This Privacy Policy (“Policy”) describes how Accountability Intelligence™ (“we”, “us”, “our” or the “Company”) collects,
uses, discloses, retains, and disposes of personal information in connection with the Accountability Intelligence™
platform (the “Services”). This Policy applies to all individuals who access or use the Services, including registered users,
organizational customers, and visitors to our website, and is administered in accordance with the Personal Information
Protection and Electronic Documents Act (PIPEDA) and any applicable provincial privacy legislation. This Policy governs
personal information collected in connection with the Services regardless of the jurisdiction from which the Services are
accessed, provided the Company’s operations and data storage are presently limited to Canada.
We are committed to providing clear and timely notice of our privacy practices. This Policy is made available to all users
prior to or at the time personal information is collected, is accessible at all times on our website, and is referenced
during account registration. Where we make a material change to how we collect, use, retain, or disclose personal
information, we will provide advance notice in accordance with Section 19 (Changes to This Policy) before the change
takes effect.
We collect only the personal information reasonably necessary to achieve the purposes described in this Policy. We do
not collect personal information beyond what is needed to provide, secure, and improve the Services.
Cookies and similar tracking technologies are used to improve user experience, analyse site traffic, and personalize
content. You shall manage cookie preferences through your browser settings and, where applicable, through any
in-platform cookie preference controls made available to you.
We obtain your consent before collecting, using, retaining, or disclosing your personal information, except where an
exception under PIPEDA or applicable law permits collection, use, or disclosure without consent (for example, legal or
regulatory compliance, or the investigation of fraud). Consent shall be express (e.g., ticking a consent checkbox, agreeing to Terms during registration) or implied through your continued use of the Services where the purpose is
reasonably obvious and non-sensitive.
You shall withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice, by using the
details in Section 20. Withdrawing consent shall limit or prevent our ability to provide certain features or the Services
generally, and we will explain any such impact at the time of your request.
Where we collect information of a sensitive nature – including assessment responses that shall reveal information about
workplace conduct, performance evaluations, or other information that could cause harm if disclosed inappropriately –
we obtain your explicit, opt-in consent prior to collection, separate from general acceptance of the Terms and
Conditions. We do not infer consent to collect sensitive information from general platform use alone.
We use personal information only for the purposes for which it was collected, or for a purpose reasonably compatible
with that original purpose, unless you separately consent to an additional use or the use is required or authorized by
law. Stated purposes include:
We do not sell personal information, and we do not disclose personal information to third parties for their own
independent marketing purposes.
We retain personal information only for as long as necessary to fulfil the purposes described in this Policy, including the
following retention criteria:
During the retention period, personal information is protected using the safeguards described in Section 11 and internal
security controls, including encryption of sensitive data, restricted access controls, and regular security audits.
Retention periods are reviewed periodically and updated as legal, or business requirements change.
Once personal information is no longer required for the purposes described in this Policy and no legal or regulatory
requirement obliges continued retention, we securely destroy, erase, or anonymize it. Electronic records are
permanently deleted or rendered unrecoverable using secure deletion methods; physical records, if any, are shredded
or otherwise destroyed to prevent reconstruction. Where you request account deletion, we will remove your personal
data from active systems within a reasonable period, except where retention is required by law.
You have the right to request access to the personal information we hold about you, including confirmation of its
existence, the purposes for which it is used, and the parties to whom it has been disclosed. To submit an access
request, contact our Privacy Officer using the details in Section 20.
If you believe personal information we hold about you is inaccurate or incomplete, you shall request that we correct,
amend, or append it. Upon verifying the request, we will:
We disclose personal information to third parties only with your consent, except where disclosure without consent is
permitted or required by law (see Section 12). Third parties who shall receive personal information, with consent,
include:
We do not sell or share personal information with third parties for their own independent marketing purposes.
We create and retain a record of authorized disclosures of personal information to third parties, including the recipient,
the categories of personal information disclosed, the purpose of disclosure, and the date. These records support our
ability to provide an accounting of disclosures under Section 14 and to demonstrate accountability under PIPEDA.
Before engaging a vendor or third-party service provider that will process personal information on our behalf, we obtain
a written privacy and confidentiality commitment covering, at minimum, use restricted to the contracted purpose,
confidentiality, security safeguards commensurate with the sensitivity of the information, breach notification to us
without undue delay, and secure disposal or return of information at the end of the engagement. We periodically assess
vendor compliance with these commitments, commensurate with the sensitivity of the personal information involved
and the nature of the engagement and take corrective action – including remediation requirements or termination of
the engagement – where a vendor fails to meet its commitments.
We shall disclose personal information without consent where required or authorized by law, including in response to a
valid court order, subpoena, search warrant, or lawful request from a government or regulatory authority; to comply
with legal, regulatory, or audit requirements; or to protect the rights, property, or safety of the Company, our users, or
the public. Any such disclosure is limited to what is legally required and is documented internally.
We maintain internal processes to detect, investigate, contain, and remediate incidents involving unauthorized access,
use, or disclosure of personal information.
Where we determine that a breach of security safeguards has occurred and creates a real risk of significant harm to an
individual, we will notify affected individuals and report the breach to the Office of the Privacy Commissioner of Canada
as soon as feasible, in accordance with PIPEDA’s mandatory breach reporting requirements. Where applicable law in an
affected individual’s province imposes additional or different notification obligations, we will comply with those
obligations as well. Notifications will describe, to the extent known, the circumstances of the breach, the personal
information affected, the steps taken to reduce the risk of harm, and steps the individual can take to protect
themselves.
We create and retain a record of all detected or reported incidents involving unauthorized access, use, or disclosure of
personal information, whether the incident met the threshold for external notification, including the nature of the
incident, the personal information involved, the response taken, and the outcome. These records are retained to
support regulatory reporting obligations and continuous improvement of our safeguards.
Upon written request, and subject to identity verification, we will provide you with a general account of the personal
information we hold about you and the third parties to whom that information has been disclosed, drawing on the
disclosure records maintained under Section 10.3. This accounting is provided within the same response timelines
described in Section 8 for access requests.
We take reasonable steps to ensure that personal information used on an ongoing basis, or disclosed to third parties, is
accurate, complete, and up to date for the purposes for which it is used. Users are encouraged to keep account and
profile information current and shall update most information directly within the platform or by submitting a correction
request under Section 9.
We welcome questions and concerns about our privacy practices. You shall direct a privacy inquiry or complaint to our
Privacy Officer using the details in Section 20. We will:
We monitor ongoing compliance with this Policy and applicable privacy law through periodic internal reviews of our
privacy practices, safeguards, and vendor commitments, and through tracking of inquiries, complaints, and incidents to
identify and address recurring issues.
Our servers and data centres are presently located in Canada, and personal information is stored and processed within
Canada. If our data storage or processing arrangements change to involve a jurisdiction outside Canada, we will update
this Policy in accordance with Section 19 and disclose the general data handling practices applicable in that jurisdiction
before the change takes effect.
The Services are not intended for individuals under the age of 18, and we do not knowingly collect personal information
from children. If we become aware that we have collected personal information from a minor without appropriate
consent, we will take reasonable steps to delete that information promptly.
We shall update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or
other factors. Where a change is material, we will provide advance notice – such as by email or a prominent notice
within the Services – before the change takes effect. The “Last Reviewed” date at the top of this Policy indicates when it
was most recently updated. Continued use of the Services after a change takes effect constitutes acceptance of the
updated Policy.