Launching fall 2026Get notified →
Back to home
Legal

Privacy Policy

Effective: Date pending Last updated: 2026-08-20

1. Who we are

Tessira ("Tessira", "we", "us") is the organization responsible for the personal information we collect about you (the "organization" under PIPEDA / Alberta PIPA / BC PIPA).

  • Business: Tessira Inc., an Alberta corporation. Based in Alberta, Canada; serving condominium/strata customers in Alberta, British Columbia, and Ontario.
  • Mailing address: Suite 3400-10180 101 St NW, Edmonton, AB T5J 3S4
  • Home location: Alberta, Canada (serving condominium/strata customers in Alberta, British Columbia, and Ontario)
  • Contact: privacy@tessira.ca (privacy matters) · support@tessira.ca (general)
  • Privacy Officer: Brandon Kelly, Founder (Phase I); dedicated Privacy Officer in Phase II

2. What information we collect

2.1 Information you give us directly

  • Account information: name, email, phone number (optional), and the province of the property (drives which condominium/strata legislation applies + tax)
  • Payment information: name, billing address (incl. province, used to determine sales tax); payment card details are processed by Stripe and not stored by us
  • Property information: address or description of the condo/strata property
  • Uploaded documents: condominium/strata documents you upload for review (and any documents a third party supplies on your behalf at your request under ToS §4(e))
  • Communications: emails and messages you send us, including chat with our AI assistant ("Tess")
  • Survey + interview responses: when you voluntarily provide them

2.2 Information we collect automatically

  • Usage data: pages visited, features used, timestamps
  • Device + technical data: IP address (also used as a corroborating signal for province/place-of-supply), browser type, device type
  • Cookies + similar technologies: see §8

2.3 Information from third parties

  • We do not buy personal information from data brokers
  • We may receive a referring realtor's name and, for activation, their real-estate licence number. We collect the number with the realtor's consent, use it only to verify the licence against the public provincial registry, and then store it minimally as needed to operate the referral program.
  • Where you ask us to, we receive documents from a third party (seller, realtor, or property/strata manager) on your behalf under ToS §4(e) and handle them under the same privacy and security rules as your own documents.

2.4 What we do NOT collect

  • We do not knowingly collect personal information from minors (the Service requires you to be of the age of majority; see §11)
  • We do not collect biometric data
  • We do not collect health information
  • We do not collect race, ethnicity, religious affiliation, sexual orientation, or other protected-class attributes under our anti-discrimination commitments and the applicable human-rights legislation

3. Why we collect it (purpose)

Per PIPEDA Principle 2, Alberta PIPA, and BC PIPA, we collect personal information only for purposes we identify to you:

PurposeWhat we use it forBasis
Provide the ServiceRead your documents, determine the applicable province's law, deliver your report, answer your questionsContract performance / consent
Process payment + taxCharge for the Service, apply the correct GST/HST/PST, issue refundsContract performance / legal obligation
Communicate with youSend transactional emails about your order + subscriptionContract performance
Improve the ServiceAggregate analytics to identify patterns (not your document content for training)Legitimate interest (consent where required)
MarketingSend commercial emails IF you consentConsent (CASL)
Legal + regulatoryRespond to legal process, meet tax (CRA) and other obligationsLegal obligation
SecurityDetect and prevent abuseLegitimate interest

We do not use your personal information for purposes other than these without your additional consent.

3A. Consent and commercial email (CASL)

We comply with Canada's Anti-Spam Legislation (CASL). We treat two kinds of email very differently:

  • Transactional / service messages (order confirmations, your report is ready, subscription and renewal notices, security and account messages, replies to your enquiries). These are part of delivering the Service you asked for. They are not marketing, and we send them whether or not you opt in to marketing.
  • Commercial / marketing messages (tips, guides, product news, offers). We send these only with your express consent under CASL.

Where we ask for consent (the capture points):

  • our contact form;
  • the /for-owners (and other audience-page) email capture;
  • any downloadable guide or checklist (e.g. a buyer's or investor's checklist, the "questions for your AGM" guide). When you give your email to receive one, we tell you at that point whether you are also opting in to marketing, and opting in is never required to receive the guide itself or to use the Service.

How consent works here:

  • consent is express and specific: we describe what you'll receive, identify ourselves (Tessira), and you actively opt in (no pre-checked boxes);
  • every commercial message includes a working one-click unsubscribe and our mailing address; unsubscribe requests are honoured promptly (within the CASL-required period) via a suppression list;
  • you can withdraw consent at any time (unsubscribe link, your account settings, or privacy@tessira.ca); withdrawing marketing consent does not stop the transactional/service messages above;
  • we keep records of when and how you consented (and withdrew), as CASL requires.

