Privacy Policy
Effective date: September 16, 2026 Last updated: September 16, 2026
1. Introduction
Jacques Amzallag, operating CertificateIQ under the CourtageIQ banner ("CertificateIQ", "we", "us", "our"), offers the CertificateIQ service at certificateiq.ca (the "Service"). CertificateIQ lets licensed property and casualty insurance brokers produce certificates of insurance and cover notes from their insurers' documents.
This Policy explains how we collect, use, disclose, retain and protect personal information. It applies to the people who create an account (the "Brokers"), to the people whose information appears in dropped or issued documents (insureds, mortgagees, certificate holders, together the "Document Subjects"), and to people who consult a verification page.
This Policy is governed by Quebec's Act respecting the protection of personal information in the private sector ("Law 25") and, where applicable, by the Personal Information Protection and Electronic Documents Act (Canada, "PIPEDA"). If any provision of this Policy conflicts with the law, the law prevails.
2. Person in charge of the protection of personal information
- Name: Jacques Amzallag
- Title: Person in charge of the protection of personal information
- Email: privacy@certificateiq.ca
- Mailing address: 4001 Crémazie Street East, Suite 100, Montréal, Québec H1Z 2L2, Canada
You may contact this person at any time to exercise your rights, ask a question or file a complaint.
3. Our two roles
3.1 We are the controller of Brokers' information. When you create an account we collect your information directly (name, work email, licence numbers, brokerage, billing and usage data). We decide its purposes and are responsible for it.
3.2 We are a service provider for Document Subjects' information. The insurance documents you drop and the certificates you issue contain information about your clients and the third parties they name. You, the Broker, are the controller of that information under Law 25; we process it on your behalf, on your instructions, only to provide the Service. If you are a Document Subject and wish to exercise your rights, contact the brokerage that serves you first.
4. Information we collect
4.1 Provided by the Broker
- Account: name, work email address, password (hashed), language.
- Professional profile: province(s), regulator and licence number(s), brokerage name, phone, declared categories (personal, commercial), date of the licence declaration, marketing consent (optional, with its date).
- Billing: plan, number of seats, customer and subscription identifiers at our payment provider. Card data is collected and stored by Stripe, never by us.
- Firm: the work email addresses to which a Firm account gives seats.
4.2 Contained in documents
When you drop an insurance document it usually contains: the named insured's name and address, insured locations, vehicles (make, model, year, identification number), coverages, limits and deductibles, mortgagees and other interested parties, policy number, period and the brokerage of record. The issued document repeats the elements you confirmed, plus the certificate holder's name, address and email that you provide.
4.3 Collected automatically
- Issue log: for each issued document, the date, IP address and browser used, for evidentiary purposes and abuse prevention.
- Reads before sign-in: a one-way hash of your IP address, to apply the free-read limit. The IP address itself is not kept.
- Technical and usage data: pages visited, actions taken, timestamps, browser type, error rates.
- Cookies: strictly necessary cookies only (sign-in session, interface language). No advertising or third-party analytics cookies.
4.4 From third parties
- Public domain-registration data: to confirm a brokerage we consult the public registers (RDAP) of your work email's domain and, if needed, the brokerage's website. We keep the facts obtained (domain creation date, presence of the brokerage's name), not the page itself.
- Identity check: in the rare cases where the brokerage cannot otherwise be confirmed, we may offer an identity check through Stripe Identity. Stripe then collects an identity document and an image; we receive only the result (verified or not) and a session identifier. We never receive or keep the identity document.
- Regulators' registers: we never query, copy or keep any register of the Autorité des marchés financiers, RIBO or any other regulator.
5. Why we use this information
- To provide the Service: read the source document, present the values for your confirmation, produce the PDF, feed the verification page, send the document to the holder at your request, keep your inventory according to your plan.
- To confirm the brokerage: match the brokerage printed on the document to your email domain, to domains already confirmed and to the brokerage's website.
- To print your professional identity: your name, brokerage and licence numbers appear on every document you issue, as your practice requires.
- To bill paid plans through Stripe.
- To communicate with you: sign-in links, periodic reconfirmation of the work address, expiry and renewal alerts, replies to your reports, security notices. No marketing without your consent.
- To improve the reader: when you report a reading error, the document, the reading and your corrections are reviewed by us to fix the reader. Outside a report, we do not analyze the content of your documents for improvement; only de-identified usage signals are used.
- To prevent abuse and comply with the law: detecting abnormal volumes, multiple accounts or uses contrary to the Terms; answering valid legal requests.
We use the information for no other purpose without your consent.
