KleeroBook Your Free Consultation

Kleero

Privacy Policy

Kleero Website Privacy Policy

Effective Date: [Effective Date]
Last Updated: [Last Updated Date]

1. Introduction

Kleero, operated by [Legal Entity Name] (“Kleero,” “we,” “us,” or “our”), is an Ontario-based accounting and bookkeeping firm providing accounting, bookkeeping, payroll, financial reporting, compliance, and tax and regulatory filing support to businesses across Ontario.

This Website Privacy Policy explains how we collect, use, disclose, retain, and safeguard personal information obtained through kleero.ca and related online interactions.

This Policy applies to visitors to our website, individuals who contact us through the website, prospective clients, clients, client representatives, and other individuals whose personal information we receive through our website or related business activities.

By using our website or voluntarily providing personal information to us, you acknowledge this Policy. Where required by applicable law, we will obtain your consent before collecting, using, or disclosing your personal information.

This Policy does not replace the terms of a client engagement agreement, service agreement, confidentiality agreement, or other agreement governing our professional services. If there is a conflict between this Policy and a specific agreement, the specific agreement will apply to the extent permitted by law.

2. Applicable Privacy Laws

We are committed to handling personal information in accordance with applicable Canadian privacy legislation, including the Personal Information Protection and Electronic Documents Act (“PIPEDA”), where applicable, and any other privacy legislation that applies to our activities.

PIPEDA generally governs the collection, use, and disclosure of personal information in the course of commercial activities. Depending on the nature and location of an activity, other federal or provincial privacy laws may also apply.

For purposes of this Policy, “personal information” means information about an identifiable individual. Information relating solely to a corporation or other organization, without identifying an individual, may not constitute personal information under applicable privacy law. However, business information may constitute personal information where it identifies or can reasonably be associated with an individual, such as a sole proprietor, partner, director, officer, employee, or business owner.

3. Personal Information We May Collect

Depending on your relationship with us and how you interact with our website, we may collect the following categories of personal information:

3.1 Contact and Identification Information

  • Name;
  • Business name and job title;
  • Email address;
  • Telephone number;
  • Mailing or business address;
  • Information included in messages, consultation requests, or other communications; and
  • Any other information you voluntarily provide to us.

3.2 Prospective and Existing Client Information

If you inquire about or retain our services, we may collect information reasonably necessary to assess, provide, administer, and improve our services, including:

  • Business and ownership information;
  • Information about your business operations and industry;
  • Accounting, bookkeeping, payroll, tax, and financial information;
  • Banking, transaction, invoicing, expense, revenue, and reporting information;
  • Information relating to employees, contractors, directors, officers, shareholders, or other representatives;
  • Government account, registration, and identification information;
  • Information required for payroll, tax, regulatory, and compliance filings;
  • Information contained in documents or records provided to us; and
  • Information required to communicate with you and manage our relationship.

We will collect only information that is reasonably necessary for identified purposes. You should not provide sensitive personal information through a website form unless specifically requested or otherwise instructed by Kleero through a secure process.

3.3 Website and Technical Information

When you visit our website, we or our service providers may automatically collect technical and usage information, such as:

  • Internet Protocol (“IP”) address;
  • Browser type and version;
  • Device type and operating system;
  • Website pages visited;
  • Date, time, and duration of visits;
  • Referring website or search terms;
  • General location information derived from technical data;
  • Link and button interactions; and
  • Error, performance, and diagnostic information.

This information may be collected through cookies, pixels, tags, logs, and similar technologies.

3.4 Information from Other Sources

We may receive personal information from:

  • Your authorized representatives;
  • Business partners or professional advisers;
  • Service providers assisting with our business operations;
  • Publicly available sources;
  • Referral sources; and
  • Third parties where you have authorized the disclosure or where permitted or required by law.

Where we collect personal information from another person or organization, we will take reasonable steps to ensure that the collection is lawful and appropriate.

