PRIVACY POLICY & PRIVACY NOTICE
Effective Date: August 18, 2026
Business Name: ClearLee Books
Legal Structure: Sole Proprietorship
Email: contact@clearleebooks.ca
Website: https://clearleebooks.ca/
1. PURPOSE OF THIS PRIVACY POLICY
ClearLee Books (“we“, “us“, “our“, or the “Service Provider“) respects the privacy of individuals whose personal information we collect, use, disclose or otherwise handle in connection with our bookkeeping and related services.
This Privacy Policy explains how we collect, use, disclose, protect, retain and dispose of personal information.
It also explains the rights and choices available to individuals concerning their personal information and how individuals may contact us with privacy questions, requests or complaints.
This Privacy Policy is intended to apply to our handling of personal information in connection with:
- Our website;
- Prospective clients;
- Clients and former clients;
- Client representatives;
- Employees and contractors of clients;
- Vendors and suppliers;
- Website visitors;
- Individuals who communicate with us;
- Individuals whose information is contained in records provided to us by clients; and
- Other individuals whose personal information we reasonably require to provide our services.
This Privacy Policy is intended to operate in accordance with applicable privacy legislation, including applicable requirements of Alberta’s Personal Information Protection Act (PIPA) and British Columbia’s Personal Information Protection Act (PIPA), as applicable.
Where applicable law provides a right or protection that is inconsistent with this Privacy Policy, the applicable law will prevail.
2. WHO IS RESPONSIBLE FOR YOUR PERSONAL INFORMATION?
Because ClearLee Books is operated as a sole proprietorship and is responsible for privacy compliance and the protection of personal information in our custody or under our control.
Privacy contact: Privacy Officer
Email: contact@clearleebooks.ca
Individuals may contact the Privacy Officer regarding:
- Privacy questions;
- Access requests;
- Correction requests;
- Consent questions;
- Privacy complaints;
- Security concerns;
- Requests concerning the handling of personal information; or
- Other privacy-related matters.
3. WHAT IS PERSONAL INFORMATION?
For purposes of this Privacy Policy, “personal information” generally means information about an identifiable individual, subject to the definition and exclusions contained in applicable law.
Depending on the nature of our relationship with you, personal information may include:
- Name;
- Mailing address;
- Email address;
- Telephone number;
- Date of birth;
- Identification information;
- Business contact information;
- Financial information;
- Banking information;
- Payment information;
- Tax-related information;
- Government identification numbers;
- Payroll information;
- Employee information;
- Customer information;
- Vendor information;
- Transaction information;
- Accounting records;
- Invoices and receipts;
- Employment information;
- Compensation information;
- Information contained in financial statements;
- Information contained in correspondence;
- Information contained in documents provided by clients;
- Login or account information necessary to access authorized systems;
- IP address;
- Device information;
- Website usage information; and
- Other information reasonably necessary for the purposes described in this Privacy Policy.
We will not intentionally collect more personal information than is reasonably necessary for the purposes for which it is collected.
4. INFORMATION WE COLLECT
Depending on the services you request, we may collect personal information directly from you.
We may also receive personal information from:
- Your employees;
- Your customers;
- Your vendors;
- Your contractors;
- Your accountant;
- Your lawyer;
- Your payroll provider;
- Your financial institution;
- Government authorities;
- Accounting software;
- Payment processors;
- Other service providers;
- Individuals authorized by you; or
- Other sources where permitted by applicable law.
Where we receive personal information from a client for the purpose of providing bookkeeping services, the client remains responsible for ensuring that it has the appropriate authority to provide that information to us.
5. PURPOSES FOR COLLECTING PERSONAL INFORMATION
We collect personal information only for purposes that are reasonable and appropriate in the circumstances and permitted by applicable law.
Depending on the relationship, we may collect personal information for purposes including:
Providing Services
- Providing bookkeeping services;
- Maintaining accounting records;
- Performing reconciliations;
- Preparing financial reports;
- Processing payroll where engaged;
- Supporting GST/HST or PST bookkeeping and filing services where engaged;
- Preparing records for accountants or other professional advisers;
- Communicating with financial institutions or other authorized parties;
- Completing client requests; and
- Administering the engagement.
Client Administration
- Establishing and maintaining client accounts;
- Verifying identity or authority;
- Communicating with clients;
- Scheduling meetings;
- Managing invoices;
- Processing payments;
- Managing contracts;
- Responding to inquiries;
- Maintaining business records; and
- Managing our business relationship.
Security and Risk Management
- Protecting our systems;
- Detecting unauthorized activity;
- Preventing fraud;
- Investigating security incidents;
- Protecting confidential information;
- Maintaining backups;
- Managing access permissions; and
- Protecting the security and integrity of our business.
Legal and Regulatory Purposes
We may collect, use or disclose personal information where reasonably necessary to:
- Comply with applicable law;
- Respond to lawful requests;
- Comply with court orders;
- Respond to regulatory authorities;
- Establish, exercise or defend legal claims;
- Obtain professional or legal advice;
- Maintain required records; or
- Protect our legal rights and interests.
Business Administration
We may use personal information for:
- Accounting;
- Invoicing;
- Collections;
- Insurance;
- Professional advice;
- Business continuity;
- Record keeping;
- Quality control;
- Internal administration; and
- Other reasonable purposes related to operating our business.
6. CONSENT
Where required by applicable law, we will obtain meaningful consent before collecting, using or disclosing personal information.
Depending on the circumstances, consent may be express or implied where permitted by applicable law.
When consent is required, we will identify the purpose of the collection, use or disclosure in a manner that is reasonably understandable.
You may withdraw consent where permitted by law.
Withdrawal of consent may affect our ability to provide certain Services.
For example, if we require certain financial or employee information to perform bookkeeping services and you withdraw the consent or authority required for us to process that information, we may be unable to continue providing the affected Services.
Withdrawal of consent does not affect collection, use or disclosure that has already occurred based on valid consent or another lawful authority.
We may also collect, use or disclose personal information without consent where authorized or required by applicable law.
7. CLIENT AUTHORITY TO PROVIDE INFORMATION
If you are a business client, you may provide us with personal information belonging to your:
- Employees;
- Customers;
- Vendors;
- Contractors;
- Directors;
- Officers;
- Shareholders;
- Family members;
- Representatives; or
- Other individuals.
By providing such information, you represent that you have the authority or lawful basis required to provide the information to us for the purposes for which it is provided.
You agree to cooperate with us where an individual makes a privacy request relating to information provided by you.
Nothing in this section overrides rights or obligations imposed by applicable privacy legislation.
8. LIMITING COLLECTION
We will make reasonable efforts to limit the collection of personal information to information reasonably required for identified purposes.
For example, we generally do not need to collect personal information merely because it is available to us.
If unnecessary sensitive information is included in documents provided to us, we may take reasonable steps to avoid retaining or using that information where appropriate.
Clients should avoid sending unnecessary personal information.
9. SENSITIVE INFORMATION
Bookkeeping services may involve highly sensitive financial and employment information.
Depending on the engagement, this may include:
- Banking information;
- Payroll information;
- Compensation;
- Tax information;
- Government identification numbers;
- Employee records;
- Customer information;
- Financial statements;
- Debt information;
- Payment information; and
- Other sensitive financial records.
We will apply reasonable administrative, physical and technological safeguards appropriate to the sensitivity of the information.
Individuals and clients should not send highly sensitive information through an insecure communication method when a secure alternative has been provided.
10. USE OF PERSONAL INFORMATION
We will use personal information only for:
- The purposes identified at or before collection;
- Purposes for which consent has been provided;
- Purposes reasonably related to the original purpose where permitted by applicable law; or
- Other purposes permitted or required by applicable law.
We will not intentionally use personal information for unrelated purposes without appropriate authority.
11. DISCLOSURE OF PERSONAL INFORMATION
We may disclose personal information where reasonably necessary to provide Services or administer our business and where permitted by applicable law.
