top of page

LEGAL

Privacy Policy

How Lakha Accountax Services Inc. collects, uses, protects, and retains your personal information.

Our commitment

Lakha Accountax Services Inc. (“Lakha Accountax”, “the Firm”, “we”, “us”, “our”) is a remote accounting and tax firm incorporated in Ontario and serving clients across Canada. In the course of providing bookkeeping, payroll, tax preparation, CRA representation, and business registration services, we are entrusted with some of the most sensitive information a person or business holds. We treat that trust as central to how we operate.

This policy describes how we collect, use, disclose, store, and protect personal information, and the rights you have in relation to it. It applies to prospects, clients, former clients, website visitors, and anyone else who provides personal information to us. It is written to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada’s federal private-sector privacy law, and with Canada’s Anti-Spam Legislation (CASL).

Definitions

  • Personal information means information about an identifiable individual. It includes, for example, a name, home address, personal email, date of birth, social insurance number, income, and financial records. It does not include an individual’s business contact information (name, title, business address, business phone or email) when used to communicate with that person in their professional capacity.

  • Client means an individual, sole proprietor, partnership, or corporation that has signed an engagement letter with the Firm.

  • Privacy Officer means the person at the Firm responsible for privacy compliance, identified in Section 13.

1. Accountability

The Firm is responsible for all personal information under its control, including information transferred to third-party service providers for processing. We have designated a Privacy Officer who is accountable for compliance with this policy and with PIPEDA, and who handles all access requests, questions, and complaints. All persons working with the Firm are bound by confidentiality obligations and are required to follow this policy.

2. What we collect

We collect only the personal information reasonably needed to provide the services you have requested and to operate the Firm. The information depends on your relationship with us.

Prospects and website visitors

  • Name, email address, phone number

  • Company name, website, industry, and approximate number of employees, where you provide them on a form

  • Which guide or resource you downloaded, and which form or page you used to contact us

  • Appointment bookings, including the date, time, and any notes you add

  • Basic technical data such as browser type, device type, pages visited, and referring site

Clients

  • Full legal name, date of birth, marital status, and contact details

  • Social insurance number (SIN), business number (BN), corporation number, and CRA program account numbers

  • Fiscal year-end, incorporation documents, ownership and director information

  • Banking information, payroll records, employee details needed for payroll and T4/T5 reporting

  • Financial statements, general ledger data, receipts, invoices, bank and credit-card statements

  • Prior-year tax returns, notices of assessment, and CRA correspondence

  • Information about dependants, spouses, and household members where relevant to a tax return

  • Documents uploaded to your client portal

  • Electronically signed engagement letters and related audit trail (signer name, email, IP address, date and time)

  • Invoices, payment records, and payment confirmations

Everyone

  • Emails, messages, call notes, and other communications with the Firm

We do not collect biometric data and we do not knowingly collect personal information from individuals under 18 except as part of a parent’s or guardian’s tax return.

3. How we collect it

We collect personal information:

  • Directly from you — through forms on our website, our booking pages, guide downloads, your client portal, email, phone, text message, and video calls.

  • From the Canada Revenue Agency — once you have authorized the Firm as your representative through CRA My Business Account, CRA My Account, or a signed authorization form, we access your CRA account information through Represent a Client and file returns through EFILE.

  • From third parties you direct — such as your bank, previous accountant, bookkeeper, lawyer, or payroll provider, with your consent.

  • Automatically — through cookies and similar technologies when you use our website (see Section 10).

  • From public sources — we may contact businesses using publicly available business contact information, such as a company’s listed phone number or website. Business contact information used to reach someone in their professional role is not personal information under PIPEDA, and you can ask us to stop contacting you at any time.

4. Why we use it

We use personal information for the following purposes:

  • To respond to enquiries, schedule consultations, and follow up on requests

  • To prepare and file personal income tax returns (T1), corporate income tax returns (T2), HST/GST returns, payroll remittances, T4/T5/T5018 slips, records of employment, and other government filings

  • To perform bookkeeping, reconcile accounts, and prepare financial statements and reports

  • To register business names, incorporate companies, and open CRA program accounts on your behalf

  • To communicate with the CRA and other government bodies as your authorized representative, including responding to reviews, audits, and objections

  • To prepare, send, and obtain electronic signatures on engagement letters and other documents

  • To issue invoices, receive payments, and maintain accounting records for the Firm

  • To send guides, updates, and information you have requested or consented to receive

  • To improve our website and services

  • To meet legal, regulatory, and professional obligations, including record-retention requirements

  • To detect and prevent fraud, security incidents, and misuse of our systems

We do not use personal information for any purpose other than those listed here without first obtaining your consent, unless permitted or required by law.

5. Consent

By providing personal information to the Firm, you consent to its collection, use, and disclosure for the purposes described in this policy.

  • Express consent is obtained for sensitive information and for significant actions — for example, when you sign an engagement letter, authorize the Firm as your CRA representative, or opt in to receive marketing emails.

  • Implied consent applies where the purpose is obvious and reasonable — for example, when you submit a contact form and we reply to it.

  • Withdrawal. You may withdraw consent at any time by contacting the Privacy Officer, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent may mean we can no longer provide certain services, and we will explain the consequences before acting on your request.

