PRIVACY POLICY

This Privacy Policy is effective as of the 1st day of April 2022 and may be updated from time to time. Please verify from time to time on the website indicated below.

THIS PRIVACY POLICY IS AVAILABLE IN THE ENGLISH AND FRENCH LANGUAGES AT OUR WEBSITE WWW.SERENEACCOUNTING.COM.

CETTE POLITIQUE DE CONFIDENTIALITÉ EST DISPONIBLE EN LANGUE ANGLAISE ET EN LANGUE FRANÇAISE SUR NOTRE SITE WEB À WWW.SERENEACCOUNTING.COM.

Serene Accounting Incorporated ("Serene", "we", "our" or "us") is a cloud accounting firm which provides accounting services to small and medium size businesses.  The services which we provide include compilation engagements, taxation, bookkeeping, sales tax, payroll and other similar services (“Service”). We recognize the importance of privacy and the protection of Personal Information (as defined below). We are committed to collecting, using and disclosing your Personal Information responsibly. We will also try to be as open and transparent as possible about the way we handle your Personal Information. This Privacy Policy explains how we collect, use, disclose and protect your Personal Information when you use our Services,   in accordance with the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and the Quebec Legislation, including the Quebec Act Respecting the Protection of Personal Information in the Private Sector and other applicable laws (“Legislation”). Our Privacy Policy is governed by the principles set forth hereinbelow.

DEFINITIONS

Collection  – the act of gathering, acquiring, receiving or obtaining Personal Information from any source, includes third party sources, by any means.

Consent  – a voluntary agreement with what is being done or is being proposed to be done. Consent can either be express or implied. Express consent may be given explicitly, either orally or in writing.

Disclosure  – making Personal Information available, or releasing it, to others besides Serene.

Privacy Impact Assessment (PIA)  – an assessment of the privacy-related factors of our information system or electronic service delivery involving the collection, use, communication, keeping or destruction of Personal Information.

Personal Information – information about a specific identifiable individual, regardless of form, including, for example, name, date of birth and address.

Purpose  – the Purpose (or Purposes) for which the Personal Information is collected about you is defined more clearly in Principle 2 below.

Principle 1: Accountability

Serene is responsible for information which it collects, or which is under its control. Serene will oversee compliance with the Legislation, as applicable, such as being responsible for the day-to-day collection and processing of Personal Information, responding to inquiries about information practices and responding to requests for access to or correction of Personal Information in its custody or under control.

Serene is responsible for information in its possession or custody, including information that has been transferred to a third party for processing. We will use contractual or other means to provide a comparable level of protection while the information is being accessed and/or processed by that third party. To provide you with the Services, Serene will use service providers to perform services on Serene’s behalf such as storing and processing Personal Information. Serene will use reasonable efforts to ensure that third party service providers maintain protections for Personal Information in compliance with Legislation, as applicable.  We will conduct PIAs in order to assure that Personal Information will receive adequate protection and amend our practices accordingly in the event any shortcomings are discovered.

Serene will implement policies and practices to give effect to the Principles, including:

  • Establishing procedures to receive and respond to complaints and inquiries;
  • Establishing procedures to receive and respond to access and correction requests regarding your Personal Information; and
  • Reviewing this Privacy Policy and other procedures regarding the protection of Personal Information on a regular basis, performing and reviewing the PIAs on a regular basis, providing a framework for the keeping and destruction of Personal Information and defining the roles and responsibilities of our personnel with respect to Personal Information.

Principle 2: Identifying Purposes for Collecting Information

Serene collects Personal Information when we provide you with our Services. We may collect the following Personal Information from you:

  • Name and contact information (including address, telephone, email address, and social insurance number);
  • Date of birth;
  • Place of employment; and
  • Other related information which may be required for the performance of the Services.

The Purposes for which Personal Information is collected by Serene will be identified before or at the time the information is collected. Serene collects Personal Information for the following Purposes:

  • To provide you with our Services;
  • To identify and contact you when you request our Services;
  • To enable us to contact and maintain communication with the you;
  • To respond to your access and/or correction requests;
  • To plan, administer and manage the internal operations of Serene;
  • To fulfill other purposes permitted or required by law;
  • To meet any legal or regulatory requirements; and
  • To prepare any required documentation or returns on your behalf in respect of the Purposes.

When Personal Information has been collected and is to be used or disclosed for a purpose not previously identified, the new Purpose will be identified prior to its use or the disclosure. Your consent is required before the information can be used or disclosed for that Purpose, subject to certain legal exceptions.

We may use systems which automatically process your Personal Information for certain tasks and decisions in order to expedite processing of Personal Information for the Purposes.

Principle 3: Consent

Serene will seek knowledgeable consent for the collection, use and disclosure of Personal Information, except where it might be inappropriate to obtain your consent, and subject to some exceptions set out in law.

In order for the principles of consent to be satisfied, we have undertaken reasonable efforts to ensure that you are advised of the Purposes for which information is being used, and that you understand those Purposes. Once consent is obtained, we do not need to seek your consent again, unless the use, Purpose or disclosure changes.

Consent for the collection, use and disclosure of Personal Information may be given in a number of ways, such as:

  • signed consent form;
  • taken verbally by telephone or otherwise and then charted;
  • e-mail;
  • written correspondence; or
  • in a mandate or contract for Services and as set forth at the end of this Privacy Policy.

You may withdraw consent upon reasonable notice in which case we will cease collecting Personal Information about you, which may affect the services which we may render on your behalf or on behalf of your employer for you.

Principle 4: Limiting Collection of Personal Information

Serene may collect information from your employer. Serene limits the collection of Personal Information to that which is necessary to fulfill the Purposes.  

Principle 5: Limiting Use, Disclosure and Retention of Personal Information

Personal Information shall not be used or disclosed for purposes other than those for which the information is collected, except with your express consent, or as permitted or required by law.

Serene uses and discloses your Personal Information to service providers that help with Serene’s operations, such as providing accounting and financial, audit, legal, consulting, practice management and organizing and storing Serene’s or its clients’ data. Such service providers may only use your Personal Information for the Purposes.

Serene has protocols in place for the retention of Personal Information. We retain Personal Information for as long as necessary to fulfill the Purposes for which that Personal Information was collected and as permitted or require by applicable law. In destroying Personal Information, Serene has developed procedures to ensure secure destruction or anonymization in accordance with legal requirements.

Principle 6: Accuracy of Personal Information

Serene endeavours to maintain that your Personal Information is as accurate, complete, and as up-to-date as necessary for the Purposes that it is to be used. Information shall be sufficiently accurate, complete and up to date to minimize the possibility that inappropriate information is used to make a decision about you with respect to the provision of the Services. If you believe that Serene’s records of your Personal Information are inaccurate or incomplete, you may request in writing that Serene correct the record as described below.

Principle 7: Safeguards for Personal Information Protection

Serene takes reasonable measures to safeguard your Personal Information from unauthorized access, disclosure, use or tampering. Organizational, technological and physical safeguards are in place to protect your Personal Information against loss or theft, as well as unauthorized access, disclosure, copying, use or modification. Your Personal Information is protected by Serene, whether it is recorded on paper or electronically. Serene securely maintains and destroys Personal Information to prevent unauthorized access to the information even during disposal and destruction.

We take reasonable steps to verify your identity before granting you access to your account regarding our Services, however, you are solely responsible for maintaining the secrecy of your username, password and any other account information. We also take reasonable steps to ensure that our employees are aware of the importance of maintaining the confidentiality of Personal Information and that unauthorized persons do not gain access to Personal Information that we have disposed of or destroyed.

Personal Information that we collect may be processed and stored on servers located in Canada, Europe, the United States or elsewhere . If Personal Information is processed and/or stored outside of Canada, it will be subject to the laws of the jurisdiction where it is processed and/or stored (as the case may be). As a result, Personal Information may be subject to access requests from governments, courts, or law enforcement in those jurisdictions according to the laws in those jurisdictions.  For example, information may be shared in response to valid demands or requests from government authorities, courts and law enforcement officials in those countries. Subject to applicable laws in such other jurisdictions, we use reasonable efforts to ensure that appropriate protections are in place to maintain protections on Personal Information that are reasonably equivalent to those that apply in Canada.

We will take measures to assess whether the Personal Information will receive an adequate protection in compliance with generally accepted data protection principals that are reasonably equivalent to those that apply in Canada and we will take measures to mitigate the risks identified in any PIA.

Principle 8: Openness about Privacy

Serene will maintain internal practices relating to the management of Personal Information. This Privacy Policy provides you with a general description of our information practices, our contact information so that you may ask us questions regarding the use of your Personal Information, how you may access or correct your Personal Information held by us and an explanation as to how Serene collects, uses and discloses your Personal Information.

Principle 9: Access, Correction and Portability of Personal Information

Serene will comply with the Legislation, as applicable, as it defines your access to and correction of records.

You are free to request correction of your Personal Information where you believe there is an error or omission.

You must send a written request to access or correct your Personal Information. Your written request must contain sufficient detail to enable Serene to identify and locate the record. To access your Personal Information please contact us at the address found below. Serene will contact you if your request is deficient or it needs to clarify the information you are requesting. Serene will also need to verify your identity before processing requests for your Personal Information.

Once the Purposes for which Personal Information was collected have been achieved, we will, at your request, destroy the Personal Information.  In the event that we intend to use this Information for a serious and legitimate purpose in accordance with the Legislation, we may anonymize the Information.  You may request that we no longer disseminate your Personal Information and de-index any hyperlink attached to your name that provides access to the Information if the dissemination contravenes the law or the order of a court.

Portability  – At your request we will confirm the existence of the Personal Information and communicate it to you and allow you to obtain a copy of it in the form of a written and intelligible transcript.  Unless there are serious practical difficulties the Information will, at your request, be communicated to you in a structured commonly used technological format and will be communicated at your request to any person or body authorized by law to collect such Information.

 If you are handicapped, reasonable accommodation will be provided upon request to enable you to exercise the rights of access provided for herein.  We may charge you a reasonable amount for the transcription, reproduction or transmission of Personal Information, however, we will advise you of the cost prior to performing such service.

If we refuse to grant any requests hereunder, we shall give you the reasons therefore.

Principle 10: Challenging Compliance

You can challenge Serene’s compliance with the Principles with Serene’s Contact Person who is accountable for Serene’s compliance. The name and contact information of the Contact Person is available on request. We have in place procedures to receive and respond to your complaints or inquiries. To file a written complaint please contact us at the address found below. Serene will investigate each and every written complaint made to Serene. If a complaint is found to be justified, Serene will take appropriate measures, including, if necessary, amending any of Serene’s policies and practices.

CONTACT INFORMATION

If you have any questions, comments or concerns about this Privacy Policy, please contact Serene at: [admin@sereneaccounting.com].

Changes to this Privacy Policy

We reserve the right to change or replace this Privacy Policy at our sole discretion at any time. Please check back from time to time to ensure that you are aware of any updates or changes in this Privacy Policy. We will indicate at the top of this Privacy Policy the date the Privacy Policy was last revised.  Your continued access or use of our Services serves as acceptance of the Privacy Policy as revised and consent to the use of your data and Personal Information for the Purposes.