*** DRAFT — not yet binding. See the published page. *** Privacy Policy Effective 2026-09-03 1. What this policy covers, and what it does not This policy is about personal information belonging to the people who use T1 Manager — the accountants, preparers and administrators at a subscribing firm. For that information we are the organisation accountable under the Personal Information Protection and Electronic Documents Act (PIPEDA). It is not about the personal information of a firm's own tax clients. We hold that information because the firm asked us to, we use it only as the firm instructs, and the firm — not us — is accountable for it. How we handle it is set out in the Data Processing Agreement, which is a contract with the firm and is published in full. If you are a taxpayer whose accountant uses T1 Manager and you want to see, correct or delete your information, ask your accountant. They can do all three, and they do not need our help to do it. 2. Who is accountable [legal entity name], at [registered address], is accountable for personal information under this policy. Our Privacy Officer is [Privacy Officer name], reachable at [Privacy Officer email]. That is a real person, and they are who to write to about anything in this document — including a complaint about how we have handled it. 3. What we collect about your firm's people Only what running the service requires. There is no analytics vendor, no advertising network and no third-party tracking script on the application. - Account details: Name, work email address, the role you hold at your firm, and a hash of your password. We never store the password itself. - Sign-in records: The time of each sign-in, and the IP address it came from, kept so that you and we can spot an account being used by someone else. - Activity in the app: An audit trail of significant actions — who changed a return's stage, who sent a signature request, who exported a client file. This exists because your professional obligations require it. - Correspondence: If you email us for support, the email and our reply. - Billing details: Your firm's plan and invoices. Card numbers are handled by our payment processor and never reach our servers. 4. Cookies We set one cookie: a signed session cookie that keeps you logged in. It is marked HttpOnly and Secure, it holds no personal information beyond the fact of your session, and it is deleted when you sign out. We do not use advertising cookies, and we do not need a consent banner because there is nothing to consent to beyond the cookie that makes signing in work. 5. Why we use it To operate the service, to keep it secure, to bill for it, and to answer you when you contact us. We do not use it for anything else, and we do not build a profile of you. We rely on your consent, given when your firm signed up and when you accepted an invitation to an account. You can withdraw it by closing your account, though that necessarily ends your access to the service. We do not use personal information to train machine learning models. 6. Where it is held In Canada. Our databases, our document storage, our backups and the servers that run the application are all located in Canada, and we do not replicate data to any other country. Some of our suppliers are companies headquartered outside Canada. Where that is true it is named in the Subprocessor list, along with the country the data is actually stored in — because where a company is incorporated and where your data sits are different questions, and only the second one is about your data. 7. How long we keep it Account and audit records are kept while your firm's account is open. When it closes, they are deleted within 30 days, except where we are required to keep something longer — billing records, which Canadian tax law requires us to keep for six years. Encrypted backups are kept on a rolling schedule and expire on their own; a record deleted from the live system is gone from every backup within 90 days. 8. Your rights Under PIPEDA you can ask us for a copy of the personal information we hold about you, ask us to correct it if it is wrong, and ask how we have used it and who we have disclosed it to. Write to [Privacy Officer email]. We will respond within 30 days, at no charge. If we cannot meet that we will tell you why and when we can. If you are unhappy with our response you can complain to the Office of the Privacy Commissioner of Canada, at priv.gc.ca. We would rather you came to us first, but it is your right either way. 9. Security Each firm's data is held in a separate database schema rather than sharing tables with other firms. Social insurance numbers are encrypted with a key belonging to that firm alone. Backups are encrypted before they leave our systems. The Security overview describes this in more detail and is a published page rather than a claim in a policy. 10. Breaches If a breach of security safeguards creates a real risk of significant harm, we will report it to the Privacy Commissioner and notify affected individuals, as PIPEDA requires. Where the breach involves a firm's client data, we notify the firm without undue delay and within 72 hours of becoming aware, and the firm makes the notifications to its own clients — that obligation is theirs, and the timing is in the DPA. 11. Changes We will post any change here with a new effective date, and we will email the account owner at each firm if the change is material. Version a7f93d2f9ffc