If a realtor or other partner refers you, that referral does not by itself sign you up for marketing. Any marketing email still requires your own express opt-in.

4. AI use

Tessira is review software built and governed specifically for condominium and strata document review in Alberta, British Columbia and Ontario. It uses state-of-the-art AI models from leading providers. Specifically:

  • Your uploaded documents are first processed by secure document-processing services in Canada, then analyzed by AI to produce findings
  • Every finding is cited to its source and verified against that source before the report is issued (we call this "The Tessira Standard"); the same governance applies to every report
  • AI may assist in drafting customer-support responses

The Service provides informational analysis only. It does not make automated decisions that produce legal or similarly significant effects about you. The purchasing and other decisions remain yours and your advisors'.

We do NOT:

  • Use your uploaded documents to train AI models
  • Provide your documents to our AI service providers for their training

You can verify any finding yourself (each is cited to its source), and you may contest a finding (through the in-report chat with Tess, or by contacting us) and request a re-analysis; we will review it, consider any new information you provide, and update it if warranted. Our 48-hour satisfaction guarantee is your additional protection.

4A. De-identified and aggregated data

We may use de-identified and aggregated information derived from the documents you submit, and from your use of the Service, to improve our services and to produce industry analytics (for example: building-level benchmarks such as reserve-fund adequacy by building age and region, special-assessment frequency, fee trajectories, and document-quality measures).

How this protects you:

  • This data is de-identified and aggregated. It describes condominium/strata corporations and buildings in the aggregate, not you as an individual, and it is not used to identify you.
  • Much of a corporation's documentation (bylaws, reserve fund studies, financial statements, minutes) is information about the corporation, not about an individual, and is retained as part of this corpus.
  • Where personal information appears in or alongside those documents, our retention approach is to anonymize rather than delete when a retention window ends or you ask us to delete. Personal identifiers are removed while the building-level facts remain.
  • We apply a minimum-aggregation guard: we suppress or bucket any statistic drawn from too few buildings to ever single out an individual.
  • We never sell or share your personal information (see §5). Any product or benchmark we build from this data uses the de-identified, aggregated layer only.

You consent to this de-identified and aggregated use by using the Service. It does not change your rights over your personal information in §9, and it does not permit us to sell your personal information.

5. Who we share information with (sub-processors)

We share personal information only with service providers needed to operate Tessira. The internal named register records each provider's role, data access, location evidence, and contract-review status.

Our current service-provider categories are derived from that internal register:

Service categoryData sharedProcessing location
Document processingUploaded document contentCanada (ca-central-1); Canada Central
AI analysis and report supportDocument-derived content and limited customer-support contextUnited States
AI-powered document searchDocument-derived text chunksUnited States
Account, order, document, and report servicesAccount information, order records, uploaded documents, and delivered reportsCanada (ca-central-1)
Website hosting and deliveryIP address and request data (page address, browser and device)United States
Transactional email deliveryEmail address and transactional email contentUnited States
Customer support and privacy communicationsEmail address and message contentLocation being confirmed
Payment processingPayment tokens, billing address, and transaction detailsUnited States and Canada
Consent-gated website analyticsWebsite interaction and technical usage data after analytics consentLocation being confirmed

Notice of changes: under PIPEDA and our customer-transparency commitments, we provide 30 days' notice of material changes to our sub-processors.

We do NOT:

  • Sell personal information to anyone
  • Share personal information with advertising networks
  • Share personal information for purposes other than service delivery

6. Cross-border data transfers

  • Document processing: Canada (ca-central-1) and Canada Central
  • AI analysis and report support: United States
  • AI-powered document search: United States
  • Account, order, document, and report services: Canada (ca-central-1)
  • Website hosting and delivery: United States
  • Transactional email delivery: United States
  • Customer support and privacy communications: Location being confirmed
  • Payment processing: United States and Canada
  • Consent-gated website analytics: Location being confirmed

Some service providers process limited information in the United States; while there, that information may be subject to lawful access by foreign authorities. By using the Service, you acknowledge the cross-border processing described above. (Alberta PIPA + BC PIPA require us to tell you about out-of-Canada processing and who to contact with questions; that is this section + §13.)

7. How long we keep your information (retention)

The schedule below applies across the Service. A fixed timer does not decide when a purpose ends. Where a one-year floor applies below, Tessira follows it as policy in every province.

