Privacy Policy

Our privacy policy and how we use your data

Last updated: 24 September 2026

At CondoAide ("we", "our" or "us"), we are committed to protecting the privacy of our users. This privacy policy explains how we collect, use, disclose and protect your personal information when you use our condo management platform. This policy is governed by the Act respecting the protection of personal information in the private sector of Quebec (commonly called "Law 25"), by the Act to establish a legal framework for information technology, and by the Personal Information Protection and Electronic Documents Act (PIPEDA) for users residing outside Quebec but within Canada.

1. Information We Collect

We collect the following types of information:

  • Account information: name, email address, phone number and postal address during registration
  • Condo information: information about your syndicate, buildings, units and equipment
  • Answers to a question in an announcement: when the board attaches a question to an announcement, the answer you give in the app is kept with the unit concerned and with your name. Depending on the question, it may include an availability, a preference, a quantity, an absence of objection, a free-text comment you write yourself, and a file you upload. An answer is attributable by design: the board needs to know which unit said what. It is never anonymous and it is not a vote. The board may also record an answer someone gave it by phone or by email: that answer then carries the name of the board member who recorded it, it is shown as board-recorded, and it never replaces the answer the co-owner gives themselves in the app.
  • Usage data: information about your use of the platform, pages viewed and features used
  • Subscription payment information: to pay your CondoAide subscription, we collect either credit card information (Visa, Mastercard, American Express) that you provide to us expressly, or banking details (institution number, transit number, account number) that you likewise provide to us expressly if you choose pre-authorized debit (PAD/ACSS Debit). This information is processed directly by our payment provider Stripe, which is PCI DSS Level 1 certified (the highest level) for payment card data; banking details, which fall outside that standard, are protected by Stripe's security measures and framed by its data processing agreement (DPA). CondoAide never stores your raw card or bank account numbers — only a secure token that does not allow reconstruction of the original number. Automatic collection of co-owner common expenses by syndicates is also processed by Stripe (Stripe Payments Canada, Ltd.): co-owners who activate the debit expressly authorize a PAD/ACSS mandate and their banking details are processed by Stripe, which deposits the funds directly into the syndicate's account. CondoAide never holds these funds nor retains raw account numbers.
  • PAD mandate for the subscription: if you pay your subscription by PAD, the mandate itself — signed authorization, mandate identifiers and status, including revocations — is retained by Stripe on our behalf. In our own systems we keep only our Stripe billing references (customer and subscription identifiers) and billing history, not the mandate document. This billing data is retained for 7 years after the subscription ends for tax, accounting and legal-compliance purposes.
  • Subscription transaction history: amounts, dates, statuses (successful, failed, returned), failure reasons where applicable — for billing and accounting compliance
  • Communications: messages exchanged through our support service, including the files you attach to them, or by email where applicable. Files attached to the support form are kept in our private storage in Québec; they are no longer sent by email. Authorized CondoAide staff can download them, using two-factor authentication; the board members of the syndicate that sent the report can also view them in that report's follow-up, like the text that goes with them. When a board member reports a problem to CondoAide support from the app, the report also includes the pages of the app where it was opened and from which it was sent (without the address parameters), the person's role in the syndicate, the app version and the browser used, so we can reproduce the problem.
  • Emails sent to the syndicate's mailbox: if your syndicate uses a CondoAide address (for example conseil@viva.condoaide.ca), what you write there (the message, its attachments and the address it came from) is kept in the syndicate's file, and the entire board has access to it. The mailbox belongs to the syndicate, not to one administrator: it is not a private channel to a person, and its contents stay available to the board when its members change. The syndicate also sends its notices and announcements from that address once it is in service: if you reply to one of those messages, your reply arrives in that same mailbox, available to the same people and kept for the same period.
  • Emails sent to `postmaster@` or `abuse@` at a syndicate address: these two addresses exist to report a delivery problem or the misuse of a syndicate address. What you write there (the message, its attachments and the address it comes from) is not added to the syndicate's file, and its board of directors has no access to it: the message is forwarded to CondoAide's operations mailbox, hosted on our own infrastructure in Quebec, and only our person responsible for the protection of personal information (see section 7) reads it.
  • Communication read tracking: when your syndicate publishes an official communication in CondoAide and notifies you by email, we record when you view it in the app. This information is shared with your syndicate's administration, for the sole purpose of confirming that important notices have been received. No tracking pixels are used in emails.
  • Uploaded documents: any documents you upload to the Service (registers, attestations, reports, photos, etc.)
  • Temporary insurance-proof imports: when an authorized person imports co-owner insurance certificates in bulk, the aggregate PDF and its extracted text are stored temporarily to produce a preview and split proofs by unit. Only the necessary per-unit proofs remain after import; the aggregate file is never added to the syndicate's document registry.
  • Identity of the person who enables automatic collection of condo fees: when a syndicate administrator turns on automatic collection of condo fees, we record who turned it on and when. This is shown to the other administrators of the same syndicate when they are asked to approve a debit, and is used to require that a second person authorise a debit above the syndicate's threshold: whoever enabled the collection cannot approve the resulting debit themselves. It also answers the requirement, under Payments Canada Rule H1, to be able to identify the party behind a pre-authorised debit mandate. It never leaves the syndicate. Within it, it is not restricted to the board: it forms part of the syndicate's record, consulted by the people attached to the building — co-owners and tenants — and it is also readable by those authorised to consult the syndicate's payments, including the accountant. Other external parties (vendors, building professionals, insurers, legal advisers) have no access to it.
  • Identity of the person who declares what the declaration of co-ownership provides for contributions paid before the budget is adopted: when a person authorized to manage a syndicate's settings states that the declaration of co-ownership treats those payments as instalments on the annual contribution, we record who declared it, when, and the article of the declaration that is cited. Every change to this answer is recorded in the syndicate's audit log with the name and email address of the person who made it. The person's identifier forms part of the syndicate's record, readable by the syndicate's members in the app; their name is shown only to people authorized to manage the syndicate's settings. This information never leaves the syndicate and is not used to calculate any contribution.
  • IP address: your IP address is processed while you browse the public site and use the platform — security and anti-abuse logs kept by our hosting providers, and momentary city lookup by our aggregate analytics, after which it is immediately discarded. It is passed neither to our product telemetry nor to our error tracking. One exception: when you sign electronically — a proxy, an access agreement, or an acknowledgement of a syndicate document — the IP address and browser used are recorded durably alongside the signature, because they are its proof under section 39 of the Act to establish a legal framework for information technology. Those entries are kept per section 5.
  • Information about a person with no account: when a syndicate migrates its history from another software, a service request may name the person who filed it even though they never held a CondoAide account — a former co-owner who has since sold, for instance. We then keep their name, and nothing else, so the request remains attributable; no email address and no phone number is carried over from the export for that purpose.
  • Emergency contact designated by an occupant: someone filling in their occupancy record may designate a contact to reach in an emergency and record their name, the relationship between them, their phone number and, optionally, their email address. That person has no CondoAide account, and this information is visible only to the person who recorded it and to their syndicate's board. We never send them email: these details exist solely so the syndicate can reach them during an emergency affecting the unit, and they may appear in the book provided to fire services.
  • Mention of a person in a message: when an authorized person names you with an "@" in a service-request thread or in a work-order comment, we keep the link between that message and you, so that we know who had to be notified. That link is not an access permission: it is filtered on write against who may already read the message, and it is re-checked on every read.
  • Request filed by a tenant: when a tenant files a service request, we record at filing time that they filed it as a tenant, together with the private portion they occupy and to which the request relates. The request, its content, its attachments and the board's public replies, with their attachments, can then be viewed by the co-owners of that private portion, for requests filed since their ownership began; they cannot reply to it. When the board redirects the request to the co-owner, we keep that closing reason with the request.
  • A syndicate's designation of its own person responsible for the protection of personal information: a syndicate of co-ownership is itself an enterprise under the Act, and designating that person and publishing their title and contact details is its own duty. When it does so in CondoAide, we keep what it publishes: the title, whichever contact details it chooses to make accessible — email, phone or mailing address — and, if it decides to include it, the name, which stays optional. The published contact details may be the syndicate's rather than the person's own. This is the syndicate's designation to its own members; ours is in section 7.
  • Practical information written by the board of directors: free text a board addresses to its co-owners, its renters or its external accounts, which may contain third-party contact details — a caretaker, a supplier — depending on what the board chooses to include.
  • A vendor invoice attached to a work order: when an authorized person attaches an invoice to a work order, the application can read its text in order to suggest the invoice date, its number, the vendor's name and contact details, its GST and QST registration numbers and the amounts billed. These suggestions never save themselves: the person keeps them one by one. The GST and QST registration numbers they keep are stored on the vendor record; where the vendor is a natural person in business, they concern that person. The reading is done in Quebec by our own document analysis service; neither the file nor its text is sent to an external service or to an artificial-intelligence model.
  • RBQ register answer about a vendor's licence: when one of the syndicate's vendors has a Régie du bâtiment du Québec licence number, we keep with the vendor's record what the public register says about it: the holder name listed in the register, whether the licence is in the register, whether a restriction applies, the date the licence left the register if it did, and the date of the check. When the vendor is a person in business, that name concerns them. The check is made with VériBât when the number is entered or changed, then repeated automatically about every two days. The answer is read by the people of the syndicate who manage its vendors, its work or its finances, is used to warn them of a licence that is not in the register or is restricted, is removed with the vendor's record, and is replaced as soon as its number changes.
  • Request for a statement of common expenses due for a unit: when a person who proposes to acquire a unit, or their notary or broker, asks the syndicate for the statement of common expenses due (art. 1069 of the Civil Code of Québec), the board records that person's name, their capacity, the name of the buyer they represent, their email address, the request date, the notice given to the owner (method, date and note) and the date the statement was sent. When the board sends the statement by email, the person receives a link to the document, valid for 30 days; each viewing of that link is logged with its date and time, the originating network (a truncated IP address, which identifies or locates no one) and the browser type, to establish that the statement was provided. The issued statement shows the unit's common expenses due and unpaid, its contribution under the latest adopted budget and the upcoming installments of adopted special assessments; it does not name the owner.
  • Request for authorization to do work in a private portion: when a co-owner asks the board of directors for authorization to do work in their private portion, or the board records that request on their behalf, we collect the description of the planned work, its location in the private portion and the planned start and end dates, together with the request's status (submitted or withdrawn), the date of any withdrawal and who withdrew it. This information is read by the board and by the person who filed the request, and is used to review it. When the work will be done by a contractor, we also collect the company's name, its Régie du bâtiment du Québec licence number and, if the person provides them, a contact person's name and email address. So that the board knows whether the licence is in force, we check that number with VériBât, which consults the Régie's public register: only the licence number is sent to it, and we keep its answer (the holder's name in the register, whether the licence is in the register, whether it carries a restriction, and the date of the check). This information is read by the same people as the request. Once the work is authorized, the co-owner, or the board on their behalf, may send the contractor the work rules the board has written, through a personal link sent to the email address they provide; nothing is sent to the contractor without that step. The email names the co-owner and the building, and the contractor's replies go to the co-owner. When the contractor opens the link, we keep the date, the truncated originating network (IPv4 /24, IPv6 /48) and the browser family. If they sign their undertaking to follow the rules, we keep the name they type, the address the link was sent to, the licence number, the signed version and its fingerprint, the date and time, and the IP address and browser used, as section 39 of the Act to establish a legal framework for information technology provides. This information is read by the board and by the person who filed the request; the IP address and browser of the signature are not displayed. When the board authorizes the work, we open your private portion's entry in the syndicate's register of improvements (art. 1070 of the Civil Code of Québec) and copy into it the description and location of the work, the planned start date, the reference of the decision and its conditions, and the company's name and licence number; the contact person's name and email address are never copied. While the work is still planned, that entry is read only by the owners of the private portion and by the board; once the work is reported as finished, it is read by the syndicate's co-owners, like the rest of the register. You may add photos taken before and after the work, the invoice and an approximate value, then report the work as finished; the board confirms completion and sets the improvement's category. None of these files is required. Photos, the invoice and the approximate value are read only by the owners of your private portion, by the board and, where applicable, by the property manager; they are not visible to other co-owners. We also keep who reported the work finished and when, and who confirmed it. Two days before the planned start date, and again after the planned end date, we send you an email reminder and an in-app notification; the reminder names the request and your private portion, and blocks nothing.

2. Use of Information

We use your information to:

  • Provide and improve our condo management services
  • Preview insurance-certificate imports, verify their integrity, and produce minimized per-unit proofs
  • Read, at an authorized person's request, an invoice attached to a work order in order to suggest the data to record, and file a copy of it in the syndicate's registry under the Invoices category, accessible to the board of directors only
  • Process your payments and manage your subscription
  • Send you important communications about your account
  • Establish, at the request of the syndicate or a co-owner, that a notice or convocation was in fact sent, and to which address
  • Inform you of updates and new features (with the option to unsubscribe from non-essential communications)
  • Notify you when an authorized person names you in a service-request or work-order thread: the notice is delivered in the platform and by email, and the email repeats an extract of at most 500 characters of the message so you know what it concerns without having to open the platform. The extract is sent only to people who may already read that message.
  • Notify the co-owner who receives a private portion's notices when that portion's tenant files a service request, and notify the tenant and that co-owner when the board redirects the request to the co-owner: the notice is delivered in the platform and by email.
  • Publish, on a syndicate's behalf and to the members it addresses, its own designation of a person responsible for the protection of personal information, the documents its board addresses to them, and the practical information it adds
  • Ensure compliance with the Loi visant principalement l'encadrement des inspections en bâtiment et de la copropriété divise (S.Q. 2019, chapter 28, commonly called "Bill 16"), the regulation adopted under decree 991-2025, and other applicable regulations
  • Respond to your support requests
  • Detect and prevent fraud, abuse, and violations of our Terms of Service
  • Produce, at the request of a person who proposes to acquire a unit, the statement of common expenses due that the syndicate is authorized to provide after notifying the owner (art. 1069 of the Civil Code of Québec), notify that owner by email or record a notice given another way, send the statement to the requester as a link by email and log its viewings to establish that it was provided, and file the statement in the syndicate's registry, accessible to the board of directors and, for their own unit, to the notified owner
  • Receive and handle misuse reports and delivery-failure notices sent to postmaster@ and abuse@ at a syndicate address, to keep those addresses able to send and receive mail

