Privacy Policy

This Privacy Policy describes how your personal information is collected, used, and shared when you visit, subscribe, register at https://FuturisticTechnologies.ca (the "Site").


1. Who we are, and who is accountable

This policy applies to [FULL LEGAL ENTITY NAME] ("Futuristic Technologies", "we", "us"), operating the website at futuristictechnologies.ca and the bookkeeping automation application at futuristicai.cloud.

We have designated a Privacy Officer who is accountable for our compliance with this policy and with Canadian privacy law. All privacy questions, access requests and complaints go to them:

We are subject to the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and, as an organization operating in British Columbia, to BC's Personal Information Protection Act (PIPA). Where a client of ours is located in Quebec, Quebec's Law 25 obligations may also flow through to us under our agreement with that client.

2. Two different kinds of information — and two different roles

This distinction matters more than anything else in this policy, and most privacy policies blur it. We hold information in two capacities:

Information we collect for ourselves. When you visit our website, send us an enquiry, or hold a user account in our application, we decide what to collect and why. We are directly accountable to you for that information. See Section 3.

Client information we process on a firm's behalf. When a bookkeeping firm or accountant uploads a client's bank statement, invoice or payroll file, we act as a service provider. The firm decides what to collect and why; the firm remains accountable to the individuals concerned; and we may use that information only to deliver the service the firm has engaged us for. We do not use it for our own purposes, and we do not disclose it to anyone except as described in Section 6. See Section 4.

If you are an individual whose bank statement, cheque or paystub was processed through our application and you want to see, correct or delete that information, your request goes to the firm that engaged us, not to us directly. We will support that firm in responding, promptly and at no charge. If you are unsure who holds your file, contact our Privacy Officer and we will help you identify the right organization.

3. Information we collect directly

3.1 When you visit our website

Our website does not run Google Analytics, advertising pixels, or third-party behavioural tracking, and it does not set marketing cookies. Our web host records standard server logs — IP address, browser type, pages requested and timestamps — for security and troubleshooting.

3.2 When you contact us

Our contact form collects your name, email address, phone number, and whatever you write in the message. We use it to answer you and to follow up about the service you asked about. Form submissions are handled by our website's contact form software and synchronised to Hostinger Reach, the email tool we use to manage enquiries and send occasional updates.

Under Canada's Anti-Spam Legislation (CASL), asking us about our services gives us implied consent to send you related commercial messages for six months. Every message we send identifies us and carries a working unsubscribe link, and we act on unsubscribe requests within ten business days. You can opt out at any time by replying or writing to the Privacy Officer.

3.3 When you hold an account in our application

For each user of the application we hold a username, email address, password (stored only as a salted hash — it is never recoverable, including by us), assigned role, and the firm and client files you are permitted to see.

3.4 How the application is used

We record which pages of the application were requested, how long requests took, the IP address and browser making them, and each user's sign-in and last-seen times. We use this to keep the service running, investigate problems, and understand which features are used.

These records capture the route requested — for example /statements/batches/:id — and never the contents of a statement, transaction, payee or amount. They are visible only to our own platform administrators.

4. Client information we process for firms

Working through our application, we hold the following on behalf of the engaging firm:

WhatWhy we hold it
Bank and credit card statement PDFsThe uploaded original, kept so the firm can re-check any parsed figure against the source
Transaction recordsDate, description, amount, payee, assigned account and tax code — the output the firm reviews and posts
Statement headersAccount number, institution, statement period, opening and closing balances
Cheque imagesExtracted from the statement PDF and shown beside the matching ledger row. These may show a signature, payee and MICR line
Vendor invoices and line itemsItems, quantities, costs and adjustments parsed from supplier invoices
QuickBooks connection tokensEncrypted authorisation to post approved entries to the firm's own QuickBooks account
Vendor, customer and chart-of-accounts listsImported from the firm's QuickBooks so entries can be coded correctly
Audit logA record of who did what and when, kept so the firm can demonstrate control over its own bookkeeping

4.1 What we never do with client data

  • We do not sell, rent or trade it.
  • We do not use it to train artificial intelligence or machine learning models — ours or anyone else's.
  • We do not use one firm's data to improve results for another firm.
  • We do not use it for our own marketing, analytics or product research.
  • We do not access individual client files except when a firm asks us to investigate a specific problem, or where we must to keep the service secure and working.

5. Where your information is stored

Our application, its database and all uploaded files run on a single private server we rent.

