PIPEDA establishes requirements for protecting personal information in commercial activities. Alohi combines security controls and privacy practices to help organizations protect the information they handle through Fax.Plus and Sign.Plus.
The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada’s federal private-sector privacy law. It sets requirements for collecting, using, and disclosing personal information, including accountability, meaningful consent, appropriate safeguards, and individual access.
Faxed documents and signed agreements can contain personal, financial, and other sensitive information. Protecting this information involves more than securing a file: organizations must also understand why it is processed, who can access it, how long it is retained, and how individuals can exercise their privacy rights.
Alohi’s security controls and privacy practices help customers address these responsibilities. Each organization remains responsible for determining which laws apply to its activities and establishing appropriate policies for the information it processes.
This page is provided for general informational purposes and does not constitute legal advice. Organizations should consult their own counsel to confirm PIPEDA compliance for their specific use case.
Our approach combines technical safeguards with transparent information about data use, retention, and privacy rights. These measures support organizations assessing Fax.Plus and Sign.Plus for workflows involving personal information.
Our Privacy Policy explains what personal information we collect, why we process it, and when it may be shared with service providers. Customers and individuals can contact privacy@alohi.com with questions about our practices or requests concerning their personal information.
We describe the purposes of processing personal information in our Privacy Policy, including service delivery, account administration, support, and security. Organizations using Fax.Plus and Sign.Plus should identify their own purposes for handling document contents and obtain meaningful consent where required by applicable law.
Stored faxed and signed documents are encrypted using AES-256. Connections between Alohi’s web applications, mobile applications, or APIs and our servers use Transport Layer Security (TLS). These safeguards protect stored documents and supported application connections; customers should also assess how information is handled by recipients and connected services.
Authentication and access controls help protect customer accounts and systems. Enterprise security features for Fax.Plus and Sign.Plus include account access logs and the ability to block users. Customers should configure available controls according to staff responsibilities and remove access when it is no longer needed.
Our Privacy Policy describes how personal information is retained for service delivery, contractual obligations, and legal requirements. Customers can request deletion of personal data, subject to applicable retention obligations and permitted exceptions. Document retention should be reviewed as part of each organization’s information management policies.
Alohi uses service providers to support its services, and personal information may be processed in other countries. PIPEDA does not impose a general requirement to keep all personal information in Canada: organizations remain accountable for information transferred for processing and must ensure comparable protection. Additional provincial, sector-specific, or contractual requirements may apply.
Individuals can request access to their personal information and ask for inaccurate information to be corrected. Our Privacy Policy explains how to submit requests, including requests to withdraw consent where applicable. Where a document is managed by an Alohi customer, individuals should contact that organization about its handling of the document.
Alohi maintains security monitoring and incident response practices, supported by regular security assessments. Our Privacy Policy describes our approach to notifying customers and cooperating in the investigation of data breaches, with notifications to competent authorities made in accordance with applicable law.
For your organization’s privacy review: