Privacy Policy
Version 2026-07-23
This Privacy Policy explains how LMIAComply (“LMIAComply”, “we”, “us”) collects, uses, and protects personal information in connection with the LMIAComply service (the “Service”), a recordkeeping tool for LMIA recruitment. The Service is not an official Service Canada or ESDC service.
1. Controller
LMIAComply is the controller of the personal information described in this Policy in respect of your use of the Service. Where you use the Service on behalf of an organization to manage records about applicants and employees, your organization is the controller of that organization's business records and LMIAComply acts as a processor on the organization's behalf for those records.
2. Information you provide
When you create an account we collect your email address and, optionally, your name and account type. When you use the Service you provide business records such as employer information, LMIA case details, advertising evidence, and applicant records. You control what information is entered.
3. Information collected automatically
We collect basic technical information such as timestamps, IP address at the time of key actions (for example, acceptance of these Terms), session information, and error diagnostics needed to operate and secure the Service.
4. How information is used
We use information to: (a) provide and operate the Service; (b) enforce access controls within your organization; (c) generate the “LMIA Recruitment Compliance Summary and Audit Log” export; (d) prevent fraud and abuse and keep the Service secure; (e) provide customer support; and (f) comply with our legal obligations. We do not sell personal information.
5. Legal basis for processing
Where applicable data-protection law requires a legal basis, we rely on the following: performance of a contract with you (providing the Service you signed up for), legitimate interests (securing the Service, preventing abuse, product improvement, communicating operational information), consent (where required, for example for optional analytics or marketing communications), and legal obligation (record-keeping, tax, responding to lawful requests).
6. Access within your organization
Business records are scoped to the organization you belong to. Members of an organization can view its records; users outside the organization cannot. Access is enforced by database-level policies, not just by the application interface.
7. Sub-processors and data sharing
We share personal information with the following categories of recipients:
- Cloud infrastructure and database provider — hosts authentication, database, and file storage on our behalf under commercially reasonable safeguards.
- Merchant of Record (Paddle.com) — Paddle acts as our reseller and Merchant of Record for all paid plans. Payment information (card details, billing address, tax identifiers) is collected and processed directly by Paddle for order processing, subscription management, tax compliance, invoicing, and fraud prevention. See Paddle's Privacy Notice.
- Professional advisers — legal, accounting, and audit advisers where necessary.
- Authorities — where required by law, court order, or to protect our rights.
8. International transfers
Personal information may be processed in Canada and in other countries where our sub-processors operate. Where information is transferred outside your jurisdiction, we rely on appropriate safeguards such as standard contractual clauses or adequacy decisions where required.
9. Retention and deletion
We retain personal information for as long as your account is active and as needed to provide the Service. You may delete records you create through the application. Account deletion cascades to your personal profile. Retention of business records after user deletion is subject to the retention rules of your organization. We may retain limited information as required for legal, tax, security, or fraud-prevention purposes, after which it is deleted or anonymised.
10. Your rights
Subject to applicable law, you may request access to, correction of, deletion of, or portability of your personal information, restrict or object to certain processing, and withdraw consent where processing is based on consent. You may also lodge a complaint with your local data-protection authority (in Canada, the Office of the Privacy Commissioner). To exercise these rights, contact us through the in-application support channels.
11. Security
We use industry-standard technical and organisational measures to protect personal information, including transport encryption (HTTPS), encryption at rest for stored data, database-level access controls, and least-privilege access for personnel. No system is perfectly secure; please report suspected incidents to us immediately.
12. Cookies
We use cookies and similar technologies that are strictly necessary to keep you signed in and to operate the Service. We do not use third-party advertising cookies. Paddle may set cookies in its checkout to process your payment.
13. Changes to this Policy
Material changes will be communicated in-app. The current version identifier is shown at the top of this page.