LEGAL · PRIVACY POLICY

Privacy Policy

How OpSphere collects, uses, discloses, and protects personal information under PIPEDA.

Last updated: July 16, 2026

1. Scope and accountability

This Privacy Policy explains how OneClick Solutions Inc., operating as OpSphere, collects, uses, discloses, and protects personal information in connection with the Services and our websites. We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, including BC's Personal Information Protection Act where it applies.

We have designated a Privacy Officer accountable for our privacy program. Contact: support@oneclicksolutions.ca.

2. What we collect

Account information: name, work email, company, and role when you register or are invited to a tenant. Passwords are stored only as secure cryptographic hashes — we cannot read them.

Customer Data processed on behalf of tenants: records your organization stores in the platform (deals, projects, commissions, documents, contacts). For this data we act as a service provider to the tenant, which remains responsible for it.

Contact data about your organization's clients and counterparties: names, email addresses, and phone numbers of buyers, sellers, brokers, vendors, and other deal parties that your organization records in the platform.

Identity-verification records: where your organization uses FINTRAC compliance workflows, the platform stores identity-verification records — including metadata about government-issued identification documents (document type, reference numbers, verification method, and dates) — created by your organization to meet its record-keeping obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA). These are among the most sensitive records on the platform: access requires dedicated compliance permissions, records cannot be casually deleted, and identification-document numbers are masked in audit logs.

Financial transaction records: deal financials, commission calculations, trust deposit and receipt-of-funds records, and related accounting entries that your organization records in the course of its transactions.

Usage and device information: log data, IP address, browser type, pages viewed, and feature interactions, used for security, troubleshooting, and product improvement.

Communications: messages you send us through contact, demo, or support forms.

3. Why we collect it (identified purposes)

We use personal information to: provide and secure the Services; create and administer accounts; process subscriptions; respond to enquiries and support requests; send service notices; improve features and reliability; and meet legal obligations. We do not sell personal information, and we do not use Customer Data to advertise to your clients.

5. Limiting collection, use, and retention

We limit collection to what is necessary for the identified purposes and retain personal information only as long as needed for those purposes or to meet legal requirements. After account termination, Customer Data is available for export for 30 days and then scheduled for deletion from production systems; backups roll off on a fixed cycle. Aggregated, de-identified data that cannot identify a person may be retained for analytics.

Regulatory retention overrides ordinary deletion: records your organization creates to meet statutory record-keeping obligations — including FINTRAC identity-verification and related compliance records, which the PCMLTFA requires to be kept for at least five years — are treated as legal-hold-first. They are retained for their required regulatory period even where other records are deleted, and the platform does not provide casual deletion of these records: they are voided or superseded on the record instead.

6. Disclosure and service providers

We disclose personal information only: to service providers who host and support the platform (for example cloud hosting and database providers) under contracts that require protections consistent with this policy; when required by law, subpoena, or court order; to protect our rights, users, or the public; or with your consent.

Our production infrastructure is currently hosted by service providers in the United States, so personal information stored in the platform is stored and processed outside Canada and may be subject to the laws of those jurisdictions, including lawful access by authorities there. We use contractual and technical safeguards regardless of where data is processed, and our Security & Trust page names the hosting providers we use.

7. Safeguards

We protect personal information with safeguards appropriate to its sensitivity. Encryption: all traffic between your browser, our web application, and our API is encrypted in transit using TLS, and personal information is stored in managed cloud datastores that encrypt data at rest.

Access controls: every tenant's records are partitioned by a tenant identifier and data access is scoped to the requesting tenant on every query; within a tenant, role-based access control and fine-grained permissions limit what each user can see and do, and sensitive compliance records (including FINTRAC identity-verification records) require dedicated permissions. Material changes are recorded in an audit log with the acting user, tenant, and timestamp, and our own personnel operate under least-privilege access.

No method of transmission or storage is completely secure; we review and improve our controls on an ongoing basis. Our Security & Trust page describes these controls in more detail.

8. Accuracy

We take reasonable steps to keep personal information accurate, complete, and up to date for the purposes it is used. Account holders can review and update their own profile information in the platform; tenant administrators maintain Customer Data directly. If you believe information we hold is inaccurate, contact our Privacy Officer and we will correct it or note the disagreement.

9. Access, correction, and openness

You may request access to personal information we hold about you, ask how it has been used or disclosed, and request corrections. Tenant administrators manage most Customer Data directly in the platform. For other requests, contact our Privacy Officer; we respond within the timelines required by law and may need to verify your identity. If we refuse a request we will explain why and the recourse available, including complaint to the Office of the Privacy Commissioner of Canada.

10. Cookies and analytics

Our public website uses strictly-necessary cookies for session integrity and, where enabled, privacy-respecting analytics that measure page and feature usage in aggregate. The authenticated application stores tokens needed to keep you signed in. We do not use third-party advertising cookies. Where analytics requiring consent are introduced, we will request it before activation.

11. Breach notification

Where a breach of security safeguards creates a real risk of significant harm, we notify affected individuals and report to the Privacy Commissioner of Canada as required by PIPEDA, and we maintain records of all breaches. Tenants are notified without unreasonable delay where their Customer Data is affected.

12. Changes to this policy

We may update this policy as our practices or legal requirements change. Material changes are announced through the Services or by email before they take effect. The 'Last updated' date above reflects the current version.

Questions about this document?

Contact us at support@oneclicksolutions.ca and we will route it to the right person.

Read the Terms of Service