ezofis
ezofis ezofis

EZOFIS PRIVACY POLICY

1. Organization and Privacy Contact

The organization responsible for personal information collected through the Site is:

EZOFIS Inc. 18 King Street East, Suite 1400 Toronto, Ontario, Canada M5C 1C4 Website: www.ezofis.com Email: contact@ezofis.com Phone: +1 905 231 0955

Please use the subject line “Privacy Request” when contacting us about privacy rights, consent withdrawal, complaints, or personal information. EZOFIS has designated a Privacy Officer to coordinate website privacy matters. Where a Data Protection Officer, representative, or other statutory contact is required for a specific activity or jurisdiction, the applicable details will be provided in the relevant notice, contract, or data processing agreement

2. Purpose and Scope of This Policy

This Privacy Policy is intended to inform users about:

1. The categories of personal information we collect;

2. The sources from which personal information is collected;

3. The purposes and legal bases for processing;

4. The persons and service providers that may receive personal information;

5. International transfers, retention, and security safeguards;

6. Artificial intelligence, automated processing, and profiling;

7. The privacy rights available to individuals; and

8. Our cookies, tracking technologies, children’s privacy, complaints, and policy-update practices

3. Privacy Laws and Principles

Depending on the individual, processing activity, and jurisdiction, EZOFIS may be subject to or align its practices with applicable privacy and data protection laws, including:

  • Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and substantially similar provincial private-sector privacy laws, where applicable;
  • The European Union General Data Protection Regulation (GDPR);
  • The United Kingdom GDPR and the Data Protection Act 2018;
  • The California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the CCPA), to the extent applicable;
  • The United States Children’s Online Privacy Protection Act and COPPA Rule, where applicable; and
  • Other applicable privacy, electronic communications, anti-spam, cybersecurity, and breach-notification laws.

We seek to apply the principles of accountability, identifying purposes, consent, data minimization, limited use and retention, accuracy, safeguards, transparency, individual access, and complaint handling

4. Personal Information We Collect

We collect only information that is reasonably necessary for the purposes described in this Policy. The categories collected depend on how you interact with us

4.1 Information You Provide Directly

  • Contact and professional details: name, business email, telephone number, employer, job title, department, country, business address, and professional interests.
  • Inquiry and commercial information: demo or trial requests, project requirements, use cases, budget range, preferred contact method, meeting information, proposal requests, and sales communications.
  • Account information: username, business contact details, authentication and authorization information, account preferences, and administrator information.
  • Support and communication information: messages, tickets, feedback, call or meeting notes, uploaded files, screenshots, diagnostic information, and correspondence.
  • Event and marketing information: event registrations, webinar participation, newsletter preferences, campaign responses, and consent records.
  • Recruitment information: resume, employment history, education, professional qualifications, references, eligibility to work, and other information provided in an application.
  • Billing and transaction information: billing contact, company address, purchase order details, invoice information, tax information, subscription details, and payment status. Full payment card data is generally handled by authorized payment providers.
  • Information submitted through AI chat-based forms, portals, surveys, assessments, feedback forms, and other interactive experiences.

4.2 Information Collected Automatically

  •  Internet Protocol address and approximate location derived from that address;
  • Browser, operating system, device type, language, screen resolution, and hardware or software details;
  • Cookie identifiers, session information, advertising or analytics identifiers, and consent preferences;
  • Pages, content, links, buttons, or features viewed or used;
  • Referral source, search terms, timestamps, session duration, navigation path, and interaction events;
  • Security, authentication, diagnostic, error, performance, and access logs; and
  • Information about how communications are delivered or engaged with, such as email delivery, opens, or link interaction, where permitted.

4.2 Information Collected Automatically

  •  Internet Protocol address and approximate location derived from that address;
  • Browser, operating system, device type, language, screen resolution, and hardware or software details;
  • Cookie identifiers, session information, advertising or analytics identifiers, and consent preferences;
  • Pages, content, links, buttons, or features viewed or used;
  • Referral source, search terms, timestamps, session duration, navigation path, and interaction events;
  • Security, authentication, diagnostic, error, performance, and access logs; and
  • Information about how communications are delivered or engaged with, such as email delivery, opens, or link interaction, where permitted.

4.4 Sensitive and Special-Category Information

The public Site is not designed to request sensitive personal information unless clearly necessary for a specific service or authorized workflow. Configured customer workflows may process sensitive information, including identity, biometric,

financial, health-related, or other regulated data. Such processing is performed only where permitted by applicable law and the governing customer agreement, with appropriate access, security, and governance controls

5. Sources of Personal Information
  • Directly from you when you complete a form, create an account, communicate with us, upload information, or participate in a demo, event, trial, or service.
  • From your employer, colleague, authorized administrator, customer, supplier, partner, or other organization that provides access or submits information on your behalf.
  • From connected applications, enterprise systems, APIs, identity providers, document repositories, and integrations that you or a customer authorize.
  • From service providers supporting analytics, security, communications, CRM, recruitment, events, billing, and technical operations.
  • From publicly available business sources, professional directories, company websites, and professional networking platforms where permitted by law.
  • Automatically through cookies, logs, and similar technologies.
6. How We Use Personal Information

Purpose 

Examples 

Typical Legal Basis 

Provide and operate the Site and services 

Deliver requested content, maintain functionality, authenticate users, administer accounts, provide demos, trials, support, and contracted services. 

Contract; steps before contract; legitimate interests. 

Respond to requests and manage relationships 

Contact users, schedule meetings, prepare proposals, manage opportunities, provide onboarding, and maintain customer, supplier, and partner relationships. 

Contract; legitimate interests; consent where required. 

Improve products and experience 

Analyze usage, troubleshoot, test features, improve workflows, user experience, reliability, accessibility, and performance. 

Legitimate interests; consent for non-essential analytics where required. 

Security and fraud prevention 

Monitor threats, protect accounts, detect misuse, maintain logs, investigate incidents, enforce terms, and protect rights and systems. 

Legitimate interests; legal obligations. 

Marketing and communications 

Send newsletters, product information, event invitations, educational content, and relevant business communications. 

Consent; legitimate interests where permitted. 

Billing and administration 

Process orders, invoices, payments, taxes, renewals, subscription records, and financial reporting. 

Contract; legal obligations. 

AI and automation 

Extract, classify, summarize, route, validate, search, recommend, or automate information and workflow actions in accordance with the relevant service and instructions. 

Contract; legitimate interests; consent or other lawful basis where required. 

Recruitment 

Evaluate candidates, communicate about opportunities, conduct interviews, and maintain recruitment records. 

Steps before contract; legitimate interests; consent where required. 

Legal and compliance 

Meet regulatory, accounting, audit, litigation, law-enforcement, sanctions, and recordkeeping obligations. 

Legal obligations; legitimate interests; public interest where applicable. 

7. GDPR and UK GDPR Legal Bases

For individuals in the European Economic Area or United Kingdom, we process personal data only where at least one lawful basis applies. Depending on the activity, the applicable basis may be: 

  • Consent: you have given clear consent for a specified purpose, such as optional marketing or non-essential cookies. 
  • Contract: processing is necessary to enter into or perform a contract with you or the organization you represent. 
  • Legitimate interests: processing is necessary for a legitimate business interest, such as responding to business inquiries, improving services, maintaining security, preventing fraud, or managing business relationships, after considering individual rights and expectations. 
  • Legal obligation: processing is necessary to comply with tax, accounting, regulatory, court, law-enforcement, or other legal duties. 
  • Vital interests: processing is necessary to protect someone’s life or physical safety in an exceptional situation. 
  • Public task or substantial public interest: processing is necessary for an authorized public-interest purpose, but only where applicable and supported by law. 

When special-category personal data is processed, we also rely on an appropriate condition under applicable law. EZOFIS does not generally rely on vital interests or public task for routine website activities. 

