Privacy Policy
Compliant with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), Ontario’s applicable privacy and consumer-protection statutes, and, for individuals in Quebec, the Act respecting the protection of personal information in the private sector.
Introduction and scope
VertAcc Solutions Inc. (“VertAcc,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal information. This Privacy Policy describes how we collect, use, disclose, transfer, retain, and safeguard personal information when you visit vertacc.com (the “Site”), use the VertAcc Platform, communicate with us, or engage our services (collectively, the “Services”).
This Policy, together with the Terms of Service set out in Part B, forms a single agreement (this “Agreement”) between you and VertAcc. It applies to all visitors, prospective clients, current clients, and other individuals whose personal information we process. It supplements — and does not replace — any engagement-specific privacy or confidentiality terms set out in a written engagement letter between you and VertAcc, which will govern in the event of a direct conflict in respect of that engagement.
Definitions
The following terms have the meanings given below wherever they appear in this Agreement:
- “Personal Information” means information about an identifiable individual, as that term is defined under PIPEDA.
- “Services” means the bookkeeping, tax, advisory, software, marketing, legal-coordination, and tokenization and digital-asset services described in Part B, including access to the VertAcc Platform.
- “Site” means vertacc.com and its subdomains.
- “VertAcc Platform” or “Platform” means the software product made available at app.vertacc.com or any successor domain, through which clients and their authorized users access accounting, filing, document, and reporting tools.
- “Client” means an individual or entity that has executed an engagement letter with VertAcc or holds an active account on the Platform.
- “Personnel” means VertAcc’s employees, contractors, and service providers acting on our behalf.
- “you” / “your” means the individual accessing the Site, using the Services, or whose personal information we otherwise process.
Information we collect
We collect personal information in the following ways:
a) Information you provide directly
- Identity information (name, title, employer)
- Contact information (email address, phone number, mailing address)
- Business information (company name, industry, jurisdiction, structure, size)
- Financial information you authorize us to access (bank records, ledgers, tax filings, invoices, payroll data, supporting documentation)
- Communications with us (form submissions, email, telephone, video calls, recorded meetings where consented)
b) Information collected automatically
- Device and connection data (browser type and version, operating system, IP address, time zone, language preferences). IP address is used for security, abuse detection, and rate-limiting of public API endpoints (including the VertAcc AI chat and contact forms)
- Usage data (pages viewed, time on site, navigation paths, referring URLs, interaction events)
- First-party cookie and session identifiers (see Section 14)
c) Information from VertAcc AI chat interactions on this Site
Before you become a client, this Site offers a conversational assistant. When you use it:
- Your messages are processed in real time by our AI service provider solely to generate a response; they are not used to train third-party general-purpose models
- Conversations are not persistently stored by VertAcc unless you choose to hand off to our team via the in-chat form, in which case the recent transcript is transmitted to our team, along with your contact details, so they can pick up where the assistant left off
- Transcripts shared on handoff are retained under the schedule described in Section 10 and may be reviewed by our team for follow-up and quality assurance
d) Information collected through the VertAcc Platform
Where your engagement includes access to the Platform, we hold, on your behalf:
- Bank and card statements, and the individual transactions extracted from them
- Invoices, bills, receipts, and the vendor and customer information they contain
- Business identifiers, including your business number and GST/HST registration
- Payroll and employee records, where you use the Platform’s payroll tools
- Documents you store in your account’s document vault
- A record of the actions taken on your account, by you, your authorized users, our personnel, and the Platform’s AI systems — see Section 6
e) Information received from third parties
- Public sources (corporate registries, securities filings, news media, professional networks)
- Service integrations authorized by you (accounting software, banking platforms, payment processors)
- Cloud storage integrations authorized by you (Google Drive, Microsoft OneDrive, Dropbox) — see Section 6(h) for exactly what we access and how
- Service providers acting on our behalf (identity verification, fraud prevention, communications infrastructure)
- Referrals from existing clients and professional networks
How we use your information
We use personal information only for purposes that are reasonable and consistent with the circumstances under which it was collected, including:
- Providing, performing, maintaining, and improving the Services
- Processing payments and managing client billing
- Communicating with you about engagements, deliverables, service updates, and inquiries
- Complying with our legal, regulatory, and professional obligations, including tax-record retention
- Establishing, exercising, or defending legal claims
- Detecting, preventing, and addressing fraud, security incidents, and technical issues
- Conducting business analytics, training, and quality assurance
- Sending occasional service communications and, where you have consented, marketing communications you can opt out of at any time (see Section 15)
Consent and legal basis for processing
Under PIPEDA, we collect, use, and disclose your personal information only with your knowledge and consent, except where consent is not required by law — for example, to comply with a legal obligation, to investigate a suspected breach of an agreement or law, or in an emergency threatening life, health, or safety.
