This policy is written to be handed to the people who are asked about it: a signer who wants to know what happens to a photo of their driver’s licence, and the property manager, mortgage broker, real estate agent or attorney who has to answer them. It describes the Video Signing Room’s optional identity check only. Everything else the Service does is covered by the Privacy Policy and the Privacy Impact Assessment.
This is the most common question, so it is answered first and plainly.
Because of this, our position is that we do not create a database of biometric characteristics and the disclosure obligation in section 45 of Quebec’s Act to establish a legal framework for information technology is not engaged. Authenticating a document does not change that: nothing derived from a person’s body is computed, stored or compared at any point. Should we ever add automated facial matching, we would treat it as a new processing activity: express consent obtained separately for it, disclosure to the Commission d’accès à l’information before it goes into service, and this policy rewritten first.
| What | Why |
|---|---|
| A photograph of a government-issued ID (front) | So the host can satisfy themselves that the person signing is who they say they are. |
| A selfie (optional, at the host’s discretion) | To compare against the ID photo and the live video. |
| The outcome, the reviewer, and the time | The evidentiary record that the check happened. |
Identity verification is optional per session. A host may instead confirm identity personally on camera, which collects no images at all.
Before collecting this information we considered less intrusive ways of achieving the same purpose. This section records what was considered and why the current design was chosen.
| Alternative considered | Outcome |
|---|---|
| Collect nothing; rely on the invite link alone | Adopted as the default. Identity verification is off unless the host turns it on for a session, so most signings collect no ID at all. |
| Host confirms identity personally on live video | Adopted and supported in the product. A host who already knows the signer, or who is content to rely on the recorded video, can confirm identity without any image being uploaded. |
| ID photo only, no selfie | Adopted. The selfie is optional. Where the live video already shows the signer’s face, a separate selfie adds little. |
| Keep the images on file for a fixed period | Rejected as the default. The images exist to support one decision. Holding them afterwards adds risk without adding purpose, so they are destroyed when the decision is made. A host with a professional obligation to retain identity evidence may opt in per submission and must record the reason. |
| Automated facial recognition / liveness detection | Rejected. Disproportionate to the purpose. It would create biometric information where none exists today, engage a materially heavier regulatory regime, and introduce documented accuracy disparities across skin tone, age and gender into a decision that a qualified professional is already making on the record. |
| Verify through a third-party identity vendor | Rejected for now. It would send a signer’s ID to a further processor and, in most cases, to another country, to replace a judgement the host is professionally competent to make. |
Each session keeps a record that the host can export. For identity verification it captures the submission and the decision: who submitted, when, from what device and IP, who reviewed it, what they decided, the reason given, whether the images were destroyed or retained (and why), where the images were stored, and that the comparison was made by a person rather than by facial recognition. The signer’s consent is recorded in the same trail.
Before joining a signing session, a signer is shown what will be collected, that a person — not facial recognition — will compare it, how long it is kept, and their rights. They must tick a box and choose to join; declining ends the session for them. The consent, and the moment it was given, are recorded. Before uploading, they are told again what happens to the images.
If the host cannot verify a signer from the photographs, the signer may be asked to submit again or to confirm their identity another way. A signer may ask the host for an alternative method at any point.
We will never sell, rent, trade or otherwise profit from a signer’s identity images or verification result, use them for marketing, or use them to infer anything about a person. They are used only to complete the signing they were collected for.
Under PIPEDA and, for Quebec residents, Law 25, you may ask what we hold about you, have it corrected, withdraw your consent, request a machine-readable copy, or have it deleted. Requests are answered within 30 days and are free. See your rights and Delete your account & data.
A confidentiality incident affecting identity information is recorded in our incident register, assessed for risk of serious injury, and where that risk exists we notify the affected individuals and the Commission d’accès à l’information, together with any other regulator the law requires. See the PIA for the full procedure.
Questions about this policy, or a request about your information, go to our privacy officer: ezpdfeditor@aicanadiansolutions.ca.
This is a draft prepared for review by legal counsel and is provided for information. It is not legal advice, and it does not replace the professional obligations of a host using the Service. A French version will be published for Quebec.