Privacy and Consumer Protection Policy

Privacy and Consumer Protection Policy

1. Document Details

1.1 Privacy and Consumer Protection Policy Contains

An established comprehensive framework for protecting the privacy and consumer rights of all potential clients whose personal information is collected, used, retained or disclosed by Blu Pqy Inc. and is aligned with the following legislative requirements:

  • Personal Information Protection and Electronic Documents Act (PIPEDA) – Privacy protection and fair information practices
  • Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) – FINTRAC compliance
  • Consumer Protection Act, 2002 (Ontario) – Provincial consumer rights
  • Accessibility for Ontarians with Disabilities Act (AODA) – Accessibility standards

1.2 Objective / Goal

This policy ensures compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA), the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA), the Retail Payment Activities Act (RPAA), and Ontario's Consumer Protection Act, 2002, while promoting fair treatment, transparency, accountability, and meaningful consent.

1.3 Description

This document provides an internal and external reference for staff and partners to consult at any time.

1.4 Other Applicable Policies and Procedures

  • RPAR Compliance Manual

2. Introduction

This Privacy and Consumer Protection Policy establishes a comprehensive framework for protecting the privacy rights and consumer interests of all consumers, end users, clients, and prospective clients whose personal information is collected, used, or disclosed by Blu Pqy Inc. (“Blu Pqy” or the “Company”), through providing money services business (MSB) and payment service provider (PSP) activities.

2.1 Scope of Application

This policy applies to:

  • All personal information collected, used, disclosed, or retained by the Company in any format (electronic, paper, or otherwise)
  • All retail payment activities performed by the Company as a registered PSP
  • All money services business activities subject to FINTRAC registration
  • All interactions with consumers, end users, clients, and prospective clients across Canada
  • All employees, agents, mandataries, contractors, and third-party service providers acting on behalf of the Company
  • Personal information transferred to third parties for processing, whether domestically or internationally

2.2 Definitions

Personal Information
Any information about an identifiable individual, including but not limited to, name, address, telephone number, email address, date of birth, government-issued identification numbers, financial information, transaction records, IP addresses, and any other information that can identify an individual alone or in combination with other information.
Sensitive Personal Information
Information that requires a higher degree of protection due to its nature.
End User
Any individual or entity for whom the Company performs a retail payment activity or money services business function.
Money Services Business (MSB)
An entity engaged in money transmission, foreign exchange, or other prescribed services under the PCMLTFA.
Payment Service Provider (PSP)
An entity that performs one or more payment functions as defined under the RPAA.
Consent
Voluntary agreement to the collection, use, or disclosure of personal information for defined purposes, which may be express (explicitly provided) or implied (reasonably inferred from action or inaction).
Third-Party Processor
Any organization to which the Company transfers personal information for processing purposes.

Accountability for Personal Information

Blu Pqy has designated a Compliance Officer who is accountable for the Company's compliance with this policy and with applicable privacy legislation. You may contact the Compliance Officer at:

Compliance Officer
Blu Pqy Inc.
130 Spadina Avenue, Unit 807, Toronto, Ontario, M5V 2L4, Canada
compliance@blupqy.com

PIPEDA's 10 Fair Information Principles

This policy is structured around PIPEDA's 10 Fair Information Principles, which form the foundation for Blu Pqy's privacy management program.

3. Principle 1 – Accountability

3.1 Organizational Accountability

The Company is responsible for all personal information under its control, including information that has been transferred to third parties for processing, and has implemented a comprehensive privacy management program to ensure compliance with PIPEDA and all applicable privacy laws.

The program includes:

  • Documented policies and procedures outlining the Company's stance on the collection, use, retention and disclosure of personal information
  • A designated Officer responsible for the oversight of this privacy and consumer protection policy
  • Employee training and awareness on privacy, confidentiality, record keeping and regulatory obligations
  • Protocols for identifying, assessing and responding to any privacy breaches
  • Oversight and contractual controls for third party service providers who may process personal information on behalf of Blu Pqy
  • Periodic monitoring, audits and policy reviews to ensure compliance with PIPEDA, the PCMLTFA and industry best practices

This program will be reviewed at a minimum annually, and updated where necessary to reflect changes in legislation, regulatory guidance, technology and business operations.