8. Consent and Withdrawal

Where processing is based on consent, you may withdraw consent at any time by: 

  • Using the unsubscribe link in a marketing email; 
  • Changing cookie preferences through the cookie settings tool, where available; 
  • Disconnecting an optional integration or changing account settings, where available; or 
  • Contacting contact@ezofis.com with the subject line “Privacy Request.”
    When special-category personal data is processed, we also rely on an appropriate condition under applicable law. EZOFIS does not generally rely on vital interests or public task for routine website activities. 
9. Consequences of Not Providing Information

You are not required to provide personal information merely to browse public pages. However, if you do not provide information marked as required, we may be unable to: 

  • Respond to an inquiry or arrange a demo; 
  • Create or administer an account or trial; 
  • Authenticate access or provide security controls; 
  • Provide a proposal, subscription, support, or contracted service; 
  • Process billing, tax, or compliance information; or 
  • Complete a recruitment or partnership process. 
10. Artificial Intelligence, Automated Processing, and Profiling

EZOFIS develops and provides AI-enabled workflow capabilities. Depending on the Site interaction or configured service, automated systems may assist with document classification, OCR and extraction, search, summarization, routing, prioritization, anomaly detection, business-rule evaluation, reporting, recommendations, communications, and workflow execution. 

AI-assisted output may be incomplete or inaccurate and should be subject to appropriate validation and human oversight, especially for legal, financial, health, safety, compliance, employment, identity, or other material decisions. 

For public website interactions, EZOFIS does not intend to make decisions based solely on automated processing that produce legal or similarly significant effects. If a configured service involves such processing, the responsible customer must establish an appropriate legal basis, notices, controls, and human-review process. Where applicable, an individual may object to solely automated processing or request human review by contacting the relevant customer or EZOFIS Privacy Officer. 

Criteria used by automated systems may include submitted information, configured workflow rules, document content, matching results, validation outcomes, risk indicators, historical workflow context, and customer-defined policies. The significance and consequences depend on the configured process and will be described in the applicable service notice where required. 

11. How We Share Personal Information

We disclose personal information only where reasonably necessary for the purposes described in this Policy. 

11.1 EZOFIS Personnel and Affiliates 

Authorized employees, contractors, and affiliates may access information where needed for sales, support, implementation, security, finance, legal, product, and business operations. Access is subject to role-based controls and confidentiality obligations. 

For this customer content, EZOFIS normally processes information on the customer’s documented instructions and subject to the applicable agreement. The customer is responsible for determining the lawful basis, providing required notices, obtaining permissions or consents, configuring retention, and responding to individuals unless the agreement states otherwis

11.2 Service Providers and Subprocessors 

We may engage third parties to provide: 

  • Cloud infrastructure, hosting, storage, backup, and security services, including Microsoft Azure where applicable; 
  • AI, machine-learning, OCR, model, API, and document-processing services selected for the relevant feature or customer configuration; 
  • Customer relationship management, email, collaboration, event, webinar, and marketing services; 
  • Analytics, performance monitoring, cookie management, diagnostics, and fraud-prevention services; 
  • Payment processing, accounting, billing, tax, and financial administration; 
  • Support, ticketing, identity, authentication, electronic signature, and integration services; 
  • Recruitment, professional advisory, audit, legal, and insurance services. 
    Service providers are permitted to process information only for authorized purposes and are expected to apply appropriate confidentiality and security safeguards. For contracted services, customer-specific subprocessors may be identified in the applicable agreement or subprocessor notice. 

11.3 Other Disclosures 

  • To comply with law, regulation, subpoena, court order, legal process, or valid government request; 
  • To investigate security events, fraud, misuse, or violations of agreements; 
  • To establish, exercise, or defend legal rights and protect people, property, and systems; 
  • To auditors, insurers, lawyers, accountants, and other professional advisers; 
  • To a buyer, investor, lender, successor, or adviser in a merger, acquisition, financing, restructuring, or sale of all or part of the business; and 
  • With your direction, authorization, or consent.
    EZOFIS does not sell personal information for monetary consideration. If we ever engage in activity treated as a sale or sharing for cross-context behavioral advertising under applicable law, we will provide the legally required notice and opt-out mechanism. 
12. International Data Transfers

EZOFIS is headquartered in Canada and supports customers and service providers internationally. Personal information may be processed in Canada, the United States, the European Economic Area, the United Kingdom, India, or other countries where EZOFIS, its affiliates, customers, or authorized service providers operate. 

