PRIVACY POLICY

Privacy Policy

Your Privacy Matters

Last updated — April 2025  ·  Trustii Technologies Inc.

This Policy explains how Trustii collects, uses, shares, and protects personal data when you use our services, including through our Website and Platform (the “Services”). Trustii takes your privacy and the security of personal data very seriously. The Policy also explains your rights under the law and how you can contact us. Please read it carefully.

1

Privacy at a glance

We collect what we need

Only the data necessary to deliver the Services and meet legal obligations.

We use data for clear purposes

To provide the Website/Platform, conduct verifications, and prevent fraud.

We share carefully

Only with trusted providers (hosting, verification, payments) and only as needed.

We do not sell personal data

We do not sell or rent personal data to third parties.

You have rights

Access, correction, deletion, and more — depending on your location.

Quebec Law 25

For Quebec residents, we comply with Quebec’s private-sector privacy law as amended by Law 25.

About Profile (self-verification): Profile lets individuals generate background verification reports about themselves and share them with third parties of their choice. Some Profile features may be offered through commercial partnerships; Profile is not exclusive to any partner.
2

Who this Policy is for

This Policy applies when you:

  • visit our website at https://www.trustii.co and its subdomains (the “Website”);
  • use our background verification and risk management tools, including Trustii Background Checks and Profile (the “Platform”);
  • create or use an account on behalf of an Organization (an “Organization User”) or as an individual (a “Profile User”);
  • receive, are asked to complete, or complete a Questionnaire, in which case you are an “Applicant”; or
  • otherwise interact with us (for example, requesting information or support).
3

About Trustii and how to contact us

Trustii Technologies Inc. (“Trustii”) is a Quebec corporation located in Montreal, Quebec, Canada.

Privacy & DPO
[email protected]
Mail
465 McGill St. #700, Montreal, Quebec, H2Y 1H1
Account deletion
[email protected]
4

Our role depending on the Services used

Website & Profile

When you visit our Website or use Profile, Trustii determines why and how personal data is processed.

Organization Background Checks

When an Organization requests background checks, Trustii processes Applicant data on that Organization’s behalf.

Important: Trustii does not make decisions about Applicants. Organizations remain responsible for their own decisions and for ensuring personal data is collected and used in compliance with applicable laws.

Trustii may provide Organizations with tools for centralized management, monitoring and follow-up of verification results. When providing these services, Trustii acts on behalf of the Organization and does not determine the purposes for which data are used.

5

Personal data we collect and why

We limit the collection, use and disclosure of personal data to what is necessary for the identified purposes (data minimization). Legal bases include: performance of a contract; compliance with legal obligations; legitimate interests (security, fraud prevention); and, where required, your consent.

CategoryExamplesMain purposes
Demo / contact requestsName, email, phoneRespond to inquiries; schedule demos
Sample report requestsEmail addressSend a sample report
Organization User accountName, email, phone, organizationCreate/manage account; authenticate; two-factor authentication
Profile User accountName, email, phoneCreate/manage account; authenticate; notifications
BillingCardholder name, card details, billing address, emailProcess payments; issue invoices; manage billing
6

Applicants: Questionnaires and Reports

We collect Applicant data primarily to prepare and compile a Report summarizing Questionnaire results, and to support closely related purposes such as completing the process, communicating with Applicants, recording consent, ensuring security, preventing fraud, and complying with legal obligations.

If you do not want to provide specific data requested in a Questionnaire, you are not obligated to do so. Please contact the Organization that sent you the Questionnaire to discuss next steps.

6.1 Employment context

RequirementPersonal dataNotes
RequiredName; email; phone; date of birth; address and address history (last 5 years); current and past employment; professional reference contact detailsEmail/phone for service notifications. Date of birth confirms Applicants are over 18.
If applicable / requestedMiddle/previous names; place of birth; criminal convictions declaration; education history; driver’s license; professional license; other documentsPlace of birth may be required for certain criminal background checks.
OptionalGender; SIN number; education levelNever required. May be used in aggregated, anonymized form where permitted.

6.2 Pre-rental context

RequirementPersonal dataNotes
RequiredName; email; phone; date of birth; employment information; address and address history (last 5 years) and rental status; landlord contact details; household members/roommates and petsEmail/phone for service notifications. Date of birth confirms Applicants are over 18.
If applicable / requestedMiddle/previous names; place of birth; criminal convictions declaration; education history; driver’s license; other documentsPlace of birth may be required for certain criminal background checks.
OptionalGender; SIN number; education levelNever required. May be used in aggregated, anonymized form where permitted.

6.3 Payment information

Payment may be made by the Organization directly, delegated to the Applicant, or made by the Applicant when accessing self-serve Services. Trustii does not access or store full payment card details. Payment information is processed directly by the payment service provider, which acts as an independent controller.

7

Personal data we receive from third parties

CategoryExamplesSourcePurpose(s)
Organization User loginName, email, phoneCertain commercial partnersFacilitate sign-in to the Platform
Profile loginName, email, phoneCertain commercial partnersFacilitate sign-in; no automatic prefilling
Applicant invitationName, email and/or phoneThe requesting OrganizationSend the Questionnaire on the Organization’s behalf
Banking analysisBank account info, transaction history, derived indicatorsThird-party open banking providerAssess financial capacity indicators
8

Banking analysis (where requested)

What we do — and what we don’t:
  • We may use information from a third-party open banking provider to assess financial capacity indicators when banking analysis is requested.
  • Transaction-level details are not displayed in the Report and are not shared with the Organization.
  • We do not use banking data to profile individuals or make automated decisions.

