Legal
This policy explains how AIDARO Suite collects, uses, and protects the personal information of the staff and administrators who use our software.
A note for victims, witnesses, and family members: This policy covers the personal information of staff and administrators who log in to use AIDARO software. It does not cover client records. AIDARO acts as a data processor on behalf of the organizations that use our software. If you are a client of one of those organizations and have questions about your own information, please contact that organization directly.
This policy applies to the staff, volunteers, coordinators, and administrators who use AIDARO software on behalf of their organization. These are the people who log in to the system to do their work.
The organizations that use our software are responsible for the information they collect about the people they serve. Under Canada's federal privacy law, PIPEDA, we act as a Data Processor. The organization using our software is the Data Controller.
We collect a small amount of personal information from system users. We collect only what we need to run the software and keep it secure.
We use your information strictly to operate and secure the AIDARO software. This includes:
We do not sell your personal information. We do not use it for advertising. We do not share it with third parties except where required by law or as outlined in our Data Processing Addendum.
AIDARO uses a hybrid infrastructure model. Here is a plain summary of where different types of information are stored.
Every file, document, and attachment uploaded to AIDARO is stored on dedicated servers located within Canada. These files never leave Canadian borders.
The core application platform runs on a dedicated server in the United States. This server is owned and managed exclusively by our organization. No shared cloud is involved. Because this processing occurs in the US, temporary data sets are subject to US law. Please see our Data Processing Addendum for full details.
All system backups and disaster recovery archives are encrypted and stored within Ontario, Canada. No external parties have access to these backups.
We take security seriously because the organizations that use AIDARO work with sensitive information every day. Our security measures include:
If we discover a security breach that affects your organization's data, we will notify you within 24 hours of confirming it so that you can meet your own reporting obligations under PIPEDA.
Under Canada's federal privacy law, you have the right to:
To exercise any of these rights, contact us at support@aidaro.ca. We will respond within a reasonable time.
If a victim, witness, or family member contacts us directly to ask about their own information, we will not attempt to answer on behalf of the organization. Instead, we will pass that request to the relevant organization within 48 hours. The organization is responsible for responding under PIPEDA.
We may update this policy from time to time. When we do, the updated date at the top of this page will change. We recommend checking this page periodically. For material changes, we will notify subscribing organizations directly.
If you have questions about this privacy policy or how we handle personal information, please reach us at:
AIDARO Suite
Email: support@aidaro.ca