Skip to main content
Security & Data Protection

Your data is protected. Here's exactly how.

We built security into every layer — not as an afterthought. This page explains what we do in plain language.

You already trust this.

When you log into your RBC or TD business account online you are trusting a website with your business banking, payroll account, line of credit, and full transaction history.

OfficeEaze uses the same AES-256-GCM encryption standard your bank uses. Your data is stored in Canada. Your account is completely isolated from every other business on the platform — the same way your bank account is yours and nobody else's.

If you trust online banking — the security model is the same.

What is encrypted and how

The following information is encrypted using AES-256-GCM with a separate dedicated encryption key for each category. Encryption keys are stored in secure server infrastructure — never in the database, never in the application bundle.

  • Employee Social Insurance Numbers
    Encrypted before storage with their own dedicated key. Never stored in plain text. Masked as *** *** ** by default — the full number is never shown until you enter your account password and pass two-factor (2FA) verification, and it then auto-hides after 30 seconds. Every reveal is logged with timestamp and IP address.
  • Employee banking details
    Encrypted separately from SINs with their own key. Masked as *** *** 456 by default — revealing the full number requires the same password and 2FA step-up, and is logged. Also decrypted server-side only when generating direct deposit files.
  • Dates of birth
    Encrypted at rest.
  • Medical information
    Encrypted at rest.
  • OAuth tokens (Gmail and Outlook integrations)
    Encrypted at rest. Never logged or exposed.
  • All data in transit
    TLS encryption between your browser and our servers. Data is never transmitted in plain text.

Your data stays in Canada

All employee records, payroll data, and documents are stored in the Canadian data centre region (ca-central-1 — Montreal, Canada) operated by Lovable on Amazon Web Services infrastructure. This means your employees' information is governed by Canadian law — not US surveillance legislation.

OfficeEaze is a trade name of Lou Squared Systems Inc., incorporated federally under the Canada Business Corporations Act. We are a Canadian company subject to Canadian law. Your employees' data does not leave Canada for storage or processing.

Some service providers process limited technical data outside Canada — for example the AI model that powers your AI assistant, our email delivery service, and our SMS provider. These providers handle only what is necessary for their specific function and never receive SINs, banking details, or sensitive personal information. Full details are on our Subprocessors page.

View subprocessors →

Your account is completely isolated

Every employer account is a sealed environment. Row-level security is enforced at the database layer on every single table — it is architecturally impossible for one employer's data to be accessed by another.

Your AI assistant only ever sees your company's information. It cannot access, reference, or speculate about any other business's data — regardless of what is asked. This is enforced at the system level — not just by instruction.

Every AI assistant conversation is completely isolated to your account. Anthropic, the company that powers the AI assistant, does not use your business data to train AI models.

Data isolation and the optional dedicated environment

Standard OfficeEaze accounts use a shared database infrastructure where every employer's data is isolated by row-level security — it is architecturally impossible for one business to access another's records.

A fully dedicated environment is available as an optional paid upgrade on any CT or Enterprise tier — +$30/month (Small), +$50/month (Mid), or +$70/month (High). With it, your organization's data lives in its own separate database on Canadian AWS infrastructure (ca-central-1), completely isolated from all other OfficeEaze customers at the infrastructure level. This provides physical data separation in addition to the row-level isolation that every account already receives, and includes a separate backup schedule, SSO support (SAML/OIDC), and an optional custom domain. Dedicated environments are provisioned manually and confirmed in writing before they are activated.

A signed Data Processing Agreement (DPA) is included with all CT and Enterprise plan tiers. Standard plans (Solo, Micro, Growth, Business) operate on shared Canadian infrastructure with strong row-level security isolation and full PIPEDA compliance. To discuss CT or Enterprise plans, contact us at

What AI can and cannot access

Your AI assistant

Every time you ask your AI assistant a question the conversation is processed by Anthropic — the company that builds the AI model powering your assistant.

Here is exactly what Anthropic receives:

  • Your question.
  • Your company name, province, and industry.
  • Your assistant's name.
  • Summary business context: outstanding invoice count and total, current module you are viewing, and business health score summary.
  • The AI assistant's response.

Here is what Anthropic never receives:

  • Employee Social Insurance Numbers — never.
  • Banking details — never.
  • Payroll amounts — never.
  • Employee names — never.
  • Documents from your filing cabinet — never.
  • Any encrypted field — never.

This is not a policy decision — it is a technical one. The AI assistant is never given access to sensitive personal data in the first place. It cannot share what it cannot see.

Anthropic does not use API conversations to train their models. Your business conversations with your AI assistant are not used to improve Claude.

Your documents and files

Documents uploaded to your filing cabinet — contracts, HR files, pay stubs, T4s, receipts — are stored encrypted in Canada.

  • No AI model reads them.
  • The AI assistant cannot access your filing cabinet.
  • Anthropic never sees them.
  • Lovable never sees them.

The only AI that touches a document is a brief classification step when you upload it — assigning it to the right folder. This uses a short description of the file only — not the content.

The platform itself

OfficeEaze is built on Lovable's platform. Lovable maintains SOC 2 Type II and ISO 27001:2022 certification.

We operate on Lovable's Business plan which includes a data training opt-out — meaning our code and configuration are not used to train Lovable's AI models.

Lovable's Data Processing Agreement and Transfer Impact Assessment are available on request — privacy@officeeaze.ca .

Data typeGoes to any AI model?
Employee SINs Never
Banking details Never
Documents and files Never
Payroll amounts Never
Employee names Never
Company name and provinceAI assistant context only — not stored by Anthropic
Your questions to the AI assistantProcessed by Anthropic — not used for training
OfficeEaze codeExcluded from Lovable training — Business plan opt-out

The design decision to never give the AI assistant access to sensitive personal data was made deliberately — so that no AI model, now or in the future, can ever expose what it was never given.

Your Data Is Always Yours

You own it — always

Every document, record, and pay stub you create belongs to you. OfficeEaze has no ownership claim over your data, now or ever.

Export anytime — no permission needed

One click exports your complete payroll history, employee records, and all documents as CSVs and PDFs. No request form. No waiting. No fee.

We will never sell your data

Your data will never be sold, transferred, or used to satisfy creditors under any circumstances. This is written into our Terms of Service.

If we ever close — 30 days notice and a full export

In the event OfficeEaze ceases operations, every customer receives a minimum of 30 days written notice and a complete export of everything they ever created — before any systems go offline.

What would actually have to happen for someone to access your employees' data

For someone to access your employees' SINs or banking details in OfficeEaze they would need to:

  1. Obtain your email address and password
  2. Bypass two-factor authentication — a 6-digit code that only your phone can generate
  3. Crack AES-256-GCM encryption on the specific fields they want — which would take longer than the age of the universe with current computing power

Compare that to accessing your current paper files:

  1. Get a key to the cabinet. Or pick the lock. Or take a photo of the spreadsheet on your screen.

The filing cabinet is not more secure. It just feels more familiar.

Your data is backed up and recoverable

  • Daily automated backups
    Your data is backed up every day automatically.
  • 30-day filing cabinet recovery
    Documents can be recovered for up to 30 days after deletion.
  • Your data is yours
    Export everything at any time with one click from Settings → Export Data.
  • If you cancel
    Your account data is permanently deleted 30 days after your billing period ends. OfficeEaze does not retain your records on your behalf — you are responsible for your own CRA retention (at least 6 years for payroll), so export everything before you cancel. Never sold. Never archived for our use.
  • 30 days notice
    If OfficeEaze ever shut down we would give every customer 30 days notice and a complete data export. This commitment is in our Terms of Service.

Document retention and deletion

OfficeEaze includes a built-in document retention policy system aligned with Canadian retention requirements:

  • CRA financial records (T4s, payroll, remittance, receipts, invoices) — flagged after 7 years
  • Workplace safety records (WSIB, WCB, incidents) — flagged after 10 years
  • Former employee HR documents — flagged 4 years after the employee's last day
  • Corporate records (articles, bylaws, minutes) — never flagged, kept permanently

Documents are never automatically deleted. When documents pass their retention threshold they are flagged for your review in the Filing Cabinet. You choose what to delete — nothing is removed without your explicit confirmation. CRA requires you to keep your own financial records for at least 6 years.

This flagging applies while your account is active. If you cancel your account, all your data — documents included — is permanently deleted 30 days after your billing period ends. OfficeEaze does not retain your records on your behalf, so export anything you need to keep first.

Independently tested — not just self-assessed

Anyone can claim they take security seriously. We prove it.

Platform certifications

OfficeEaze is hosted on Lovable's platform infrastructure which holds:

  • ✓ SOC 2 Type II
  • ✓ ISO 27001:2022 (updated May 2026)
  • ✓ GDPR compliance
  • ✓ Independent penetration test — Letter of Attestation

Full compliance documentation, audit reports, and Transfer Impact Assessment available on request — privacy@officeeaze.ca

Enterprise customers may request the SOC 2 Type II report and penetration test attestation directly from that page.

OfficeEaze is hosted on Lovable's platform infrastructure which includes annual independent penetration testing as part of their ISO 27001:2022 certification programme.

If you are an enterprise customer who needs security documentation before signing — email .

Data Processing Agreement

OfficeEaze's use of Lovable Inc., our platform infrastructure provider, is governed by Lovable's Data Processing Agreement, which applies to OfficeEaze's plan and forms part of our agreement with Lovable. Lovable maintains SOC 2 Type II and ISO 27001:2022 certification, its terms prohibit use of customer data for AI training, and they govern data breach notification and deletion obligations.

Our standard Data Processing Agreement is available for immediate download — covering processing purposes, security obligations, sub-processor management, breach notification timelines, Canadian data residency, and data deletion on termination.

Download our Data Processing Agreement (PDF)

For a countersigned copy, or to request a DPA before subscribing, contact .

Payment security

OfficeEaze uses Helcim Inc. for payment processing — a Canadian company headquartered in Calgary, Alberta, certified at PCI DSS Level 1, the highest level of payment card industry compliance.

Your card number, CVV, and banking details never touch OfficeEaze servers. When you enter payment information, it goes directly from your browser to Helcim's secure servers. Helcim returns a payment token — a reference ID with no payment value on its own — and that token is the only payment-related item stored in OfficeEaze.

What OfficeEaze stores: your billing name, plan type, subscription status, and Helcim's payment token.

What OfficeEaze never stores: card number, CVV, expiry date, full banking account number, or any raw payment credential.

Payment data processed by Helcim remains in Canada. Helcim's full security and compliance documentation is available at helcim.com/security.

Access controls and audit trail

  • Strong authentication strongly recommended
    Two-factor authentication (2FA) is the single most effective protection for your account. We strongly recommend enabling it: a passkey (Face ID or fingerprint) — which exceeds standard 2FA — or a time-based authenticator app. Sensitive data such as SINs, banking details, and the Filing Cabinet require 2FA to access. If you choose to defer or disable 2FA, your account operates with password-only security and you accept the increased risk of unauthorized access — OfficeEaze is not responsible for any breach or data loss that occurs while 2FA is not enabled on your account. If access to your authenticator app is lost, account recovery is available via SMS to the verified phone number on file — no support ticket required.
  • Session timeout
    After 20 minutes of inactivity, employer sessions show an 'Are you still there?' warning with a 2-minute countdown, then automatically log out. All changes are saved automatically before logout.
  • Strong password requirements
    Passwords must be a minimum of 12 characters and include uppercase, lowercase, a number, and a special character. Passwords are hashed and never stored in plain text.
  • Full audit trail
    Every access to sensitive data is logged with timestamp, user identity, and IP address.
  • Immutable audit logs
    Security, payroll, and permission logs cannot be modified or deleted even by administrators.
  • Team member permissions
    Restrict what each team member can see and do. A scheduler does not see payroll. A bookkeeper does not see HR files.

What we won't say

We won't tell you we are 100% secure. No system is.

We won't tell you we are unhackable. Nothing is.

We won't use the phrase "military-grade encryption" — it is a marketing term that means nothing specific.

What we will tell you is that we built OfficeEaze the way we would want our own employees' data protected — with encryption on every sensitive field, Canadian data storage, independent security testing, a complete audit trail, and a team that reads every security question personally.

If you have a specific security question or concern email — Jennifer reads every one personally.

Questions about security? Contact
Have more questions? Visit our FAQ.
Check system availability at status.officeeaze.ca.
If OfficeEaze is unavailable, use our offline backup calculator for payroll and CRA deadline reference — no login required.
Last reviewed: June 2026
OfficeEaze is a trade name of Lou Squared Systems Inc., incorporated under the Canada Business Corporations Act.
Harris — OfficeEaze AI assistant
Harris
OfficeEaze AI · Online
Never done payroll before? I'll teach you as you go.