Depending on the circumstances, information may be disclosed to:
- Accounting software providers;
- Cloud-storage providers;
- Electronic-signature providers;
- Client portal providers;
- Payment processors;
- Financial institutions;
- Payroll platforms;
- Information-technology providers;
- Cybersecurity providers;
- Backup providers;
- Professional advisers;
- Lawyers;
- Accountants;
- Insurance providers;
- Government authorities;
- Regulators;
- Service providers engaged by us; and
- Other persons authorized by the individual or client.
We may also disclose personal information where required or authorized by law.
We do not sell personal information to third parties.
We do not rent personal information to third parties.
12. SERVICE PROVIDERS AND CLOUD TECHNOLOGY
We may use third-party technology and service providers to operate our business and provide bookkeeping services.
These providers may process or store personal information on our behalf.
Examples may include:
- Accounting platforms;
- Cloud-storage platforms;
- Email providers;
- Electronic-signature platforms;
- Client portals;
- Payment processors;
- Payroll platforms;
- Cybersecurity providers;
- Backup systems;
- Scheduling systems;
- Communication platforms; and
- Information-technology providers.
We seek to select service providers that provide appropriate safeguards for the nature and sensitivity of the information being processed.
Where appropriate, we may enter into contractual arrangements addressing confidentiality, privacy and security.
13. INFORMATION STORED OUTSIDE CANADA
Some third-party service providers may store or process information outside Canada.
Depending on the technology and providers used by our business, personal information may be stored or processed in Canada, the United States or another jurisdiction.
Information stored or processed outside Canada may be subject to the laws of that jurisdiction.
Before using a specific third-party provider, we will consider the privacy and security implications appropriate to the nature of the information and services involved.
Clients who require all information to remain physically within Canada should discuss that requirement with us before engaging our Services.
Where applicable law imposes additional requirements concerning cross-border handling of personal information, we will comply with those requirements.
14. SECURITY SAFEGUARDS
We use reasonable administrative, physical and technological safeguards appropriate to the sensitivity of personal information.
Safeguards may include:
Administrative Safeguards
- Privacy policies;
- Confidentiality obligations;
- Access controls;
- Staff or contractor instructions;
- Privacy training where appropriate;
- Security procedures;
- Incident-response procedures;
- Record-management procedures; and
- Periodic review of privacy practices.
Physical Safeguards
- Secure work areas;
- Restricted physical access;
- Secure storage;
- Protection of paper records;
- Secure disposal of physical records; and
- Measures designed to prevent unauthorized access.
Technological Safeguards
Where appropriate, we may use:
- Password protection;
- Multi-factor authentication;
- Encryption;
- Access controls;
- Secure cloud platforms;
- Anti-malware protection;
- Firewalls;
- Secure backups;
- Device security;
- Software updates;
- Audit logs; and
- Other reasonable security measures.
No security system can guarantee absolute protection.
Accordingly, while we take reasonable measures to protect personal information, we cannot guarantee that information will never be accessed, disclosed, altered, lost, stolen or destroyed through circumstances beyond our reasonable control.
15. EMPLOYEE AND CONTRACTOR ACCESS
If we use employees, contractors or subcontractors in the future, access to personal information will be limited to individuals who reasonably require access for authorized business purposes.
Individuals with access may be subject to confidentiality and privacy obligations.
We will take reasonable steps to ensure that individuals handling personal information understand their privacy and security responsibilities.
16. ACCURACY OF PERSONAL INFORMATION
We rely on clients and individuals to provide accurate and current information.
Where appropriate, we will take reasonable steps to ensure that personal information we use is accurate and complete for the purpose for which it is being used.
If you identify inaccurate personal information, you may request correction as described below.
17. ACCESS TO PERSONAL INFORMATION
Subject to applicable legal exceptions, individuals may request access to their personal information in our custody or under our control.
A request should be submitted in writing to our Privacy Officer.
The request should provide sufficient information for us to identify:
- The individual;
- The information being requested;
- The relevant time period; and
- Any other information reasonably necessary to locate the records.
