Privacy Policy
How SpeedNum Technologies Inc. collects, uses, shares and protects personal information — under PIPEDA and applicable provincial privacy legislation.
Last updated: June 15, 2026
1. Overview
SpeedNum Technologies Inc. ("SpeedNum", "we", "us") provides practice-management software to accounting firms. This policy explains what personal information we collect, why, how we protect it, and the choices you have.
We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, provincial privacy legislation including Alberta's PIPA, British Columbia's PIPA and Quebec's Law 25.
2. Our role: controller and processor
We act in two capacities, and the distinction matters for your rights.
For information about our own customers — the firms and firm users who sign up — we determine why and how it is processed. We are the controller.
For information a firm uploads about its own clients, we process it on that firm's instructions. The firm is the controller and we are the processor. If you are a client of a firm using the Service and want your information accessed, corrected or deleted, contact that firm; we will support them in responding.
3. What we collect
- Account information: name, work email, phone, job title, firm name and role.
- Billing information: billing contact, address and payment method (payment card details are handled by our payment processor and are not stored on our systems).
- Customer Data: the client records, contacts, services, tasks, deadlines, documents and engagement letters your firm creates in the Service.
- Usage data: pages accessed, features used, timestamps and approximate location derived from IP address.
- Technical data: IP address, browser and device type, and log data.
- Support communications: the content of messages you send us.
4. Why we use it
- To provide, maintain and support the Service.
- To authenticate users and secure accounts.
- To bill for paid plans and manage subscriptions.
- To send service and security notices, which are not optional while you hold an account.
- To send product and marketing email, which is optional and which you can withdraw at any time.
- To diagnose faults, prevent abuse and improve reliability and performance.
- To meet legal, regulatory and professional obligations.
5. Consent and legal basis
We rely on your consent, on the necessity of processing to perform our contract with you, and on legitimate interests such as securing the Service and preventing fraud.
Marketing email is sent only with express or implied consent as permitted under Canada's Anti-Spam Legislation, and every marketing message carries an unsubscribe link. Withdrawing marketing consent does not stop transactional and security notices.
6. Where your data lives
Customer Data is stored in Canada, in the ca-central-1 region. Backups remain in Canada.
Some sub-processors that support the Service — for example email delivery and error monitoring — may process limited technical or contact data outside Canada. Where they do, we put contractual protections in place and limit the data transferred to what the function requires.
8. How we protect it
No system is perfectly secure. If a breach creates a real risk of significant harm, we will notify the Office of the Privacy Commissioner of Canada and affected individuals as required, and we keep a record of all breaches including those below the reporting threshold.
- Encryption in transit (TLS) and at rest.
- Per-tenant isolation enforced by row-level security in the database, independently of the application layer.
- Asymmetric verification of session tokens against the identity provider's public keys.
- Role-based access control, with least privilege for our own personnel.
- An append-only audit log of mutations, retained for the life of the account.
- Regular backups with tested restores.
9. How long we keep it
We keep Customer Data for as long as your account is active. After termination, data is available for export for 30 days and is then deleted or irreversibly anonymised within 90 days, except where we must retain it to meet a legal or tax obligation.
Audit logs and billing records are retained for seven years to meet Canadian record-keeping requirements. Backups are cycled out within 35 days.
10. Your rights
Subject to applicable law, you may:
- Access the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Withdraw consent to non-essential processing, including marketing.
- Request deletion, where we are not required to retain the information.
- Request a copy of your data in a portable format.
- Complain to us, and to the Office of the Privacy Commissioner of Canada or your provincial regulator.
12. Children
The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.
13. Changes to this policy
We may update this policy. Where a change is material we will give notice by email or in-product notice before it takes effect. The date at the top of this page shows when it was last revised.
14. Contact us
Privacy enquiries and requests: privacy@speednum.com.
Our privacy officer can be reached at SpeedNum Technologies Inc. · MOSAIC ENCOR 56-4850 Terwillegar Common N.W. · Edmonton, Alberta T6R 0T6 · Canada · +1-780-952-6108.
If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca, or your provincial privacy regulator.