Privacy Policy
Privacy Policy
Your privacy is important
This Privacy Policy describes the Personal Information NotaryZen Technologies Inc. collects through its websites, applications, and document-service workflows, why we use it, who processes it, how long we retain it, and the safeguards and choices that apply.
1. Introduction
NotaryZen Technologies Inc. dba NotaryZen and our affiliates and subsidiaries (collectively, "us" or, "we", or "our") recognize the importance of privacy and the sensitivity of personal information. We take our responsibility to safeguard the personal information of all parties engaging with our services (collectively, "you", or "your", or "them"), very seriously and are dedicated to maintaining your trust through our commitment to privacy and security.
This Privacy Policy (the "Policy") outlines how we collect, use, disclose, and protect your personal information in accordance with the Personal Information Protection and Electronic Documents Act ("PIPEDA") and applicable provincial privacy legislation, including Quebec's Act respecting the protection of personal information in the private sector (commonly referred to as "Law 25"), when using our platform www.NotaryZen.ca and www.NotaryZen.com (collectively, the "Platform").
Please read this Policy carefully. We identify the purposes for collecting, using, or disclosing Personal Information at or before collection and seek consent where required. Because government identification and legal documents can be highly sensitive, a general visit to the Platform is not treated as consent to unrelated uses of those materials.
2. Personal Information We Collect About You
In order to provide our Platform's services, including in-person notarial services, eligible virtual commissioning and witnessing, identity verification, electronic signing, and document tools (the "Services"), we may collect the following types of Personal Information:
-
Contact Information: Details such as your mailing address, phone number, email address, and billing information.
-
Identification Information: Images and details from government-issued identification, your likeness, and identity-verification results when necessary to verify identity, prevent fraud, or meet legal and professional obligations. See our ID policy for the types of identification we accept.
-
Appointment Information: Details regarding the scheduling of Services, including the date, time, and particular requirements or notes pertaining to the appointments you arrange via our Platform.
-
Document Information: Unsigned, generated, and signed legal documents and related details such as document type, parties, signers, recipients, and completion status. These documents may contain sensitive information about you or other people.
-
Service Usage Information: Information related to virtual commissioning, witnessing, identity verification, and electronic signing, including IP addresses, timestamps, audit trails, and session activity. Where a service involves an audio-video record, we disclose that at or before collection.
-
AI-Interaction Data: If you choose an AI-assisted drafting or summarization feature, we process the prompts, document content, preferences, and output needed to provide that feature. We do not use government-issued identification or uploaded legal documents to train generalized AI models without separate, express consent.
-
Payment Information: Details such as your credit card brand and last four digits. Full card details are never stored on our servers. All payment information is processed securely through Stripe, a PCI DSS Level 1 certified payment processor. We do not store full card numbers, CVVs, or PINs.
-
Technical and Interaction Information: We may collect data about your interaction with our Platform, including the type of service chosen, your browser, pages visited, approximate location derived from IP address, time spent, device identifiers, operating system, performance traces, and error diagnostics. If an error-session replay is captured, text and form inputs are masked and media is blocked by configuration.
-
Feedback and Communication Information: We may request or receive feedback, questions, comments, or suggestions to enhance our Services and communication with you. Your participation in providing this information is entirely voluntary.
(collectively, "Personal Information")
3. How We Collect Your Personal Information
We use different channels and methods to collect Personal Information, including through:
-
Directly from you when you voluntarily engage with our Platform;
-
When you execute payments, capturing banking and credit card information;
-
In collaboration with our payment processing partners;
-
When you submit an inquiry or request via our contact form;
-
When you communicate with us via email, phone, or otherwise;
-
When you participate in a survey or feedback request we send;
-
When you apply for job positions within our organization;
-
When you provide reviews, testimonials, or feedback about our Services; and,
-
Through cookies and similar technologies (see Section 10);
We do not scrape Personal Information for marketing profiles. We may receive information from the independent professional handling your service and from service providers involved in authentication, payments, identity verification, electronic signing, hosting, security, and analytics. We aim to collect only the Personal Information reasonably necessary for identified purposes.