We may require reasonable verification of identity before providing access to personal information.
We will respond to access requests within the time required by applicable law, subject to lawful extensions and exceptions.
BC PIPA provides individuals with a right to request access to their personal information held by a private-sector organization.
Alberta PIPA similarly provides individuals with a right to request access to their personal information.
18. CORRECTION OF PERSONAL INFORMATION
If you believe that personal information we hold about you is inaccurate or incomplete, you may request correction.
Requests should be submitted in writing to the Privacy Officer.
We may request supporting information where reasonably necessary.
Where appropriate, we will correct information or note the requested correction in accordance with applicable law.
19. PRIVACY COMPLAINTS
If you believe we have mishandled your personal information, please contact our Privacy Officer first.
We encourage individuals to provide sufficient information to allow us to investigate the concern.
A complaint may include:
- What happened;
- When it happened;
- What information was involved;
- Who was involved, if known;
- Why you believe the handling of information was inappropriate; and
- What resolution you are seeking.
We will review privacy complaints and take reasonable steps to investigate and respond.
We may request additional information where necessary.
20. COMPLAINTS TO A PRIVACY COMMISSIONER
If you are not satisfied with our response, you may have the right to contact the applicable privacy commissioner.
For Alberta matters, the relevant regulator is the:
Office of the Information and Privacy Commissioner of Alberta (OIPC Alberta).
Office of the Information and Privacy Commissioner of Alberta
For British Columbia matters, the relevant regulator is the:
Office of the Information and Privacy Commissioner for British Columbia (OIPC BC).
Office of the Information and Privacy Commissioner for British Columbia
Applicable jurisdiction will depend on the circumstances and the legislation governing the particular matter.
21. RETENTION OF PERSONAL INFORMATION
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, for the administration of the client relationship, for legitimate business purposes, or as required or permitted by law.
Retention periods may vary depending on:
- The nature of the information;
- The type of service provided;
- Legal requirements;
- Accounting requirements;
- Tax requirements;
- Insurance requirements;
- Contractual requirements;
- Potential disputes or claims; and
- Other legitimate business requirements.
When personal information is no longer reasonably required and there is no legal requirement to retain it, we will take reasonable steps to securely destroy, delete or anonymize it.
22. DISPOSAL OF PERSONAL INFORMATION
When records containing personal information are no longer required, we may dispose of them using reasonable methods appropriate to the nature of the records.
This may include:
- Secure deletion;
- Secure destruction;
- Shredding;
- Removal from active systems;
- Deletion from reasonably accessible storage; or
- Other appropriate disposal methods.
Where immediate deletion from backup systems is not reasonably practicable, information may remain temporarily in secure backups until the normal backup-retention cycle removes it.
23. CLIENT RECORDS
Bookkeeping clients remain responsible for maintaining their own business records and backups.
Our retention of records does not replace the Client’s legal record-keeping responsibilities.
Clients should maintain independent copies of important accounting and financial records.
Upon termination of services, we may provide or make available Client records in accordance with the Engagement Letter and applicable law.
24. PRIVACY INCIDENTS AND BREACHES
A privacy incident may include:
- Unauthorized access;
- Unauthorized disclosure;
- Lost or stolen devices;
- Misdirected email;
- Unauthorized use;
- Cyberattack;
- Malware;
- Phishing;
- Accidental disclosure;
- Loss of records; or
- Other circumstances involving unauthorized handling of personal information.
If we become aware of a privacy incident, we will assess the circumstances and take reasonable steps appropriate to the situation.
Depending on applicable law and the circumstances, steps may include:
- Containing the incident;
- Securing affected systems;
- Investigating the incident;
- Determining what information was affected;
- Assessing the risk of harm;
- Taking corrective action;
- Documenting the incident;
- Notifying affected individuals where required or appropriate; and
- Notifying regulators or other authorities where required.
We will not assume that every security event constitutes a legally reportable breach. We will assess incidents based on applicable law and the circumstances.