Consent may be express — for example, when you complete a form, create a Platform account, or execute an engagement letter — or implied by your conduct, such as when you voluntarily provide information in the course of an active engagement. You may withdraw consent at any time, subject to legal and contractual restrictions, using the process described in Section 13. Withdrawing consent may limit or end our ability to provide the Services affected by it.
How the VertAcc Platform handles your data
The Platform is built around a specific, deliberate model of access, and this Section states it plainly rather than leaving it implicit.
a) Our personnel can read the data in your account
VertAcc’s own accountants and other authorized personnel can access the financial data, documents, and records held in your Platform account. This is not incidental — the Platform’s AI performs bookkeeping and filing work under the supervision of our accountants, and both the AI and the humans supervising it need to be able to see your books to do that work. There is no tier of the Platform in which your data is inaccessible to VertAcc.
b) What encryption does, and does not, protect against
Sensitive fields — including banking details and business identification numbers — are encrypted using industry-standard cryptographic methods before they are stored. This protects your data against unauthorized access at the database or infrastructure level, including in the event of a theft of the underlying storage. It is not a barrier between you and VertAcc personnel performing the Services on your account, and we do not represent it as one.
c) Separation between clients
Each client’s data is logically segregated at the database level, so that one client cannot access another client’s information through the Platform.
d) Access controls within your own account
Where you add additional users to your account — employees, bookkeepers, or other collaborators — you may restrict the areas of the Platform each user can access. Those restrictions are enforced at the database level, not solely by the application interface, so they cannot be bypassed by a user who queries the system directly.
e) The audit trail
Material actions taken on your account — by you, your authorized users, our personnel, or the Platform’s AI systems — are logged with a timestamp and the identity of the actor. This log cannot be edited or deleted, by you or by us.
f) Limits on what the AI can do without you
The Platform’s AI does not execute an action that would move money, send a communication in your name, or alter a posted accounting record without your prior approval. That limitation is enforced at the system level and does not depend solely on the AI’s own judgment — see Section 7.
g) Account security
Platform accounts support multi-factor authentication and recovery codes, and an active session is automatically ended after a period of inactivity.
h) Google Drive, OneDrive, Dropbox, and Calendar integrations
If you choose to connect a cloud storage account or an external calendar, this is what happens, stated specifically rather than by general reference to “service integrations”:
- What we ask for — cloud storage. For Google Drive, we request only the
drive.filescope and your basic account email — never broad access to your Drive. Under this scope, Google grants VertAcc access only to the individual files and folders you explicitly select through Google’s own file picker. We cannot see, list, or open anything in your Drive that you did not select, and we never ask Google for broader access than this. The same principle applies to Microsoft OneDrive (read-only access to files and basic profile information) and Dropbox (read-only access to the folder you choose). - What we ask for — calendar. If you connect Google Calendar, we request only the
calendar.readonlyscope and your basic account email — read-only, and never able to create, edit, or delete anything on your calendar. The same read-only principle applies to Microsoft Calendar (Outlook / Microsoft 365). - What we do with it. We use the selected files solely to import your financial documents — receipts, bills, statements, and similar records — into your VertAcc document vault, so they can be processed as part of the Services. Calendar access is used solely to display your existing events alongside your VertAcc deadlines in one calendar view, and to surface a one-click join link for any synced event that already has a Google Meet or Microsoft Teams link attached. Access is read-only at the provider’s end in every case: VertAcc cannot modify, delete, or move anything in your Google Drive, OneDrive, Dropbox, or Google/Microsoft Calendar account.
- Google API Services User Data Policy. VertAcc’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through the Google Drive and Google Calendar integrations is not used for advertising, is not sold, and is not used to train generalized AI or machine-learning models, whether ours or a third party’s.
- Who can see it. The same personnel and Platform AI access described in Section 6(a) applies to documents imported and calendar events synced this way — they become part of your records, handled under the same controls as anything you upload or enter directly.
- Disconnecting. You can disconnect a cloud storage or calendar integration at any time from the Platform. Doing so immediately revokes VertAcc’s access token with the provider and deletes our stored copy of it, so nothing further can be read. Documents already imported or calendar events already synced before disconnection remain in your account as part of your business records, under the retention schedule in Section 10, unless you separately delete them.
Artificial intelligence and automated decision-making
We use artificial-intelligence systems, including VertAcc AI, to support the Services — drafting responses to inquiries, categorizing transactions, drafting correspondence, and surfacing information from your own records.
No decision made solely by automated processing, and that produces a legal or similarly significant effect on you, is made without an avenue for review by a qualified member of our team. In particular, and as described in Section 6(f), any action that would move money or send an external communication on your behalf requires your explicit approval before it takes effect — the AI proposes and stops; it does not execute unilaterally.
Personal information processed by our AI systems, including your own accounting records, is not used to train general-purpose, publicly available AI models operated by third parties.
This processing is performed by a third-party AI service provider, which means the personal information involved — including calendar events and documents connected under Section 6(h) — is transferred to, and processed in, the United States. See Section 9 for how we safeguard information transferred outside Canada.
Information sharing and disclosure
We do not sell your personal information. We disclose personal information only in the following circumstances:
- Service providers: third-party vendors that perform services on our behalf — including cloud hosting and database infrastructure, payment processing, secure document storage, email and communications, and analytics — and are bound by written confidentiality and data-protection obligations
- Professional advisors: our lawyers, accountants, auditors, and insurers, where reasonably required
- Government and regulatory authorities: when disclosure is required by law, court order, subpoena, or by a regulatory authority with jurisdiction (including the Canada Revenue Agency)
- Business transfers: in connection with a contemplated or completed merger, acquisition, financing, restructuring, or sale of assets, subject to confidentiality obligations on recipients
- With your consent or at your direction: with third parties you authorize, including counterparties in transactions we facilitate
- To protect rights and safety: where reasonably necessary to protect our rights, property, or safety, or the rights, property, or safety of our clients or others
Cross-border and international data transfers
Client accounting and financial records held on the VertAcc Platform are hosted on infrastructure located in Canada. Certain supporting service providers process limited categories of information outside Canada, including in the United States — for example, those supporting email delivery, analytics, payment processing, and the artificial-intelligence systems described in Sections 6(h) and 7. Those AI systems categorize transactions, draft correspondence, and surface information from documents and calendar events you connect (Section 6(h)), so the personal information involved in that processing is included in this transfer. As stated in Sections 6(h) and 7, this is processing, not training — the same information is not used to train generalized AI or machine-learning models, whether ours or a third party’s. When personal information is transferred outside Canada, it becomes subject to the laws of that jurisdiction and may be accessible to its courts, law enforcement, and national-security authorities.
We require every such service provider to maintain a comparable level of protection through written contracts that include data-protection terms consistent with PIPEDA. You may contact us for more information about the safeguards we use for a specific transfer.
Data retention
We retain personal information for only as long as is reasonably necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, regulatory, or reporting requirements. Different categories of information are held on different schedules:
- Engagement records — financial documents, tax filings, working papers, and correspondence — are retained for a minimum of seven (7) years from the end of the relevant tax year or engagement, under the Canadian Income Tax Act and the Excise Tax Act.
- The Platform’s audit log (Section 6(e)) is retained indefinitely as a permanent record of activity on your account and is not subject to routine deletion.
- On-site chat transcripts (Section 3(c)) are deleted thirty (30) days after the last activity on the conversation, unless handed off to our team, in which case the engagement-record schedule above applies.
When personal information is no longer required for any of the above purposes, it is securely destroyed, erased, or anonymized in accordance with our internal retention schedule.