4. Principle 2 – Identifying Purposes

4.1 Purpose Identification Requirement

Blu Pqy identifies and communicates the purposes for which personal information is collected prior to or at the time of collection.

4.2 Purposes for Collection, Use, and Disclosure

The Company collects, uses, and discloses personal information for the following purposes:

  • The delivery of MSB services including but not limited to money transfers, foreign exchange, remittance and payment processing
  • To verify the identity and meet regulatory obligations under the PCMLTFA (including KYC, record keeping, ongoing monitoring and reporting)
  • To detect, investigate and prevent fraud, money laundering, terrorist financing and unauthorized transactions
  • When communicating with clients regarding account information, transactions, and customer support
  • To meet legal and regulatory obligations under Canadian law
  • For business operations such as maintaining account records

Service Delivery

  • Processing money transfers, currency exchanges, and payment transactions
  • Opening and maintaining client accounts and service agreements
  • Executing client instructions and facilitating transactions
  • Providing customer service and support
  • Communicating with clients about their transactions and accounts

Legal and Regulatory Compliance

  • Verifying client identity as required by FINTRAC regulations (MSB obligations)
  • Conducting customer due diligence and enhanced due diligence for high-risk clients
  • Complying with FINTRAC's reporting requirements under the PCMLTFA
  • Complying with Bank of Canada reporting requirements under the RPAA
  • Responding to lawful requests from regulators, law enforcement, and government authorities
  • Meeting record-keeping requirements under PCMLTFA and RPAA
  • Complying with court orders, subpoenas, and legal processes

Risk Management and Security

  • Detecting, preventing, and investigating fraud, money laundering, and terrorist financing
  • Protecting the security and integrity of the Company's systems and services
  • Conducting transaction monitoring and risk assessments
  • Implementing sanctions screening and anti-money laundering controls
  • Protecting against unauthorized transactions and identity theft

Business Operations

  • Assessing creditworthiness or eligibility for services where applicable
  • Managing business relationships and communicating about services
  • Maintaining business records and transaction history

4.3 Purpose Limitation

The Company uses personal information only for the purposes identified at the time of collection, unless additional consent is obtained or the use is required by law.

5. Principle 3 – Consent

5.1 Consent Requirement

The Company obtains meaningful, informed, and voluntary consent before collecting, using, or disclosing personal information, except where otherwise permitted or required by law.

5.2 Meaningful Consent

Individuals are informed of the purposes for which their information is being collected so they can make an informed decision about providing consent.

5.3 Forms of Consent

The Company obtains Express Consent when collecting sensitive personal information or when required by law, and Implied Consent is obtained for routine MSB services.

5.4 Obtaining Consent

Blu Pqy provides individuals with clear, concise information about the purposes for which their information is collected and ensures consent is obtained before or at the time of collection.

5.5 Withdrawing Consent

Individuals may withdraw consent at any time (providing reasonable notice), subject to legal and contractual restrictions. Withdrawing consent may limit the Company's ability to provide services. The withdrawal will be documented by Blu Pqy and the Company will cease using or disclosing the information for the purposes for which the individual previously consented, unless the information must be retained where required by law.

5.6 Exceptions to Consent

PIPEDA permits collection, use, or disclosure of personal information without consent in specific circumstances, including:

Legal Requirements: When required or authorized by law, such as:

  • FINTRAC reporting obligations (suspicious transaction reports, large cash transaction reports, electronic funds transfer reports)
  • Court orders, subpoenas, and legal processes
  • Regulatory investigations and examinations
  • Law enforcement investigations with appropriate legal authority

Investigation of Legal Violations: When collecting the information is reasonable for investigating contraventions of laws or breaches of agreements.

When relying on exceptions to consent, the Company documents the legal basis and collects only the minimum information necessary.

5.7 Consent and Regulatory Obligations

Certain disclosures to FINTRAC, law enforcement, the Bank of Canada, and other regulatory bodies are legally required and occur without the individual's consent or knowledge.