4. How We Use Your Personal Information
We use the Personal Information we collect about you for various purposes in the provision of our Services, including:
-
To present our Platform and its contents to you;
-
To facilitate the scheduling, processing, and completion of Services provided through our platform;
-
To verify identity, prevent fraud, secure accounts and transactions, and create service audit records;
-
To process uploaded documents and AI-interaction data only to deliver the document feature requested by you, unless we obtain separate consent for another use;
-
For processing payments, including banking and credit card information, through our secure third-party processors;
-
To conduct quality control, market analysis, and understand user interaction with our Platform, which helps us improve our Platform's performance and ensure a secure and optimized user experience;
-
To send marketing communications where you have requested them or where otherwise permitted by law, with an unsubscribe option;
-
To fulfill the purposes for which you provided the information or that were described when it was collected, or any other purpose for which you provide it; and,
-
In accordance with applicable law.
Please note that we will only use your Personal Information as described above unless we have received your explicit consent to use it for other purposes or are required or permitted to do so by law.
5. Disclosure of Personal Information
We may disclose Personal Information that we collect or you provide as described in this Policy:
-
To the independent professional assigned to or selected for your requested service, and to other participants you direct us to include;
-
To our subsidiaries and affiliates;
-
In accordance with applicable law, to a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Information held by us about our customers and users is among the assets transferred;
-
To contractors, service providers, and other third parties we use to support our business, such as Stripe for payment processing, Syngrafii for electronic signature and identity-verification services, Resend for email delivery, Google Cloud / Firebase for data storage and authentication, Vercel for hosting and analytics, Google Analytics for usage measurement, and Sentry for error monitoring and masked error-session replay, who are required to protect the information and process it for the contracted purpose;
-
To fulfill the purpose for which you provide it;
-
For any other purpose disclosed by us when you provide the information;
-
To third-party payment processors for subscription management; and,
-
With your consent.
We may also disclose your Personal Information:
-
To comply with any court order, law, or legal process, including to respond to any government or regulatory request, in accordance with applicable law;
-
To enforce or apply our terms of use found at https://www.NotaryZen.ca/terms-and-conditions/ and other agreements, including for billing and collection purposes; and,
If we believe disclosure is necessary or appropriate to protect our rights, property, and safety as well as the rights, property, and safety of our customers or others. This includes exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction.
6. Transferring Your Personal Information
We may transfer Personal Information that we collect or that you provide as described in this Policy to our subsidiaries or affiliates, contractors, service providers, and other third parties we use to support our business and who are contractually obligated to keep personal information confidential, use it only for the purposes for which we disclose it to them, and to process the Personal Information with the same standards set out in this policy.
We may process, store, and transfer your Personal Information in and to a foreign country, with different privacy laws that may or may not be as comprehensive as Canadian law. For example, certain functionalities, such as our e-signature features, may be facilitated by resources and technology located in the United States. In these circumstances, the governments, courts, law enforcement, or regulatory agencies of that country may be able to obtain access to your Personal Information through the laws of the foreign country. Whenever we engage a service provider, we require that its privacy and security standards adhere to this policy and applicable Canadian privacy legislation.
You are welcome to contact us to obtain further information about our policies regarding service providers outside of Canada. See Section 16 for contact details. NotaryZen remains responsible for Personal Information transferred to a service provider for processing on our behalf. Where consent is required for a transfer or a new purpose, we will seek it in a form appropriate to the sensitivity of the information.
7. Security of Personal Information
The security of your Personal Information is very important to us. We use physical, technical, and administrative safeguards designed for the sensitivity of legal documents and identity records. These measures include encryption in transit, access controls, authentication safeguards, restricted administrative access, security logging, and service-provider controls. Payment-card data is handled by our payment processor rather than stored in full by NotaryZen. No safeguard can eliminate every risk.
The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Platform, you are responsible for keeping this password confidential. We ask you not to share your password with anyone. We urge you to be careful about giving out information in public areas of the Platform like message boards, which any Platform visitor can view.
Unfortunately, the transmission of information via the Internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to our Platform. Any transmission of Personal Information is at your own risk. We are not responsible for the circumvention of any privacy settings or security measures contained on the Platform.