3. Sharing of Information

We do not sell your personal information. We share certain information with the following sub-processors, who act on our behalf and are bound by a data processing agreement:

  • Supabase — Database hosting and file storage. Categories: all application data. Location: Canada (ca-central-1 region, Montreal).
  • Vercel — Web application hosting. Categories: application traffic, no permanent storage. Location: Canada (Montreal / yul1 region) — application execution and its logs stay in Quebec. Vercel Inc. is a US company; the processing is framed by its data processing agreement (DPA).
  • Stripe — Subscription payment processing (credit cards + PAD/ACSS Debit bank withdrawals from the syndicate to CondoAide) and automatic condo-fee collection by pre-authorized debit (PAD/ACSS) from co-owners to the syndicate's account. Categories: payer name, email, billing address, payment method, banking information of co-owners who enabled the debit, subscription and cotisation transaction history. Location: Canada and United States.
  • Amazon Web Services (Amazon SES) — Delivery of the Service's transactional emails (confirmations, notices, reminders) and of authentication emails (account confirmation, sign-in link, password reset). Categories: recipient email address and name, email subject and content, delivery logs (deliveries, bounces, complaints). Location: Canada (ca-central-1 region, Montreal). Emails and their delivery logs are processed in Quebec. Amazon Web Services, Inc. is a US company; processing stays in Canada and is covered by the AWS data processing agreement (DPA). This is the same link we already have indirectly, since Supabase's infrastructure also runs on AWS in Canada. Amazon also handles reception of emails sent to syndicate mailboxes, where that option is active: it receives the message, scans it for spam and malware, and places it temporarily, for at most 30 days, in encrypted storage in the same region, before we load it into our own database in Quebec. Amazon also forwards emails sent to postmaster@ and abuse@ at a syndicate address to CondoAide's operations mailbox, within the same region.
  • Brevo — Marketing emails and management of our contact lists (newsletter, non-essential communications). Also serves as the fallback relay for transactional emails when the primary send fails. Categories: email addresses, name, communication preferences, email content. Location: European Union.
  • Anthropic — AI assistant (opt-in features only). Categories: user requests on opt-in AI features. Location: United States.
  • OVHcloud (self-hosted document embeddings) — Hosts our self-hosted embedding model (bge-m3): text from registre documents at every access level is converted into numeric vectors for authorized search. Access remains governed by the source document's classification; the AI assistant searches only documents shared with all co-owners. Categories: text extracted from registre documents. Location: Canada (Beauharnois, Québec). Self-hosted software; no data leaves Québec and the operational sub-processor is OVHcloud.
  • OVHcloud (self-hosted document analysis) — Hosts our self-hosted document analysis service: it reads the PDF files an authorized person imports, and the scanned images of an invoice through optical character recognition (maintenance log, reserve fund study, the syndicate's bank account statement and a vendor invoice attached to a work order) to extract the tasks, study data, transactions or invoice data the person reviews before keeping them. The file is read during the analysis and then discarded by this service; only the data the person keeps is saved in the application. Categories: content of imported documents, including, for a bank statement, transaction dates, amounts and descriptions, which may name a co-owner, a supplier or another payee, and, for an invoice, its date, its number, the vendor's name and contact details, its GST and QST registration numbers and the amounts billed. Location: Canada (Beauharnois, Québec). Self-hosted software; the operational sub-processor is OVHcloud.
  • OVHcloud (self-hosted OpenReplay) — Hosts our OpenReplay installation: product telemetry + session recording for technical support. Categories: pseudonymized user identifier, interaction events (pages visited, features used), technical metadata (browser, OS), visual reconstruction of navigation with automatic masking of form fields and sensitive screens. Location: Canada (Montréal, Québec). Self-hosted software — OpenReplay Inc. is not a sub-processor; the operational sub-processor is OVHcloud (hosting and storage).
  • OVHcloud (self-hosted GlitchTip) — Hosts our GlitchTip installation: application error and exception tracking, plus application logging. Categories: exception stack trace, log messages, pseudonymized user identifier, URL where the error occurred, technical metadata. Request bodies (form data, authentication headers, cookies) are automatically dropped before storage. Location: Canada (Montréal, Québec). Self-hosted software — the GlitchTip team is not a sub-processor; the operational sub-processor is OVHcloud.
  • OVHcloud (self-hosted Plausible) — Hosts our Plausible installation: cookieless, aggregate web analytics (visitor count, pages viewed, traffic sources, city and country) on the public pages of the site. No direct personal information is captured: no cookies, no persistent visitor identifier, no device fingerprint. The IP address is used momentarily to determine the city, then immediately discarded; it is never stored. Statistics are aggregate. Location: Canada (Montréal, Québec). Self-hosted software — the operational sub-processor is OVHcloud.
  • OVHcloud (self-hosted video-conferencing server) — Hosting for our video-conferencing server (LiveKit), which relays audio and video for assembly meetings held online. The stream passes through in real time and is not recorded: no meeting is retained, by us or by the host. Categories: participants' image and voice during the meeting, display name, connection timestamps. Location: Canada (Beauharnois, Quebec). Self-hosted software — LiveKit Inc. is not a sub-processor; the operational sub-processor is OVHcloud.
  • iDrive e2 (off-site backups) — Storage of our backups: a copy of the database every four hours and a daily copy of uploaded files (registry documents, attachments). The backups retain the information entrusted to the Service. Vector search indexes and their processing queue are not copied because they are rebuilt from source files after a restore. Categories: every category described above. Retention: 30 days. Location: Canada (Montreal, Quebec).
  • OVHcloud (secondary backup copy) — A second copy of the same backups, synchronised once a day from iDrive e2, so that the failure of a single provider cannot take the backups with it. Same categories and retention as iDrive e2. Location: Canada (Beauharnois, Quebec).
  • OVHcloud (backup production) — Hosts the job that produces our backups: every four hours it reads the database and encrypts the copy on this server before sending it to iDrive e2; once a day it copies uploaded files to iDrive e2, then synchronises the secondary copy. Data only passes through this server during each copy; no backup is kept there. Categories: every category described above. Location: Canada (Beauharnois, Quebec). Self-hosted software; the operational sub-processor is OVHcloud.
  • VériBât, another service of Solutions Nicvi inc. VériBât is operated by the same company as CondoAide: it is not a sub-processor, and the information sent to it does not leave the company. It uses it only to answer the check CondoAide asks for, never for its other activities. Checking the Régie du bâtiment du Québec licence number of a contractor against the Régie's public register, when a co-owner names the contractor in a work authorization request or the board of directors adds it to its vendors, then about every two days for the syndicate's vendors. Categories: the licence number, or the text typed to find it (the start of a number or a company name, which may be the name of a person in business); no other information is sent. VériBât returns at most ten entries from the public register (number, holder name and other names, municipality, licence status), never contact details. VériBât does not keep that text; it keeps the number only in the log of a check that failed. Location: Canada (Montreal region / yul1).
  • Aggregate web analytics — cookieless. To measure overall traffic on our public pages (visitor count, most-viewed pages, traffic sources, city and country breakdown), we use a self-hosted Plausible installation on the same OVHcloud infrastructure in Montréal. Plausible sets no cookies on your device, stores no persistent identifier, and captures no direct personal information. The IP address is used momentarily to determine the city, then immediately discarded; it is never stored. Statistics are aggregate and are not linked to an identifiable visitor. This aggregate measurement runs for all visitors regardless of your cookie banner choice, because no personal information is involved. Retention: 24 months.
  • This list is updated when we add or remove a sub-processor. Significant changes will be communicated through this policy and by email.
  • Members of your syndicate and its mandated manager: depending on the permissions configured in your account, certain information may be visible to other members of your syndicate (for example, your name and payment status may be visible to administrators and the treasurer). When your syndicate entrusts its management to a property management company and adds it to its account as manager, that person has access, to carry out its mandate, to the syndicate's financial information: budgets, accounting entries, contributions, co-owners' payment information (debit mandates, payment history, arrears) and vendors' payment details. The manager cannot adopt a budget, decide a special assessment or alone approve a payment above the threshold set by the board of directors.
  • Legal authorities: we may disclose your personal information if required by law, by court order, or to protect our rights, your safety, or that of others.
  • Insurer and incident responders: we carry professional liability and cyber insurance with CFC Underwriting Limited, on behalf of Lloyd's underwriters. In the event of a confidentiality incident only, information about you may be disclosed to the insurer and to the providers on its approved response panel (CFC Response), for technical investigation, legal defence, crisis communications and preparing the notices required by law. These providers act under mandate and are bound by confidentiality. They operate from the United States and the United Kingdom; see section 9. Nothing is disclosed to them outside an incident.
  • Commercial transaction: if another business acquires or considers acquiring our operations or assets, or if we undergo a reorganization or a financing, we may have to share your information with the other parties involved. Unlikely as it is, we must disclose it.

