HANIF ACCOUNTING & ADVISORY, CPA
Sub-Processor Policy and List
Effective Date: [DATE]
Version: [v1.0]
Contact: hasan@hanifadvisory.ca
1. Introduction
1.1 What is a sub-processor?
A sub-processor is anythird-party organization that Hanif Accounting & Advisory, CPA ("HanifAccounting," "we," "us," "the Firm") engages to process personal information on our behalf in order to deliver our services to you. Examples include cloud accounting platforms, document-capture tools, email and calendar providers, payment processors, and independent contractors who assist with engagement work. Our services are non-assurance only:accounting, bookkeeping, tax, budgeting, forecasting, controllership, andfractional-CFO services.
1.2 Why we publish this list
We publish this list in the interest of transparency and accountability. It lets our clients know which organizations may handle their personal information, where that information is processed, and what safeguards apply.
1.3 Our role and accountability
Hanif Accounting is the organization with control over your personal information (the "data controller" in international terms). Under the Personal Information Protection and Electronic Documents Act (PIPEDA), Schedule 1, Principle4.1.3: "An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. The organization shall use contractual or other means to provide a comparable level of protection while the information is being processed by a third party." We remain accountable for your personal information at all times, including when it is processed by the sub-processorslisted below.
1.4 Cross-border processing acknowledgment
Some of our sub-processors — and the Firm's own owner-operator and contractors — process personal information outside Canada, principally in the United States and in Pakistan. PIPEDA does not prohibit cross-border transfers for processing, but it requires that we provide a comparable level of protection through contractual and other means, and that we be transparent that information sent to another jurisdiction may be accessed by the courts, law enforcement, and national security authorities of that jurisdiction. See Sections 3 and 4.
1.5 Quebec Law 25 posture
Where we serve clients inQuebec, the Act respecting the protection of personal information in the private sector (Quebec, as modernized by Law 25) applies. Section 17 requires that, before communicating personal information outside Quebec, we conduct a privacy impact assessment (PIA) that takes into account the sensitivity of the information, the purposes for which it is to be used, the protection measures(including contractual) that would apply, and the legal framework applicable inthe destination jurisdiction. We have conducted such assessments for ourcross-border sub-processors and have contractual safeguards in place. Records of these assessments are maintained by our Privacy Officer. (A transfer"outside Quebec" includes transfers to other Canadian provinces; for example, an Ontario-hosted or US-hosted service is a transfer outside Quebecrequiring assessment.)
1.6 How we notify you of changes
We will provide clients with atleast 30 days' advance notice of any material change to this sub-processor list— for example, the addition of a new sub-processor or a change in processing location — by email and/or by posting an updated version on our website. Clients who object to a new sub-processor may contact us using the details in Section 7.
1.7 Effective date and version control
This policy is effective as of[DATE]. The current version is [v1.0]. See Section 8.
2. Sub-Processor Table
The categories below describe the types of personal information that may be shared with each provider in the course of delivering our services.
Google Workspace (Google LLC / Google Cloud)
Service / purpose: Email, document creation and storage, shared drives, calendar, video meetings.
Categories of personal information: Client contact details, correspondence, financial documents, and any personal information contained in files we exchange.
Location of processing: Configurable. Google Workspace's "data regions" feature allows covered data to be stored at rest in the United States or the European Union only — there is no Canada-only data-region option for standard Google Workspace at rest. (A"Canada Data Boundary" exists only for certain Google Cloud Platform products under Assured Workloads, not for Workspace.) Default processing occurs on Google's global infrastructure, including the US. [TO VERIFY: the data-region setting applied to our tenant.]
Certifications: SOC 2 Type II, SOC 3, ISO/IEC 27001,ISO/IEC 27017, ISO/IEC 27018.
Privacy policy: https://policies.google.com/privacy
DPA: https://workspace.google.com/terms/dpa_terms.html
Cross-border safeguard: Cloud Data Processing Addendum incorporating Standard Contractual Clauses; data-region controls;encryption at rest and in transit, with optional client-side encryption.