25. EMAIL AND ELECTRONIC COMMUNICATIONS
Email and electronic communication are convenient but involve inherent risks.
We may communicate with clients electronically where appropriate.
Electronic communications may involve risks including:
- Misdelivery;
- Interception;
- Phishing;
- Malware;
- Unauthorized access;
- Spoofing;
- Account compromise; and
- Other security risks.
We will use reasonable safeguards appropriate to the circumstances.
Clients should notify us immediately if they receive a suspicious message appearing to come from us.
We will never knowingly request a client’s complete password by ordinary email.
26. CLIENT PORTALS AND SECURE FILE TRANSFER
Where available, clients should use our designated secure client portal or file-transfer method for sensitive documents.
Examples of sensitive documents include:
- Bank statements;
- Payroll records;
- Tax documents;
- Government identification;
- Employee records;
- Financial statements;
- Documents containing Social Insurance Numbers;
- Documents containing banking information.
We may decline to accept highly sensitive documents through an insecure channel where a secure alternative is reasonably available.
27. PASSWORDS AND AUTHENTICATION INFORMATION
Clients should not send passwords, authentication codes, security answers or similar credentials by ordinary email unless specifically instructed through a secure process.
Where third-party software supports delegated access, clients should generally use delegated access rather than sharing personal credentials.
Clients remain responsible for securing their own accounts and credentials.
28. COOKIES AND WEBSITE TECHNOLOGIES
Our website may use cookies or similar technologies to operate the website, remember preferences, analyze website usage, improve functionality, or support security.
Depending on the technologies used on the website, these may include:
- Essential cookies;
- Analytics cookies;
- Functional cookies;
- Security technologies; or
- Other website technologies.
We will update this section if our website technology materially changes.
Where applicable law requires consent for a particular technology, we will seek consent in accordance with applicable requirements.
29. WEBSITE ANALYTICS
We may use website analytics tools to understand general website traffic and improve our website.
Depending on the tools used, information may include:
- IP address;
- Browser type;
- Device type;
- Approximate location;
- Pages visited;
- Referral source;
- Time spent on pages; and
- Other technical information.
We will configure analytics tools and handle resulting information in accordance with applicable privacy requirements and our reasonable privacy practices.
30. MARKETING COMMUNICATIONS
We may communicate with existing or prospective clients about our services, where permitted by applicable law.
Marketing communications may include:
- Email;
- Website communications;
- Service announcements;
- Educational information;
- Business updates;
- Promotional communications.
Where applicable law requires consent, we will obtain and manage consent in accordance with applicable requirements.
You may unsubscribe from marketing communications using the unsubscribe mechanism provided or by contacting us.
Unsubscribing from marketing communications will not necessarily stop operational communications relating to an existing client relationship.
31. SOCIAL MEDIA
If you interact with us through social-media platforms, the platform may collect and process personal information independently of us.
Your use of those platforms is governed by their respective privacy policies.
We are not responsible for the privacy practices of third-party social-media platforms.
32. THIRD-PARTY WEBSITES
Our website or communications may contain links to third-party websites.
We are not responsible for the privacy practices, security or content of third-party websites.
We encourage users to review the privacy policies of websites they visit.
33. CHILDREN’S INFORMATION
Our Services are intended for businesses and adults.
We do not intentionally collect personal information directly from children for our own purposes.
If a client provides information concerning a child as part of legitimate bookkeeping or business records, that information will be handled for the purposes of providing the Services and in accordance with applicable law.
34. BUSINESS TRANSACTIONS
If our business is reorganized, sold, transferred, merged, financed or otherwise undergoes a business transaction, personal information may be transferred as part of the transaction where permitted by applicable law.
Any such transfer will be handled in accordance with applicable privacy requirements.
35. LEGAL DISCLOSURES
We may disclose personal information where reasonably necessary to:
- Comply with law;
- Respond to a court order;
- Respond to a subpoena or other lawful process;
- Respond to government authorities;
- Meet regulatory obligations;
- Establish or defend legal claims;
- Obtain legal advice;
- Protect our rights or property;
- Protect the safety of an individual; or
- Otherwise act as permitted or required by applicable law.