4. Data Security

We take the security of your data seriously:

  • Encryption in transit: TLS 1.3 between your browser and our servers
  • Encryption at rest: AES-256 on the database, backups and stored files
  • Passwords: hashed with bcrypt (never stored in plain text, never reversible)
  • Authentication tokens: cryptographically signed with ECDSA on the P-256 curve (ES256); the signing key is never shared with the services that verify tokens
  • Authentication: secure authentication with two-factor authentication options
  • Hosted in Quebec: application served by Vercel (Montreal / yul1 region); database and stored files on Supabase (ca-central-1 / Montreal region). Your condo association data is not transferred outside Canada in normal operation of the Service. Exceptions (subscription payments, opt-in AI features) are described in section 9.
  • Access controls: strict role-based permissions, logging of all sensitive actions
  • Backups in Quebec: Supabase backups with point-in-time recovery (7 days) and daily snapshots; additional backups kept at two distinct Quebec providers (Montreal and Beauharnois), 30-day retention
  • Tokenization: bank and credit card information is never stored in plain text on our servers — it is tokenized by Stripe (PCI DSS Level 1 certified for card data)
  • Certified sub-processors: Supabase, Vercel and Amazon Web Services are SOC 2 Type 2 certified; Stripe is SOC 2 Type 2 and PCI DSS Level 1 certified
  • We commit to an annual third-party penetration test ("pentest").

5. Data Retention

We retain your information as long as your account is active or as required by law. Specific retention periods:

