The Doorr platform is an online broker management platform for mortgage brokers (“Brokers”) that manages workflow from mortgage applications to client engagement.
- Collection of Personal Information
We collect personal information that you provide to us or authorize us to collect. We also collect information automatically when you use the Service (e.g., cookies and other technical data described in Section 4 below). For example, we collect your personal information when:
- You register for an account or make a purchase on the Service;
- You communicate with us;
- You input information on the Service, such as when you upload documents or information to your account; and/or
- You choose to sync/integrate a third party account or service (e.g., an email account or an account with a financial institution) with the Service.
We may collect the following information:
- Contact and account registration information, such as full name, physical address, email address, phone number and image/photo.
- Payment information, including credit card details.
- Information that you input / upload on the Service in connection with a mortgage application, such as Social Insurance Number, demographic information (e.g., date of birth and marital status), employment and salary information, property information (e.g., property value, mortgage and down payment) and financial information (e.g., financial holdings, assets, investments, income and indebtedness).
- Information that you provide when you integrate/sync a third-party account or service with the Service, such as banking information through bank account integration and email communications, contacts and calendar information through email account integration (as set out below).
- Broker registration or licensing information.
- Communications on the Service.
- Information you provide to us when you contact us, provide feedback, make a complaint or other inquiries.
- Other personal information required to provide you with access to the Service.
Information about Another Person
You may be able to enter personal information about another person on the Service (e.g., employees, clients or a co-applicant). In such cases, you are responsible for ensuring that you are compliant with relevant data protection laws, including obtaining the necessary consent for sharing another individual’s personal information with us.
- Use of Personal Information
We use personal information to:
- Register and manage an account.
- Verify your identity and the information that you provide to us.
- Deliver and provide access to the Service and the tools and features that you have requested through the Service.
- Facilitate interaction between Brokers and their clients.
- Verify transactions and process payments.
- Send you communications and notifications, including updates on your subscription or account.
- Send you promotional communications such as special offers on products and services, newsletters or other promotions (if you have opted-in to receive such communications).
- Administer, troubleshoot, improve and manage the Service.
- Analyze the accuracy and effectiveness of the Service.
- Analyze and understand our visitors.
- Meet obligations as required by applicable laws.
- Detect and prevent fraud or other illegal or unauthorized activities.
- Tailor and personalize your experience while visiting and using the Service.
- Respond to inquiries, complaints, disputes and other communications to us.
- Other purposes that we identify to you from time to time.
- Payment Processor
- Technical Data and Analytics
Like many online services, we automatically collect technical data when you visit and use the Service.
Technical Data: When you access and use the Service, we may automatically collect certain technical information about your visit, including the date, time, browser type, your internet service provider, your IP address, device information (including device identifiers), geo-location information, computer and network performance data, the version of the application that you are using, the URL that you are coming from and your navigation history in order to customize and personalize your experience on the Service, improve the Service, understand usage of the Service and for statistical research purposes.
Cookies and similar technologies: We use “cookies” (session and persistent), scripts, pixel tags, web beacons and other similar technologies and digital markers on the Service. These automatically collect data from a visitor to the Service. Cookies help us recognize repeat visitors, personalize the Service and communications and tailor content to match particular interests. We also use these technologies to track usage trends and patterns on the Service.
You are always free to decline cookies. If you decline “cookies” or delete them from your computer, you will still be able to access the Service, but you may find that some areas do not work as smoothly as when cookies are enabled on your system.
- Disclosure of Personal Information
We disclose personal information that we hold to third parties in the following circumstances:
Lenders: We may disclose your personal information to financial institutions and other lenders in connection with your mortgage application.
Required by Law: We will disclose personal information in our custody when we believe that the disclosure is required by law, including to comply with a judicial proceeding, court order, or legal process served on us and when we receive a request from law enforcement authorities. We will only disclose personal information to law enforcement authorities upon demonstration of lawful authority.
Investigations: We will disclose personal information where it is reasonable for the purposes of investigating a breach of an agreement or a contravention of the law that has been, is being or is about to be committed and it is reasonable to expect that disclosure with the knowledge or consent of the individual would compromise the investigation.
Fraud: We will disclose personal information where it is reasonable for the purposes of preventing, detecting or suppressing fraud and it is reasonable to expect that the disclosure with the knowledge or consent of the individual would compromise the ability to prevent, detect or suppress the fraud.
Business Transaction: We may disclose and share your personal information to explore and/or undertake a corporate transaction, including a merger, acquisition, amalgamation, IPO, reorganization or sale of Doorr and/or the Platform. We will enter into an agreement that ensures that your personal information will be used and disclosed solely for the purposes related to the transaction and will be protected by security safeguards appropriate to the sensitivity of the information.
- Transfer of Personal Information
We may transfer personal information to third-party service providers, suppliers and sub-contractors who assist us in providing and administering the Service. We may transfer personal information to a third-party service provider outside of your jurisdiction of residence for storage and processing. In the event that your personal information is transferred abroad, the government, courts, law enforcement or regulatory agencies of that jurisdiction may be able to obtain disclosure of the data through the laws of that jurisdiction.
However, all mortgage-related personal information is stored and processed only in Canada.
- Aggregate Data
We may aggregate (i.e. assemble on a basis that does not enable one to personally identify you) the information we collect from you, including any technical data we automatically collect. Aggregated data may be used by us to improve the Service, to conduct data analytics and for marketing purposes, and may be shared with and used by our partners, advertisers and other third parties.
- Security of Personal Information
We are committed to data security and protect personal information through integrated physical, technological and administrative safeguards. In particular, personal information is protected by security safeguards appropriate to the level of sensitivity of the data through (i) physical measures, such as secure areas; (ii) technical measures, such as secure servers; and (iii) organizational measures such as access policies based on the need-to-know and employee security through vetting and supervision.
Secure Data Storage: Doorr’s document management system uses server side encryption based on AES-256. Doorr’s databases are encrypted at rest and in transit using Amazon Web Services (AWS) Key Management Service. All Doorr servers are located with AWS (Amazon Web Services Cloud). Further information on AWS security can be found at the following link: http://aws.amazon.com/security/.
Incident Management: Door has implemented an incident management program designed to prevent, assess and mitigate unauthorized access to personal information. This starts with automated monitoring to detect incidents and includes escalation procedures and a reaction process to investigate and manage incidents. If a data breach occurs, we will notify you as soon as feasible (in accordance with applicable data protection laws) and will comply with all legal requirements to mitigate any harms resulting from such a breach.
- Data Retention
Personal information is retained only for as long as it is necessary for the purposes for which it was collected or transferred. When personal information is no longer required for the purposes for which it was collected or transferred, we will delete the information or convert the information into aggregated or de-identified data.
We do not provide the Service to children. If you are under the age of majority in your jurisdiction of residence, you may only use the Service with the involvement of a parent or guardian.
- Privacy Rights
Individual Access: If you make a request, we will let you know what personal information we have about you, what it is being used for, and with whom it has been shared. We will provide you with access to your personal information that is in our possession, subject to certain exceptions, including information that is referenced to another individual’s personal information that we cannot sever, or information subject to solicitor-client privilege, or other legal restrictions that may prevent us from fulfilling your access request. To inquire contact us at: email@example.com (include “Attention: Privacy Officer” in the subject line).
We will respond to your request within one month, free of charge, unless the volume or the complexity of the request requires a longer process. We will notify you if we require an extension and may charge a reasonable fee to cover administrative costs.
Rectification: If you notice any inaccuracies or wish to update any part of your personal information, we will rectify the information as necessary. We will provide rectification as soon as possible within one month. If we refuse the request, we will provide justification.
Withdraw Consent: We recognize the right of individuals to withdraw consent. This includes the right to withdraw consent after having provided consent. Please contact the Privacy Officer to withdraw consent.
- Opt-Out of Promotional Communications
In the event you wish to unsubscribe from receiving promotional email communications from us, you may opt-out by:
- Removing yourself by clicking “unsubscribe” at the bottom of an email we send you, or
- Contact us at: firstname.lastname@example.org
- Contact Us
Still Need Help? You may contact us at any of the following:
5075 Yonge St. – Suite 806
Toronto, ON M2N 6C6
THIRD-PARTY INTEGRATION SERVICE PROVIDERS
Last updated: March 1, 2020
You are strongly advised to review the privacy policies of these third-parties before you enable integration. You are solely responsible for reviewing and understanding these policies.