8. Retention of Personal Information
Except as otherwise permitted or required by applicable law or regulation, we retain Personal Information only for as long as reasonably necessary for the identified purpose, applicable professional record-keeping requirements, dispute management, and legal, accounting, or reporting obligations. There is no single retention period that applies to every document or service. Our current criteria are:
| Type of Information | Retention Criteria |
|---|---|
| Service request records | For as long as reasonably needed for service history, contract administration, disputes, applicable professional obligations, and legal holds |
| Payment records | For the period required for tax, accounting, chargeback, fraud-prevention, and legal purposes |
| Government-issued identification images | Normally deleted once the image is 90 days old, or earlier after service completion |
| Documents or generated PDFs left unattached by an incomplete or failed submission | Eligible for deletion once more than 72 hours old and removed through scheduled cleanup |
| Uploaded, generated, or signed legal documents | While needed to deliver the requested service and provide authorized access, followed by any applicable dispute, professional-record, or legal-hold period |
| Electronic signing and commissioning records | For the applicable audit, evidentiary, professional-record, dispute, and legal-hold period |
| User account information | While the account is active and during the deletion process, subject to information that must be retained for another listed purpose |
| Authentication session cookie | Up to 14 days |
At the end of the applicable period, we delete, securely destroy, or anonymize the Personal Information using methods appropriate to its sensitivity. A legal hold, active dispute, investigation, or applicable professional obligation may extend retention for the affected records. You may contact our Privacy Officer for the criteria that apply to a particular Service or record.
Under some circumstances we may anonymize your Personal Information so that it can no longer be associated with or identify you. We reserve the right to use such anonymous and de-identified data for any legitimate business purpose without further notice to you or your consent.
9. Links to Other Platforms
The Platform may include links to third-party websites, plug-ins, services, social networks, or applications. Clicking on those links or enabling those connections may allow the third-party to collect or share data about you. If you follow a link to a third-party website or engage a third-party plugin, please note that these third-parties have their own privacy policies and we do not accept any responsibility or liability for these policies. We do not control these third-party websites, and as such, we encourage you to read the privacy policy of every website you visit.
10. Cookies, Analytics, and Browser Storage
The Platform currently uses cookies and browser storage. Depending on the page and features you use, these technologies include:
- Essential authentication and security: A secure session cookie keeps a signed-in user authenticated for up to 14 days. Security providers such as reCAPTCHA may also use device and interaction signals to detect abuse.
- Preferences and workflow continuity: Local storage or session storage may remember theme preferences, referral information, and temporary service-flow choices on your device.
- Analytics and diagnostics: Google Analytics and Vercel Analytics help us understand page visits, navigation, device/browser information, and feature interactions. Sentry provides error monitoring, limited performance tracing, and masked replay when an error is sampled. We do not intentionally send uploaded document contents, government-ID images, URL query strings, or form-field contents as analytics event data.
- Third-party functionality: Stripe, Syngrafii, Google/Firebase, and other providers may use cookies or similar technologies when their payment, signing, identity, authentication, or embedded features are used.
You can block or delete cookies and browser storage using your browser controls. Blocking essential technologies may prevent sign-in, payment, identity-verification, signing, preferences, or other service flows from working. Analytics choices available through your browser or the applicable provider may not disable essential Platform storage.
We do not use Flash cookies, and we do not describe the Platform as using advertising-network cookies unless that practice is introduced and this Policy is updated first.
11. Third-Party Technologies
Third-party providers process information under their own privacy notices as well as their agreements with us. Their processing may occur outside Canada and may be subject to lawful access in those jurisdictions. See Sections 5 and 6 for the providers and transfer practices relevant to the Platform. Please contact our Privacy Officer if you need more information about a provider used for a particular Service.
12. Minors
Accounts and self-directed Services are not available to people under the age of majority in their jurisdiction. However, an adult may provide Personal Information about a minor when it is necessary for a legitimate document or service, such as a travel-consent or vital-statistics document. The adult must have authority to provide that information, and we limit its use to the requested Service and the purposes described in this Policy.
Minors must not create an account or submit information directly through the Platform. If we learn that a minor submitted Personal Information directly without valid authorization, we will take appropriate steps to delete it, subject to any legal retention requirement.
If you believe we might have any information from or about a Minor, please contact our privacy officer in accordance with Section 16 of this Policy.
13. Access and Correction
It is important that the Personal Information we hold about you is accurate and current. Please keep us informed if your Personal Information changes.
If you want to review, verify, correct, or withdraw consent to the use of your Personal Information please contact our Privacy Officer, whose contact details are outlined in Section 16 of this Policy.
We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect.
