Canada Privacy Notice (PIPEDA)
Last updated: July 16, 2026
This notice explains how HelmIQ handles personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) for our Canadian customers and the individuals whose information they manage in the product. It sits alongside our Privacy Policy and Data Processing Agreement.
HelmIQ handles personal information in two capacities. We are the organization accountable for the account data we collect to run the service (your name, work email, firm membership, and operational logs). We are a service provider for the data your firm loads into HelmIQ (contacts, companies, deals, notes, email and call content), which we process only on your firm's instructions under the Data Processing Agreement. For that data, your firm is the organization primarily accountable to its own contacts under PIPEDA.
Accountable Privacy Officer
Jack Pitts, Privacy Officer, is accountable for HelmIQ's compliance with PIPEDA. Reach the Privacy Officer at jack@helmiq.net.
1. The ten fair information principles
PIPEDA is built on ten fair information principles. Here is how HelmIQ meets each one:
- 1. Accountability. HelmIQ is responsible for the personal information under its control and has designated a Privacy Officer (Jack Pitts, named above) accountable for our compliance. We hold our sub-processors to comparable protection by contract.
- 2. Identifying Purposes. We identify why we collect personal information at or before the time we collect it: to create and operate your account, deliver the CRM service, secure the platform, and meet legal obligations. Firms that load contact data identify their own purposes to their own contacts.
- 3. Consent. Where consent is required, we obtain it. Account holders consent when they sign up. For the firm data a customer loads, the customer firm is responsible for the consent or other lawful authority to process its contacts' information. Individuals may withdraw consent, subject to legal or contractual limits.
- 4. Limiting Collection. We collect only the personal information needed to provide and secure the service: your name, work email, account identifiers, and the firm records a customer chooses to store. We do not collect information for undisclosed purposes.
- 5. Limiting Use, Disclosure, and Retention. We use and disclose personal information only for the purposes it was collected, or as the law permits or requires. We retain it while the account is active and for a limited window afterward, then delete it (see the Privacy Policy for detail).
- 6. Accuracy. We keep personal information as accurate, complete, and current as the purpose requires. Account holders can correct their own details in Settings, and firms can edit the records they manage. Other correction requests reach us through the Privacy Officer.
- 7. Safeguards. We protect personal information with security appropriate to its sensitivity: encryption at rest (AES-256), encryption in transit (TLS), per-tenant isolation, access controls, and audit logging. See the safeguards section below.
- 8. Openness. We make our privacy practices readily available. This notice, the Privacy Policy, the Data Processing Agreement, and the Sub-processors list are all public.
- 9. Individual Access. On request, we tell an individual what personal information we hold, how it is used, and to whom it has been disclosed, and we let them access and correct it, subject to the limited exceptions the law allows. See the access section below.
- 10. Challenging Compliance. Anyone can challenge our compliance with these principles by contacting the Privacy Officer. Unresolved concerns can be escalated to the Office of the Privacy Commissioner of Canada, as described below.
2. Where your information is stored (cross-border transfer)
HelmIQ is operated from the United States and stores customer data in US data centers. Personal information about Canadian individuals may therefore be processed and stored in the United States. While it is there, it can be subject to lawful access requests by US courts, law enforcement, and regulatory authorities under US law, in the same way Canadian information is subject to Canadian law while it is here.
We are transparent about this so Canadian customers and their contacts can make an informed choice. To protect the information wherever it is handled, we apply contractual and technical safeguards: encryption at rest (AES-256), encryption in transit (TLS), per-tenant isolation so one firm can never see another firm's data, access controls, and audit logging. Our sub-processors are bound by contract to comparable protection.
3. Security safeguards
We protect personal information with safeguards appropriate to its sensitivity:
- Encryption at rest (AES-256) and in transit (TLS).
- Strict per-tenant isolation: every record is scoped to one organization, and a session can only ever read or write its own organization's data.
- Role-based access controls and least-privilege access.
- Audit logging of access to and changes in the system.
The current controls and our sub-processor list, with purpose and region, are published on our Security page.
4. Accessing or correcting your information
You have the right to ask what personal information we hold about you, how it is used, and to whom it has been disclosed, and to have it corrected if it is inaccurate or incomplete. There are two paths, depending on who controls the data:
- Data your firm loaded into HelmIQ. Your firm controls that data. Direct access and correction requests to the firm whose account holds your information. If you contact us first, we will refer you to that firm, or act on the firm's instruction as its service provider.
- Your own HelmIQ account data. You can access and export your data, correct your details, and delete your account directly in Settings, or by writing to our Privacy Officer at jack@helmiq.net.
We verify your identity before acting (typically by confirming control of the account email) and respond within the timeframe PIPEDA requires, generally within 30 days. Access is subject to the limited exceptions the law allows (for example, information that would reveal another person's data).
5. Challenging our compliance
If you have a concern or complaint about how HelmIQ handles personal information, contact our Privacy Officer, Jack Pitts, at jack@helmiq.net. We will investigate every complaint, respond in writing, and correct our practices where a complaint is justified.
If we do not resolve your concern to your satisfaction, you can escalate it to the Office of the Privacy Commissioner of Canada (OPC), the independent federal authority that oversees PIPEDA. The OPC receives and investigates privacy complaints, mediates disputes between individuals and organizations, and can make recommendations and findings. You can reach the OPC at priv.gc.ca.
6. Contact
For any question about this notice or your PIPEDA rights, contact our Privacy Officer, Jack Pitts, at jack@helmiq.net. For general product support, you can also reach us at jack@helmiq.net.
This notice summarizes our practices and is not legal advice. Canadian customers requiring a signed Data Processing Agreement or additional PIPEDA assurances should write to our Privacy Officer at jack@helmiq.net.