6. Disclosure
We sell no personal information. We disclose it only:
- to our sub-processors, listed at /legal/subprocessors, contractually bound to process it for us alone;
- to the members of your brokerage, on the Firm plan, who share the same inventory;
- to the recipients you choose, when you send a document by email from the Service; you are always in copy;
- to the public, in a limited way, through the verification page: document status, number, named insured, insurer, period and coverages for a commercial policy; for a personal-lines policy, amounts appear only after the last four characters of the number printed on the document are entered;
- to authorities, only on a valid legal request, with notice to you where the law allows;
- in a business transfer, with notice and the option to close your account before the transfer.
7. Transfers outside Quebec
Some sub-processors are located outside Quebec:
- Anthropic, PBC (United States): document reading by artificial intelligence.
- Vercel, Inc. (United States): application hosting.
- Resend, Inc. (United States): email delivery.
- Stripe, Inc. (United States): payments and identity checks.
- Supabase, Inc. (US company; data hosted in Canada, AWS region ca-central-1, Montréal): database, authentication and files.
In accordance with section 17 of Law 25 we assessed, for each transfer, the sensitivity of the information, the purposes, the protection measures and the applicable legal regime. Each sub-processor is bound by an agreement imposing encryption in transit and at rest, incident notification, restricted access and a prohibition on using the information for its own purposes. A summary of these assessments is available on request at privacy@certificateiq.ca.
8. Retention
| Category | Period |
|---|---|
| Broker account and profile | While the account is active, then 30 days after the closure request |
| Source document (Free plan) | Deleted 24 hours after issue, or 24 hours after drop if no document is issued |
| Source document (Pro and Firm plans) | 30 days after drop |
| File dropped before sign-in | 24 hours |
| Issued document, PDF (Free plan) | Downloadable for 24 hours, then deleted |
| Issued document, PDF (Pro and Firm plans) | While the account is active, and up to 7 years after the document expires |
| Ledger entry of an issued document (number, status, elements shown on the verification page) | 7 years after the document expires or is revoked, on every plan, so the verification page stays reliable |
| Issue log and action log | 7 years, with the ledger entry |
| Reading-error report (copy of the document, reading, corrections) | Up to 12 months after the report is handled |
| IP hash of reads before sign-in | 90 days |
| Billing records | 7 years from the transaction (tax law) |
| Backups | Purged within 7 days of deletion of the primary record |
| Inference logs at our AI provider | Up to 30 days, for abuse detection, never for training |
After these periods, information is securely deleted or irreversibly anonymized.
9. Your rights
If you are a Broker you have the right to be informed, to access your information, to have it corrected, to request its deletion subject to legal retention obligations, to withdraw consent where processing relies on it, to receive your information in a structured, commonly used format (the Service offers an export of your inventory), and to be informed of any decision based exclusively on automated processing. CertificateIQ makes no such decision about you: the artificial-intelligence reading is a proposal that you confirm or correct.
To exercise your rights, write to privacy@certificateiq.ca. We answer within 30 days and may need to verify your identity. Exercising your rights is free except for manifestly abusive requests.
If you are a Document Subject, contact the brokerage that issued the document first. We will help it respond.
10. Artificial intelligence
Documents are read by an Anthropic model. The content of the dropped document is sent to Anthropic for reading and returned to us in structured form. This reading is the Service's core function and cannot be turned off. Anthropic does not train its models on our data and keeps inference logs for at most 30 days. The model makes no decision: every value is checked by code and confirmed by the Broker before it appears on a document.
11. Security
We apply reasonable measures: encryption in transit (TLS 1.2 or higher) and at rest; access control per brokerage and per role; logging of significant actions; restricted administrative access with multi-factor authentication; signed, time-limited download links; periodic review of sub-processor access. In the event of a confidentiality incident presenting a risk of serious injury, we notify the Commission d'accès à l'information and the people concerned in accordance with Law 25.
12. Minors
The Service is for professionals. We do not knowingly collect information from people under 14. An insurance document may name a minor; you are then its controller, as the Broker.
13. Complaints
Write first to privacy@certificateiq.ca. If you are not satisfied with our answer, you may file a complaint with the Commission d'accès à l'information du Québec:
Commission d'accès à l'information du Québec 525, boulevard René-Lévesque Est, 2e étage, bureau 2.36 Québec (Québec) G1R 5S9 Telephone: 418 528-7741 (Québec) / 514 873-4196 (Montréal), toll-free 1 888 528-7741 Website: https://www.cai.gouv.qc.ca
14. Changes
We may update this Policy. Material changes are announced at least 30 days before they take effect, by email or by a banner in the Service, and the "Last updated" date is adjusted.
15. Contact
- Email: privacy@certificateiq.ca
- Mailing address: 4001 Crémazie Street East, Suite 100, Montréal, Québec H1Z 2L2, Canada
For any other question: support@certificateiq.ca.
This Privacy Policy was last updated on September 16, 2026. Earlier versions are available on request.