Privacy Policy

PRIVACY POLICY — GOOSE TECHNOLOGIES INC. (O/A Apprify)
Last Updated: December 9, 2025

1. Overview; Scope of This Policy

This Privacy Policy describes how Goose Technologies Inc. (O/A Apprify) (“Goose Technologies Inc.,” “Apprify,” “we,” “us,” or “our”), an Ontario corporation, collects, uses, discloses, stores, and otherwise processes Personal Information in connection with the Apprify AI Mortgage Assistant, including all related websites, applications, and integrations (collectively, the “Service”).

This Policy is designed to meet the requirements of:
-PIPEDA
- Ontario privacy laws
-Applicable U.S. state privacy laws (including CCPA / CPRA)
-Financial sector requirements, where relevant (including GLBA service provider obligations)
- Where stricter laws apply to certain individuals, Apprify complies with those heightened standards.

2. Key Definitions

Personal Information means information about an identifiable individual under PIPEDA and information that could reasonably be linked to a consumer or household under U.S. state privacy laws.

Processing means any operation involving Personal Information, including collection, use, disclosure, storage, organization, transfer, or deletion.

Sensitive Personal Information includes government identification numbers, financial account numbers, and information relating to minors.

3. Categories of Personal Information We Process

We may process the following categories of Personal Information:

- Identifiers: name, business contact details, account credentials
- Professional information: brokerage or organization affiliation, licensing status
- Financial information: mortgage application data, supporting documents, property and transaction details
- AI-generated data: summaries, classifications, risk notes, or insights (strictly suggestive)
- Technical information: device identifiers, logs, IP address, browser details
- Communications: support tickets, feedback, audit logs

User Responsibility for Uploaded Data

Users must ensure that:

- They have lawful authority to upload Personal Information
-The data uploaded is relevant and necessary
- Any borrower or third-party information is uploaded with proper notices, consent, or authorization

4. Purposes of Processing

We process Personal Information to:

- Provide and operate the Service
-Authenticate users and administer accounts
-Facilitate mortgage workflows and document collaboration
-Analyze and classify documents using AI to support mortgage professionals
-Generate audit trails for compliance and recordkeeping
-Improve, maintain, and secure the Service
-Communicate regarding accounts, updates, or support needs
-Detect and prevent fraud or unauthorized access
-Meet legal, regulatory, and industry obligations
-Enforce agreements, including the Terms of Use

Apprify uses AI to generate insights, document summaries, classifications, and workflow suggestions.

5. Legal Bases; Consent

Under PIPEDA, Apprify relies on:

- Knowledge and consent (express or implied)
- Legal authority where consent is not required, such as investigations or fraud prevention

Under applicable U.S. laws, we honor rights to know, access, correct, delete, or opt out where required.

Apprify does not sell Personal Information.

6. Disclosure of Personal Information

We disclose Personal Information only to:

- Authorized users within your organization
-Lenders, credit partners, insurers, or related mortgage counterparties
-Verified service providers necessary to operate the Service
-Third parties when authorized by you
-Regulators, law enforcement, or courts when legally required
-Successors in the event of a merger, acquisition, or sale (with appropriate safeguards)

We do not disclose Personal Information for third-party advertising.

7. International Transfers

Apprify stores and processes Personal Information in Canada and the United States. Laws in each jurisdiction may permit lawful access by authorities.

We require service providers to meet strict security and confidentiality requirements.

8. Safeguards

Apprify maintains administrative, technical, and physical safeguards, including:

- Encryption at rest and in transit
-Least-privilege access controls
-Multi-factor authentication for privileged access
-Secure development practices
-Vulnerability management and monitoring
-Vendor due diligence
-Employee training

9. Incident Response and Notification

Apprify maintains breach detection and response procedures.
Where a breach creates a real risk of significant harm, affected individuals and regulators will be notified as required by law.

10. Retention and Secure Disposal

We retain Personal Information only as long as necessary for:

- Operational purposes
-Legal, regulatory, or audit requirements
-Fraud prevention
-Dispute resolution

When no longer required, Personal Information is securely deleted or anonymized.

11. Your Rights

Canadian Rights

You may request:

- Access to your Personal Information
-Correction of inaccuracies
-Explanations of use or disclosure
-Withdrawal of consent (subject to legal limits)

U.S. State Rights (if applicable)

May include:

- Access
- Deletion
-Correction
-Opt-out of sharing
-Data portability
-Limitations on sensitive data use

Requests may be submitted to contact@apprify.ca

12. Cookies

We use necessary cookies for:

- Security
-Authentication
-Session management
-Performance and load balancing

Optional analytics cookies may be used with consent or opt-out controls where required.

13. Children’s Privacy

The Service is intended for professionals only.
We do not knowingly collect Personal Information from children under the age of 13.

14. Changes to This Policy

We may update this Privacy Policy from time to time.
Material changes will be communicated via email or Service notifications.

15. Contact Information

‍Email: contact@apprify.ca
Telephone: (416) 838-2951