Data security
We implement reasonable administrative, physical, and technical safeguards to protect personal information against loss, theft, unauthorized access, disclosure, copying, use, or modification:
- Encryption of personal information in transit using industry-standard protocols, and encryption of sensitive fields at rest using AES-256-GCM or an equivalent standard
- Database-enforced separation between clients and, within an account, between users with different areas of access (Section 6(c)–(d))
- Multi-factor authentication and automatic session expiry for Platform accounts
- An immutable, append-only audit trail of material account activity (Section 6(e))
- Role-based access controls, background checks, and confidentiality obligations for all personnel and contractors
- Regular security assessments, vulnerability management, and patching
- Vendor security reviews and contractual data-protection obligations on service providers
- Documented incident-response procedures
No method of transmission over the Internet or method of electronic storage is one-hundred percent secure. While we take commercially reasonable measures to protect personal information, we cannot guarantee its absolute security.
Data breach notification
If a breach of security safeguards involving personal information under our control occurs, and it is reasonable to believe the breach creates a real risk of significant harm to an individual, we will notify each affected individual and report the breach to the Office of the Privacy Commissioner of Canada, in each case as soon as feasible, in accordance with PIPEDA. We maintain a record of every breach of security safeguards, regardless of whether notification was required, for a minimum of twenty-four (24) months.
Your privacy rights
a) Rights under PIPEDA and applicable provincial law
- Access: request a copy of the personal information we hold about you
- Correction: request correction or update of inaccurate or incomplete information
- Withdrawal of consent: withdraw consent to our processing of your personal information, subject to legal and contractual restrictions; withdrawal may affect our ability to provide certain Services
- Challenge: challenge our compliance with this Policy or applicable privacy law
- Complaint: file a complaint with the Office of the Privacy Commissioner of Canada or your provincial privacy commissioner
b) Additional rights for individuals in Quebec
Under Quebec’s Act respecting the protection of personal information in the private sector, individuals in Quebec also have the right to:
- Request that we cease disseminating their personal information, or de-index a hyperlink giving access to it, where the dissemination contravenes the law or a court order
- Be informed, on request, of the personal information we hold about them, the categories of persons and organizations with access to it, and its retention period
- Be informed of any decision made exclusively on the basis of automated processing of their personal information, of the reasons and the principal factors that led to it, and to submit observations to a member of our personnel able to review the decision — the same review right described in Section 7
Requests under this Section should be submitted in writing to info@vertacc.com. We will respond within thirty (30) days. In some cases we may require additional information to verify your identity before acting on your request.
Cookies, tracking, and Do Not Track
The Site uses first-party cookies and similar technologies to operate the Site, remember your preferences, and maintain session integrity. We do not use third-party advertising cookies and do not sell visitor data to advertising networks.
Aggregate traffic measurement is provided by Cloudflare Web Analytics. It records page views, the site or search engine you arrived from, and general device and country information. It does this without cookies, without fingerprinting your browser, and without building a profile of you across other sites, which is why the Site does not ask you to accept a tracking banner. We see totals and trends, not individuals.
You may control cookies through your browser settings. Disabling cookies may affect the functionality of some parts of the Site. Our systems do not currently respond to browser “Do Not Track” signals or the Global Privacy Control; you may still exercise the rights described in Section 13 regardless of whether such a signal is set.
Marketing communications and consent
Where we send a commercial electronic message — an electronic message that encourages participation in a commercial activity — we do so with your express or implied consent, in accordance with Canada’s Anti-Spam Legislation (CASL). Every such message identifies VertAcc as the sender and includes a functioning method to unsubscribe.
You may withdraw consent to marketing communications at any time using the unsubscribe mechanism provided, or by contacting us using the details in Section 19. Withdrawing consent to marketing communications does not affect our ability to send communications necessary to perform an active engagement.
Accessibility
We aim to make the Site usable by people of all abilities, consistent with the accessibility standards under Ontario’s Accessibility for Ontarians with Disabilities Act (AODA). If you encounter an accessibility barrier on the Site, contact us using the details in Section 19 and we will work with you to address it.
Children’s privacy
The Services are directed to businesses and individuals over the age of majority. We do not knowingly collect personal information from individuals under the age of eighteen (18). If you believe a child has provided personal information to us, please contact us so we can take appropriate action.
Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated by posting the updated Policy on the Site with a revised effective date. Your continued use of the Site or Services after changes take effect constitutes acceptance of the updated Policy.
Contact us and our Privacy Officer
Questions, requests, or concerns regarding this Policy or our handling of personal information may be directed to our Privacy Officer: