Trust & Compliance

PIPEDA Compliance

Kima Technologies Inc.  ·  Last reviewed: July 14, 2026

Kima Technologies Inc. is committed to protecting personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. This page explains how we apply PIPEDA's ten fair information principles across our products — and how using Kima supports your own compliance obligations as a licensed mortgage professional.

Built for Canada

All platform data is stored on servers located in Canada. Kima is designed from the ground up for the Canadian regulatory environment — PIPEDA, provincial privacy acts, and mortgage industry requirements.

About PIPEDA

PIPEDA governs how private-sector organisations in Canada collect, use, and disclose personal information in the course of commercial activity. It applies to federally regulated businesses and, where no substantially similar provincial legislation exists, to all commercial activity across Canada.

As a mortgage professional, you are also subject to PIPEDA (and potentially Alberta's PIPA, BC's PIPA, or Quebec's Law 25) when you collect client information. When you process that information through Kima's platform, we act as your data processor — operating under your instructions while you remain the data controller responsible for your clients.

JurisdictionLegislationStatus
Federal (all provinces)PIPEDACompliant
QuebecLaw 25 (Act respecting the protection of personal information)Compliant
AlbertaPIPA (Personal Information Protection Act)Compliant
British ColumbiaPIPA (Personal Information Protection Act)Compliant

PIPEDA's Ten Fair Information Principles

PIPEDA is built around ten fair information principles. Here is how Kima applies each one.

01

Accountability

Kima Technologies Inc. is accountable for all personal information under our control. Our designated Privacy Officer can be reached at legal@usekima.com. We maintain this PIPEDA compliance program and review it annually. When we transfer data to sub-processors (such as AI providers), we require contractual commitments that protect personal information to an equivalent standard.

02

Identifying Purposes

We identify the purpose for collecting personal information before or at the time of collection. Our Privacy Policy documents all collection purposes, including website analytics, demo request processing, and the processing of call recordings, client records, and deal documents through our platform products.

03

Consent

We collect, use, or disclose personal information only with the knowledge and consent of the individual, except where law permits otherwise. For website visitors, we rely on implied consent for functional cookies and seek explicit consent for analytics. Platform users provide explicit consent at account creation. We also contractually require that brokers using CallSmart obtain their clients' informed consent before recording any call.

04

Limiting Collection

We collect only the information necessary for the purposes we have identified. Our demo form collects professional details relevant to evaluating the platform. CallSmart processes only the content of calls submitted for analysis — we do not retain source audio beyond 90 days and apply data minimisation when transmitting content to AI sub-processors.

05

Limiting Use, Disclosure, and Retention

Personal information is used only for the purposes for which it was collected. We do not sell personal information. We do not use Customer Data to train AI models without explicit consent. Data is retained only as long as necessary for its identified purpose — call recordings are deleted after 90 days, uploaded documents after 7 days, and account data within 90 days of cancellation. Full retention periods are documented in our Privacy Policy.

06

Accuracy

We take reasonable steps to ensure that personal information is accurate, complete, and up to date. Users can update their account information at any time through their profile settings. We encourage users to correct any inaccuracies in AI-generated outputs before relying on or sharing them, and we provide editing tools within the platform for this purpose.

07

Safeguards

We protect personal information with security safeguards appropriate to its sensitivity. Our measures include: TLS 1.2+ encryption in transit, AES-256 encryption at rest, role-based access controls, Canadian server infrastructure, 7-day expiring document upload links, and regular security assessments. In the event of a breach posing real risk of significant harm, we will notify the Office of the Privacy Commissioner and affected individuals within 72 hours as required by PIPEDA.

08

Openness

We make our privacy policies and practices readily available. Our Privacy Policy is publicly accessible and written in plain language. This PIPEDA compliance page describes our practices in detail. We disclose all sub-processors and cross-border data flows. Questions about our privacy practices can be directed to legal@usekima.com.

09

Individual Access

Individuals have the right to access their personal information held by Kima and to challenge its accuracy. We will respond to access requests within 30 days. To submit a request, email legal@usekima.com with your name and account details. We may ask you to verify your identity before processing the request. In limited circumstances permitted by PIPEDA, we may decline to provide access (for example, if doing so would reveal confidential commercial information or another individual's personal information).

10

Challenging Compliance

Individuals may challenge our compliance with PIPEDA by contacting our Privacy Officer at legal@usekima.com. We will investigate all complaints and respond within 30 days. If your concern is not resolved to your satisfaction, you may file a complaint with the Office of the Privacy Commissioner of Canada.