36. NO SALE OF PERSONAL INFORMATION
We do not sell personal information.
We do not rent personal information for monetary consideration.
We may use third-party service providers as reasonably necessary to operate our business and provide our Services.
37. PRIVACY BY DESIGN
Where reasonably practicable, we seek to consider privacy and security when selecting:
- Software;
- Cloud providers;
- Client portals;
- Communication systems;
- Storage systems;
- Business processes; and
- Other technologies involving personal information.
We seek to limit access to personal information to what is reasonably necessary.
38. EMPLOYEE AND CONTRACTOR TRAINING
If we engage employees, contractors or subcontractors who handle personal information, we will take reasonable steps appropriate to the size and nature of our business to ensure they understand applicable privacy and confidentiality obligations.
39. PRIVACY MANAGEMENT
We maintain privacy policies and practices appropriate to the size, nature and complexity of our business.
These practices may include:
- Identifying personal information handled by the business;
- Limiting collection;
- Managing consent;
- Controlling access;
- Protecting information;
- Managing retention;
- Secure disposal;
- Responding to privacy requests;
- Responding to privacy complaints;
- Responding to privacy incidents;
- Reviewing third-party service providers; and
- Periodically reviewing privacy practices.
BC’s privacy regulator specifically recommends that private-sector organizations develop and follow privacy policies and practices and make those policies available on request.
Alberta’s OIPC likewise recommends written privacy policies and practices addressing matters such as consent, protection, accuracy, storage, disposal and security breaches.
40. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect:
- Changes in our Services;
- Changes in technology;
- Changes in privacy practices;
- Changes in legal requirements;
- Changes in third-party service providers; or
- Other operational changes.
The updated version will be posted on our website with a revised “Last Updated” date.
Where required by law, we will provide additional notice or obtain consent for material changes.
41. CONTACT US
If you have questions about this Privacy Policy or our privacy practices, contact:
Privacy Officer
Business: ClearLee Books
Email: contact@clearleebooks.ca
Privacy Requests
Please identify the nature of your request and provide enough information for us to identify the relevant records or relationship.
For security purposes, we may need to verify your identity before responding to an access or correction request.
42. PRIVACY COMPLAINT PROCESS
We encourage individuals to contact us first so that we have an opportunity to investigate and address their concern.
Our complaint process is:
Step 1 — Contact the Privacy Officer
Send the complaint to:
contact@clearleebooks.ca
Step 2 — Investigation
We will review the complaint and may request additional information.
Step 3 — Response
We will provide a response within the timeframe required by applicable law or, where no specific statutory timeframe applies, within a reasonable period.
Step 4 — External Complaint
If you remain dissatisfied, you may contact the applicable privacy commissioner.
Alberta:
British Columbia:
43. IMPORTANT NOTICE FOR CLIENTS
Clients should understand that bookkeeping services require us to process financial and personal information.
By engaging our Services, the Client acknowledges that:
- Personal information may be contained in financial records;
- We may need to access such information to perform the Services;
- We may use appropriate third-party service providers;
- Information may be stored electronically;
- Certain service providers may process information outside Canada;
- Electronic communications carry inherent risks;
- The Client remains responsible for ensuring it has authority to provide personal information to us;
- The Client should avoid providing unnecessary personal information; and
- The Client should promptly notify us of suspected privacy or security incidents.
44. APPLICABLE LAW
This Privacy Policy will be interpreted in accordance with applicable Canadian privacy legislation.
Depending on the circumstances, this may include Alberta’s Personal Information Protection Act, British Columbia’s Personal Information Protection Act, federal privacy legislation where applicable, and other applicable privacy laws.
We will not use this Privacy Policy to contract out of rights or obligations that cannot legally be excluded.
45. EFFECTIVE DATE
Effective Date: August 18, 2026
Business Name: ClearLee Books
Privacy Email: contact@clearleebooks.ca