  • General account data — 90 days after account closure, unless otherwise required by law.
  • Condo documents (registers, log book, attestations) — According to the periods prescribed by the Loi visant principalement l'encadrement des inspections en bâtiment et de la copropriété divise (S.Q. 2019, chapter 28, "Bill 16") and the Civil Code of Quebec.
  • Temporary aggregate PDF for an insurance-proof import — Until the import succeeds or reaches a terminal failure, is cancelled or replaced, or for no more than three hours, whichever comes first. The aggregate file and its extracted text are then deleted from production systems. Residual encrypted copies may persist in backups for up to 30 additional days before rotation and destruction.
  • PAD mandate for subscription payment (metadata held by us; signed document retained by Stripe on our behalf) — 7 years after the mandate ends, for tax, accounting and legal-compliance purposes.
  • Subscription transaction data (payments to CondoAide) — 7 years for tax, accounting and regulatory compliance purposes.
  • Co-owner condo-fee collection PAD mandate (Payment Service — metadata held by us; signed document retained by Stripe on the syndicate's behalf) — 7 years after the mandate ends, for tax, accounting and legal-compliance purposes.
  • Condo-fee transaction data (co-owner debits via the Payment Service) — 7 years for tax, accounting and regulatory compliance purposes.
  • Assembly meeting chat (side channel during a virtual meeting) — Kept with the assembly record for as long as it exists — at minimum beyond the 90-day contestation period of art. 1103 CCQ. These messages are never reproduced in the minutes or filed in the syndicate register; a message's author may request its removal at any time.
  • Assembly-meeting presence log (participant connections and disconnections) — Kept with the assembly record for as long as it exists — at minimum beyond the 90-day contestation period of art. 1103 CCQ. This log is corroborating evidence of who was actually connected during the sitting; it does not replace the official attendance sheet of the minutes (art. 1102/1103 CCQ). Hosted in Quebec (Supabase, Canadian region).
  • Identity of the person who enabled automatic collection of condo fees — The field recorded on the syndicate's profile remains for as long as the syndicate uses the Service, including after automatic collection is turned off — turning it off does not make it untrue that it was turned on. It is replaced as soon as another person turns the collection back on. The corresponding audit-log entry, and the authorisation attached to the debits already made, follow the 7-year period for sensitive-action logs and payment records, and that period governs: for as long as those records are kept, so is the identity of the person who authorised those debits.
  • Identity of the person who declared what the declaration of co-ownership provides for contributions paid before the budget was adopted — The person's identifier, the date and the cited article recorded on the syndicate's record remain for as long as that answer stays in effect, and are erased as soon as another answer is saved. Deleting the person's login account does not erase the identifier: it attests who made the declaration on the syndicate's behalf, and it is destroyed with the syndicate's file. The corresponding audit-log entries, which carry the person's name and email address, follow the 7-year period for sensitive-action logs.
  • Proxy registration log (mandate to be represented at a meeting) — Retained as long as the syndicate's file exists, and destroyed with it. This log records the electronic registration of the mandate: the time of signature, the IP address and the browser used, as section 39 of the Act to establish a legal framework for information technology requires for an electronic signature. It now outlives deletion of the proxy itself, which lengthens its retention compared with the previous behaviour: deleting a mandate used to erase the proof that it had existed, and that proof matters precisely when a proxy disappears. The link to the mandate is severed at that point, but the entry stays attached to the syndicate concerned and readable by its board.
  • Acknowledgements and signed access agreements (syndicate documents, role agreements) — Kept for as long as the syndicate's file exists, and destroyed with it. Each row attests that a person read a specific version of a document — governance policy, privacy policy, building by-laws, access agreement — and records the moment of signature, the IP address and the browser used, as section 39 of the Act to establish a legal framework for information technology provides. The row is append-only: it cannot be altered or deleted on its own, or it would prove nothing. Deactivating a document does not remove acknowledgements already collected, since the reading did happen. The syndicate's board can see who signed what and when; a co-owner sees only their own.
  • Audit logs (sensitive actions) — 7 years for compliance purposes.
  • Support communications — 3 years after the last interaction. A file attached to a support message is deleted three years after the message is sent; a file uploaded for a message that is never sent is deleted at most four hours after it was uploaded.
  • Outbound email queue (notices, convocations, reminders) — 90 days after sending. The queue holds the recipient's address and the data used to compose the message: greeting name, unit number, and the details specific to the notice. The rendered message is not kept. This period is operational: it covers delivery follow-up and bounce handling. For most notices, the record of sending also appears in the file the notice belongs to. Convocations to an assembly or a board meeting, their updates, agenda additions and reminders are different: for those, the queue is currently the only place the recipient detail exists. Those rows are kept until 90 days after the assembly or meeting concerned, then deleted; that is the period a co-owner has to ask the court to annul an assembly decision (art. 1103 CCQ). A row whose sending failed for good is deleted 30 days after that final failure.
  • Emails received in the syndicate's mailbox (message, attachments and sender address) — 36 months from reception. Text of the email copied elsewhere in the syndicate's file, such as into a service request, a survey answer or a message reply, is removed at the same moment, and the request or the answer remains, showing a dated notice where the text was. An email filed to a record (work order, contract, litigation) or under a legal hold is kept for as long as that filing or hold lasts.
  • Board reply sent from the syndicate's mailbox — 36 months from sending, with the same exceptions as the email it answers.
  • Emails sent to `postmaster@` or `abuse@` at a syndicate address (message, attachments and sender's address) — 36 months from receipt, in CondoAide's operations mailbox. They are never added to the syndicate's file.
  • Quarantined email (spam or malware detected) — 30 days from reception.
  • Raw copy of the message at the receiving provider — 30 days. It is a transport buffer, not an archive.
  • Email-address suppression state (permanent bounce or complaint) — Kept for as long as the address remains suppressed. When a transactional email permanently bounces or a complaint is received, the address is placed on a suppression list so the Service stops writing to it; that is the entire purpose of the entry, and it lasts as long as the address stays undeliverable. The entry is removed once the address is reachable again, after correction and verified delivery, or following a valid erasure request where no other ground requires keeping it; you can ask for its removal by writing to privacy@condoaide.ca. The row holds the address, the reason, the provider, the technical message identifier and the timestamps of the first and most recent events; no email content is retained. This entry concerns delivery, not consent: it withdraws no newsletter consent and does not alter the marketing lists, which remain governed separately.
  • After the periods above, data is permanently deleted from our production systems. Copies may persist in backups for an additional period (up to 30 days) before rotation and destruction.
  • Service requests (including history migrated from another software) — Kept for as long as the syndicate is active, then 90 days after the account closes, on the same footing as general account data. A migrated request keeps its original date, so it may predate your arrival on CondoAide by years.
  • Links sharing a registry document in a service request — The link secret is never retained. Its cryptographic digest, the document and request it covers, its expiry and revocation state are retained until the link expires. Each link expires after 30 days and can be revoked earlier by the board. The external-access log is kept for 36 months after each access, even if the link or document is deleted in the meantime.
  • A syndicate's designation of its person responsible, and its dashboard information cards — Kept for as long as they stand. Withdrawing the designation deletes the record; clearing a card's text deletes it. Closing the syndicate's account removes both.
  • Answers to a question in an announcement — Kept with the announcement they belong to, and destroyed with the syndicate's account under the general rule above. A period specific to this category is under review: an answer about an availability has no reason to outlive the work it helped schedule, unlike a request. The retention calendar will be updated once that period is adopted.
  • Attachment to a syndicate message (file added by the board, image inserted in the message body) — Kept with the message it belongs to, and destroyed with it. The file has no period of its own: its lifetime is the message's, and deleting the message deletes the file. Since September 2026 the board may attach either a registry document or a file that belongs to the message alone; only the second is covered here. That file is not filed in the syndicate's registry, carries no access level of its own, and is readable only by the message's recipients — a narrower circle than the registry can express, for instance when the message is addressed to a single unit. An image inserted in the message body follows the same rule: it is displayed in the app and is never sent by email, in keeping with our rule that notices carry a link rather than a file.
  • Request for a statement of common expenses due, and the issued statement — The request (identity, capacity and email of the person making it, the buyer's name, the notice to the owner and the delivery) is kept for as long as the syndicate's file exists and destroyed with it; a withdrawn request is not deleted, so the record of the notice given to the owner remains. The delivery link stops working 30 days after it is sent. The log of its viewings (date and time, truncated IP address, browser type) is kept for three years, the period of a recovery action, then deleted. The issued statement is filed in the syndicate's registry and follows the retention rule for condo documents.
  • Work rules sent to a contractor (link, openings and signature) — The link secret is never retained; its cryptographic digest is erased as soon as the link expires (30 days) or is revoked. The link sent and the contractor's signature are kept as long as the work authorization request, and destroyed with it. Openings of the link (date, truncated network and browser family) are kept for three years.
  • Register of improvements to a private portion (entry, before and after photos, invoice, declared approximate value) — Kept permanently, like the syndicate's register of improvements itself: art. 1070 of the Civil Code of Québec requires improvements made by a co-owner to remain identifiable against the description of their private portion. Information copied from the authorization request follows this period and remains in the register even if the request is deleted.
  • Upload request for a file added to the register of improvements — Seven days after the upload for the uploader's identifier and the link to the entry; the technical trace that remains afterwards names no one.