6. Who else touches the data

We keep this list short deliberately, and we keep it current. The organizations below are the only third parties involved in delivering our service:

ProviderRoleWhat reaches them
Intuit (QuickBooks Online)Accounting platformOnly the transactions a user reviews and approves, pushed into that firm's own QuickBooks account. The connection uses Intuit's own secure sign-in — we never see or store QuickBooks passwords.
Google (Gmail)Outbound emailWhere a firm enables in-app email, messages are sent from the firm's own mailbox using credentials the firm supplies. Mail does not pass through a shared relay of ours.
Let's EncryptSecurity certificatesCertificate issuance only. No personal information.

6.1 Other disclosures

We may also disclose personal information where we are legally required to — a court order, subpoena, warrant, or a lawful demand from a regulator or law enforcement agency. We will not disclose more than the demand requires, and we will notify the affected firm unless we are legally barred from doing so. If our business is ever sold or merged, information may transfer to the acquirer, who would remain bound by this policy; we would notify firms beforehand.

7. How we protect it

We apply safeguards proportional to how sensitive this data is, which — bank records, cheque images and SINs — is about as sensitive as commercial data gets:

  • Documents stay on our server. Statement parsing happens in-process. No third-party document service is involved.
  • All traffic is encrypted in transit using TLS with automatically renewed certificates.
  • Passwords are stored as salted PBKDF2 hashes at 260,000 iterations. They cannot be recovered or read by anyone, including us.
  • QuickBooks tokens, Social Insurance Numbers and email credentials are encrypted at rest with AES.
  • The database is not reachable from the internet — only the application itself can connect to it.
  • Access is role-based across five roles, and every single request re-checks the user's role, firm and client scope against the database. Revoking someone's access takes effect immediately, not when their session expires.
  • Each firm's data is isolated at the query layer. A request for another firm's records returns "not found" rather than "access denied", so other firms' data is not even discoverable.
  • Every action is written to an audit log, and the log survives the deletion of the user who created the entry.
  • Sign-in is rate-limited against brute-force attempts, and the application refuses to start if configured with default credentials.

No system is perfectly secure, and we will not claim otherwise. We hold no third-party security certification such as SOC 2, and we will not imply one until we have earned it. If you need our current security posture in detail for a vendor assessment, ask the Privacy Officer and we will answer specific questions in writing.

8. How long we keep it

InformationKept for
Statement PDFs, transactions, cheque images, invoicesAs long as the engaging firm keeps them, or until the firm or we close the account. Deleting a client file removes its database records and its stored files.
Audit logRetained for the life of the account, because its purpose is to be tamper-evident.
Website enquiries[CONFIRM — suggested: 24 months from last contact]
Records of any security breach24 months, as PIPEDA requires.

Deletion is permanent and cannot be undone. When a firm deletes a client file, we remove the dependent records first and the stored files only once the deletion has fully committed, so nothing is left pointing at data that no longer exists.

9. Your rights, and how to use them

You may ask us to:

  • Confirm whether we hold personal information about you, and what we have used or disclosed it for;
  • Access a copy of it;
  • Correct it if it is inaccurate or incomplete;
  • Withdraw consent for uses that are not required by law or by a contract we have with you, understanding that this may mean we can no longer provide the service;
  • Delete it, where we are not legally required to keep it.

Write to the Privacy Officer using the details in Section 1. We may ask you to confirm your identity before we release anything — a necessary step, not an obstacle.

We will respond within 30 days. If we genuinely need longer, we will tell you in writing within those first 30 days, explain why, give you the new date, and tell you about your right to complain to the Privacy Commissioner. Access is free; if a request would require substantial cost we will tell you the estimate first and let you decide whether to proceed. If we refuse a request in whole or in part, we will explain why and tell you how to challenge it.

As noted in Section 2, if your information reached us through a bookkeeping firm, your request should go to that firm. We will help them meet their deadline.

10. If something goes wrong

If a security breach occurs and it creates a real risk of significant harm, we will report it to the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, as PIPEDA requires. We will also notify the engaging firm of any breach affecting their client data — whether or not it meets the reporting threshold — so the firm can meet its own obligations. We keep a record of every breach for 24 months.

11. Children

Our service is sold to businesses and is not directed at children. We do not knowingly collect personal information directly from anyone under 18.

12. Changes to this policy

We will post any change here and update the "last updated" date. If a change materially affects how we handle personal information — a new sub-processor, a new purpose, a new data flow off our server — we will notify engaged firms directly before it takes effect.

13. Complaints

Start with our Privacy Officer. We will acknowledge your complaint, investigate it, and tell you the outcome and what we have changed as a result.

If you are not satisfied with our response, you may complain to either regulator:

  • Federal: Office of the Privacy Commissioner of Canada — priv.gc.ca · 1-800-282-1376
  • British Columbia: Office of the Information and Privacy Commissioner for BC — oipc.bc.ca · 1-800-663-7867