, account details, or transaction data for screening.

The provider matches the query against datasets compiled from publicly available government sanctions lists, PEP registries, and similar sources, and returns candidate matches with scores. We store the query, results, and your dispositions as part of your compliance records. Screening data about listed persons originates from public sources; neither we nor the provider verifies its accuracy. Individuals who believe screening data about them is inaccurate should be directed by you (as the party with the customer relationship) to the underlying public source or to the data provider; we will reasonably assist.

A "preview" screening of an unsaved prospect transmits the same projection but stores no results.

4.7 Document Reviewers (Notice to Reviewers)

Clients may use the Services to request that a person (a "reviewer") — for example, a manager or external advisor — review or attest to a document. If you are a reviewer:

  • You receive a single-use, time-limited secure link by email at the direction of our client, who is responsible for choosing to send it to you.
  • When you act on the link, we collect the information you provide (name, title, email, outcome, and any comment) together with technical metadata (IP address, browser user-agent, timestamp, and the checksum of the document version you reviewed).
  • We collect this information to create a tamper-evident record of the review for our client's compliance purposes, to prevent fraud and misuse of review links, and to secure the Service. Review outcome records are immutable once created and are retained as part of the client's records per Section 9.
  • Your information in a review record is controlled by the client who requested the review; direct access, correction, or deletion requests to them, or contact us at support@complyplus.ca and we will coordinate with the client. Analytics and marketing tools are not loaded on review pages.

5. Information Use

Scope note: Personal information about your customers that you enter into or generate through the Services is processed only as your service provider to provide the Services, per Sections 4.1 and 4.2. The marketing, analytics, and business-operations uses below apply to information about you, your users, and your account not to your customers' identifiable personal information (which we use only to provide the Services and, in anonymized form, per this Section and Section 12.4).

We use personal information and your business information, including information about your use of the service, to:

Service Delivery:

  • Operate and maintain the platform and its modules (reporting, screening, risk management, calendar, records, training administration)
  • Facilitate preparation and submission of reports to FINTRAC at your direction
  • Prepare draft reports from data you deliver under Managed Reporting Assistance engagements
  • Transmit screening queries to and receive results from our screening data provider
  • Generate reminders, digests, review requests, and other notifications you configure
  • Store, version, and make available documents and records you upload
  • Manage user authentication and access
  • Process instructions and requests
  • Enable user collaboration and review workflows
  • Store and manage reference data (customer profiles, locations, transaction records)

Account Management:

  • Create and maintain user accounts
  • Process payments
  • Communicate with you about your account or Service usage
  • Provide customer support and respond to inquiries (including via our support ticketing provider)
  • Send transactional notifications (e.g., report confirmations, system alerts, security notifications, calendar reminders, review-outcome notices)

Legal Compliance:

  • Comply with legal obligations, including the PCMLTFA
  • Respond to lawful requests from authorities, courts, or regulatory agencies
  • Enforce our Terms of Service and other agreements
  • Detect and prevent fraud, security incidents, or policy violations
  • Protect rights, property, and safety
  • Retain required records and maintain audit trails (including consent records)

Service Improvement:

  • Analyze Service usage to identify areas for improvement
  • Develop and deploy new features
  • Conduct research and development to improve our technology
  • Optimize Service performance
  • Monitor system health and reliability

AI and Machine Learning:

  • Train AI models using anonymized transaction data
  • Detect suspicious transactions
  • Generate compliance insights from transaction data
  • Provide decision-support tools (human review required)

We do not use AI training data to identify you or any individual.

Analytics:

  • Create aggregated, anonymized data for analytics and research
  • Analyze industry trends
  • Publish insights using anonymized data

Such data may be used without restriction.