6. Your Rights

Under the Act respecting the protection of personal information in the private sector of Quebec ("Law 25"), PIPEDA, and applicable laws, you have the right to:

  • Access your personal information
  • Correct inaccurate or incomplete information
  • Request deletion of your data (subject to our legal retention obligations, for example PAD mandates retained for 7 years)
  • Withdraw your consent to certain processing (opt-in AI features can be disabled at any time)
  • Receive your data in a structured and portable format (JSON or CSV export)
  • Object to processing (notably marketing communications)
  • Automated decision: to be informed of the personal information and the principal factors used, and of the contact details of the person who can review the decision and to whom you may submit observations, if you are the subject of a decision based exclusively on automated processing (s. 12.1)
  • Revoke your PAD mandate for the subscription at any time, free of charge, in accordance with Payments Canada Rule H1
  • File a complaint with the Commission d'accès à l'information du Québec (cai.gouv.qc.ca) or the Office of the Privacy Commissioner of Canada (priv.gc.ca) for users outside Quebec
  • To exercise any of these rights, contact our Person Responsible for the Protection of Personal Information (see section 7).

7. Person Responsible for the Protection of Personal Information

In accordance with section 3.1 of the Act respecting the protection of personal information in the private sector, CondoAide has designated a Person Responsible for the Protection of Personal Information. This person is your point of contact for any question about the processing of your personal information, to exercise your rights, or to report a concern, an incident or file a complaint.

  • Name: Nicolae Racovita
  • Title: President of CondoAide and Person Responsible for the Protection of Personal Information
  • Email: privacy@condoaide.ca
  • Postal address: 4143 chemin Ste-Angélique, Saint-Lazare (Quebec) J7T 2N5, Canada
  • Our personal information governance policies and practices are published on our Governance page, as section 3.2 of the Act requires.

8. Privacy Incident Notification

In accordance with the Act respecting the protection of personal information in the private sector and the Personal Information Protection and Electronic Documents Act (Canada), in the event of a privacy incident presenting a risk of serious injury to a person concerned, we undertake to:

  • Take necessary measures to manage the incident, limit the harm and prevent recurrence.
  • Engage our insurer and its approved response panel as soon as the incident is discovered. Technical investigation, legal defence and preparation of notices may be handled by these providers, and the information disclosed to them is limited to what the response requires. This step does not delay the notifications set out below.
  • Inform affected individuals without undue delay, by email or any other appropriate means.
  • Inform the Commission d'accès à l'information du Québec within reasonable timeframes. Our internal target is to notify within 72 hours of incident confirmation.
  • Document each incident in an internal register, including the nature, causes, corrective measures and lessons learned.
  • Cooperate fully with personal information protection authorities in case of investigation.

9. International Data Transfers

Some of our sub-processors process personal information outside Quebec or Canada (see the list in section 3). For transfers outside Quebec and Canada:

  • We assess the adequacy of the legislative protections offered in the destination jurisdiction
  • We put in place appropriate contractual protections with each sub-processor (Data Processing Agreements)
  • We limit transfers to what is necessary for the provision of the Service
  • For AI features (Anthropic), requests are only sent if you explicitly enable the relevant opt-in features
  • For payments (Stripe — Canada and United States), the cross-border transfer serves the performance of the subscription and the collection of common expenses through the Payment Service, which you expressly authorize. It includes co-owners' banking details (financial information). This flow is framed by Stripe's data processing agreement (DPA); account numbers are never stored in plain text by CondoAide. A privacy impact assessment lets us satisfy ourselves that the residual risk attached to this transfer is minimal and manageable.
  • For incident response (CFC Underwriting Limited and the providers on its approved panel, CFC Response), the transfer occurs only in the event of a confidentiality incident and is for investigation, defence and issuing notices. The entities involved are established in the United Kingdom and the United States (London and Austin, Texas). Nothing is disclosed to them in the normal course of the Service.
  • If you have questions about a specific transfer or wish to object to a particular processing activity, contact privacy@condoaide.ca.

10. Cookies, Telemetry and Session Recording

Cookie banner. For unauthenticated visitors on the public site and on sign-in pages, OpenReplay telemetry is only enabled if you accept it via the banner that appears on your first visit. Your choice is stored locally (localStorage) and can be changed at any time via the "Reset cookie preferences" link at the bottom of every page. Refusing telemetry does not affect your use of the service — strictly necessary cookies (session, security, language) remain active. OpenReplay session recording. When authenticated, OpenReplay records a reconstruction of your navigation (clicks, scrolls, page changes) to help our support team reproduce a problem when you report it. Enabled by default, can be disabled at any time via Profile → Session recording for support. Form fields and screens containing sensitive information (PAD, attestation, registry, financial statements, insurance proofs, compliance, syndicate members, payments) are masked automatically. GlitchTip error tracking. Remains active regardless of your choice because it is strictly necessary for service quality. Minimized configuration: pseudonymized user identifier, request bodies (form data, authentication headers, cookies) automatically dropped, IP address not transmitted. Retention: 30 days for all flows — events and session recordings on OpenReplay; application logs and error events on GlitchTip. Resolved GlitchTip issue groups are kept 90 days for regression detection. For more information, see our Cookie Policy.

11. Information Concerning Children

The Service is not intended for persons under 14 years of age. We do not knowingly collect personal information from children. If you believe a child has provided personal information to CondoAide, contact privacy@condoaide.ca so that we can proceed with deletion.

12. Changes

We may modify this policy from time to time. We will notify you of material changes by email or through the platform. The last update date is indicated at the top of this page. Continued use of the Service after a modification constitutes your acceptance of the updated version.

13. Contact Us

For any questions about this policy or to exercise your rights:

Person Responsible for the Protection of Personal Information: privacy@condoaide.ca

General support: support@condoaide.ca

Postal address: CondoAide, 4143 chemin Ste-Angélique, Saint-Lazare (Quebec) J7T 2N5, Canada

Appendix — Change History

Version history of this policy:

  • Version 1.0 - February 1, 2025 — Initial version.
  • Version 1.1 - May 7, 2026 — Added PAD/ACSS Debit payment method; public designation of the Person Responsible for the Protection of Personal Information; expansion of the sub-processor list; addition of the privacy incident notification section; addition of the international data transfers section; addition of PIPEDA and Office of the Privacy Commissioner of Canada references.
  • Version 1.2 - June 2, 2026 — Launch of automatic condo-fee collection by pre-authorized debit (PAD/ACSS): Stripe (Stripe Payments Canada, Ltd.) now also processes co-owner contribution debits to the syndicate's account. Sections 1 and 3 and the sub-processor list updated accordingly.
  • Version 1.3 - June 13, 2026 — Clarifications on Stripe's processing of condo fees: added distinct retention periods for the co-owner condo-fee mandate and transactions (section 5), and described the cross-border transfer of co-owners' banking details via Stripe, covered by a privacy impact assessment (section 9).
  • Version 1.4 - July 12, 2026 — Added the assembly meeting chat: message retention period (section 5). Messages are hosted in Québec (Supabase, Canadian region) — no new cross-border transfer.
  • Version 1.5 - July 13, 2026 — Added the assembly-meeting presence log: retention period for the log of participant connections and disconnections (section 5). The log is hosted in Quebec (Supabase, Canadian region) — no new cross-border transfer.
  • Version 1.6 - July 23, 2026 — Removed OpenAI from the sub-processor list: registre document embeddings are now produced by a self-hosted model (bge-m3) in Québec, at OVHcloud (Beauharnois). Anthropic remains our only artificial-intelligence provider, for opt-in features only. Section 3 updated.
  • Version 1.7 - July 30, 2026 — Added Amazon Web Services (Amazon SES) to the sub-processor list: transactional and authentication emails are now sent from Québec (ca-central-1 region, Montreal). Brevo is re-scoped to marketing emails, contact-list management and the fallback relay role for transactional emails (European Union). Sections 3 and 4 updated.
  • Version 1.8 - July 30, 2026 — Integration of our external legal counsel's review: the statute is named in full (Act respecting the protection of personal information in the private sector), with the Act to establish a legal framework for information technology added and Bill 16 given its official title; the scope of Stripe's PCI DSS certification is clarified (card data); IP address processing and how payment information is collected are disclosed; sharing in a commercial transaction is added (section 3); the automated-decision right (section 6) and the incident steps (section 8) are reworded; and section 9 now states that the transfers concerned are those outside Quebec.
  • Version 1.9 - 12 August 2026 — Declaration of three sub-processors that were already operating without appearing on the list: iDrive e2 (Montreal), which holds our off-site backups, OVHcloud (Beauharnois), which holds the secondary copy, and OVHcloud (Beauharnois) for the self-hosted video-conferencing server used by assembly meetings, none of whose streams are recorded. Because a backup contains every category of information entrusted to the Service, both destinations are now named. Correction of two inaccurate security statements: authentication tokens are signed with ECDSA on the P-256 curve (ES256) rather than HMAC-SHA256, and the mention of an automated weekly restore test is removed, that job being disabled. The commitment to an annual third-party penetration test is kept but loses its late-2026 deadline. No new processing, no new category and no transfer outside Quebec.
  • Version 1.10 - 12 August 2026 — Automatic collection of condo fees: added the identity of the person who enables it and the time they did (section 1), and their retention period (section 5). This is used to require that a second person authorise a debit above the syndicate's threshold, and to identify the party behind the mandate as Payments Canada Rule H1 requires. No new processor, no new purpose and no flow outside Québec.
  • Version 1.11 - 13 August 2026 — Proxy registration log: added its retention period (section 5). For every mandate signed electronically, this log records the time of signature and the IP address and browser used, as section 39 of the Act to establish a legal framework for information technology requires. It was previously destroyed together with the mandate it related to; it now survives until the syndicate's file is destroyed, which lengthens its retention. The reason is that proof a proxy existed matters precisely when that proxy disappears. No new category of information is collected and no new recipient gains access.
  • Version 1.12 - 16 August 2026 — Outbound email queue: added its retention period (section 5). The queue carries notices, convocations and reminders; it holds the recipient's address and the data used to compose the message, without keeping the rendered result. It had no period until now. It is set at 90 days after sending, and 30 days after a final failure for a message that never left. The period is operational rather than evidentiary: proof that a notice was sent is recorded in the file it belongs to, not in this queue.
  • Version 1.13 - 16 August 2026 — Email sending queue: correction to section 5. Version 1.12 stated that proof of sending did not depend on this queue. That was true for most notices, but not for convocations to an assembly or a board meeting, their updates, agenda additions and reminders: for those, the recipient detail currently exists nowhere else. The period for those rows is raised to 90 days after the assembly or meeting concerned; the rest of the queue stays at 90 days after sending.
  • Version 1.14 - 22 August 2026 — Insurance-proof imports: added the temporary processing of the aggregate PDF and its extracted text to sections 1 and 2, and their maximum three-hour retention to section 5. The aggregate file is never added to the syndicate's document registry; only the minimized per-unit proofs are added to it. Processing stays with Supabase in Quebec, with no new sub-processor or transfer outside Quebec.
  • Version 1.15 - 22 August 2026 — Email-address suppression state: a line added to section 5. When a transactional email permanently bounces or a complaint is received, the address is placed on a suppression list so the Service stops writing to it. This concerns delivery, not consent: it withdraws no newsletter consent and does not alter the marketing lists, which remain governed separately. The row holds the address, the reason, the provider, the timestamps of the first and most recent events and the technical message identifier; no email content is retained. No new processor and no new flow outside Quebec: Amazon (SES, Montréal) is already listed in section 3.
  • Version 1.16 - 24 August 2026 — Email-address suppression state: the line announced in version 1.15 is now actually present in section 5, with its retention period. Version 1.15 announced the line without adding it, and without stating a period; the correction is recorded rather than erased. The retention is a condition rather than a number of days: the entry stays for as long as the address is undeliverable, and is removed once delivery is restored and verified, or following a valid erasure request. No newly collected information, no new processor and no new flow outside Quebec.
  • Version 1.17 - 27 August 2026 — A board announcement can now carry a question that the co-owner answers in the app: this category was added to section 1, including the free-text comment and the file the co-owner supplies themselves, and the corresponding retention entry was added to section 5, with its specific period still under review. An answer is attributable by design and is not a vote. No new sub-processor and no new transfer outside Québec.
  • Version 1.18 - 28 August 2026 — Professional liability and cyber insurance taken out. The insurer and the providers on its approved response panel become possible recipients of personal information, but only in the event of a confidentiality incident. New recipient category in section 3, clarification in section 8, and a new flow outside Quebec in section 9 (United Kingdom and United States). No new processor in the normal course of the Service.
  • Version 1.19 - 1 September 2026 — A syndicate message may once again own its own files, instead of every attachment being filed in the registry. New period in section 5: a message attachment has no period of its own; it is kept with the message and destroyed with it. The file is not filed in the registry and is readable only by the message's recipients — a narrower circle than the registry's access levels can express. An image inserted in a message body follows the same rule and is never sent by email. No new processor, purpose, location, or automated decision.
  • Version 1.20 - 10 September 2026 — Added to section 1: the identity of the person who declares what the declaration of co-ownership provides for contributions paid before the budget is adopted, meaning who declared it, when, and the article of the declaration that is cited, along with the recording of every change in the syndicate's audit log with the person's name and email address. Added the corresponding retention period to section 5. No new sub-processor, no new flow outside Quebec and no automated decision.
