1. What this is and why it exists
This agreement governs personal information that your firm puts into T1 Manager about its own clients — names, addresses, dates of birth, Social Insurance Numbers, income slips, and the documents that go with a personal tax return. It is referred to here as "client data".
Under PIPEDA your firm remains accountable to its clients for that information even while we hold it, and satisfies that accountability by contract with us. This is that contract. It forms part of the Terms of Service and takes precedence over them wherever the two disagree about client data.
Our roles: your firm decides what client data is collected and what happens to it. We only act on your instructions. In the language of Canadian privacy law your firm is the accountable organisation and we are its service provider; in the language of other jurisdictions your firm is the controller and we are the processor.
2. What we may do with client data
Only what is necessary to provide the service to you, and only on your instructions. Your use of the features of the service is your instruction — sending a signature request instructs us to transmit that document, and inviting a colleague instructs us to give them access.
We will not:
- Use client data for any purpose of our own, including product analytics or research.
- Use client data, in any form, to train machine learning models.
- Sell, rent, or share client data with anyone, except the subprocessors listed in the schedule to this agreement.
- Disclose client data to a third party unless you instruct us to or the law compels us — and where the law compels us, we will tell you before we comply unless we are legally prohibited from telling you.
3. Confidentiality
Everyone at our end who could reach client data is bound by a written confidentiality obligation that survives their leaving. Access is limited to the individuals who need it to operate the service.
4. Where your clients' data lives
In Canada. Specifically:
- The database holding your firm's records is in Canada.
- Documents your firm and its clients upload are stored in Canada.
- The servers that run the application — the ones that decrypt and render your data — are in Canada. This matters separately from storage: data at rest in one country and processed in another has been disclosed in the second one.
- Backups are encrypted before they leave our systems and are stored in Canada.
- We do not maintain a replica of client data outside Canada.
5. Social Insurance Numbers
SINs get treatment beyond the rest of client data, because they are the single most damaging field in a tax practice's records.
A SIN is encrypted before it is written, using a key belonging to your firm alone and held separately from your firm's data. A copy of your firm's database, on its own, does not yield a readable SIN. SINs are not written to application logs, are masked on screen except where a user deliberately reveals one, and are not included in error reports.
6. Subprocessors
We use a small number of other companies to provide the service. They are listed in the Subprocessor list, which forms part of this agreement and names what each one does and which country the data is in.
Every subprocessor is bound by obligations no weaker than these, and we remain responsible to you for what they do.
Before adding or replacing a subprocessor we will give you at least 30 days' notice by email to your account owner. If you object on reasonable data protection grounds within those 30 days, and we cannot resolve it, you may terminate this agreement and the subscription without penalty and we will refund the unused part of your term.
7. Whether we can look at your data
Not routinely, and never silently. This clause is deliberately specific because "our staff may access data as necessary to provide support" is the sentence that makes most such agreements meaningless.
- We access your firm's client data only when you ask us to — for example when you report a problem we cannot reproduce without it — or where it is strictly necessary to restore the service in an emergency.
- Every such access is recorded, with who accessed it, when, and the reason. The record is kept in a log that cannot be edited from the application.
- Where the access was for an emergency rather than at your request, we tell you within 72 hours of it happening.
- You can ask us for the access log for your firm at any time and we will provide it within 5 business days.
8. Security
We maintain technical and organisational measures appropriate to the sensitivity of tax records. The Security overview describes them and forms part of this agreement.
The measures that matter most, stated here so they are contractual rather than marketing:
- Each firm's data is held in a separate database schema. A query scoped to the wrong firm returns nothing rather than another firm's records.
- Data is encrypted in transit, and SINs additionally at rest under a per-firm key.
- Backups are encrypted before leaving our systems, and restoring one is rehearsed on a schedule rather than assumed to work.
- Access to production systems requires multi-factor authentication.
9. If there is a breach
If we become aware of a breach of security safeguards affecting your client data, we will notify you without undue delay and in any case within 72 hours of becoming aware of it.
The notification will tell you what happened, which of your data was affected, what we have done, and what we recommend you do. We will keep you updated as we learn more rather than waiting until we have a complete picture.
Notifying your clients and reporting to the Privacy Commissioner is your firm's obligation, because your firm is the accountable organisation. We will give you whatever information and assistance you reasonably need to do it, at no charge.
We maintain our own records of breaches as PIPEDA requires.
10. Helping you answer your clients
If one of your clients asks you for their information, asks you to correct it, or asks you to delete it, you can do all three yourself in the application — the export, the edit and the deletion are features, not support requests.
If a client contacts us directly, we will not answer them about their data. We will tell them to contact your firm and let you know they approached us.
11. Getting your data out, and deletion
You can export your firm's complete data at any time, in formats that do not require our software to read — documents as files in a folder structure, records as spreadsheets.
When your subscription ends, your data stays available for export for 30 days. After that we delete it from live systems within a further 30 days, and it ages out of encrypted backups within 90 days of deletion.
We will confirm the deletion in writing if you ask. Where the law requires us to keep something — billing records — we keep only that, and only for as long as required.
12. Audit
You may ask us, once in any 12-month period, for the information you reasonably need to satisfy yourself that we are meeting this agreement, and we will provide it within 30 days. That includes the access log for your firm, our current subprocessor list, and a description of our backup and restore testing.
If your professional regulator or insurer requires something more, tell us and we will work out how to satisfy it.
13. Duration
This agreement applies for as long as we hold any of your client data, including through the export and deletion periods after your subscription ends.