Legal

Privacy Policy

Effective date:

Cordillera Labs Ltd. (“Cordillera”, “we”, “us”, or “our”) operates Corpbook, a corporate-records and compliance software service for Canadian organizations. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information in connection with Corpbook.

1. Scope and Applicable Privacy Law

Cordillera is based in British Columbia, Canada. We handle personal information in accordance with the federal Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia’s Personal Information Protection Act (BC PIPA) where applicable, and other Canadian privacy laws that may apply to our operations.

Corpbook customers may also have their own legal obligations to individuals whose personal information they enter into the Service. If your organization uses Corpbook to manage corporate records, you are responsible for giving required notices, obtaining required consents, and ensuring you have authority to disclose that information to us for processing.

2. Personal Information We Collect

Depending on how Corpbook is used, we may collect and process:

  • Account information: name, email address, password hash, email-verification status, authentication settings, session details, security events, and multi-factor authentication status.
  • Company information: company name, jurisdiction, corporation number, business number, incorporation details, fiscal year end, registered office information, governing statutes, tax classifications, subscription tier, and company settings.
  • Corporate-record information: director, officer, shareholder, member, advisor, significant-individual, and beneficial ownership information, including names, email addresses, dates of birth, addresses, citizenships, Canadian citizen or permanent resident status, Canadian tax residency status, roles, appointment or resignation dates, shareholdings, share transactions, control details, service addresses, missing-information notes, and capacity-related fields.
  • Documents and files: uploaded corporate documents and in-product authored content, document metadata, tags, versions, current markdown, file names, file sizes, file formats, and storage paths.
  • Communications and workflow records: support messages, invites, compliance contacts, reminder preferences, sent email records, booking requests, meeting notices, questionnaire tracking, and related delivery status information.
  • Usage, device, and security data: IP address, browser or client information, the pages and actions accessed, timestamps, session and API-key context, and security and audit logs used to operate, secure, and troubleshoot the Service.
  • Billing data: plan tier, subscription status, renewal period, and payment status, together with the customer and subscription identifiers and payment-method details held with our payment processor. Our payment processor handles full card numbers and card security codes; Corpbook does not store those values.

As of the effective date of this Policy, Corpbook does not collect or store Social Insurance Numbers (SINs) or Individual Tax Numbers (ITNs). If we enable SIN/ITN collection in the future, we will update this Policy and provide product notices before any collection begins.

3. Why We Collect and Use Personal Information

We collect and use personal information for purposes that include:

  • creating, verifying, authenticating, securing, and administering accounts;
  • providing corporate-record, register, document, questionnaire, reminder, billing, and collaboration features;
  • displaying, validating, searching, and updating corporate records and documents;
  • sending transactional emails, account notices, invites, questionnaires, reminders, booking confirmations, password and email-change notices, and security notices;
  • processing subscriptions, invoices, taxes, payment status, cancellations, and billing support through Stripe;
  • maintaining audit logs, access controls, security monitoring, incident response, troubleshooting, and abuse prevention;
  • responding to support, privacy, legal, operational, and compliance requests;
  • complying with applicable law, court orders, regulatory requests, contracts, and enforcement obligations;
  • improving reliability, usability, security, and product functionality.

4. Consent, Authority, and Withdrawal

We rely on consent, contract performance, legal obligations, and our legitimate business interests in providing and securing Corpbook. Consent may be given directly by an account holder, by an organization using Corpbook, or through an authorized user who enters or invites an individual to provide information.

You may withdraw consent to optional uses where withdrawal is legally and operationally available. Withdrawal may limit or prevent our ability to provide the Service. We may continue to retain or use information where required or permitted by law, including for security, billing, audit, dispute, legal, backup, or compliance reasons.

5. How We Protect Your Information

Most of the information in Corpbook is operational data that the Service must be able to read to function — for example, names, addresses, dates of birth, citizenship and residency details, ownership and control records, documents, reminders, and billing records. This information is not held under a “zero-access” model, and we do not represent that Corpbook is unable to read it. We protect it instead through controls on who may access it and how.

We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit, access controls and authorization checks, secure handling of credentials, audit logging of access and changes, and controls on uploads and storage. No security program can guarantee perfect protection.

If we introduce a SIN/ITN field in the future, it is intended to use stronger, narrower controls than ordinary operational data. Because that capability is not currently active, this Policy makes no present-tense claim that SINs or ITNs are collected, sealed, filed, or otherwise handled by Corpbook.