QuickBooks Online (Intuit Inc.)
Service / purpose: Cloud bookkeeping and accounting.
Categories of personal information: Client and customer names, contact details, financial-transaction data, payroll data where applicable, banking details.
Location of processing: Primary/live data is hosted on Intuit-managed systems on Amazon Web Services across multiple regions in the United States in an active/passive configuration; a backup of Canadian customers' data is stored in Canada. (Per Intuit's QuickBooks Online Canada security page, live data is hosted in the US with a Canadian backup.)
Certifications: PCI DSS, SOC reporting, ISO/IEC27001. [TO VERIFY: current SOC 2 Type II scope for the QuickBooks Online product via Intuit's compliance portal under NDA — Intuit's own statements onQBO SOC 2 coverage have been inconsistent.]
Privacy policy: https://www.intuit.com/privacy/statement/
DPA: Provided via Intuit account/legal; the GlobalPrivacy Statement is incorporated by reference into the Canadian Terms of Service (https://www.intuit.com/legal/terms/en-ca/quickbooks/online/).
Cross-border safeguard: Contractual terms; AES-256encryption at rest, TLS in transit.
Xero (Xero Limited)
Service / purpose: Cloud bookkeeping and accounting.
Categories of personal information: As for QuickBooksOnline.
Location of processing: United States. Xero hosts onAmazon Web Services with data centres in the US; there is no Canada region. [TOVERIFY current hosting region with Xero.]
Certifications: ISO/IEC 27001; underlying AWS holdsISO 27001, PCI DSS Service Provider Level 1, and SOC 1/SOC 2.
Privacy policy: https://www.xero.com/legal/privacy/
DPA: https://www.xero.com/legal/data-processing-agreement/[TO VERIFY current URL]
Cross-border safeguard: DPA with Standard Contractual Clauses; encryption in transit and at rest.
Zoho Books (Zoho Corporation)
Service / purpose: Cloud bookkeeping and accounting.
Categories of personal information: As for QuickBooks Online.
Location of processing: Configurable by data centreat sign-up. Zoho operates Canadian data centres in Montreal and Toronto, which opened on November 2, 2023 (Zoho's 13th and 14th data centres globally), enabling Canadian data residency for accounts provisioned in the Canada region.As Zoho's Managing Director for Canada, Chandrashekar LSP, stated, "The new data centers and their operations carry all the required certifications, which assures our customers that their data is securely stored only within Canadian boundaries." Note that the Canadian data centres were initially available to new customers, with existing customers migrated over time. [TOVERIFY: confirm our account is provisioned in the Canada data centre.]
Certifications: SOC 1 Type II, SOC 2 Type II, ISO/IEC27001, ISO/IEC 27017, ISO/IEC 27018, PCI DSS.
Privacy policy: https://www.zoho.com/privacy.html
DPA: https://www.zoho.com/gdpr/dpa.html
Cross-border safeguard: Canadian data residency option; DPA with Standard Contractual Clauses.
NetSuite (Oracle NetSuite — Oracle America, Inc.)
Service / purpose: Cloud ERP / accounting for larger engagements.
Categories of personal information: As for QuickBooks Online, plus broader business records.
Location of processing: Oracle Cloud Infrastructure data centres across North America, Europe, and Asia-Pacific. [TO VERIFY: the specific data-centre region for our account.]
Certifications: SOC 1 Type II and SOC 2 Type II (SSAE18 / ISAE 3402), ISO/IEC 27001, ISO/IEC 27018, ISO/IEC 42001, PCI DSS, PCI SSF.
Privacy policy: https://www.oracle.com/legal/privacy/
DPA: https://www.oracle.com/corporate/contracts/cloud-services/data-processing-agreement.html
Cross-border safeguard: Oracle Data Processing Agreement with Standard Contractual Clauses.
Dext (Dext Software Limited)
Service / purpose: Receipt and invoice capture /pre-accounting data extraction.
Categories of personal information: Receipts, invoices, supplier and customer data, and any personal information contained incaptured documents.
Location of processing: Hosted on Amazon WebServices; Dext operates internationally and may transfer data to the United States.
Certifications: ISO/IEC 27001:2022 (Dext); AWS data centres certified for ISO 27001, PCI DSS Service Provider Level 1, and SOC1/SOC 2.
Privacy policy: https://dext.com/en/privacy-policy
DPA: https://dext.com/en/data-processor-agreement
Cross-border safeguard: Data Processor Agreement under GDPR Article 28; encryption; ISO 27001 controls.
Hubdoc (a Xero product)
Service / purpose: Receipt and document capture.
Categories of personal information: Receipts, bills, statements, and contained personal information.
Location of processing: United States (Hubdoc is a Xero product hosted on AWS US infrastructure). [TO VERIFY current hosting.]
Certifications: Inherits Xero/AWS controls (ISO27001; SOC 2 via AWS).
Privacy policy: https://www.xero.com/legal/privacy/
DPA: Covered under Xero's data processing agreement.
Cross-border safeguard: DPA with Standard Contractual Clauses; encryption.
HubSpot (HubSpot, Inc.)
Service / purpose: Customer relationship management(CRM) and marketing.
Categories of personal information: Prospect andclient names, business contact details, email correspondence, marketing-engagement data.
Location of processing: Hosted on Amazon WebServices. HubSpot operates five data centres — EU (Frankfurt, Germany), US-East(Virginia), US-West (Oregon), Canada (Montreal), and Australia (Sydney); the Canada, Oregon, and Sydney centres launched on February 4, 2025. Per HubSpot'sData Centers page, "New customers purchasing a subscription service will be assigned a hosting location based on the geo-location of their IP address atsign up. Customers who only use free services will be assigned a data center in the United States." Certain processing (e.g., Operations Hub sync, supportaccess, usage data) may still occur in the US regardless of the assigned region.[TO VERIFY: confirm whether our portal is hosted in the Canada data centre;free-tier accounts default to the US.]
Certifications: HubSpot relies on AWS, whose controls"are independently validated as part of AWS's SOC 2 Type 2 report and ISO27001 certification." HubSpot itself is not ISO 27001 certified.
Privacy policy: https://legal.hubspot.com/privacy-policy
DPA: https://legal.hubspot.com/dpa
Cross-border safeguard: DPA with Standard Contractual Clauses (Module 2/3); regional data hosting.
Stripe (Stripe Payments Canada Ltd. / Stripe, Inc.)
Service / purpose: Payment processing for client invoices.
Categories of personal information: Payer name, billing details, payment-card data (handled directly by Stripe), transaction data.
Location of processing: United States (Stripe'sglobal infrastructure). The Canadian contracting entity is Stripe Payments Canada Ltd.; following 2022 FINTRAC regulations, Stripe is registered as amoney services business in Canada.
Certifications: PCI DSS Service Provider Level 1 (themost stringent level available), SOC 1, SOC 2.
Privacy policy: https://stripe.com/privacy
DPA: https://stripe.com/legal/dpa
Cross-border safeguard: DPA with Standard ContractualClauses; PCI-DSS-validated card handling; tokenization. Hanif Accounting doesnot store full card numbers.
Wise (Wise Payments Canada Inc. / Wise Payments Limited)
Service / purpose: International payments and currency conversion.
Categories of personal information: Payer/payee name, banking and contact details, transaction data.
Location of processing: Global infrastructure including the United States and Europe. [TO VERIFY specific storage location.]
Regulatory status: Per Wise's own regulatory disclosure: "Wise Payments Canada Inc. is registered with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) as a Money Service Business (MSB) with registration number M15193392. Quebec has a MSB licence with Revenu Québec under licence number 902804."
Certifications: [TO VERIFY: Wise security certifications— ISO 27001 / SOC 2 not publicly confirmed.]
Privacy policy: https://wise.com/ca/legal/privacy-policy
DPA: Available via Wise business terms.
Cross-border safeguard: Contractual safeguards;regulated financial institution; encryption.