Privacy laws in another country may differ from those in your jurisdiction, and information may be accessible to courts, law-enforcement, or national-security authorities under local law. Where required, EZOFIS uses appropriate safeguards, which may include: 

  • European Commission or UK adequacy decisions; 
  • EU Standard Contractual Clauses and the UK International Data Transfer Addendum or Agreement; 
  • Data processing agreements and contractual confidentiality and security commitments; 
  • Transfer risk assessments and supplementary technical or organizational measures; and 
  • Customer-selected data residency or deployment options where available and contractually agreed. 
13. Retention of Personal Information

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including service delivery, security, dispute resolution, accounting, audit, legal, regulatory, and contractual requirements. Retention is determined by the nature of the information, sensitivity, risk, user expectations, contractual commitments, and legal obligations. 

Information Type 

General Retention Approach 

Website inquiries, demos, and business communications 

Generally retained while the inquiry or relationship remains active and for a reasonable follow-up period, unless deletion is requested or a longer period is required. 

Marketing records 

Retained until consent is withdrawn or the individual opts out; minimal suppression information may be retained to honour the opt-out. 

Accounts and service records 

Retained for the subscription or service relationship and afterward as required for contract, security, legal, and support purposes. 

Billing, tax, and transaction records 

Retained for the period required by applicable accounting, tax, audit, and corporate laws. 

Security and diagnostic logs 

Retained for a limited period appropriate to security, troubleshooting, fraud prevention, and incident investigation. 

Recruitment information 

Retained for the relevant recruitment process and a reasonable period afterward, subject to consent and applicable law. 

Customer content 

Retained and deleted according to the customer agreement, configured retention policies, documented instructions, backups, and legal requirements. 

Cookies 

Retained for the duration identified in the cookie banner, cookie settings tool, or relevant third-party notice. 

 When retention ends, information is deleted, anonymized, aggregated, or securely isolated unless continued retention is required or permitted by law. 

14. Security Safeguards

EZOFIS uses administrative, technical, physical, and organizational safeguards designed to protect personal information against loss, theft, misuse, unauthorized access, disclosure, alteration, and destruction. Depending on the service and configuration, safeguards may include: 

  • Encryption in transit and at rest where appropriate; 
  • Role-based and document-level access controls; 
  • Authentication, authorization, logging, monitoring, and audit trails; 
  • Secure Microsoft Azure infrastructure and other approved hosting environments where applicable; 
  • Network, application, endpoint, and vulnerability-management controls; 
  • Backup, business continuity, incident response, and recovery procedures; 
  • Confidentiality commitments, training, access reviews, and least-privilege practices; 
  • Secure development, change management, testing, and vendor-risk procedures; and 
  • Security and compliance controls designed to support enterprise and SOC 2 Type II requirements where applicable.
    No method of internet transmission or electronic storage is completely secure. We therefore cannot guarantee absolute security, but we work to apply safeguards proportionate to the nature and sensitivity of the information. 
15. Privacy and Security Incidents

If EZOFIS becomes aware of a breach involving personal information, we will investigate, contain, document, and remediate the incident. We will notify affected organizations, individuals, regulators, or other parties where required by applicable law or contract. 

For information subject to PIPEDA, EZOFIS will assess whether a breach creates a real risk of significant harm and will meet applicable reporting, notification, and breach-record obligations. 

16. Individual Privacy Rights

Privacy rights vary by jurisdiction and may be subject to legal limitations, exemptions, and identity verification. 

16.1 Canada 

  • Request access to personal information held by EZOFIS; 
  • Request correction of inaccurate or incomplete information; 
  • Withdraw consent, subject to legal and contractual restrictions; 
  • Ask questions or challenge compliance with applicable privacy principles; and 
  • File a complaint with the Office of the Privacy Commissioner of Canada or a relevant provincial authority. 

16.2 European Economic Area and United Kingdom 

  • Right to be informed; 
  • Right of access; 
  • Right to rectification; 
  • Right to erasure; 
  • Right to restrict processing; 
  • Right to data portability; 
  • Right to object, including an absolute right to object to direct marketing; 
  • Right to withdraw consent at any time; 
  • Right not to be subject to certain solely automated decisions; and 
  • Right to complain to a competent supervisory authority. 

