Privacy Policy
What personal information the service holds, why, who else touches it, where it lives, and how to get at or correct your own.
Version 1.0 · In effect since
1. Who holds what
vivaBooks sits behind an accounting firm. The firm decides whose information goes into the system and why; we hold and process it on the firm’s instructions so the software can do its job. In privacy terms the firm is accountable for the personal information of its clients and their employees, and we are its service provider.
If you are an employee whose payroll is run through this system, the shorter Employee Privacy Notice is written for you. If you are a firm, the terms on which we process on your behalf are in the Data Processing Addendum.
2. What the service holds
Payroll cannot be run without genuinely sensitive information, so this list is specific rather than a set of categories.
| Category | Examples |
|---|---|
| Identifiers | Name, date of birth, home address, personal phone number and email, emergency contact. |
| Government identifiers | Social Insurance Number, CRA business and payroll account numbers. |
| Financial | Direct-deposit bank account details, pay rate, salary, hours, deductions, year-to-date totals. |
| Employment | Job title, hire and termination dates, reason for separation on a Record of Employment, leave requests and the reason given for them, union dues and charitable donations reported on a T4. |
| Tax filings | T4 slips and Records of Employment, including every reported box, and dental-benefit coverage codes. |
| Documents | Whatever a firm or its client uploads: bank and credit-card statements, prior-year slips, incorporation records, and government photo identification where a firm asks for it. |
| Account and technical | Sign-in email, session cookies, IP address and user-agent recorded against sensitive-record access, and error diagnostics. |
3. Why we hold it
- To calculate pay and source deductions, and to produce pay statements.
- To generate T4 slips, Records of Employment, and remittance figures.
- To let firms request, collect and store the records their engagement needs.
- To authenticate users and keep accounts secure.
- To send the messages described in our email practices below.
- To meet our own record-keeping obligations, and to detect and investigate misuse.
We do not use personal information for advertising, we do not sell it, and we do not use it to train machine-learning models. Where a model is used at all, exactly what is sent to it is described in the AI Disclosure.
4. Who else touches it
Running the service requires a small number of infrastructure providers. Each is listed — with what it receives and the country it operates in — on the Subprocessors page, which is kept current. Each is bound by contract to protect the information to a standard comparable to what we apply, and to use it only to provide its service to us.
We also disclose information where the law requires it — a court order, a lawful demand from a tax authority — and, on a firm’s instruction, to a system that firm has chosen to connect, such as its accounting ledger.
5. Where it is stored
We are moving customer data to Canadian infrastructure. We will not describe the service as Canadian-hosted until that move is complete, and this page will be updated with a new version number when it is.
Firms with Canada Revenue Agency record-keeping obligations should be aware that the CRA expects books and records to be kept in Canada unless it has given written permission otherwise, and that records merely accessible from Canada do not satisfy that expectation. We raise it here because it is your obligation and you should be able to see the answer before you rely on us for it.
6. How long we keep it
Payroll records support filings that the Canada Revenue Agency can review for six years from the end of the tax year they relate to, so records tied to a filing are kept for at least that long. Beyond that:
- Deleting a client or an employee removes their records from the service.
- Archived employees are retained so historical payroll stays auditable.
- Diagnostic and email logs are kept for a limited operational period and then removed.
- When a subscription ends, data is handled as described in the Data Processing Addendum.
7. Getting at your own information
You can ask us to:
- tell you what personal information we hold about you and what it has been used for;
- correct it where it is wrong;
- give you a copy in a structured, commonly used format;
- delete it, where we are not required to keep it for a tax or legal reason.
Write to the Privacy Officer using the details below. We respond within 30 days. If your information is in the system because an employer or their accounting firm put it there, we may need to route the request through them — they decide what is held and why — but we will tell you that rather than leave you without an answer.
You can also withdraw consent to non-essential email at any time using the unsubscribe link in any reminder we send. That does not stop the messages needed to run payroll or to access your account.
8. How it is protected
Controls are described in the Security Overview. No system is perfectly secure, and we do not claim otherwise.
If something goes wrong
We keep a register of confidentiality incidents. Where a breach creates a real risk of significant harm we notify the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec where Quebec residents are affected, and the affected individuals — and we notify the firm whose data it is without undue delay so it can meet its own obligations.
9. Cookies
We use sign-in cookies and nothing else. There is no advertising technology and no third-party analytics in this product. Details are on the Cookies & Tracking page.
10. Children
The service is sold to businesses and is not directed at children. Where a young worker is on a payroll, their information is in the system because their employer put it there, and this policy applies to it in the same way.
11. Changes
When this policy changes, the version number and effective date at the top of the page change with it. Material changes are notified in the application before they take effect.
12. Privacy Officer
We have designated a Privacy Officer accountable for our compliance with this policy. Address privacy questions, access requests and complaints to:
Privacy Officer, TVN Core Solutions Ltd.
570 Hood Road, Unit 14 #1625
Markham, ON L3R 4G7
Canada
tvncoresolutions@gmail.com
If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or — if you are in Quebec, Alberta or British Columbia — to your provincial privacy regulator.