Your information
Confidentiality is the core of what an accountant does. This policy explains what personal information Local Ledger CPA collects, why, who sees it, how long we keep it, and what you can ask of us.
Last updated
September 23, 2026
Applies to
This website, prospective clients and clients
Governing law
PIPEDA and the laws of Ontario
•
We collect only what we need to answer you and to do your accounting, tax and payroll work.
•
We never sell or rent personal information, and we do not use advertising or tracking cookies on this website.
•
We share information only with the people who need it to do the work (such as the Canada Revenue Agency when we file for you), with trusted service providers bound to protect it, or when the law requires it.
•
You can ask to see, correct or withdraw consent for your information at any time by writing to our Privacy Officer.
01
Local Ledger CPA (“Local Ledger”, “we”, “us”) is a firm of Chartered Professional Accountants located at 320 Plains Road East, Burlington, Ontario L7T 0C1. We provide bookkeeping, tax compliance, business valuation, payroll and HR, management reporting and strategic advisory services to small and medium-sized businesses.
This policy applies to personal information we collect through this website, by email, phone or in person, and in the course of providing services. “Personal information” means information about an identifiable individual. Information about a business itself, such as its legal name or business number, is generally not personal information, but we protect it with the same professional confidentiality.
02
Ontario does not have its own general privacy law for private businesses, so our handling of personal information is governed by the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and its ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance.
We are also bound by:
•
the confidentiality obligations of the CPA Ontario Code of Professional Conduct, which prohibit us from disclosing confidential client information except with your consent or where the law or our professional obligations require it;
•
Canada’s Anti-Spam Legislation (CASL) for commercial electronic messages;
•
the record-keeping rules of the Income Tax Act, the Excise Tax Act and other tax and employment laws that set how long certain records must be kept.
The federal government has proposed replacing PIPEDA with a new statute (Bill C-36, the proposed Protecting Privacy and Consumer Data Act). As of the date above it has not become law. We will update this policy if and when it comes into force.
03
You can read this website without telling us who you are. If you use the contact form, we collect your business name, email address and the message you write. Our web host may automatically record standard technical information, such as your IP address, browser type and the pages requested, in server logs used for security and troubleshooting.
Your name, business name, contact details, and whatever you choose to tell us about your business and what you need. If you book a call, we receive the details you enter in the booking tool.
Depending on the engagement, this may include:
•
names, addresses, phone numbers, email addresses and dates of birth of owners, directors and shareholders;
•
Social Insurance Numbers and CRA identifiers needed to prepare and file returns;
•
financial records, bank and credit card statements, invoices, receipts, and tax slips and assessments;
•
identity verification information we are required to collect under professional and anti-money-laundering standards;
•
for payroll and HR services, information about your employees, such as names, addresses, Social Insurance Numbers, pay rates, hours, deductions, banking details for direct deposit, and records of employment.
Where you give us personal information about other people, such as employees, shareholders or family members, you confirm that you have the authority to share it with us for the purposes in this policy.
04
We use personal information only for the purposes we identify when we collect it, or that a reasonable person would consider appropriate in the circumstances, including to:
•
respond to your enquiries and schedule consultations;
•
confirm your identity and decide whether we can accept an engagement;
•
deliver the services you engage us for, including preparing and filing returns and remittances on your behalf;
•
bill for our services and manage our client relationship;
•
meet our legal, regulatory and professional obligations, including practice inspection and quality-management requirements;
•
send you information you have agreed to receive (see section 9).
We do not use your information for any new purpose without first asking for your consent, unless the law allows or requires it.
05
We ask for your consent when we collect personal information. Consent may be express, for example when you tick the box on our contact form or sign an engagement letter, or implied, for example when you email us a question and expect a reply. For sensitive information, such as Social Insurance Numbers and financial records, we rely on express consent, normally given through your engagement letter.
You can withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. We will explain what withdrawing consent means. For example, we cannot file a tax return without the information it requires, and we cannot delete records the law obliges us to keep.
07
We prefer providers that store data in Canada. Some of our service providers, including those that process our website form, booking and email, may store or process information outside Canada, most often in the United States. When they do, the information is protected by our contracts with them, but it may be accessible to courts, law enforcement and national security authorities in that country under its laws. You can ask our Privacy Officer which providers we use and where they store data.
08
This website does not use advertising cookies, analytics or tracking pixels, and it does not build a profile of you. Its fonts and images are served from the site itself rather than from third-party networks.
•
Contact form. What you submit is transmitted to a third-party form service that delivers it to our inbox. It is used only to respond to you.
•
Booking a call. Our “Book a call” buttons take you to an external scheduling service. Anything you enter there is also governed by that service’s own privacy policy.
•
Social media. Links to our Facebook, Instagram and LinkedIn pages take you to those platforms, which have their own privacy practices. We do not embed their tracking on our pages.
If we ever add analytics or other cookies that are not strictly necessary, we will update this policy first and, where required, ask for your consent.
09
We send commercial electronic messages, such as newsletters, tax-season reminders and service updates, only with your consent as required by CASL. Every such message identifies us, includes our contact information and contains a working unsubscribe link. We will act on an unsubscribe request within 10 business days. Messages that are necessary to deliver services you have engaged us for, such as filing deadlines and invoices, are not marketing and will continue while you are a client.
10
We keep personal information only as long as needed for the purposes it was collected for, or as long as the law and our professional standards require.
•
Client files and working papers: generally at least six years after the end of the last tax year they relate to, in line with the Income Tax Act and the Excise Tax Act, and longer where a matter is under review, appeal or dispute.
•
Enquiries from people who do not become clients: up to 24 months, then deleted.
•
Records of privacy breaches: at least 24 months, as PIPEDA requires.
When information is no longer needed, we securely destroy it by shredding paper records and permanently erasing electronic ones, or we make it anonymous.
11
We protect personal information with safeguards appropriate to its sensitivity, including:
•
physical measures, such as locked offices and filing cabinets;
•
technical measures, such as encryption, multi-factor authentication, access controls, secure client portals and up-to-date security software;
•
organizational measures, such as confidentiality agreements, staff privacy training, and access granted only to people who need it for their work.
Please do not send Social Insurance Numbers or full financial records by ordinary email. Ask us for a secure upload link instead.
12
If a breach of security safeguards involving your personal information creates a real risk of significant harm to you, we will notify you as soon as feasible and report it to the Office of the Privacy Commissioner of Canada, as PIPEDA requires. We will tell you what happened, what information was involved, what we have done, and what you can do to reduce the risk. We may also notify other organizations, such as banks or government agencies, that can help reduce the harm.
13
Under PIPEDA you have the right to:
•
access the personal information we hold about you and learn how it has been used and to whom it has been disclosed;
•
correct information that is inaccurate or incomplete;
•
withdraw consent, subject to the limits in section 5;
•
challenge our compliance with this policy and the law.
Send your request in writing to our Privacy Officer. We may ask you to verify your identity. We will respond within 30 days, or tell you within that time if we need an extension permitted by law. Access is free of charge; if a request would involve significant cost, we will give you an estimate first. If we cannot give you access to some information, for example because it would reveal personal information about someone else or is subject to legal privilege, we will tell you why.
14
Our services and this website are intended for adults and businesses. We do not knowingly collect personal information from children through this website. Where a client’s tax or payroll work involves information about a minor, such as a dependant, we collect it from the parent or guardian and protect it under this policy.
15
We have designated a Privacy Officer who is accountable for our compliance with this policy. Please contact them with any question, request or concern:
Privacy Officer, Local Ledger CPA
320 Plains Road East, Burlington, Ontario L7T 0C1
hello@localledgercpa.ca (subject line “Privacy request”)
825-888-0777
We will investigate every complaint and, if it is justified, take appropriate steps, including changing our practices. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada, 30 Victoria Street, Gatineau, Quebec K1A 1H3, toll-free 1-800-282-1376, priv.gc.ca.
16
We may update this policy to reflect changes in the law, including the proposed replacement of PIPEDA, or in how we work. The “Last updated” date at the top shows when it last changed. If we make a significant change to how we use information we already hold, we will tell our clients directly before it takes effect.
A specialized CPA firm dedicated to the financial health of small and medium enterprises.
© 2026 Local Ledger CPA. Burlington, Ontario.
Chartered Professional Accountants · Privacy Policy