  • Version 1.21 - 15 September 2026 — Service requests filed by a tenant: added to section 1, the tenant capacity recorded at filing time, the private portion concerned, the closing reason "redirected to the co-owner", and the viewing of the request, its attachments and the board's public replies by the co-owners of that private portion, for requests filed since their ownership began. Added to section 2, the notices sent to the co-owner who receives the private portion's notices and to the tenant. No new sub-processor, no new flow outside Quebec, no new retention period and no automated decision.
  • Version 1.22 - 15 September 2026 — Added to section 3 the document analysis service self-hosted at OVHcloud in Beauharnois (Quebec), which reads maintenance logs, reserve fund studies and, now, the bank account statements an authorized person imports as PDF. The categories concerned are specified: content of imported documents, including bank transaction dates, amounts and descriptions. No new retention period, no new flow outside Quebec and no automated decision.
  • Version 1.23 - 15 September 2026 — Added to section 1 the syndicate's mailbox: what you write to a CondoAide syndicate address is kept in the syndicate's file and read by the entire board. Added to section 5 the retention periods for received mail (36 months from reception, with text copied elsewhere in the file removed at the same moment, unless the email is filed to a record or under a legal hold), for the board's reply sent from that mailbox (36 months from sending), for a quarantined email (30 days) and for the raw copy at the receiving provider (30 days). Clarified in section 3 and on the Security page (sections 1 and 6) that Amazon SES also receives and temporarily stores messages in the ca-central-1 (Montreal) region. No new flow outside Quebec and no automated decision.
  • Version 1.24 - 15 September 2026 — Vendor invoice attached to a work order: added to section 1 the invoice content read at an authorized person's request (date, number, vendor name and contact details, GST and QST registration numbers, amounts) and the keeping of those numbers on the vendor record. Added to section 2 the corresponding purpose: suggesting the data to record and filing a copy of the invoice in the syndicate's registry under the Invoices category, reserved to the board of directors. Clarified in section 3 that the self-hosted document analysis service at OVHcloud in Beauharnois also reads invoices, including through optical character recognition when the file is an image. No new sub-processor, no new flow outside Quebec and no exclusively automated decision: every suggested value is kept or discarded by a person.
  • Version 1.25 - 16 September 2026 — Added to section 1 the answer a board member records on a unit's behalf: when a co-owner answers a question attached to an announcement by phone or by email, the board may record that answer in the app. It then carries the name of the board member who recorded it, it is shown as board-recorded, and it never replaces the answer the co-owner gives themselves. No new sub-processor, no flow out of Québec and no new retention period.
  • Version 1.26 - 16 September 2026 — Added to section 1 the request for a statement of common expenses due for a unit (art. 1069 of the Civil Code of Québec): the name, capacity and email of the person making it, the buyer's name, the notice given to the owner, the sending of the statement as an email link and the log of its viewings (date and time, truncated IP address, browser type). Added to section 2 the disclosure of that statement to the person proposing to acquire the unit, after notice to the owner, and to section 5 their retention periods, including three years for the viewing log. No new sub-processor, no flow out of Québec.
  • Version 1.27 - 17 September 2026 — Added to section 1 emails sent to postmaster@ and abuse@ at a syndicate address: they are not added to the syndicate's file but forwarded to CondoAide's operations mailbox, which only the person responsible for the protection of personal information reads. Added to section 2 the corresponding purpose, to section 3 and the Security page their forwarding through Amazon SES within the same region, and to section 5 their 36-month retention period. No new service provider and nothing leaves Quebec.
  • Version 1.28 - 17 September 2026 — Section 3: when a syndicate entrusts its management to a property management company and adds it to its account as manager, that manager now has access, to carry out its mandate, to the syndicate's financial information, including co-owners' payment information (debit mandates, payment history, arrears) and vendors' payment details. Adopting a budget, deciding a special assessment and approving a payment above the threshold remain reserved to the board of directors. No new sub-processor, no flow out of Québec and no new retention period.
  • Version 1.29 - 17 September 2026 — Clarification, in section 1: when the syndicate's mailbox is in service, the syndicate also sends the notices and announcements it addresses to you from that address, so a reply to one of those messages arrives in that same mailbox, available to the same people and kept for the same period. The email address of an administrator's personal account is no longer sent to co-owners with those notices.
  • Version 1.30 - 21 September 2026 — Sections 1 and 3: when a co-owner says a contractor will do the work in a work authorization request, we collect the company's name, its Régie du bâtiment du Québec licence number and, if provided, a contact person's name and email. We check that number with a new sub-processor, VériBât, which consults the Régie's public register from Montreal: only the licence number is sent to it. No flow out of Québec and no new retention period: this information follows the request.
  • Version 1.31 - 21 September 2026 — Sections 1 and 5: once work is authorized, the co-owner may send the syndicate's work rules for contractors to their contractor, who signs them through a link without creating an account. We keep the link's openings (truncated network and browser family, three years) and the proof of the signature (typed name, the link's address, signed version, date and time, IP address and browser), as long as the request. No new sub-processor and no flow out of Québec.
  • Version 1.32 - 22 September 2026 — Sections 1 and 5: files attached to the support form are now kept in our private storage in Québec (Supabase, Canadian region) instead of being sent by email, and only authorized CondoAide staff can download them. New retention periods: three years after the message is sent, and at most four hours for a file whose message is never sent. No new sub-processor and no transfer outside Québec.
  • Version 1.33 - 22 September 2026 — Sections 1 and 5: authorized work now opens your private portion's entry in the syndicate's register of improvements, where you can add before and after photos, the invoice and an approximate value, then report the work as finished for the board to confirm. Those files and that value are read only by the owners of your private portion, the board and, where applicable, the property manager; the approximate value is no longer visible to other co-owners, and an entry whose work is still planned is reserved to them until the work is reported finished. New periods: the entry and its files are kept permanently, including information copied from the request, which remains if the request is deleted; seven days for the identifier carried by an upload request. Email and in-app reminders before the planned start and after the planned end. No new processor and no transfer outside Québec.
  • Version 1.34 - 22 September 2026 — Section 3: to find a contractor's licence, you can now type the start of its number or the company name, in a work authorization request as well as in the board's list of vendors. That text is sent to VériBât, which returns at most ten entries from the public register of the Régie du bâtiment du Québec; before, only a full number was sent. A company name may be the name of a person in business. CondoAide does not record these searches in your file: only the licence chosen is, as before. No new sub-processor and no transfer outside Québec.
  • Version 1.35 - 22 September 2026 — Sections 1 and 3: for vendors with a Régie du bâtiment du Québec licence number, we now keep the public register's answer with the vendor's record (holder name, presence in the register, restriction, date it left the register and date of the check), to warn the syndicate of a licence that is missing from the register or restricted. The number is checked with VériBât when it is entered or changed, then about every two days. Only the licence number is sent. The answer is removed with the vendor's record and replaced as soon as its number changes. No new sub-processor and no transfer outside Québec.
  • Version 1.36 - 23 September 2026 — Section 1: a report sent to CondoAide support from the app also includes the pages where it was opened and from which it was sent, the person's role in the syndicate, the app version and the browser used. This information is used to reproduce the reported problem and follows the retention of support communications. No new sub-processor, no new transfer outside Québec, no new retention period and no automated decision.
  • Version 1.37 - 24 September 2026 — Section 1: files attached to a report to CondoAide support, including screenshots pasted into a reply, can also be viewed by the board members of the syndicate that sent the report, in that report's follow-up, like the text that goes with them. Authorized CondoAide staff still download them with two-factor authentication. No new sub-processor, no new transfer outside Québec, no new retention period and no automated decision.