Data Residency

All Kima platform data — including call recordings, deal records, documents, and CRM data — is stored on servers physically located in Canada. We do not replicate or backup platform data to servers outside of Canada.

Stored in Canada

  • Call recordings and transcripts
  • AI-generated notes and emails
  • Deal and pipeline records
  • Uploaded financial documents
  • CRM client data
  • Account information

Processed outside Canada

  • AI inference (OpenAI, Anthropic, Google) — transcript content only, under DPAs
  • Demo scheduling (Calendly) — name and email only
  • Website analytics (Google Analytics) — anonymised usage data
  • Form submissions (Netlify) — demo form data

Where data is processed outside Canada, we rely on contractual safeguards including Data Processing Agreements (DPAs) that require sub-processors to protect personal information to a standard equivalent to PIPEDA.

Your Obligations as a Broker

As a licensed mortgage professional, you are independently subject to PIPEDA (and applicable provincial privacy legislation) when collecting and processing your clients' personal information. Using Kima does not transfer your compliance obligations to us — we are your processor, you are the controller.

What you are responsible for

Client consent for recording

Before using CallSmart to process any client call, you must obtain your client's informed consent to be recorded and to have that recording processed by AI. Document this consent.

Privacy notice to clients

Your clients are entitled to know that their information will be processed by a third-party platform. Include reference to your technology partners in your brokerage's privacy notice.

Accuracy of outputs

AI-generated content may contain errors. You are responsible for reviewing and verifying all outputs before using them in client communications or regulatory submissions.

Responding to client requests

If a client requests access to or deletion of their personal information, you must fulfil that request. Contact us at legal@usekima.com and we will assist you in retrieving or deleting data held in the platform.

Document upload consent (DealCheck)

When sending a DealCheck upload link to a client, ensure they understand their documents will be processed and stored within the Kima platform and transmitted to AI services for analysis.

We recommend consulting with a privacy lawyer familiar with PIPEDA to ensure your brokerage's practices are fully compliant. Kima cannot provide legal advice.

Quebec Law 25

Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25) is Canada's most stringent provincial privacy legislation. Kima's practices are designed to meet Law 25 requirements in addition to PIPEDA, including:

Law 25 RequirementKima's approach
Privacy Officer designatedPrivacy Officer reachable at legal@usekima.com
Privacy Impact Assessments (PIAs)Conducted before deploying new technologies that process personal information
Data portabilityExport provided in machine-readable format within 30 days on request
Right to de-indexingRequests handled by Privacy Officer within 30 days
Automated decision-making disclosureDisclosed in Privacy Policy; human review available for AI outputs that affect users
Confidentiality by defaultPrivacy settings default to most protective option; no data sharing without explicit consent
Incident reportingReported to Commission d'accès à l'information (CAI) within 72 hours

Quebec residents may file complaints with the Commission d'accès à l'information du Québec (CAI) if concerns are not resolved by our Privacy Officer.

Breach Response

In the event of a privacy breach, Kima follows a documented incident response procedure:

01

Contain

Immediately isolate affected systems and revoke compromised credentials to prevent further exposure.

02

Assess

Determine the scope, nature, and sensitivity of the information involved and whether there is a real risk of significant harm to individuals.

03

Notify

Where a real risk of significant harm exists, notify the Office of the Privacy Commissioner of Canada (and the CAI for Quebec residents) and affected individuals within 72 hours.

04

Remediate

Implement corrective measures, update security controls, and maintain a breach log as required by PIPEDA's Breach of Security Safeguards Regulations.

To report a suspected privacy breach or vulnerability, contact us immediately at legal@usekima.com.

Privacy Officer

All privacy-related inquiries, access requests, complaints, and breach reports should be directed to our Privacy Officer:

Kima Technologies Inc.
Privacy Officer
legal@usekima.com

We aim to acknowledge all privacy requests within 5 business days and respond fully within 30 days. If additional time is required, we will notify you within the initial 30-day period.

Regulatory bodies

Federal

Office of the Privacy Commissioner of Canada
priv.gc.ca

Quebec

Commission d'accès à l'information
cai.quebec.ca

Alberta

Office of the Information and Privacy Commissioner of Alberta
oipc.ab.ca

British Columbia

Office of the Information and Privacy Commissioner for BC
oipc.bc.ca