4. How We Use Personal Information

We may use personal information for the following purposes:

  • Responding to questions, consultation requests, and other inquiries;
  • Scheduling and conducting consultations;
  • Assessing whether our services may meet your needs;
  • Providing accounting, bookkeeping, payroll, financial reporting, compliance, tax, and regulatory filing services;
  • Setting up, maintaining, and supporting accounting and financial systems;
  • Cleaning up or correcting accounting and financial records;
  • Preparing, reviewing, submitting, and managing filings and reports;
  • Communicating with clients, prospective clients, representatives, and service providers;
  • Verifying identity and authority;
  • Managing billing, payments, accounts, and business records;
  • Maintaining accurate accounting, professional, and administrative records;
  • Complying with legal, regulatory, professional, insurance, and contractual obligations;
  • Detecting, preventing, investigating, and responding to fraud, security incidents, unauthorized activity, or other unlawful conduct;
  • Operating, maintaining, securing, and improving our website and systems;
  • Understanding website traffic and usage through analytics;
  • Sending service-related communications;
  • Sending marketing or informational communications where permitted by law and, where required, with your consent;
  • Establishing, exercising, or defending legal rights; and
  • Fulfilling other purposes identified at or before the time information is collected, or otherwise permitted or required by law.

We will not use personal information for a new purpose that is materially different from the original purpose without obtaining additional consent, unless the new use is permitted or required by law.

5. Consent and Other Legal Grounds

5.1 Consent

Where required by applicable law, we will obtain meaningful consent for the collection, use, and disclosure of personal information. Consent may be express or implied, depending on the sensitivity of the information, the circumstances, and your reasonable expectations.

Consent may be provided by:

  • Submitting information through a website form;
  • Contacting us by email or telephone;
  • Requesting information or a consultation;
  • Entering into a service or engagement agreement;
  • Providing information to enable us to perform requested services; or
  • Selecting an available consent or preference option.

For sensitive information, including financial and payroll information, we will generally seek express consent or rely on a specific legal, contractual, or professional requirement.

5.2 Other Permitted Grounds

Depending on the circumstances, we may collect, use, or disclose personal information without consent where permitted or required by applicable law. This may include circumstances where the information is necessary to:

  • Provide a requested service;
  • Perform or administer a contract;
  • Comply with legal, regulatory, professional, or court-imposed obligations;
  • Protect against fraud, security threats, or other unlawful activity;
  • Establish, exercise, or defend legal claims;
  • Protect the rights, property, safety, or security of Kleero, our clients, our personnel, or another person; or
  • Fulfill another purpose permitted by applicable privacy law.

5.3 Withdrawal of Consent

Subject to legal, contractual, professional, or other reasonable restrictions, you may withdraw consent to the collection, use, or disclosure of your personal information by contacting us using the information in Section 17.

Withdrawing consent may affect our ability to provide certain services, respond to an inquiry, administer an account, or meet legal or professional obligations. Withdrawal of consent does not affect the lawfulness of any collection, use, or disclosure that occurred before withdrawal.

You may unsubscribe from marketing emails by using the unsubscribe mechanism included in the message or by contacting us. We may continue to send non-promotional, service-related, administrative, or legally required communications.

6. Cookies and Analytics

Our website may use cookies and similar technologies. Cookies are small data files placed on your device that help websites operate, remember preferences, understand usage, and improve functionality.

We may use:

  • Strictly necessary cookies required for website operation, security, or basic functionality;
  • Preference or functionality cookies that remember settings or choices;
  • Analytics cookies, such as cookies associated with Google Analytics, to understand website traffic, visitor interactions, and general usage patterns; and
  • Other technologies used for website performance, security, or measurement.

Analytics providers may collect information about your device, browser, IP address, website interactions, and general location. Their collection and use of information may be subject to their own privacy policies and terms.

You may be able to control or disable cookies through your browser settings or available website cookie controls. Disabling certain cookies may affect website functionality. Browser-based “Do Not Track” signals may not be recognized by all systems.

Where required by applicable law, we will seek consent before placing non-essential cookies or using similar technologies.