When banking analysis is enabled, Trustii receives and processes banking data including: connected bank accounts (account numbers, type, financial institution, balance and limits), up to 365 days of transaction history, and derived financial attributes and indicators.

In a pre-rental context, banking analysis may be used to assess an Applicant’s capacity to meet rental obligations. In a pre-employment context, it is enabled only in exceptional circumstances where the Organization demonstrates a legitimate risk-related justification. Banking data are used solely to support human assessment and do not result in automated decisions.

9

Sensitive personal data

Except as disclosed herein, Trustii does not seek to collect sensitive personal data through the Questionnaire (e.g., political opinions, racial or ethnic origin, health, religious beliefs, trade union membership, or sexual orientation).

Biometric and identity-related data are considered sensitive personal data under applicable privacy laws. Where identity verification requires biometric inputs, such data are processed solely for verification and fraud prevention purposes, based on explicit consent or as otherwise permitted by law. Trustii does not store biometric templates and retains such data only for the period strictly necessary to complete the verification.

Banking data are treated as highly sensitive and subject to enhanced safeguards. Raw banking data are retained only as long as necessary, after which they are deleted or irreversibly anonymized.

10

Who we share personal data with

We share personal data only with trusted third parties when necessary to deliver the Services and subject to contractual safeguards. We do not sell personal data.

Personal data categoryRecipient typeTypical purpose
Website / Platform usage dataAnalytics and infrastructure providersHost services, monitor performance, maintain security
Account and contact dataIdentity management and communications providersAuthenticate users, manage accounts, deliver notifications
Applicant Questionnaire dataVerification and screening providersPerform requested verifications and return results
Identity verification dataIdentity verification providersVerify identity and prevent fraud
Payment and billing dataPayment processing providersProcess payments and manage billing
11

Cookies and similar technologies

We use cookies and similar technologies (e.g., tags, pixels, and web beacons) on the Website and, where applicable, the Platform. Where required by law, we use non-essential cookies only with your consent via our cookie banner. You can manage cookies through the banner and your browser settings.

We use cookies to: operate the Website and Platform and maintain security; understand usage and improve performance; remember preferences and facilitate sign-in; and, where enabled and permitted, measure and improve advertising effectiveness.

If you disable cookies, some features may not work as intended.
12

Security, fraud prevention and service integrity

Trustii implements administrative, technical, and physical safeguards proportionate to the sensitivity of personal data. Access is limited to authorized personnel and service providers who need it, in alignment with recognized information security best practices and standards.

We maintain procedures to detect, respond to, and manage suspected security incidents. Where required by law, we will notify affected individuals and/or competent authorities within required timeframes.

We may collect limited technical information (e.g., IP address, device/browser type, access timestamps) for security monitoring, fraud prevention, and auditing. We may generate aggregated and/or anonymized data for business insights; individuals are not identifiable from such data.

13

International and inter-provincial transfers

13.1 EEA / U.K. transfers (where applicable)

Personal data may be transferred to other countries. We use appropriate safeguards such as contractual protections and other measures required under applicable law. You may request more information by contacting our Privacy and Data Protection Officer.

13.2 Transfers outside Quebec (Quebec residents)

Trustii endeavours to keep personal data in Quebec. When we transfer personal data outside Quebec, we conduct a Privacy Impact Assessment as required by Law 25 and implement appropriate safeguards.

14

Data retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Policy, taking into account the nature of the data, applicable legal requirements, and legitimate business needs such as security, fraud prevention, dispute resolution, and audit obligations.

Retention periods vary depending on whether data relates to an Applicant, an Organization User, or a Profile User. Certain categories of data, such as raw banking data, may be retained for internal processing and fraud prevention purposes even where they do not appear in the final Report.

Where permitted by law, we may keep aggregated and anonymized personal data for legitimate business purposes. You may request deletion of your account by emailing [email protected].

15

Your rights and how to exercise them

You may have certain rights regarding your personal data. Rights vary by jurisdiction and may be subject to legal exceptions.

RightWhat it means
AccessRequest access to your personal data and information about processing
CorrectionCorrect inaccurate or outdated personal data
DeletionRequest deletion in certain circumstances
Withdraw consentWhere processing is based on consent
PortabilityReceive certain personal data in a structured, portable format where required by applicable law
Objection / restrictionObject to or restrict certain processing (where available)
Opt-out of marketingUnsubscribe from marketing communications
ComplainFile a complaint with a competent authority

How to exercise your rights

  • Contact our Privacy and Data Protection Officer at [email protected].
  • Include enough information for us to verify your identity and locate the relevant data.
  • We will respond to verified requests within the timeframes required by applicable law.
  • If you are not satisfied with our response, you may contact the appropriate authority.
16

Automated decision-making

Trustii does not use automated decision-making with legal or similarly significant effects about individuals when providing the Services.

17

Children’s privacy

The Services are intended for individuals who are at least 18 years old (or the age of majority where you live). We do not knowingly collect personal data from children under applicable minimum ages. If we become aware that we have collected such data, we will delete it.

18

Changes to this Policy

We may update this Policy from time to time. The date at the top indicates when it was last updated. We will post a prominent notice if we make significant changes.

Thanks for reading. Please keep your personal data safe — we promise to do the same.

[email protected]