6. Principle 4 – Limiting Collection

6.1 Collection Limitation

The Company limits the collection of personal information to that which is necessary and relevant for the identified purposes. The Company does not collect information indiscriminately.

6.2 Information Minimization

Before collecting personal information, the Company:

  • Assesses whether the information is necessary for the identified purpose
  • Determines whether the same purpose can be achieved with less information or de-identified information
  • Collects only the minimum information required
  • Avoids collecting information “just in case” it might be useful later

6.3 Fair and Lawful Collection

All personal information is collected:

  • By fair and lawful means
  • With the knowledge of the individual (except where permitted by law)
  • In accordance with consent requirements
  • Through transparent processes

The Company does not use deceptive, misleading, or covert collection methods.

6.4 Types of Information Collected

The Company collects the following categories of personal information based on service requirements:

  • Identity Information: Legal name, date of birth, residential address and/or business address, forms of identification, citizenship and jurisdiction of residence, occupation and/or nature of business
  • Financial Information: Bank account details, payment card information, transaction history and records, source of funds and wealth, beneficial ownership information for entities
  • Contact Information: Including but not limited to telephone numbers, email addresses and mailing addresses
  • Transaction Information: Including but not limited to account, currency, date of transaction, purpose of transaction, beneficiary and originator information for transfers and countries involved in transactions
  • Technical Information: Including but not limited to IP addresses, device identifiers, log files and usage information

Other Information:

  • Correspondence and communications with the Company
  • Complaint records and dispute resolution documentation
  • Politically exposed person (PEP) status
  • Sanctions screening results

7. Principle 5 – Limiting Use, Disclosure, and Retention

7.1 Use and Disclosure Limitation

Personal information is used and disclosed only for the purposes for which it was collected, as identified to the individual, unless:

  • The individual consents to a new use or disclosure
  • The use or disclosure is required or authorized by law
  • The use or disclosure falls within a recognized PIPEDA exception

7.2 Disclosure to Third Parties

The Company may disclose personal information to the following third parties for specified purposes:

  • Service Providers and Processors
  • Regulatory and Governmental authorities
  • Cross-Border Data Transfers (third party processors outside of Canada)

Individuals should be aware that personal information processed in foreign jurisdictions may be subject to lawful access by foreign government authorities, courts, and law enforcement agencies under the laws of those jurisdictions.

7.3 Internal Disclosure

Within the Company, personal information is accessible only to employees, agents, and contractors who:

  • Have a legitimate business need to access the information
  • Are authorized to access the information for specific purposes
  • Have completed privacy and security training
  • Are bound by confidentiality obligations

Access to personal information is restricted through role-based access controls and is monitored.

7.4 Data Retention

The Company retains personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by law.

Retention Periods:

  • Client Identification Records: Client identification and verification records are retained for at least five years from the end of the business relationship.
  • Transaction Records: Minimum 5 years from date of transaction (PCMLTFA requirement)
  • FINTRAC Reports: Minimum 5 years from date of report submission
  • Service Agreements: Duration of relationship plus 5 years
  • Complaint Records: 6 years from resolution date
  • Marketing Consent Records: Until consent is withdrawn plus 1 year
  • Employee Records: Duration of employment plus 7 years (or as required by employment law)
  • Information Used for Decision-Making: Sufficient time to allow individuals to request access and exhaust appeals (typically 1–2 years minimum)
  • Corporate and Financial Records: 7 years (as required by corporate and tax law)

Personal information is not retained indefinitely. The Company has implemented maximum retention periods based on legal requirements, business needs, and privacy principles.

7.5 Secure Disposal

When personal information is no longer required for identified purposes and retention periods have expired, the Company securely disposes of the information by:

  • Permanently deleting electronic records through secure data wiping or destruction protocols
  • Shredding or incinerating physical documents
  • Ensuring backup copies are also destroyed
  • Maintaining records of disposal activities

Personal information is made anonymous (de-identified and aggregated) when it is to be used for statistical analysis, research, or historical purposes, ensuring individuals cannot be re-identified.