7. Disclosure of Personal Information

We may disclose personal information to the following categories of recipients, where reasonably necessary for the purposes described in this Policy:

7.1 Service Providers

We may use third-party service providers to support our business and provide services to you. These providers may include:

  • Accounting and financial technology platforms, such as QuickBooks Online, Xero, and Sage;
  • Payroll and payroll-processing platforms, such as Wagepoint and QuickBooks Online Payroll;
  • Document collection, expense management, and financial workflow platforms;
  • Cloud hosting, storage, backup, and document management providers;
  • Email, communications, scheduling, and customer relationship management providers;
  • Website hosting, maintenance, security, and support providers;
  • Analytics and website measurement providers, including Google Analytics;
  • Payment processors, financial institutions, and billing providers;
  • Information technology, cybersecurity, and technical support providers;
  • Professional advisers, auditors, insurers, and legal counsel; and
  • Other providers engaged to perform services on our behalf.

Service providers are expected to use personal information only for authorized purposes and to maintain appropriate confidentiality and security safeguards. We remain accountable for personal information in our custody or control, including information handled by service providers on our behalf.

7.2 Legal and Regulatory Disclosures

We may disclose personal information where permitted or required by law, including to:

  • The Canada Revenue Agency and other governmental or regulatory authorities;
  • Courts, tribunals, law enforcement, or public authorities;
  • Professional, licensing, or regulatory bodies;
  • Auditors, insurers, or claims administrators;
  • Parties involved in legal proceedings or dispute resolution; and
  • Other persons or organizations where disclosure is necessary to comply with a legal obligation or protect rights, property, safety, or security.

7.3 Business Transactions

If Kleero is involved in a merger, acquisition, financing, reorganization, sale of assets, or other business transaction, personal information may be disclosed to the parties involved, subject to applicable law and appropriate confidentiality protections.

We do not sell personal information.

8. Client Information Processed on Behalf of Clients

In providing accounting, bookkeeping, payroll, tax, reporting, and compliance services, Kleero may process personal information that belongs to or is controlled by a client.

Where we process personal information on behalf of a client:

  • Our use of the information will generally be governed by the applicable client engagement or service agreement;
  • We will process the information for authorized business, accounting, bookkeeping, payroll, tax, reporting, compliance, and related purposes;
  • We will use reasonable safeguards appropriate to the nature and sensitivity of the information;
  • We may disclose the information to authorized service providers where necessary to provide the requested services; and
  • We may disclose information where required or permitted by law or the client’s instructions.

Individuals whose information is provided to us by a client may need to direct requests concerning the client’s collection, use, or control of that information to the relevant client. We will reasonably assist with such requests where appropriate and legally permitted.

9. Cross-Border Processing and Storage

Some of our service providers may store or process personal information in Canada, the United States, or other jurisdictions outside Ontario or Canada.

Where personal information is processed outside Canada:

  • The information may be subject to the laws of the jurisdiction where it is stored or processed;
  • It may be accessible to courts, law enforcement, national security authorities, or regulators in that jurisdiction;
  • We will take reasonable steps to assess service providers and implement contractual, technical, and organizational safeguards appropriate to the circumstances; and
  • We will remain accountable for personal information under our custody or control, subject to applicable law.

By providing personal information to us or using services that require third-party processing, you acknowledge that your information may be processed in another jurisdiction, as described in this Policy and any applicable agreement.

10. Retention and Secure Disposal

We retain personal information only for as long as reasonably necessary to fulfill the purposes for which it was collected, provide services, maintain business and professional records, comply with legal, regulatory, accounting, tax, insurance, contractual, and professional obligations, resolve disputes, enforce agreements, and protect our rights.

Retention periods may vary depending on:

  • The nature and sensitivity of the information;
  • The purpose for which it was collected;
  • Whether you are a prospective, current, or former client;
  • Legal, regulatory, professional, and contractual requirements;
  • The likelihood of a dispute, complaint, audit, or legal proceeding; and
  • Operational and security requirements.

When personal information is no longer required, we will take reasonable steps to securely destroy, erase, anonymize, or de-identify it, subject to applicable retention obligations and legitimate business requirements.

Records relating to privacy breaches will be maintained as required by applicable law.