We may request specific information from you to help us confirm your identity and your right to access the Personal Information that we hold about you or to make your requested changes. Applicable law may allow or require us to refuse to provide you with access to some or all of the Personal Information that we hold about you, or we may have destroyed, erased, or made your Personal Information anonymous in accordance with our record retention obligations and practices. If we cannot provide you with access to your Personal Information, we will inform you of the reasons why, subject to any legal or regulatory restrictions.
14. Withdrawing Your Consent
Where you have provided your consent to the collection, use, and disclosure of your Personal Information, you have the legal right to withdraw your consent under certain circumstances. To withdraw your consent, please contact our Privacy Officer, whose contact details are outlined in Section 16 of this Policy. Please note that if you withdraw your consent we may not be able to provide you with a particular product or service. We will explain the impact to you at the time to help you with your decision.
15. Changes to Our Policy
This Policy may change from time to time. We will post changes on this page, update the "Last Updated" date, and provide additional notice where appropriate.
If a material change introduces a new collection, use, or disclosure for which consent is required, we will explain the change and obtain that consent before applying the new practice to your Personal Information. Continued use alone is not treated as consent where express consent is required.
16. Privacy Officer
We welcome your questions, comments, and requests regarding this Policy and our privacy practices. Please contact our Privacy Officer at:
Privacy Officer: David Barder
NotaryZen Technologies Inc.
Email: privacy@NotaryZen.ca
We are committed to addressing any concerns you may have and will respond to your inquiry within a reasonable time.
17. Complaints
If you are not satisfied with our response to your privacy-related inquiry, you may contact the regulator with jurisdiction. For private-sector activity governed by PIPEDA, this is generally the Office of the Privacy Commissioner of Canada. The Information and Privacy Commissioner of Ontario has jurisdiction only where an Ontario statute within its mandate applies, such as public-sector or health-information legislation.
Office of the Privacy Commissioner of Canada
30 Victoria Street
Gatineau, Quebec K1A 1H3
Toll-free: 1-800-282-1376
Platform: www.priv.gc.ca
Information and Privacy Commissioner of Ontario
2 Bloor Street East, Suite 1400
Toronto, Ontario M4W 1A8
Toll-free: 1-800-387-0073
Platform: www.ipc.on.ca
18. Breach Notification
In the event of a breach of security safeguards involving your Personal Information that poses a real risk of significant harm, we will:
- Report the breach to the Office of the Privacy Commissioner of Canada (and, where applicable, to Quebec's Commission d'accès à l'information) as soon as feasible after determining that the breach has occurred;
- Notify you directly as soon as feasible, describing the nature of the breach, the Personal Information involved, the steps we have taken to reduce the risk of harm, and what you can do to protect yourself; and
- Maintain a record of all breaches of security safeguards, whether or not they meet the reporting threshold, for a minimum of 24 months as required by PIPEDA.
If you believe your Personal Information held by us may have been compromised, please contact our Privacy Officer immediately (see Section 16).
19. Quebec Residents — Additional Rights Under Law 25
If you are a resident of Quebec, you have the following additional rights under Quebec's Act respecting the protection of personal information in the private sector (Law 25):
- Right to Data Portability: You may request that we provide your Personal Information in a structured, commonly used technological format, or that we transfer it directly to another organization authorized to receive it, subject to applicable conditions.
- Right to De-indexation: You may request that we cease disseminating your Personal Information or that any hyperlink attached to your name giving access to your information be de-indexed, where the dissemination contravenes the law or a court order.
- Privacy Impact Assessments: We conduct privacy impact assessments when acquiring, developing, or overhauling information systems or electronic services that involve the collection, use, or disclosure of Personal Information.
- Automated Decision-Making: If we use automated decision-making processes that produce decisions affecting you, you have the right to be informed that such a process was used and to submit observations to a member of our staff who is in a position to review the decision.
To exercise any of these rights, please contact our Privacy Officer (see Section 16).
20. Data Access Requests
You have the right to request access to, or a copy of, all Personal Information we hold about you. You may also request the deletion of your Personal Information, subject to our legal retention obligations (see Section 8). We will respond to your request within 30 days.
Signed-in users can submit and track requests directly: Submit a data access or deletion request →. Otherwise, please contact our Privacy Officer (see Section 16).
By using our Services, you acknowledge that you have had an opportunity to review this Policy. Where consent is required, we seek it in a form appropriate to the sensitivity of the information and the purpose.
We appreciate your trust in us and will continue to work diligently to protect your Personal Information and provide you with the best possible service. Last Updated: July 22, 2026