16.3 California 

To the extent the CCPA applies, California residents may have rights to: 

  • Know the categories and specific pieces of personal information collected; 
  • Know the sources, purposes, and categories of third parties receiving information; 
  • Request deletion or correction; 
  • Opt out of the sale or sharing of personal information; 
  • Limit certain uses and disclosures of sensitive personal information; 
  • Receive information in a portable format; and 
  • Exercise rights without unlawful discrimination.
    EZOFIS does not sell personal information for monetary consideration. We will process recognized opt-out preference signals, such as Global Privacy Control, where required by applicable law and relevant to the Siteactual data practices. 
17. Exercising Your Rights

To submit a privacy request, email contact@ezofis.com with the subject line “Privacy Request” and provide sufficient information to identify the relevant interaction or account. We may request reasonable verification to protect against unauthorized disclosure. 

An authorized agent may submit a request where permitted by law, but we may require proof of authorization and verification of the individual. We aim to respond within the time required by applicable law. In Canada, access requests are generally handled within the statutory period, subject to lawful extensions. 

If EZOFIS processes information only on behalf of a customer, we may direct the request to that customer or assist the customer in accordance with the applicable agreement. 

18. Marketing Communications and Anti-Spam Compliance

We may send business communications where permitted by law. Marketing emails include an unsubscribe mechanism. You may also opt out by contacting contact@ezofis.com. Operational, security, billing, and service communications may still be sent where necessary. 

We maintain records needed to manage consent and suppression preferences and seek to comply with applicable electronic marketing and anti-spam laws, including Canadas anti-spam requirements where applicable. 

19. Cookies and Similar Technologies

Cookies are small files or identifiers stored on or associated with a device. We may use cookies, pixels, tags, local storage, scripts, and similar technologies for the purposes below. 

Cookie Type 

Purpose 

Choice 

Strictly Necessary 

Security, session management, consent records, authentication, load balancing, and essential Site operation. 

Generally cannot be disabled through the Site. 

Functional 

Remember language, preferences, form selections, and user choices. 

May be controlled through cookie settings or browser controls. 

Analytics 

Understand visits, engagement, performance, errors, and how Site content is used. 

Consent is requested where required. 

Targeting or Advertising 

Measure campaigns and, if used, support relevant advertising or cross-site activity. 

Consent and opt-out controls are provided where required. 

Third-Party 

Enable services supplied by third parties, such as embedded media, analytics, chat, events, or integrations. 

Controlled by cookie settings and third-party policies where applicable. 

You may manage non-essential cookies through the Sites cookie banner or settings tool, where available, and through browser controls. Disabling cookies may reduce functionality. Cookie names, providers, purposes, and durations should be displayed in the Sites live cookie settings tool and updated as technology changes. 

20. Do Not Track and Global Privacy Control

Some browsers transmit a Do Not Track (DNT) signal. Because there is no universally accepted DNT standard, the Site may not respond to DNT signals. Where applicable law requires recognition of a universal opt-out mechanism, such as Global Privacy Control, EZOFIS will process the signal in accordance with the Sites actual sale or sharing activities and applicable requirements. 

21. Children’s Privacy

The Site and EZOFIS business services are intended for organizations and adults acting in a professional capacity. They are not directed to children under 16, and we do not knowingly collect personal information directly from children through the public Site. 

The United States COPPA Rule generally applies to online services directed to children under 13 or services with actual knowledge that they collect personal information from a child under 13. EZOFIS does not operate the public Site for that purpose. If we learn that a child submitted personal information without appropriate authorization, we will take reasonable steps to delete it. 

A parent or guardian who believes a child has provided personal information may contact contact@ezofis.com to request access, correction, consent withdrawal, or deletion. Customer workflows involving minors are governed by the customers instructions, notices, consents, and applicable agreement. 

22. Third-Party Websites and Services

The Site may contain links to or integrations with third-party websites and services. EZOFIS does not control their privacy or security practices and is not responsible for their content, policies, or actions. Review the applicable third-party notices before providing information or enabling an integration. 

23. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in law, technology, services, vendors, or data practices. The revised policy will display a new effective or last-updated date. Where a change materially affects privacy rights or previously stated purposes, we may provide additional notice through the Site, email, account communication, or another appropriate method. 

24. Complaints and Regulatory Authorities

Please contact EZOFIS first so we can review and, where possible, resolve a concern. You may also complain to the regulator with jurisdiction over your location or the relevant processing activity, including: 

  • Office of the Privacy Commissioner of Canada: www.priv.gc.ca; 
  • A competent European Economic Area data protection authority; 
  • United Kingdom Information Commissioner’s Office: www.ico.org.uk; 
  • California Privacy Protection Agency: www.cppa.ca.gov; or 
  • Another applicable state, provincial, national, or sectoral regulator. 
25. Contact Information

Questions, concerns, complaints, consent withdrawals, and privacy-rights requests may be sent to: 

Privacy Officer 
EZOFIS Inc. 
18 King Street East, Suite 1400 
Toronto, Ontario, Canada M5C 1C4 
Email: contact@ezofis.com 
Phone: +1 905 231 0955 
Website: www.ezofis.com 

Please include the subject line “Privacy Request” and describe the request clearly. Do not send passwords, full payment card details, or unnecessary sensitive information by ordinary email. 

Appendix A: California Collection and Disclosure Summary

This appendix applies only to the extent EZOFIS is subject to the CCPA for a particular processing activity. The following categories may have been collected during the preceding 12 months, depending on the interaction: 

Category 

Examples 

Sources 

Business Purposes / Recipient Categories 

Identifiers 

Name, email, phone, IP address, account identifier. 

You, employer, account administrator, cookies, systems. 

Service delivery, security, support, marketing; disclosed to service providers and authorized personnel. 

Customer records information 

Business address, signature, billing and contact information. 

You, employer, transaction records. 

Contracts, billing, support, compliance; disclosed to finance, professional, and service providers. 

Commercial information 

Products, services, subscriptions, demo interests, transaction history. 

You, CRM, billing systems. 

Sales, account management, analytics, service delivery. 

Internet or network activity 

Pages viewed, clicks, device, browser, logs. 

Cookies, Site, security tools. 

Analytics, security, troubleshooting; disclosed to hosting and analytics providers. 

Professional information 

Employer, title, department, resume, work history. 

You, employer, public professional sources. 

Business relationships, recruitment, support. 

Audio, visual, or similar information 

Meeting recordings, support screenshots, uploaded images, if provided. 

You, meetings, support interactions. 

Support, training, service delivery, records. 

Inferences 

Business interests, likely use cases, workflow preferences. 

Interactions, CRM, analytics. 

Relevant communications, product improvement, sales planning. 

Sensitive personal information 

Account credentials, identity documents, precise data only if configured or supplied. 

You or customer-configured workflows. 

Authentication, security, contracted processing; limited to authorized purposes. 

 

Appendix B: Website Publication Checklist

For this policy to accurately reflect the live Site, EZOFIS should keep the following operational items aligned with the published text: 

  • Maintain an active privacy contact and internal request-handling process. 
  • Use a cookie banner and preference centre where non-essential cookies require consent. 
  • Maintain a current cookie inventory and identify cookie providers, purposes, and durations. 
  • Maintain a service-provider and subprocessor inventory. 
  • Keep data retention practices consistent with customer agreements and internal schedules. 
  • Ensure marketing unsubscribe requests and consent records are honoured. 
  • Maintain processes for privacy requests, verification, breach assessment, and regulatory notifications. 
  • Update the policy when new AI providers, integrations, tracking technologies, or material processing purposes are introduced. 

 

Cart (0 items)

Create your account

Select the fields to be shown. Others will be hidden. Drag and drop to rearrange the order.
  • Image
  • SKU
  • Rating
  • Price
  • Stock
  • Availability
  • Add to cart
  • Description
  • Content
  • Weight
  • Dimensions
  • Additional information
Click outside to hide the comparison bar
Compare