7.6 Data Retention Guidelines

The Company has implemented retention and disposal guidelines that:

  • Specify minimum and maximum retention periods for each category of personal information
  • Consider legal and regulatory requirements
  • Account for limitation periods and appeal mechanisms
  • Balance business needs against privacy principles
  • Include automated deletion processes where feasible
  • Are reviewed and updated regularly

8. Principle 6 – Accuracy

8.1 Accuracy Requirement

Personal information used by the Company must be as accurate, complete, and up-to-date as necessary for the purposes for which it is used.

8.2 Ensuring Accuracy

The Company ensures accuracy by:

  • Collecting information directly from individuals when possible
  • Verifying identity information through government-issued documents and reliable methods
  • Confirming information with individuals at regular intervals
  • Updating records when individuals provide new information
  • Implementing data validation rules in systems to prevent entry errors
  • Conducting periodic reviews of client information

8.3 Accuracy for Decision-Making

When personal information is used to make decisions about individuals (for example, service eligibility, risk assessments, compliance decisions), the Company takes particular care to ensure the information is accurate, current, and gives the individual an opportunity to review and amend incorrect information before decisions are made.

8.4 Individual Responsibility

Individuals are responsible for providing accurate and complete information to the Company. Additionally, they must notify the Company of any changes to their personal information.

The Company cannot be held responsible for inaccuracies resulting from information provided by the individual or failure to notify the Company of changes.

8.5 Correction Process

Individuals may challenge the accuracy and completeness of their personal information and request corrections by contacting the Company to highlight any inaccuracies and provide supporting documentation or evidence.

Upon receiving a correction request, the Company will:

  • Investigate the accuracy concern promptly
  • Correct verified inaccuracies without delay
  • Notify the individual of corrections made
  • If a correction is disputed, document the individual's claim and include it with the record
  • Notify third parties to whom the inaccurate information was disclosed (if appropriate)

9. Principle 7 – Safeguards

9.1 Security Safeguards Requirement

The Company protects personal information with security safeguards appropriate to the sensitivity of the information.

9.2 Sensitivity Assessment

Security safeguards are tailored to the sensitivity of personal information, considering:

  • The nature of the information (highly sensitive financial and identification information requires stronger protection)
  • The amount of information
  • The context of use
  • The potential harm from unauthorized access, use, or disclosure (identity theft, financial loss, reputational damage)

9.3 Security Measures

The Company implements physical, technological, and organizational security measures including:

Physical Safeguards

  • Secure facilities with controlled access (key cards, visitor logs, security personnel)
  • Locked filing cabinets and secure storage for physical records
  • Secure disposal facilities for confidential documents (cross-cut shredders, secure bins)
  • Clean desk policies requiring physical documents to be secured when not in use
  • Visitor restrictions to areas containing personal information

Technological Safeguards

  • Encryption of personal information in transit (TLS/SSL for data transmission) and at rest (database and file encryption)
  • Firewalls, intrusion detection systems, and anti-malware protection
  • Multi-factor authentication for access to systems containing personal information
  • Role-based access controls limiting access to authorized personnel only
  • Secure password policies and management
  • Regular security updates and patch management
  • Logging and monitoring of access to personal information
  • Secure backup and disaster recovery systems
  • Data loss prevention tools
  • Regular penetration testing and vulnerability assessments

Organizational Safeguards

  • Privacy and security policies and procedures
  • Mandatory privacy and security training for all personnel
  • Confidentiality agreements for employees, contractors, and third parties
  • Background checks for employees with access to sensitive information
  • Incident response and breach management protocols
  • Access management processes (provisioning, review, de-provisioning)
  • Regular security audits and compliance monitoring
  • Privacy impact assessments for new systems and initiatives

9.4 Third-Party Security

When personal information is transferred to third parties:

  • Due diligence assesses the third party's security capabilities
  • Contracts require security safeguards appropriate to information sensitivity
  • The Company monitors third-party security through audits, certifications, and reviews
  • Security incidents involving third parties are reported to the Company

9.5 Employee Security Obligations

All employees, contractors, and agents must:

  • Access personal information only for authorized business purposes
  • Protect passwords and authentication credentials
  • Lock workstations when unattended
  • Report lost or stolen devices containing personal information immediately
  • Report security incidents and suspected breaches promptly
  • Comply with all security policies and procedures

Violations of security obligations may result in disciplinary action.

