Privacy Policy
Effective Date: [Effective Date]
Last Updated: [Last Updated Date]
1. Introduction
Welcome to Exodus OS, operated by [Legal Company Name] ("Kalbot Solutions", "we", "us", or "our"). Exodus OS is a Canadian software-as-a-service (SaaS) platform designed for property management companies, landlords, tenants, vendors/contractors, and internal property management teams.
This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you use our website (https://exodusos.ca), platform, and related services (collectively, the "Services").
2. Scope
This policy applies to website visitors, prospects, customers, account users, property managers, landlords, tenants, vendors/contractors, and other individuals whose information is processed through Exodus OS.
Please note that customer organizations using Exodus OS are responsible for their own privacy notices and the lawful use of the data they upload, collect, or manage through the platform. In many cases, Kalbot Solutions acts as a service provider/processor processing data on behalf of our customers.
3. Personal Information We Collect
Depending on how you interact with Exodus OS, we may collect:
- Account and identity information: Name, email address, phone number, company name, role, and login details.
- Property management information: Property records, unit records, lease details, tenant records, landlord records, vendor records, maintenance requests, inspections, notices, tasks, files, documents, photos, communications, signatures, and related operational records.
- Financial/accounting information: Invoices, payments, charges, ledger entries, vendor bills, rent/payment status, QuickBooks IDs, sync status, transaction metadata, and accounting integration data. Exodus OS does not intentionally collect full bank login credentials unless expressly stated through an authorized integration.
- Communication data: Emails, SMS messages, call logs (if applicable), in-app messages, support tickets, chat logs, notification preferences, and delivery status.
- Technical data: IP address, browser type, device information, operating system, pages visited, timestamps, system logs, cookies, analytics events, and security events.
- AI interaction data: Prompts, messages, business-data queries, AI-generated outputs, feedback, and metadata where AI features are used.
- Billing/subscription data: Plan details, usage metrics, invoices, and payment status. Payment card data, if applicable, is handled securely by third-party payment processors.
4. How We Collect Information
We collect personal information in several ways:
- Directly from users when creating an account or using the platform.
- From customer organizations and their administrators.
- From tenants, landlords, vendors, contractors, and invited users interacting with the platform.
- Through website forms, onboarding processes, customer support, and general platform use.
- Through authorized integrations and APIs, including QuickBooks Online / Intuit, email/SMS providers, calendar tools, CRM tools, cloud storage, and other connected services.
- Automatically through cookies, system logs, and analytics tracking.
5. Why We Use Personal Information
We use personal information to:
- Provide, operate, maintain, and improve Exodus OS.
- Manage accounts, authentication, roles, permissions, and security.
- Support property management workflows.
- Generate notices, documents, reminders, communications, reports, tasks, inspections, maintenance workflows, ledgers, invoices, and operational records.
- Sync data with QuickBooks Online and other authorized integrations.
- Send transactional and service-related communications.
- Send marketing communications (only where permitted by law and with unsubscribe options where required).
- Provide customer support.
- Monitor security, prevent abuse, debug issues, audit activities, and maintain system logs.
- Analyze usage trends and improve features.
- Provide AI-assisted features.
- Comply with legal, tax, accounting, contractual, and regulatory obligations.
- Enforce our Terms of Service and resolve disputes.
6. Consent and Legal Basis
By using Exodus OS, you consent to the collection, use, and disclosure of your personal information as described in this policy. Consent may be express or implied depending on the context and applicable Canadian privacy law (such as PIPEDA).
You can withdraw your consent where legally available by contacting us. However, withdrawing consent may limit or prevent your use of the platform.
Organizations using our platform are responsible for obtaining any necessary consents from tenants, landlords, vendors, employees, contractors, and other individuals whose data they enter or process through Exodus OS.
7. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to improve your experience. These may include:
- Essential cookies: Required for the platform to function.
- Authentication/security cookies: Used to keep you logged in and secure your account.
- Preference cookies: Used to remember your settings.
- Analytics cookies: Used to understand how visitors interact with our website.
- Advertising/remarketing cookies: Used to deliver relevant advertisements (if applicable).
You can manage or disable cookies through your browser settings or our cookie consent banner. Please note that disabling essential cookies may impact the functionality of the platform.
8. Communications, Email, SMS, and CASL
Exodus OS may send transactional or service messages, such as account alerts, security notices, workflow notifications, rent/payment notices, maintenance updates, reminders, and support messages.
Marketing messages are sent only where permitted by Canada's Anti-Spam Legislation (CASL). Commercial electronic messages include required sender identification and an unsubscribe/opt-out mechanism. You can unsubscribe from marketing communications at any time, but you may still receive necessary transactional, security, or service messages.
Customers are responsible for ensuring that their own messages sent through Exodus OS comply with CASL and other applicable laws.
9. QuickBooks Online / Intuit Integration
If a customer connects QuickBooks Online, Exodus OS may access and sync authorized QuickBooks data such as customers, vendors, invoices, payments, accounts, items/products/services, taxes, bills, journal/ledger-related metadata, and sync identifiers depending on enabled features.
Access is authorized through Intuit/QuickBooks OAuth or other approved authorization flow. Exodus OS uses QuickBooks data only to provide requested accounting, invoicing, reconciliation, reporting, and property management features. We do not sell QuickBooks customer data, nor do we share it across customer accounts except in aggregated/anonymized form where permitted.
Users can disconnect or revoke access at any time, but doing so may disable sync features. Customers remain responsible for reviewing accounting records, tax treatment, invoices, financial reports, and QuickBooks data accuracy. Exodus OS is not accounting, tax, legal, or financial advice.
[Insert any additional Intuit-required production review language here]
10. AI Features and Automated Outputs
Exodus OS may include AI-assisted features for drafting messages, documents, listings, summaries, workflows, classifications, support, search, and business insights.
AI output can be incomplete, inaccurate, outdated, or inappropriate. Users must review AI-generated content before using it, especially legal notices, lease documents, accounting entries, tenant communications, and financial reports. Exodus OS does not replace legal counsel, accountants, tax advisors, licensed property managers, or professional judgement.
Customer administrators are responsible for deciding whether AI features are appropriate for their organization. Users must not submit prohibited or sensitive information unless authorized.
11. How We Share Information
We may share personal information in the following circumstances:
- Within customer accounts and to authorized users based on configured permissions.
- With trusted service providers and processors who assist in operating our platform.
- With third-party integrations authorized by the customer.
- With professional advisors (such as lawyers or accountants).
- In connection with a business transfer, merger, or acquisition.
- To comply with the law, court orders, regulators, or lawful requests.
- To protect our rights, security, users, and the integrity of the platform.
We do not sell personal information.
12. Third-Party Services and Integrations
Third-party tools and integrations have their own terms and privacy policies. Examples of potential third-party providers include:
- Intuit / QuickBooks Online
- GoHighLevel
- Supabase
- Vercel
- OpenAI or other AI providers
- Email, SMS, and voice communication providers
- Payment processors
- Analytics providers
- Cloud hosting and storage providers
13. Data Storage, Location, and Cross-Border Transfers
Your data may be stored and processed in Canada, the United States, and other jurisdictions by our service providers. As a result, your personal information may be subject to the laws of those jurisdictions, including lawful access requests by government authorities.
14. Security Safeguards
We maintain administrative, technical, and physical safeguards to protect personal information. These include encryption in transit, access controls, role-based permissions, authentication, secure backups, monitoring, vendor controls, least-privilege access, and incident response procedures where applicable.
While we strive to protect your data, no system is 100% secure, and we cannot guarantee absolute security.
15. Data Retention
We retain personal information for as long as needed to provide our services, maintain an active account, fulfill legal, accounting, and tax obligations, resolve disputes, maintain backups and security logs, and for legitimate business purposes.
Customers may request data deletion subject to legal and technical limitations.
16. Access, Correction, Deletion, and Privacy Requests
You have the right to request access to, correction of, or deletion of your personal information, subject to applicable law. To make a request, contact our Privacy Officer. We may require identity verification before disclosing information.
Please note that if your information is controlled by an Exodus OS customer (such as your property manager), we may need to direct your request to that customer organization.
17. Children's Privacy
Exodus OS is business software and is not intended for use by children or minors.
18. Breach and Incident Handling
We maintain incident response procedures. In the event of a security breach involving personal information, we will assess the incident and handle notifications in accordance with applicable legal obligations.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Material changes may be communicated to active account holders.
20. Contact Information
If you have any questions, concerns, or privacy requests, please contact us:
Privacy Officer: [Privacy Officer Name]
Email: [Privacy Email]
Support: [Support Email]
Business Address: [Business Address]