Security and Fraud Prevention:

  • Monitor for suspicious activity and security threats (including rate-limiting and abuse prevention on public review links)
  • Implement security and authentication controls
  • Conduct security assessments and respond to incidents
  • Protect against fraudulent or illegal activity

Communications and Updates:

  • Notify you about changes to the Service or our policies
  • Send service updates and security alerts
  • Provide AML training and resources
  • Communicate service disruptions

Marketing Communications:

  • Inform about new features
  • Invite to events and webinars
  • Share educational content and compliance updates
  • Request feedback and user research participation

Opt out anytime via email links, account settings, or support@complyplus.ca. Transactional communications remain unaffected.

Business Operations:

  • Operate business and maintain records
  • Pursue mergers, acquisitions, and asset sales
  • Maintain continuity and backups
  • Conduct audits and quality assurance

Other Purposes: For purposes disclosed at collection; for purposes with your consent; and as otherwise permitted or required by applicable law. We will not use personal information or your business information for materially different purposes without consent or as permitted by law.

6. Legal Basis for Processing

We process personal information and your business information on the following legal bases:

  • With your consent: Where you have consented to collection, use, or disclosure for specific purposes. You may withdraw consent by contacting support@complyplus.ca, subject to legal or contractual restrictions.
  • As necessary to perform our contractual obligations: including platform access for authorized users; report preparation and FINTRAC submission; screening at your direction; calendar, records, and review workflows you initiate; user authentication and account security; processing billing and payment transactions; customer support and technical assistance; and delivering software updates and Service improvements.
  • Legal Compliance: including complying with legal and regulatory requests; responding to lawful authority requests; enforcing our agreements and collecting payments; detecting and preventing fraud, security, and technical issues; and complying with record retention requirements under applicable law.
  • Legitimate Interests: including developing and improving Service features; analyzing usage and optimizing user experience; training AI/ML models using anonymized data; protecting Service security and preventing unauthorized access; protecting rights, property, and safety; operating our business and maintaining continuity; evaluating business transactions; analyzing transaction data for AML compliance; and storing transaction histories for compliance tools.
  • Third-Party Data: You warrant lawful authority to provide customer data to us and to direct screening of the individuals and entities you screen.

7. Data Storage and Security

Data Storage and Location:

We store primary data on Canadian servers where feasible. Service providers may be subject to the laws of the US or foreign jurisdictions per Section 13.

  • Primary Database (Supabase): Company data, user accounts, customer records, screening results, calendar data, document metadata, and reports are stored in a PostgreSQL database on Canadian servers (AWS Canada). Supabase, Inc. is a US company subject to US jurisdiction.
  • Document Storage: Uploaded documents are stored in private Supabase Storage buckets on the same Canadian infrastructure.
  • Application Hosting (Netlify): The web application is hosted on Netlify's infrastructure. Serverless functions run in Canada (AWS Canada) and may temporarily handle customer data; edge functions operate on Netlify's global network. Netlify, Inc. is a US company subject to US jurisdiction and processes limited operational data (IP addresses, request metadata, error logs).
  • Credential Store (AWS Secrets Manager): Encrypted API credentials are stored in a US AWS region.
  • Academy (separate infrastructure): Training Service data is held in a separate database instance operated by us; portal-based academy administration reads learner progress from it when displayed.

Security Measures: We implement reasonable administrative, technical, and organizational measures, including encryption in transit and at rest, role-based access controls, row-level security, tamper-resistant audit logging, server-side file validation and checksums for uploaded documents, hashed single-use review tokens, rate limiting on public endpoints, and error-report scrubbing. Access to customer data by Comply+ personnel (including for support and Managed Reporting Assistance) is limited to authorized staff on a need-to-know basis, under confidentiality obligations.

Security Limitations and Disclaimers: While we implement reasonable security measures to protect personal information, you acknowledge and agree that: no system is completely secure and we cannot guarantee absolute security of your information; transmission of information is at your own risk outside our direct control; the security of your information also depends on you (maintain the confidentiality of your login credentials, use strong passwords, enable multi-factor authentication, and do not share account access); and we cannot control third-party security practices.

Security Incident Response: If we become aware of a security breach affecting your personal information, we will: conduct a prompt investigation to assess the nature and scope of the incident; take reasonable steps to contain and remediate the incident; notify you without undue delay in accordance with applicable law; notify the Office of the Privacy Commissioner of Canada and/or affected individuals if required by PIPEDA or other applicable privacy legislation; provide information about the incident, affected data, our response, and mitigation recommendations; and cooperate with you in any investigation or remediation efforts. Notification may be delayed if required by law enforcement or regulatory authorities.

Operational Logs and Retention: Operational and audit logs are retained per Section 9.

8. Sub-Processors

We engage third-party service providers ("sub-processors") to deliver, support, and improve the Service.

Jurisdiction and Data Location: Sub-processors use Canadian infrastructure where indicated but may be subject to US or other foreign jurisdiction.

Current Sub-Processors:

Sub-ProcessorPurposeData ProcessedLocation / Jurisdiction
Supabase, Inc.Database, authentication, document storage, backend infrastructure, scheduled jobsAll company-specific data: user accounts, customer records, risk ratings, screening results, calendar data, uploaded documents, reports, audit logsCanada (AWS Canada) — US jurisdiction
Netlify, Inc.Web application hosting, serverless functions, CDNOperational data (IP addresses, request logs); temporarily processes report, screening, and document data during workflowsCanada (AWS Canada); global CDN — US jurisdiction
Amazon Web Services (AWS)Cloud infrastructure underlying Supabase; encrypted credential storage (Secrets Manager)Underlying storage/processing; encrypted FINTRAC and KYC-provider API credentialsCanada (ca-central-1); credential store currently in a US region — US jurisdiction
OpenSanctions Datenbanken GmbHSanctions, PEP, and watchlist screening data (API)Screening queries: names, aliases, dates of birth, countries (see Section 4.6)Germany / EU-hosted — German jurisdiction
OpenAI, L.L.C.AI document extraction, KYC data structuring, STR narrative drafting (anonymized), transaction analysis (aiSTR™)Uploaded ID/entity documents; transaction data, patterns, and risk indicators; narrative data (anonymized before transmission as described in Section 3.3)United States
Resend, Inc.Transactional email delivery (all Service email: invitations, calendar reminders, weekly digests, review requests and outcomes, training invitations)Recipient names and email addresses, email content (which may include compliance status summaries and secure review links)United States
Stripe, Inc.Payment processing and subscription billingBilling identity, payment card details, subscription and transaction historyUnited States
Functional Software, Inc. (Sentry)Error and performance monitoringError reports, stack traces, performance telemetry (scrubbed of screened-person data and review tokens)United States
PostHog, Inc.Product analyticsUser ID, usage events; email only after policy acceptanceUnited States / EU
Google LLC (Analytics / Tag Manager)Website analytics, marketing attribution, conversion trackingIP addresses, cookies, browser information, page views, referral source, user journey dataUnited States
Atlassian Pty Ltd (Jira)Support ticketingTicket content, your name and email, attachments you submit with support requestsUnited States / Australia
Granola Labs, Inc. (Granola.ai)AI-powered note-taking and call transcriptionCall audio, transcripts, meeting summaries, participant namesUnited States
Internal alerting tools (Slack Technologies / Discord Inc.)Internal operational alerts to Comply+ staff (e.g., submission success/failure monitoring, new signups)Limited metadata: organization name, report type/status, error textUnited States

Customer-Connected Services (your contracts, not sub-processors): If you connect your own accounts with KYC/identity-verification providers (e.g., SumSub, Persona) or use your own FINTRAC enrollment, data exchanged with those providers is governed by your agreements with them. We transmit to and receive data from them at your direction using the credentials you supply.

We will update this list as sub-processors change. Material changes will be communicated per Section 15.

9. Data Retention

We retain personal information only as long as necessary for collection purposes, legal compliance, dispute resolution, and agreement enforcement.