6. Disclosure and Subprocessors

We do not sell personal information and do not use personal information for third-party behavioural advertising. We may disclose personal information to service providers, subprocessors, professional advisors, authorities, or transaction parties where reasonably required for the purposes described in this Policy.

The service providers and subprocessors we rely on include:

  • Stripe: payment processing, subscriptions, invoices, tax calculation, the billing portal, and in-person payments where used.
  • Typewire (Canada): sends account, transactional, and notification emails on our behalf.
  • Google Calendar / Google Meet: scheduling availability, calendar events, invitations, and meeting links where booking workflows are used.
  • Cloud hosting, database, and storage providers (Canada): operate the Canadian infrastructure that runs Corpbook and stores your corporate records and documents.

We do not use third-party advertising or behavioural-tracking services. If we add analytics, error-monitoring, customer-support, or similar providers in the future, we will update this Policy before they receive personal information.

7. Data Residency and Cross-Border Processing

Corpbook’s core infrastructure — the databases and document storage that hold your corporate records, registers, and minute-book documents — is hosted in Canada. We deliberately keep this information within Canadian jurisdiction and do not move your corporate records outside Canada in the ordinary course of providing the Service. Keeping these records in Canada means they are governed by Canadian law and are not directly subject to foreign data-access regimes.

Our operational service providers, including hosting, storage, and email delivery, are located in Canada. The main exceptions are two optional functions whose providers may process some information outside Canada:

  • Payments. When you subscribe to a paid plan, billing and payment information is processed by Stripe, which operates internationally. Stripe receives only what is needed to process payments — it does not receive your corporate records.
  • Calendar and meetings. If you use our booking or meeting features, scheduling and meeting information is processed by Google (Calendar / Meet). Google receives only what is needed for those features — it does not receive your corporate records.

Where information is processed outside Canada by these providers, it may be subject to the laws of the jurisdictions in which they operate, including access by courts or authorities there. Your corporate records themselves remain hosted in Canada. We use contractual, technical, and organizational safeguards appropriate to the information and the provider.

8. Retention and Deletion

We retain personal information for as long as reasonably necessary to provide Corpbook, maintain records, administer accounts, process payments, secure the Service, resolve disputes, enforce agreements, comply with law, and support business operations.

Archiving a company hides it from active views while preserving its data so it can be restored later. Deleting a company removes the company record and most associated data. Removal of stored documents and files is performed on a best-effort basis, so we do not promise that every stored file is erased immediately when a company is deleted.

We retain audit and security logs separately from deleted accounts and companies, typically for up to 13 months. Billing, tax, invoice, support, legal, backup, security, and abuse-prevention records may be retained longer where required or permitted by law.

Self-service user-account deletion is not currently implemented. You may request deletion or assistance by contacting us, but deletion may be limited by company ownership, legal retention duties, audit requirements, billing records, backups, security needs, and the rights of other users or organizations connected to the same corporate records.

9. Your Access, Correction, and Deletion Rights

Subject to legal exceptions, you may request access to personal information we hold about you, ask us to correct inaccurate information, withdraw consent where withdrawal is available, or request deletion. We may need to verify your identity and authority before responding. If the information is controlled by one of our customers, we may direct you to that customer or work with the customer to respond.

Send privacy requests to privacy@cordilleralabs.ca or info@cordilleralabs.ca.

10. Cookies and Similar Technologies

Corpbook uses cookies and local storage needed for authentication, session management, security, theme preferences, and product operation. We do not currently use third-party advertising cookies or tracking pixels.

11. Security Incidents

If we determine that a security breach involving personal information has occurred, we will assess the incident and provide notices to affected individuals, customers, regulators, or other parties where required by applicable law. We may also take steps such as revoking sessions or API keys, forcing password resets, suspending access, preserving logs, or cooperating with authorities.

12. Children

Corpbook is not directed to children or minors. We do not knowingly collect personal information from minors except where a customer enters information as part of lawful corporate records and has authority to do so.

13. Changes to This Policy

We may update this Policy from time to time. For material changes, we will use reasonable efforts to provide notice, such as by email, in-product notice, or posting an updated version. Continued use after the effective date means the updated Policy applies to later processing.

14. Contact

Privacy questions, access requests, correction requests, deletion requests, and complaints may be sent to Cordillera Labs Ltd., British Columbia, Canada, at privacy@cordilleralabs.ca or info@cordilleralabs.ca.