1. Scope and Accountability
This Policy applies to personal information controlled by Aimlake Inc. through aimlake.com, Client Space, business communications and service delivery. “Personal information” means information about an identifiable individual, subject to exclusions under applicable law. Aimlake’s Canadian privacy practices are guided by the Personal Information Protection and Electronic Documents Act (PIPEDA) and other applicable privacy laws.
Aimlake is responsible for personal information under its control and has designated a Privacy Officer to receive questions, access requests and complaints. When Aimlake processes personal information solely for a client, the client may remain the organization that determines the purposes of processing.
2. Information We Collect
Depending on how you interact with Aimlake, we may collect:
- Identity and contact information: name, business name, role, email address, telephone number and mailing address.
- Account information: Client Space login details, password hash, account preferences and authentication or session records.
- Commercial information: requested services, proposals, contracts, project requirements, invoices, payment status and transaction records. Payment-card details may be handled directly by a payment processor rather than stored by Aimlake.
- Project and support information: communications, meeting notes, approvals, files, reports, content, credentials or system access supplied for service delivery.
- Website and device information: IP address, browser and device type, operating system, referring page, timestamps, requested pages and security logs.
- Marketing preferences: subscriptions, communication choices and engagement with permitted marketing messages.
- Recruitment and professional information: résumé, portfolio, work history and other information submitted for an employment or contractor opportunity.
Please do not provide sensitive or regulated information unless Aimlake has requested it and the parties have agreed on appropriate safeguards.
3. Sources of Information
We collect information directly from you, from an organization you represent, through website and Client Space interactions, from approved service providers and integrations, and from public or professional sources when reasonably relevant to a business relationship. Clients may also provide information about their personnel, customers or users for an authorized project.
4. How We Use Personal Information
Aimlake may use personal information to:
- respond to inquiries, assess needs, prepare proposals and administer contracts;
- create and secure accounts, authenticate users and provide Client Space reports;
- plan, perform, support and improve contracted services;
- process payments, maintain business records and collect amounts owing;
- communicate about projects, service changes, security matters and support;
- operate, troubleshoot, protect and improve the website and technology systems;
- detect fraud, misuse, unauthorized access and other security risks;
- send marketing communications where permitted and manage opt-out requests;
- establish, exercise or defend legal rights and comply with legal obligations; and
- create aggregated or de-identified insights that do not reasonably identify an individual.
Aimlake will not use personal information for a materially new purpose without appropriate notice and, where required, consent.
5. Consent and Lawful Processing
Aimlake obtains consent appropriate to the sensitivity of the information and the circumstances. Consent may be express or implied where permitted by law. You may withdraw consent for future processing, subject to reasonable notice and legal or contractual restrictions.
Some information is necessary to provide requested services, maintain an account or meet legal requirements. Withdrawing consent may therefore limit Aimlake’s ability to continue a service. Aimlake may also collect, use or disclose information without consent where applicable law authorizes or requires it.
7. Service Providers and International Transfers
Some service providers may process or store information outside Ontario or Canada, including in the United States or another jurisdiction. Information in another country may be subject to that country’s laws and lawful access by its courts, governments or law-enforcement authorities.
Aimlake remains accountable for personal information transferred to a service provider for processing and uses contractual, organizational and technical measures appropriate to the circumstances. Contact the Privacy Officer for more information about relevant providers or processing locations.
9. Artificial Intelligence and Automated Tools
Aimlake may use AI-assisted tools for research, drafting, analysis, automation, development or service delivery. We apply human review appropriate to the task and take reasonable steps to limit personal information submitted to such tools.
Aimlake will not intentionally use sensitive client information to train a public AI model without authorization. Client-specific AI processing, automated decision-making, retention, model training restrictions and data locations may be addressed in the applicable agreement. Do not submit confidential or sensitive information to an Aimlake AI feature unless the intended processing is clearly disclosed.
10. Personal Information Processed for Clients
When Aimlake processes personal information on behalf of a client, the client is responsible for providing required notices, obtaining valid consent or other authority, and giving lawful instructions. Aimlake processes that information for the contracted purpose and according to the definitive agreement.
Requests concerning information controlled by an Aimlake client should normally be directed to that client. Aimlake will provide reasonable assistance where contractually required and legally permitted.
11. Retention and Disposal
Aimlake retains personal information only as long as reasonably necessary for the identified purposes, contractual commitments, dispute resolution, security, backup cycles and legal, tax or accounting requirements. Retention periods vary by record type and sensitivity.
When information is no longer required, Aimlake securely deletes, destroys or de-identifies it, subject to technical limitations and lawful retention obligations. Backup copies may remain until they are overwritten through ordinary retention cycles.
12. Security and Privacy Breaches
Aimlake uses administrative, technical and physical safeguards appropriate to the sensitivity, volume, format and storage of personal information. Measures may include access controls, password hashing, authentication, restricted permissions, secure transmission, monitoring, backups and staff or contractor confidentiality obligations.
No system is completely secure. If a breach of security safeguards occurs, Aimlake will investigate, contain and document it and will notify affected individuals and regulators where applicable law requires, including where a breach creates a real risk of significant harm.
13. Access, Correction and Other Privacy Rights
Subject to applicable law, you may request access to personal information Aimlake holds about you, ask how it has been used or disclosed, and request correction of inaccurate or incomplete information. You may also withdraw consent, challenge compliance or ask about retention and processing practices.
Submit a written request to the Privacy Officer. Aimlake may take reasonable steps to verify identity and authority before responding. Access may be limited where disclosure would reveal another person’s information, confidential commercial information, solicitor-client privileged material, or where another legal exception applies. Aimlake will explain any lawful refusal.
14. Marketing Communications
Aimlake sends commercial electronic messages only where permitted by applicable law. You can unsubscribe using the link in a marketing email or by contacting Aimlake. Transactional, security, account and active-service communications may continue when necessary even after a marketing opt-out.
15. Children’s Privacy
Aimlake’s website and business services are not directed to children under 13, and Aimlake does not knowingly collect their personal information through the website. If you believe a child has provided personal information without appropriate authorization, contact the Privacy Officer so Aimlake can review and delete it where required.
16. Third-Party Websites and Platforms
The website may link to social networks, platforms or websites that Aimlake does not control. Their privacy practices and terms apply when you visit or use them. A link does not mean Aimlake is responsible for the third party’s handling of information.
17. Changes to This Policy
Aimlake may update this Policy to reflect changes in law, technology, services or information practices. The revised version will be posted on this page with a new “Last updated” date. Aimlake will provide additional notice or obtain consent where a material change requires it.
18. Contact the Privacy Officer
Privacy Officer - Aimlake Inc.42 Densgrove Rd
Scarborough, Ontario M1G 2A3, Canada
Email: mail@aimlake.com
Phone: +1 (437) 696-8191
Please describe your request or concern and include enough information for Aimlake to identify the relevant records. Aimlake will investigate privacy complaints and respond within the period required by applicable law. If a concern is not resolved, you may contact the appropriate privacy regulator, including the Office of the Privacy Commissioner of Canada.