Trust & Compliance
PIPEDA Compliance
Kima Technologies Inc. is committed to protecting personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. This page explains how we apply PIPEDA's ten fair information principles across our products — and how using Kima supports your own compliance obligations as a licensed mortgage professional.
Built for Canada
All platform data is stored on servers located in Canada. Kima is designed from the ground up for the Canadian regulatory environment — PIPEDA, provincial privacy acts, and mortgage industry requirements.
About PIPEDA
PIPEDA governs how private-sector organisations in Canada collect, use, and disclose personal information in the course of commercial activity. It applies to federally regulated businesses and, where no substantially similar provincial legislation exists, to all commercial activity across Canada.
As a mortgage professional, you are also subject to PIPEDA (and potentially Alberta's PIPA, BC's PIPA, or Quebec's Law 25) when you collect client information. When you process that information through Kima's platform, we act as your data processor — operating under your instructions while you remain the data controller responsible for your clients.
| Jurisdiction | Legislation | Status |
|---|---|---|
| Federal (all provinces) | PIPEDA | Compliant |
| Quebec | Law 25 (Act respecting the protection of personal information) | Compliant |
| Alberta | PIPA (Personal Information Protection Act) | Compliant |
| British Columbia | PIPA (Personal Information Protection Act) | Compliant |
PIPEDA's Ten Fair Information Principles
PIPEDA is built around ten fair information principles. Here is how Kima applies each one.
Accountability
Kima Technologies Inc. is accountable for all personal information under our control. Our designated Privacy Officer can be reached at legal@usekima.com. We maintain this PIPEDA compliance program and review it annually. When we transfer data to sub-processors (such as AI providers), we require contractual commitments that protect personal information to an equivalent standard.
Identifying Purposes
We identify the purpose for collecting personal information before or at the time of collection. Our Privacy Policy documents all collection purposes, including website analytics, demo request processing, and the processing of call recordings, client records, and deal documents through our platform products.
Consent
We collect, use, or disclose personal information only with the knowledge and consent of the individual, except where law permits otherwise. For website visitors, we rely on implied consent for functional cookies and seek explicit consent for analytics. Platform users provide explicit consent at account creation. We also contractually require that brokers using CallSmart obtain their clients' informed consent before recording any call.
Limiting Collection
We collect only the information necessary for the purposes we have identified. Our demo form collects professional details relevant to evaluating the platform. CallSmart processes only the content of calls submitted for analysis — we do not retain source audio beyond 90 days and apply data minimisation when transmitting content to AI sub-processors.
Limiting Use, Disclosure, and Retention
Personal information is used only for the purposes for which it was collected. We do not sell personal information. We do not use Customer Data to train AI models without explicit consent. Data is retained only as long as necessary for its identified purpose — call recordings are deleted after 90 days, uploaded documents after 7 days, and account data within 90 days of cancellation. Full retention periods are documented in our Privacy Policy.
Accuracy
We take reasonable steps to ensure that personal information is accurate, complete, and up to date. Users can update their account information at any time through their profile settings. We encourage users to correct any inaccuracies in AI-generated outputs before relying on or sharing them, and we provide editing tools within the platform for this purpose.
Safeguards
We protect personal information with security safeguards appropriate to its sensitivity. Our measures include: TLS 1.2+ encryption in transit, AES-256 encryption at rest, role-based access controls, Canadian server infrastructure, 7-day expiring document upload links, and regular security assessments. In the event of a breach posing real risk of significant harm, we will notify the Office of the Privacy Commissioner and affected individuals within 72 hours as required by PIPEDA.
Openness
We make our privacy policies and practices readily available. Our Privacy Policy is publicly accessible and written in plain language. This PIPEDA compliance page describes our practices in detail. We disclose all sub-processors and cross-border data flows. Questions about our privacy practices can be directed to legal@usekima.com.
Individual Access
Individuals have the right to access their personal information held by Kima and to challenge its accuracy. We will respond to access requests within 30 days. To submit a request, email legal@usekima.com with your name and account details. We may ask you to verify your identity before processing the request. In limited circumstances permitted by PIPEDA, we may decline to provide access (for example, if doing so would reveal confidential commercial information or another individual's personal information).
Challenging Compliance
Individuals may challenge our compliance with PIPEDA by contacting our Privacy Officer at legal@usekima.com. We will investigate all complaints and respond within 30 days. If your concern is not resolved to your satisfaction, you may file a complaint with the Office of the Privacy Commissioner of Canada.
Data Residency
All Kima platform data — including call recordings, deal records, documents, and CRM data — is stored on servers physically located in Canada. We do not replicate or backup platform data to servers outside of Canada.
Stored in Canada
- Call recordings and transcripts
- AI-generated notes and emails
- Deal and pipeline records
- Uploaded financial documents
- CRM client data
- Account information
Processed outside Canada
- AI inference (OpenAI, Anthropic, Google) — transcript content only, under DPAs
- Demo scheduling (Calendly) — name and email only
- Website analytics (Google Analytics) — anonymised usage data
- Form submissions (Netlify) — demo form data
Where data is processed outside Canada, we rely on contractual safeguards including Data Processing Agreements (DPAs) that require sub-processors to protect personal information to a standard equivalent to PIPEDA.
Your Obligations as a Broker
As a licensed mortgage professional, you are independently subject to PIPEDA (and applicable provincial privacy legislation) when collecting and processing your clients' personal information. Using Kima does not transfer your compliance obligations to us — we are your processor, you are the controller.
What you are responsible for
Client consent for recording
Before using CallSmart to process any client call, you must obtain your client's informed consent to be recorded and to have that recording processed by AI. Document this consent.
Privacy notice to clients
Your clients are entitled to know that their information will be processed by a third-party platform. Include reference to your technology partners in your brokerage's privacy notice.
Accuracy of outputs
AI-generated content may contain errors. You are responsible for reviewing and verifying all outputs before using them in client communications or regulatory submissions.
Responding to client requests
If a client requests access to or deletion of their personal information, you must fulfil that request. Contact us at legal@usekima.com and we will assist you in retrieving or deleting data held in the platform.
Document upload consent (DealCheck)
When sending a DealCheck upload link to a client, ensure they understand their documents will be processed and stored within the Kima platform and transmitted to AI services for analysis.
We recommend consulting with a privacy lawyer familiar with PIPEDA to ensure your brokerage's practices are fully compliant. Kima cannot provide legal advice.
Quebec Law 25
Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25) is Canada's most stringent provincial privacy legislation. Kima's practices are designed to meet Law 25 requirements in addition to PIPEDA, including:
| Law 25 Requirement | Kima's approach |
|---|---|
| Privacy Officer designated | Privacy Officer reachable at legal@usekima.com |
| Privacy Impact Assessments (PIAs) | Conducted before deploying new technologies that process personal information |
| Data portability | Export provided in machine-readable format within 30 days on request |
| Right to de-indexing | Requests handled by Privacy Officer within 30 days |
| Automated decision-making disclosure | Disclosed in Privacy Policy; human review available for AI outputs that affect users |
| Confidentiality by default | Privacy settings default to most protective option; no data sharing without explicit consent |
| Incident reporting | Reported to Commission d'accès à l'information (CAI) within 72 hours |
Quebec residents may file complaints with the Commission d'accès à l'information du Québec (CAI) if concerns are not resolved by our Privacy Officer.
Breach Response
In the event of a privacy breach, Kima follows a documented incident response procedure:
Contain
Immediately isolate affected systems and revoke compromised credentials to prevent further exposure.
Assess
Determine the scope, nature, and sensitivity of the information involved and whether there is a real risk of significant harm to individuals.
Notify
Where a real risk of significant harm exists, notify the Office of the Privacy Commissioner of Canada (and the CAI for Quebec residents) and affected individuals within 72 hours.
Remediate
Implement corrective measures, update security controls, and maintain a breach log as required by PIPEDA's Breach of Security Safeguards Regulations.
To report a suspected privacy breach or vulnerability, contact us immediately at legal@usekima.com.
Privacy Officer
All privacy-related inquiries, access requests, complaints, and breach reports should be directed to our Privacy Officer:
Kima Technologies Inc.
Privacy Officer
legal@usekima.com
We aim to acknowledge all privacy requests within 5 business days and respond fully within 30 days. If additional time is required, we will notify you within the initial 30-day period.
Regulatory bodies
Federal
Office of the Privacy Commissioner of Canada
priv.gc.ca
Quebec
Commission d'accès à l'information
cai.quebec.ca
Alberta
Office of the Information and Privacy Commissioner of Alberta
oipc.ab.ca
British Columbia
Office of the Information and Privacy Commissioner for BC
oipc.bc.ca