Privacy Policy

Last updated: May 5, 2026

Note: This policy template is aligned with PIPEDA and GLBA Safeguards Rule requirements. Have legal counsel review before publishing.

Information We Collect

We collect information you provide directly (name, email, firm details), information generated through your use of the Service (usage logs, document metadata), and technical information (IP address, browser type, device identifiers). We do not read or process the contents of documents uploaded by your clients.

How We Use Your Information

We use your information to provide and improve the Service, send transactional communications, maintain security and audit records, comply with legal obligations, and resolve disputes. We do not sell personal information to third parties.

Data Residency

Canadian users may elect to have their data stored exclusively in Canada (Cloudflare R2 Canadian zone, Neon ca-central-1). US users' data is stored in US data centers. You select your preferred region during account setup. This selection can be changed by contacting support.

Your Rights (PIPEDA)

Under PIPEDA, you have the right to: access your personal information, correct inaccurate information, withdraw consent for certain uses, and request deletion of your account and associated data. To exercise these rights, use Settings → Data & Privacy or contact privacy@idutax.com.

Data Retention

Account data is retained for the duration of your subscription plus 30 days following cancellation. Audit logs are retained for 7 years to support tax compliance requirements. After the retention period, data is permanently and securely deleted.

Contact

Privacy inquiries: privacy@idutax.com. For data subject requests, use the in-app export tool or contact us directly.