11. Security Safeguards

We use reasonable physical, organizational, contractual, and technological safeguards appropriate to the sensitivity of the personal information we hold. Depending on the circumstances, safeguards may include:

  • Access controls and need-to-know restrictions;
  • Authentication and password controls;
  • Encryption or secure transmission methods where appropriate;
  • Secure cloud and system configurations;
  • Monitoring, logging, and security controls;
  • Confidentiality obligations for personnel and service providers;
  • Employee and contractor privacy and security training;
  • Backup and recovery procedures;
  • Secure document handling and disposal;
  • Incident detection and response procedures; and
  • Periodic review of privacy and security practices.

No method of transmission, storage, or security control can guarantee absolute security. You are responsible for using reasonable security practices when communicating with us, including protecting passwords and avoiding sending sensitive financial or personal information through unsecured channels.

12. Privacy Breaches

A privacy breach may occur where personal information is lost, stolen, accessed, used, disclosed, or otherwise handled without authorization.

If a breach occurs, we will take reasonable steps to:

  1. Contain and investigate the incident;
  2. Assess the nature, scope, and potential risk of harm;
  3. Notify affected individuals and other organizations where required or appropriate;
  4. Report the breach to the Office of the Privacy Commissioner of Canada or another applicable regulator where required by law;
  5. Take steps to reduce or mitigate potential harm; and
  6. Maintain records of the breach as required by applicable law.

Where required by PIPEDA, we will report a breach to the Office of the Privacy Commissioner of Canada and notify affected individuals if it is reasonable to believe that the breach creates a real risk of significant harm.

13. Accuracy of Personal Information

We take reasonable steps to ensure that personal information is sufficiently accurate, complete, and current for the purposes for which it is used.

You should promptly notify us if your information changes or if you believe information we hold about you is inaccurate or incomplete.

14. Your Privacy Rights

Subject to applicable legal exceptions and verification requirements, you may have the right to:

  • Request access to personal information we hold about you;
  • Request information about how your personal information is being used or disclosed;
  • Request correction of inaccurate or incomplete personal information;
  • Withdraw consent to certain collections, uses, or disclosures;
  • Request information about our privacy practices and safeguards;
  • Ask questions or raise concerns about our handling of personal information; and
  • File a complaint with the applicable privacy regulator.

To make an access or correction request, please contact us using the information in Section 17. Your request should provide enough detail for us to identify the information requested and verify your identity.

We may require reasonable identification before responding to a request. In certain circumstances, applicable law may permit or require us to refuse access, limit disclosure, or decline a correction request. If we refuse a request, we will provide an explanation where required by law and identify any available recourse.

We will respond to access requests within the time required by applicable law, subject to permitted extensions and exceptions.

15. Complaints

If you have a question or concern about our collection, use, disclosure, retention, or protection of personal information, please contact us first so that we can investigate and attempt to resolve the issue.

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada where PIPEDA applies:

Office of the Privacy Commissioner of Canada
30 Victoria Street
Gatineau, Quebec K1A 1H3
Canada

Telephone: 1-800-282-1376
Website: https://www.priv.gc.ca

You may also have the right to complain to another applicable federal or provincial privacy regulator, depending on the circumstances.

16. Children’s Privacy

Our website and services are directed toward businesses and business representatives and are not intended for children.

We do not knowingly collect personal information from children through the website. If you believe a child has provided personal information to us, please contact us so that we can review and take appropriate steps.

17. Contacting Kleero About Privacy

For privacy questions, access or correction requests, consent withdrawals, or complaints, please contact:

Privacy Officer
Kleero
Email: [privacy@kleero.ca]
General Email: info@kleero.ca
Telephone: (519) 800-4492
Mailing Address: [Kleero Mailing Address]

Please include “Privacy Inquiry” in the subject line of an email or correspondence.

18. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, privacy practices, legal requirements, or business operations.

The updated Policy will be posted on our website with a revised “Last Updated” date. Where required by law, we will provide additional notice or obtain consent for material changes.

19. Governing Law

This Policy is governed by the laws applicable in the Province of Ontario and the applicable laws of Canada. Any dispute concerning this Policy will be subject to the jurisdiction of the applicable courts and privacy regulators in Ontario and Canada.