Webflow (Webflow, Inc.)
Service / purpose: Website hosting and content management.
Categories of personal information: Limited —information submitted through website forms (e.g., name, email, message) and standard server logs.
Location of processing: United States. Webflow hosting is delivered via Amazon Web Services and the Fastly CDN (with Cloudflare on current plans). There is no Canadian data-residency option for standard Webflow hosting; region selection is available only via Enterprise Webflow Custom Hosting.
Certifications: SOC 2 Type II; underlying AWS holdsISO 27001, SOC 2, and PCI DSS. [TO VERIFY current Webflow certifications.]
Privacy policy: https://webflow.com/legal/privacy
DPA: https://webflow.com/legal/dpa
Cross-border safeguard: DPA with Standard Contractual Clauses; US-based hosting acknowledged in Section 4.
Smartlead (Smartlead.ai)
Service / purpose: Cold-email outreach / email automation for business development.
Categories of personal information: Business contact details of prospects (name, business email, company) and outreach-engagement data only. Client engagement data is not shared with Smartlead.
Location of processing: United States and other locations; Smartlead's DPA states non-EU user data may be processed in the United States, Australia, Europe, India, and elsewhere.
Certifications: Relies on AWS infrastructure. [TOVERIFY: Smart lead holds no published SOC 2 / ISO 27001 certification of itsown; confirm current status before relying on it.]
Privacy policy: https://www.smartlead.ai/privacy-policy
DPA: https://www.smartlead.ai/dpa
Cross-border safeguard: DPA under applicable data-protection laws; encryption.
Calendly (Calendly, LLC)
Service / purpose: Meeting scheduling.
Categories of personal information: Name, email, meeting details, and (if embedded on our website) cookie data from website visitors.
Location of processing: United States. Calendly ishosted on Google Cloud Platform / Kubernetes, with data stored in US data centres.
Certifications: SOC 2 Type II, SOC 3, ISO/IEC 27001,CSA STAR Level One; GDPR and CCPA compliant.
Privacy policy: https://calendly.com/legal/privacy-notice
DPA: https://calendly.com/legal/data-processing-addendum
Cross-border safeguard: DPA incorporating Standard Contractual Clauses and the UK Addendum; Data Privacy Framework self-certification.
Independent contractors in Pakistan (category — not named individuals)
Service / purpose: Bookkeeping, accounting preparation, tax-working-paper preparation, and administrative support, performed under the supervision of the Ontario-registered CPA.
Categories of personal information: Whatever client engagement data is necessary for the assigned task.
Location of processing: Pakistan.
Certifications: Not applicable (individuals/smallfirms); bound instead by written confidentiality and data-processing agreements.
Safeguards: Written confidentiality and data-processing agreements; AES-256 encryption at rest and TLS in transit;multi-factor authentication; role-based access controls following least-privilege principles; contractual breach-notification obligations; data return-and-destruction obligations at end of engagement; and audit/inspection rights. All work is supervised by the Ontario CPA consistent with CPA Ontario'srules governing association with, and supervision of, non-members. See Section3.
Deel (Deel, Inc.) — may be used in future
Service / purpose: Potential future employer-of-record (EOR) and contractor-payment services for Pakistan-based staff.
Categories of personal information: Staff/contractor personal and payroll data (not client engagement data).
Location of processing: AWS-hosted infrastructure with primary operations in Ireland and a disaster-recovery site in France.
Certifications: ISO/IEC 27001, SOC 1, SOC 2, SOC 3;GDPR compliant; AES-256 encryption.
Privacy policy: https://www.deel.com/privacy/
DPA: Available via https://trust.deel.com/
Cross-border safeguard: DPA with Standard Contractual Clauses. Marked "may be used in future" — not currently engaged.
3. Pakistan-Located Processing
Hanif Accounting discloses the following clearly and prominently:
- Owner-operator location: The Firm's owner andsole CPA resides and operates from Pakistan. While the Firm is registered with CPA Ontario and maintains a registered office in Ottawa, Ontario, day-to-day professional work is performed from Pakistan.
- Contractors: We may engage Pakistani contractors(ACCA members, Pakistani Chartered Accountants, and administrative staff) to assist with engagement and administrative work.
- Future EOR: We may in future use an employer-of-record service (Deel) to engage Pakistan-based staff.
- Legal-framework acknowledgment: Pakistan is noton any Canadian list of jurisdictions providing comparable protection, and Pakistan does not currently have a comprehensive private-sector data-protection law in force. The Personal Data Protection Bill, 2023 remains in draft and has not been enacted. Accordingly, personal information processed in Pakistan does not benefit from a statutory data-protection regime equivalent to Canadian law.
- Lawful-access risk: Personal information located in Pakistan may be subject to access by Pakistani government authorities, law enforcement, or courts under local law, including under the Prevention of Electronic Crimes Act, 2016. We can not override the laws of a foreign jurisdiction by contract.
- Safeguards in place: To provide a comparable level of protection, we maintain written confidentiality and data-processing agreements with all Pakistan-based personnel and contractors; AES-256 encryption at rest and TLS encryption in transit; multi-factor authentication on all systems; role-based access controls following least-privilege principles; contractual breach-notification obligations; data return-and-destruction obligations at the end of an engagement; and audit/inspection rights. All professional work is supervised by the Ontario-registered CPA.
4. United States-Located Processing
Several of our sub-processors —including Google Workspace (default/US region), QuickBooks Online, Xero, Hubdoc, Stripe, Webflow, Smartlead, and Calendly — process and/or store personal information in the United States. We acknowledge that personal information stored in the United States may be subject to lawful access by US authorities under laws such as the CLOUD Act and Section 702 of the Foreign Intelligence Surveillance Act (FISA). We address this risk through contractual safeguards (Data Processing Agreements with Standard Contractual Clauses), encryption, and data-minimization, and we have taken it into account in our Quebec Law 25 transfer assessments.
5. Your Rights Regarding Sub-Processors
You have:
- The right to be informed about the sub-processors that may handle your personal information (this policy).
- The right to object to a specific sub-processoron reasonable data-protection grounds. We will work with you in good faith to find an alternative where practical; some sub-processors are integral toservice delivery, and an objection may, in limited cases, mean we can not continue the engagement.
- The right to access copies of the data-processing agreements we have in place with our sub-processors, on request and subject to confidentiality terms.
- The right to terminate the engagement if we can not reach agreement on a sub-processor arrangement.
6. Our Vendor Management Practices
- Due diligence: Before engaging a sub-processor,we assess its security posture, certifications, data-processing locations, and contractual terms, and (for transfers outside Quebec) we conduct a Law 25 privacy impact assessment.
- Annual review: We review our sub-processors'data-processing agreements and certifications at least annually.
- Breach monitoring: We monitor sub-processor breach notifications and security bulletins and will notify affected clients and applicable regulators as required by PIPEDA, Alberta PIPA, and Quebec Law25.
- Audit / inspection: Where contractually available, we exercise audit and inspection rights, including reviewing SOC 2 /ISO 27001 reports.
7. Contact
Questions about this policy, our sub-processors, or our use of service providers outside Canada may be directed to our Privacy Officer:
Privacy Officer, HanifAccounting & Advisory, CPA
hasan@hanifadvisory.ca
5-2000 Thurston Drive, Ottawa, Ontario, K1G 4K7, Canada
As required by Alberta PIPAsection 13.1, the position above is able to answer questions on behalf of the Firm regarding our use of service providers outside Canada, and this policy describes the countries (the United States and Pakistan) in which collection, use, or disclosure of personal information may occur, and the purposes for which our foreign service providers are authorized to process it.(Section 13.1 requires an organization using or transferring personal information to a service provider outside Canada to notify individuals how toobtain access to its policies and the name or title of a contact person.)
8. Version Control
Version
Date
Summary of changes
[v1.0]
[DATE]
Initial publication
Last updated: [DATE]. A changelog is maintained and available on request.