Active Subscription Data:

  • Company-Specific Reference Data: Customer profiles, risk ratings and history, screening results and dispositions, calendar obligations and events, location information, transaction history, and other reference data are retained while your subscription is active or until you delete them (subject to append-only records noted below).
  • Draft Reports: Retained until submitted or deleted.
  • Submitted Report Records: Retained while your subscription is active as a convenience for reference and export. Not substitutes for your record-keeping obligations.
  • Documents (Records module): Retained until you delete them. Deleted documents are recoverable for a 30-day grace period, after which they are permanently purged, including all versions, notes, and associated review/attestation records. Purged content cannot be recovered.
  • Review and Attestation Records: Immutable once created; retained with the associated document and purged with it (or upon account termination). Export the attestation register regularly if you need it for regulatory purposes.
  • Screening Run Records and Risk History: Maintained as append-only records while your subscription is active, to preserve the integrity of your compliance trail.
  • Managed Reporting Assistance data: Files and data you deliver for report preparation are retained under the same rules as company-specific reference data.
  • User Account Information: Retained while subscription and user account are active.
  • Billing and Payment Information: Retained for seven (7) years as required for accounting, tax, and legal compliance.
  • Audit / Event Logs (including consent records, submission events, export events; with IP address and user-agent): Retained for the duration of your subscription and thereafter for as long as reasonably necessary for security, audit-trail integrity, fraud prevention, and compliance purposes, including where retention is required for legal holds or investigations. These logs are not currently subject to a fixed or automatic deletion schedule.
  • Operational / Diagnostic Logs: Retained up to 12 months, then deleted or anonymized.

Training Service Data: Training service data (user codes, progress, exam results, certificates, training cycles) may be deleted at any time without notice. You are responsible for exporting and maintaining training completion records.

Sandbox and Test Environments: Accounts without paid subscriptions are sandbox/test environments for evaluation only, not for production use or long-term storage. Sandbox accounts have no data persistence guarantee; data may be purged at any time without notice. You must not use sandbox environments for production compliance or live customer data.

Terminated or Expired Subscriptions: Upon termination or expiration of your subscription:

  • Data Deletion: Company-specific data (including documents, screening records, calendar data, and report records) may be deleted or anonymized within 30 days of termination.
  • Account Deactivation: User accounts are immediately deactivated. Account data may be deleted within 30 days.
  • No Data Recovery: Once deleted, data cannot be recovered. You are solely responsible for exporting and saving any data you require prior to termination. We recommend exporting all necessary data — reports, customer records, screening results, documents, and attestation registers — before canceling your subscription.
  • Exceptions: We may retain information where required by law (billing records, legal holds, anonymized data).

Service Discontinuation: If we discontinue the Services entirely, we will use commercially reasonable efforts to provide at least ninety (90) days' notice so you can export your data (see the wind-down provisions of our Terms of Service), after which remaining data may be permanently deleted or anonymized, subject to the exceptions above.

Anonymization: Anonymized data is not considered personal information nor your business information and may be used indefinitely for business purposes without restriction.

Legal Holds and Exceptions: We may retain information longer where: required or permitted by applicable law or regulation; subject to a legal hold, litigation, government investigation, or regulatory inquiry; necessary to establish, exercise, or defend legal claims; required to comply with audit, accounting, or tax obligations; or you have specifically requested retention.

Your Retention Obligations: You remain responsible for PCMLTFA and FINTRAC record-retention requirements (generally at least five years for prescribed records). The Service does not substitute for your record-keeping system; you must maintain your own copies.

Requesting Deletion: To delete data before termination, use the Service interface or contact support@complyplus.ca. Deletion may affect Service functionality and your regulatory compliance.

10. Your Responsibilities

By using the Service, you acknowledge and agree to the following responsibilities:

Data Controller Obligations:

  • Obtain necessary consents and establish lawful bases to collect, share, and screen customer information for AML compliance.
  • Provide privacy notices to your customers about data collection, use, disclosure, screening, and cross-border processing.
  • Ensure accuracy and completeness of information entered; we are not responsible for your data errors.
  • Respond to privacy rights requests from your customers (including individuals you screen).
  • Choose reviewers appropriately and lawfully when using document review workflows.