We do not require consent to the collection of personal information beyond what is necessary as a condition of providing services.

6. Who we share it with

We do not sell, rent, or trade personal information.

We disclose personal information only:

To government bodies as required to serve you — primarily the Canada Revenue Agency, and where applicable provincial bodies such as the Ontario Ministry of Finance, the Ontario Business Registry, the Workplace Safety and Insurance Board, and Service Canada.

To service providers that host or support our systems. We rely on reputable third-party providers for website hosting, customer relationship management and appointment booking, email and calendar, video meetings, document storage, our client portal and electronic-signature system, invoicing and firm accounting, tax-preparation and EFILE transmission software, and payment processing. These providers process personal information only on our instructions, are permitted to use it only to provide their services to us, and are required to protect it with safeguards comparable to our own. A current list of the categories of providers we use is available from the Privacy Officer on request.

When required or permitted by law — for example, in response to a court order, subpoena, or lawful request from a regulator, or to comply with professional obligations.

In a business transaction — if the Firm is sold, merged, or reorganized, personal information may be transferred to the successor, who will be bound by this policy.

7. Information stored outside Canada

Some of our service providers store or process data on servers outside Canada, including in the United States. While your information is outside Canada it is subject to the laws of that country, and foreign governments, courts, or law-enforcement agencies may be able to access it under those laws. We select providers with strong security practices and contractual commitments to protect personal information, but we cannot guarantee that foreign law will not apply.

8. How we protect it

We use safeguards appropriate to the sensitivity of the information, including:

  • Encrypted connections (HTTPS/TLS) for our website, portal, and email systems

  • Private, unique client-portal links and access keys

  • Password-protected accounts with two-factor authentication on all systems that hold client information

  • Access limited to the people who need the information to serve you

  • Confidentiality obligations for everyone who works with the Firm

  • Secure deletion of records at the end of the retention period

We ask that sensitive documents — anything containing a SIN, bank details, or full financial records — be shared through your client portal rather than by email or text message.

No method of transmission or storage is completely secure. If we become aware of a breach of security safeguards that creates a real risk of significant harm to you, we will notify you and report the breach to the Office of the Privacy Commissioner of Canada as required by PIPEDA, and we will keep a record of the breach.

9. How long we keep it

We keep personal information only as long as needed to fulfil the purposes for which it was collected and to meet legal and professional obligations.

  • Client tax and accounting records are retained for at least six years from the end of the last tax year to which they relate, as required by the Income Tax Act and the Excise Tax Act.

  • Engagement letters and signature audit trails are retained for the life of the engagement plus six years.

  • Prospect information (form submissions, booking records, guide downloads) is retained for up to two years after the last contact, unless you become a client or ask us to delete it sooner.

  • Firm financial records are retained as required by law.

When information is no longer needed, it is securely deleted from our systems and from our service providers’ systems where we control that data.

10. Cookies and website analytics

Our website uses cookies that are necessary for it to function and may use basic analytics to understand how visitors use the site. We do not use cookies to track you across other websites for advertising. You can control or delete cookies through your browser settings; disabling necessary cookies may affect how parts of the site work.

Our booking pages and forms are provided through a third-party platform embedded in our site; that platform may set its own cookies to make the booking process work.

11. Marketing communications

We send commercial electronic messages only in accordance with CASL. You will receive marketing emails from us only if you have requested a guide or resource, asked to be kept informed, or are an existing client. Every marketing email includes an unsubscribe link, and you can also opt out at any time by replying to a message or contacting the Privacy Officer. Opting out of marketing does not affect service-related messages such as appointment confirmations, invoices, or filing reminders.

12. Your rights

You have the right to:

  • Know what personal information we hold about you and how it has been used and disclosed

  • Access that information, subject to limited legal exceptions

  • Correct information that is inaccurate or incomplete

  • Withdraw consent, subject to Section 5

  • Request deletion, where retention is not required by law

  • Complain about our handling of your information

To exercise any of these rights, contact the Privacy Officer in writing. We may need to verify your identity before responding. We will respond within 30 days; if more time is needed we will tell you why and when to expect a reply. Access is provided free of charge except where the request is unusually large, in which case we will give you an estimate before proceeding. If we refuse a request, we will explain the reason and how to challenge the decision.

Residents of Quebec, Alberta, and British Columbia may have additional rights under their provincial privacy laws; we honour those rights where they apply.

13. Contact us

Questions, access or correction requests, consent withdrawals, and complaints should be directed to our Privacy Officer:

Abdul Wahab, Privacy Officer
Lakha Accountax Services Inc.
Milton, Ontario, Canada
Email: info@lakhaaccountax.com
Phone: (289) 670-2820

 

We operate remotely. Access requests, complaints, and other written correspondence are accepted by email. If you require a mailing address, contact us and we will provide one.

 

We will investigate every complaint and respond in writing. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada:

 

Office of the Privacy Commissioner of Canada
30 Victoria Street, Gatineau, Quebec K1A 1H3
Toll-free: 1-800-282-1376
Website: priv.gc.ca

14. Changes to this policy

We review this policy at least annually and update it when our practices, service providers, or the law change. The effective date at the top shows when it was last revised. Material changes will be posted on this page, and clients will be notified by email. Continued use of our services or website after a change means you accept the updated policy.

bottom of page