Canadian-established · Virtual boutique advisory across six global markets · +1 (226) 749-3621

Security

Security & Data Protection

The safeguards NDS applies to protect confidential client, tax and financial information.

Last updated: September 24, 2026

Important: This policy is intended to describe NDS practices and allocate responsibilities. It is not legal advice. NDS should have Canadian counsel review it periodically and whenever its services or data practices change.

1. Our commitment

NDS Consulting Inc. treats client tax, financial and identity records as highly sensitive confidential information. This Security and Data Protection Statement describes the administrative, technical and physical safeguards NDS applies, consistent with PIPEDA's safeguarding principle, applicable provincial privacy laws, CRA guidance for tax preparers and professional confidentiality obligations.

2. Confidentiality

All client information is confidential. Personnel and contractors with access are bound by confidentiality obligations and access information only as needed for an engagement. NDS does not sell, rent or trade personal information and does not use client documents to train public AI models.

3. Encryption

Data sent between your browser or phone and NDS systems is encrypted in transit using HTTPS/TLS. Documents, records and databases are stored with encryption at rest by our cloud infrastructure providers. Payment card details are handled directly by a PCI DSS–compliant payment processor; NDS never receives or stores full card numbers.

4. Access control and authentication

The client portal requires authenticated sign-in (Google, password or secure one-time email link). Row-level security rules ensure each client can only see their own documents, invoices, messages and filings. Staff tools are restricted to authorized NDS accounts, and document downloads use short-lived signed links rather than public URLs.

5. Secure document handling

Uploaded files are stored in private storage, never on public web pages. We ask clients not to send SINs, banking credentials, passwords or CRA access codes by ordinary email or public forms; please use the secure portal. NDS will never ask for your CRA My Account password.

6. Monitoring and incident response

NDS and its providers maintain security logs, monitor for unusual activity and apply updates. If a breach of security safeguards creates a real risk of significant harm, NDS will notify affected individuals and report to the Office of the Privacy Commissioner of Canada as required by PIPEDA, keep a record of the breach and take steps to contain it.

7. Service providers

NDS uses reputable cloud hosting, authentication, email, scheduling and payment providers bound by contractual confidentiality and security obligations. Some may process data outside Canada, where it may be subject to foreign law; see the Privacy Policy.

8. Your role

Use a strong, unique password or Google account with two-step verification, keep your devices updated, sign out on shared devices and report suspected unauthorized access immediately to privacy@ndsconsulting.ca. No system is completely secure, and NDS cannot guarantee absolute security of information transmitted over the internet.