Compliance Obligations: You are the reporting entity under PCMLTFA and must: determine reportable transactions; ensure accurate and timely FINTRAC reports; maintain an independent AML compliance program; train personnel; conduct ongoing monitoring and risk assessments; determine screening cadence and disposition matches; meet PCMLTFA record-keeping requirements; and comply with all applicable laws. The Service assists your compliance but does not replace your obligations.

Record-Keeping: Export and maintain all required reports, documents, attestation registers, screening records, training certificates, and supporting documentation outside the Service. Export all required data before termination data may be permanently deleted within 30 days (subject to the exceptions in Section 9).

Security: Safeguard login credentials, passwords, and API keys; use strong, unique passwords; enable MFA; restrict access to authorized personnel and promptly remove departed users; keep devices and networks secure; report unauthorized access to support@complyplus.ca; log out on shared computers. Treat document review links as sensitive anyone with an unexpired link can access the document.

Verification and Review Obligations: Independently verify all AI outputs and screening results before use; review all reports before FINTRAC submission; validate data accuracy. You are responsible for all content submitted under your FINTRAC reporting entity identifier.

Usage Compliance: Use the Service lawfully and per our Terms; no illegal activities or rights violations; respect IP rights.

Cooperation Obligations: Cooperate with security and regulatory investigations; review and comply with policy changes.

Third-Party Services and Integrations: Maintain your FINTRAC registration, API credentials, and compliance with FINTRAC requirements; manage your own provider relationships (e.g., KYC providers) and comply with their terms.

Accuracy of Information Provided to Us: Provide accurate contact, billing, and account details; maintain a valid email address (reminders and notices depend on it); accurately represent your organization, binding authority, and authorized users.

11. Your Rights

Subject to applicable privacy laws, you have rights regarding your personal information.

11.1 Right to Access

You may request access to your personal information: what personal information we have collected; how we have used and disclosed it; to whom we have disclosed it; and the source (if not collected directly from you). We will respond within 30 days. We may charge reasonable fees with advance notice. Users may access personal information through their account profile.

11.2 Exceptions to Access

Access may be limited where: information is protected by legal privilege; providing access would impose unreasonable cost or disproportionate effort; it would reveal others' personal or confidential commercial information; it is part of formal proceedings or investigations; access is prohibited by law or court order; it would compromise security or reveal proprietary information; or the request is frivolous, vexatious, or in bad faith. If we cannot provide access, we will notify you of the reasons (subject to legal or regulatory restrictions) and your right to challenge our decision.

11.3 Right to Correction

You have the right to request correction of inaccurate or incomplete personal information we hold about you. Contact support@complyplus.ca with details of the inaccurate information and requested corrections. Note: append-only compliance records (e.g., screening run history, review outcomes, audit logs) are corrected by annotation rather than alteration, to preserve audit-trail integrity. Where appropriate, we will transmit corrected information to third parties who received the inaccurate information from us. Screening data about listed persons originates from public sources; see Section 4.6.

11.4 Right to Withdraw Consent

You may withdraw consent for processing based on consent under certain circumstances. Contact support@complyplus.ca or use the address in Section 17. Upon withdrawal: we may not be able to provide the Service or features; your subscription may need to be terminated; and we may retain personal information where we have another legal basis. You cannot withdraw consent for: contract performance; legal requirements; completed transactions/services; or processing previously relied upon (irreversible).

11.5 Right to Request Deletion

You may request deletion of personal information in certain circumstances. Contact support@complyplus.ca for specific or full deletion. We will delete personal information if: it is no longer necessary for its collection purposes; you have withdrawn consent and we have no other legal basis to retain it; you have successfully objected to processing; it was unlawfully collected or processed; or deletion is required by applicable law. We may be unable to delete where retention is necessary for: legal obligations or court orders; establishment, exercise, or defense of legal claims; fulfilling our contractual obligations to you; legitimate business purposes (e.g., fraud prevention); or record retention requirements under applicable law. Terminate your subscription to delete personal information; data may be deleted within 30 days, subject to the exceptions in Section 9. You must export needed data first.