Data categoryRetention rule
Account and service recordsKept for the life of the account. On closure, you have a 90-day export window, then personal identifiers are anonymized.
Uploaded documents and delivered reportsKept for the life of the account. After the closure export window, personal identifiers are anonymized and building-level content is retained in de-identified form.
Personal information used to make a decision that directly affects an individualKept while its stated purpose remains open, and never destroyed or de-identified within one year of that decision. Expiry is an event: the account is closed and every related support or dispute matter is concluded.
Payment and tax recordsKept for the period Canadian tax law requires. Personal information is then anonymized where the legal obligation permits.
Security and audit recordsKept while the security, support, or audit purpose remains open, subject to the one-year policy floor when used in a decision that directly affects an individual.
Marketing consent and suppression recordsKept while needed to prove consent or withdrawal and to honour opt-outs, subject to the one-year policy floor when used in a decision that directly affects an individual.

If you request deletion, we will delete or de-identify personal information except what we must retain for legal obligations or to honour a suppression or opt-out. Deleting your account starts the export and de-identification process above. Building-level and other de-identified information is not personal information and remains part of the service corpus.

8. Cookies, analytics, and tracking

We use a small number of cookies and similar technologies:

Cookie / technologyPurposeProviderOptional?Default
SessionKeep you logged inTessira (first-party)RequiredOn
AuthenticationVerify your identityTessira (first-party)RequiredOn
PreferenceRemember your settings (incl. your cookie choice)Tessira (first-party)RequiredOn
Analytics: Google Analytics 4 (GA4)Understand aggregate usage patterns (which pages are visited, how the site performs) so we can improve itGoogle (third-party analytics provider)OptionalOFF until you consent

Analytics is consent-gated. We use Google Analytics 4 as our analytics provider. GA4 is loaded only after you accept analytics cookies in our consent banner. Until then, no analytics cookies are set and no analytics data is sent. We run GA4 in a privacy-protective configuration (consent mode; IP addresses are not used to identify you). You can change or withdraw your choice at any time via the cookie banner / your browser settings.

What we do NOT do: we do not use advertising trackers, cross-site tracking, behavioural retargeting, or "sell"/share your information with advertising networks. GA4 is used for our own aggregate analytics only, not for advertising or to build a marketing profile of you.

(Quebec Law 25 / EU cookie-consent specifics apply only if those markets are added in Phase II/III. Before expansion, this policy must be re-verified against the current official requirements for those markets.)

9. Your privacy rights

You have the right to:

  • Access: Request a copy of personal information we hold about you under PIPEDA Principle 9
  • Correct: Request correction of inaccurate information
  • Delete: Request deletion of your account and personal information (subject to legal retention requirements)
  • Object / Restrict: Object to or restrict specific uses of your information in some circumstances
  • Portability: Receive your information in a machine-readable format
  • Withdraw consent: Withdraw any consent you previously gave (CASL marketing consent, optional data sharing, etc.), subject to legal/contractual limits
  • Flag a finding for re-analysis: If you believe an AI-produced finding in your report is incorrect, flag it and we will re-analyze that specific finding and correct it if warranted (see ToS §7)
  • Complain: File a complaint with the relevant privacy regulator (§13)

To exercise any of these rights, email privacy@tessira.ca or use the request mechanisms in your account.

10. Security

We protect your personal information with controls that are verified in our infrastructure registry:

  • The customer portal isolates each customer's data with per-user row-level access controls.
  • Service credentials are referenced through vault pointers rather than stored in code or configuration.
  • Access and system activity are recorded in the ABOS audit store.

No security is perfect. We commit to:

  • Notifying you about a security incident affecting your data when notification is warranted. Under Alberta PIPA s.34.1(1), notice to the Commissioner is made "without unreasonable delay." Under federal PIPEDA s.10.1, required reporting and individual notice are made "as soon as feasible." BC PIPA states no statutory breach-notification duty, so we do not attribute a timeframe to it.
  • Providing specific information about what was affected and what you should do (per our incident communication templates)

11. Children's privacy

The Service is intended only for adults able to enter a binding contract (18+, or 19+ in British Columbia; ToS §1). It is not directed to minors, and we do not knowingly collect personal information from anyone under the age of majority. If you believe a minor has provided us with personal information, please contact us and we will delete it.

12. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to active customers via email at least 30 days before they take effect.

13. Contact us about privacy

Email: privacy@tessira.ca Mail: Tessira, Suite 3400-10180 101 St NW, Edmonton, AB T5J 3S4, Canada

You may also contact the relevant privacy regulator:

  • Canada: Office of the Privacy Commissioner of Canada: priv.gc.ca / 1-800-282-1376 (federal PIPEDA; covers Ontario private-sector activity)
  • Alberta: Office of the Information and Privacy Commissioner of Alberta: oipc.ab.ca / 1-888-878-4044
  • British Columbia: Office of the Information and Privacy Commissioner for BC: oipc.bc.ca / 1-250-387-5629