11.6 Accuracy of Information

We require accurate, current personal information and business information to provide the Service and contact you. Update contact information, organization details, billing information, and authorized user lists through your account profile or support@complyplus.ca.

11.7 Identity Verification

We verify identity before responding to privacy requests. We may request information to confirm identity and rights. For third-party requests, we require authorization proof and may verify identity.

11.8 Response Timelines and Procedures

We will acknowledge receipt of your request within five (5) business days and respond within 30 days or as required by law. If we need more time (typically up to 30 additional days), we will notify you with the reason and new timeline. Most requests are free, except where they require significant resources or law permits a fee.

11.9 Marketing Communications

Opt out by: clicking the "unsubscribe" link in marketing emails; adjusting your communication preferences in your account profile; or contacting support@complyplus.ca. Opting out will not affect transactional or Service-related communications (e.g., account notifications, security alerts, system updates, billing notices), communications necessary to provide the Service, or communications required by law. Note that calendar reminders and digests are Service communications controlled by your notification settings in the product. Opt-outs are processed within 10 business days.

11.10 Individuals Whose Data Our Clients Enter (Including Screened Individuals and Reviewers)

If your information was entered into the Service by one of our clients (as your service provider, financial services provider, or counterparty), that client controls your information. Direct access, correction, or deletion requests to them. You may also contact us at support@complyplus.ca; we will verify your request and coordinate with the client, and respond directly where the law requires us to.

11.11 Challenging Our Compliance

If you have privacy concerns: Step 1: Contact our Privacy Officer at support@complyplus.ca or the mailing address in Section 17. We will investigate and respond. Step 2 Escalation: If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada or your Provincial Privacy Commissioner. Step 3 Legal Remedies: You may pursue legal remedies through the courts as applicable.

12. Disclosures of Your Information

We may disclose personal information or your business information, including information about your use of the service, in the following circumstances:

12.1 Disclosure to FINTRAC

We disclose information to FINTRAC when reports are submitted through the Service: at your direction as the reporting entity; using your FINTRAC reporting entity identifier and API credentials; and in accordance with PCMLTFA obligations. You are solely responsible for reports submitted to FINTRAC.

12.2 Disclosure to Sub-Processors and Service Providers

We disclose personal information and your business information to service providers who support the Service, as listed in Section 8, including database and document hosting, application hosting and serverless computing, cloud infrastructure, screening data providers, AI processing, email delivery, analytics providers, payment processors, customer support and communication tools, and security and monitoring services.

12.3 Disclosure to Recipients You Designate

When you use review/attestation workflows, we send the document link and related context to the reviewers you designate. When you invite learners to training, we send invitation emails to the addresses you provide. You are responsible for the accuracy and appropriateness of these recipients.

12.4 Aggregated or De-Identified Data

We may use and disclose aggregated, de-identified, or anonymized information without restriction, including: to industry organizations or regulatory bodies for benchmarking or research purposes; in whitepapers, case studies, or educational content about AML compliance trends (in aggregate form only); to potential investors, partners, or acquirers for business development purposes; and in academic or policy research about financial crime compliance. Aggregated or anonymized data cannot reasonably identify you or your organization.

12.5 With Your Consent

We may disclose personal information or your business information for purposes disclosed at collection or with your express consent. Withdraw consent at support@complyplus.ca, subject to legal/contractual restrictions.

12.6 Legal Compliance and Law Enforcement

We may disclose personal information or your business information as required/permitted by law: to comply with court orders, laws, subpoenas, warrants, or government/regulatory requests; to cooperate with privacy commissioners or regulatory authorities; and to comply with lawful requests for national security, public safety, or criminal enforcement. We notify you of requests where legally permissible.

12.7 Enforcement of Agreements

We may disclose personal information or your business information to enforce our rights and agreements, including for billing, collections, investigating violations, enforcing IP rights, breach claims, and recovering amounts owed.

12.8 Protection of Rights and Safety

We may disclose personal information or your business information to: protect the rights, property, or safety of Comply+, our employees, our customers, or the public; prevent or address fraud, security threats, or technical issues; protect against legal liability or harm to our business operations; detect, prevent, or respond to criminal activity, including money laundering or terrorist financing; and respond to emergencies involving danger of death or serious physical injury.

12.9 Business Transfers

We may disclose personal information or your business information to a buyer, investor, or successor in the event of: a merger, acquisition, or consolidation; a sale of all or substantially all of Comply+'s assets or business; a restructuring or reorganization; dissolution of the business; or bankruptcy, receivership, liquidation, or similar proceeding. The acquiring party will honor this Privacy Policy or provide notice and opt-out rights as required.

12.10 Professional Advisors

We may disclose personal information or your business information to our professional advisors, who are bound by confidentiality obligations.

12.11 Affiliated Companies

We may share personal information or your business information with affiliates for purposes in this Privacy Policy, subject to the same commitments.

12.12 Other Disclosures with Notice

We may disclose personal information or your business information where: we provide you with notice at the time of collection; the disclosure is required or authorized by law; or you have provided consent to the disclosure.

  • Disclosure Principles: We limit disclosures to the minimum information necessary, to recipients who have a legitimate need for the information, and to circumstances where appropriate safeguards are in place. We do not sell, rent, or trade your personal information or your business information to third parties for their marketing purposes.

13. International Transfers

13.1 Key Risk

Primary data is stored in Canada, but our service providers are subject to US and other foreign jurisdictions, and certain processing (screening, AI, email, payments, support, and encrypted credential storage) occurs in the United States or Europe. Foreign authorities may compel access under their laws.

13.2 Your Obligations

You must inform your customers about foreign processing and government-access risks and assess whether this is acceptable for your use case. US and other foreign legal processes may not provide the same privacy protections, procedural safeguards, or judicial oversight as Canadian law. You are responsible for determining whether your use of the Service complies with applicable privacy laws, including requirements related to cross-border data transfers.

13.3 Safeguards and Limitations

We implement the following safeguards despite foreign jurisdiction risks: Canadian primary data storage where feasible; contractual protections requiring service providers to meet PIPEDA-level standards, implement safeguards, notify us of legal demands where permitted, challenge unlawful requests, and limit disclosure; minimization (e.g., screening queries send only the limited projection in Section 4.6; STR narrative drafting anonymizes before transmission); encryption in transit and at rest; and transparency through this policy. These safeguards cannot prevent lawful foreign government access, which service providers must honor regardless of contractual requirements.

13.4 Consent to US and Foreign Jurisdiction

By using the Service, you acknowledge and consent to: service providers being subject to US or foreign jurisdiction despite Canadian storage; US or foreign authorities potentially accessing your data; our inability to prevent, challenge, or always be notified of such access; storage by US companies (even when physically in Canada) being subject to US laws and government access; processing of specified data categories in the United States and Europe as described in Sections 4.6, 8, and 13.1; and data transmission through US-controlled infrastructure. If you do not consent, do not use the Service.

13.5 Your Customers' Information — Your Disclosure Obligations

You are responsible for: informing your customers that their data will be processed by service providers subject to foreign jurisdiction (including that screening queries are processed in Europe and AI/email/credential processing occurs in the United States) and may be accessible to foreign authorities; and obtaining necessary consents and ensuring PIPEDA compliance.

13.6 Changes to Data Locations or Jurisdictions

We may change data locations when modifying sub-processors or infrastructure, with material changes communicated per Section 15.

13.7 Limitations on Our Control and Liability

We cannot prevent lawful foreign government access to data held by our service providers but will use providers with strong privacy practices and challenge inappropriate requests where possible.

14. Data Breach Notification and Response

14.1 Data Breach Definition

A "data breach" means unauthorized access to or loss of personal information posing real risk of significant harm.

14.2 Investigation and Response

Upon becoming aware of a data breach, we will contain it, secure systems, and investigate to determine affected information, impacted individuals, and remediation steps.

14.3 Notification to You

If a data breach poses a real risk of significant harm to you or affected individuals, we will notify you without undue delay by email to your primary contact. Our notification will include: breach description, affected data types, remediation steps, and mitigation recommendations. We will provide updates as we learn more.

14.4 Notification to Regulatory Authorities

If legally required, we will notify relevant privacy commissioners and regulatory authorities within applicable timelines. FINTRAC Breaches: You are solely responsible for assessing and fulfilling any FINTRAC reporting obligations. Consult legal counsel.

14.5 Notification to Affected Individuals

If individuals are at risk, we will coordinate with you on notification approach and timing. As data controller, you may have independent notification obligations (including to your customers and to reviewers you designated). We will provide breach details and assistance to support your notification obligations.

14.6 Delay or Restriction of Notification

We may delay notification if required by authorities or court order, if notification would impede a criminal investigation or threaten national security, if notification would cause additional harm, or if we are prohibited by court order. We will notify you when legally permissible.

14.7 Cooperation and Your Obligations

Upon notification, you agree to: review the notification and assess your obligations; take recommended steps to mitigate potential harm; notify your customers if legally required or if you control the affected data; cooperate with us in investigating and responding to the breach; preserve any evidence of suspicious activity in your account; and not publicly disclose breach details without coordinating with us (except as legally required).

14.8 Your Reporting Obligations

If you discover a security incident involving the Service or your account, you must: immediately notify us at support@complyplus.ca; provide incident details including what occurred, when discovered, and what data was affected; cooperate with our investigation; and immediately secure your account (e.g., change passwords, revoke compromised access).

14.9 Security Limitations and Disclaimers

While we make reasonable efforts to notify you of breaches and respond to incidents, you acknowledge: we cannot guarantee security or prevent all breaches; transmission is at your own risk; we are not responsible for breaches affecting third-party systems (including FINTRAC's systems after reports are submitted; your own systems, networks, or devices; internet service providers; reviewers' email accounts or systems; or sub-processors, except as provided in our contracts with them); you are responsible for securing your credentials, devices, and networks; and our liability for security breaches is limited as set forth in our Terms of Service.

14.10 Contact for Security Issues

Email: support@complyplus.ca (Subject: SECURITY INCIDENT)

15. Changes to This Policy

We may update this Privacy Policy. Website-only changes are effective upon posting without separate notice. Service-related changes will be notified by:

(a) website or in-Service notice;

(b) email to your account;

(c) displaying notice upon login; or

(d) providing notice through other reasonable means. Continued use after changes constitutes acceptance. If you disagree, discontinue use and terminate per the Terms of Service. You must maintain a current email address with us and periodically review this policy for changes.

16. Governing Law

This Privacy Policy is governed by Alberta and Canadian federal law. Disputes are subject to Terms of Service provisions.

17. Contact

For privacy complaints and inquiries, contact:

Privacy Officer:

  • support@complyplus.ca
  • 2733420 ALBERTA INC., #204, 10359 104 Street NW, Edmonton, AB T5J 1B9

18. Survival

The following provisions survive termination of your use of the Service: Sections 4.6 (Screening Data), 4.7 (Document Reviewers), 5 (Information Use, to the extent related to anonymized data), 8 (Sub-Processors), 9 (Data Retention), 10 (Your Responsibilities), 11 (Your Rights, as applicable), 12 (Disclosures of Your Information), 13 (International Transfers), 14.9 (Security Limitations and Disclaimers), 16 (Governing Law), and 17 (Contact).

This privacy policy was last updated on August 5, 2026 (Version 3.0).

This privacy policy was last updated on August 5, 2026 (Version 3.0)