9.6 Ongoing Security Review

The Company regularly reviews and updates security safeguards to:

  • Address emerging threats and vulnerabilities
  • Incorporate new security technologies
  • Respond to security incidents and lessons learned
  • Ensure continued appropriateness to information sensitivity

10. Principle 8 – Openness

10.1 Openness Requirement

The Company is open and transparent about its policies and practices for managing personal information, making information readily available to individuals.

10.2 Privacy Information to Be Made Available

The Company makes the following information readily available:

  • A description of personal information held by the Company (types and categories)
  • A description of how personal information is used and disclosed
  • Policies and procedures for providing individuals access to their personal information
  • How to make privacy complaints and the complaint resolution process
  • Information about cross-border data transfers and foreign processing
  • Breach notification procedures

10.3 Plain Language

Privacy information is communicated in plain language that is clear, concise, and accessible to individuals with varying levels of literacy.

10.4 Privacy Notices

In addition to this comprehensive policy, the Company provides concise privacy notices:

  • At points of collection (application forms, websites, kiosks)
  • In service agreements and terms of use
  • When significant changes to privacy practices occur
  • In response to specific privacy questions

10.5 Policy Updates

When the Company makes significant changes to privacy policies or practices, it must notify individuals with existing relations of any material changes.

11. Principle 9 – Individual Access

11.1 Access Rights

Individuals have the right to:

  • Be informed of the existence, use, and disclosure of their personal information held by the Company
  • Access their personal information
  • Challenge the accuracy and completeness of their information and have it corrected as appropriate

11.2 No Cost Access

The Company provides access to personal information without charging a fee, except in limited circumstances where:

  • Responding to the request requires significant resources or third-party costs
  • The individual has made repetitive or vexatious requests

If a fee is charged, the Company will:

  • Inform the individual of the fee before proceeding
  • Provide an estimate of the cost
  • Obtain the individual's consent to proceed
  • Charge only reasonable, cost-recovery fees

11.3 Exceptions and Limitations to Access

The Company may refuse or limit access to personal information where:

  • Disclosure would reveal confidential commercial information or trade secrets
  • Disclosure would reveal personal information about another individual (unless that individual consents or the information can be severed)
  • The information is protected by solicitor-client privilege or litigation privilege
  • Disclosure could reasonably be expected to threaten the life or security of another individual
  • The information was collected for investigating a breach of agreement or contravention of law
  • The information was generated in the course of a formal dispute resolution process
  • The information is subject to legal restrictions on disclosure

When access is refused in whole or in part, the Company will:

  • Inform the individual of the reason for refusal
  • Cite the specific exception relied upon
  • Inform the individual of their right to challenge the refusal with the Privacy Commissioner of Canada

12. Principle 10 – Challenging Compliance

12.1 Right to Challenge

Individuals have the right to challenge the Company's compliance with PIPEDA's fair information principles and this Privacy and Consumer Protection Policy.

12.2 Internal Complaint Process

Individuals may submit privacy complaints by:

  • Contacting the Company in writing (email, mail, or online form)
  • Describing the nature of the privacy concern or alleged violation
  • Providing relevant details (dates, individuals involved, information affected)

12.3 Investigation of Complaints

Upon receiving a privacy complaint, the Company will:

  • Acknowledge receipt within 5 business days
  • Assign the complaint to an appropriate investigator
  • Investigate the complaint objectively and impartially
  • Review relevant records, policies, and evidence
  • Interview relevant personnel if necessary
  • Provide a written response within 30 days (or provide an explanation if more time is needed)
  • Explain the findings and any corrective actions taken

All privacy complaints are logged and tracked to ensure timely resolution and to identify systemic issues.

12.4 Escalation to Privacy Commissioner

If an individual is not satisfied with the Company's response to a privacy complaint, they may escalate the matter to the Office of the Privacy Commissioner of Canada (OPC):

Privacy Commissioner of Canada

The Privacy Commissioner has the authority to:

  • Investigate complaints about PIPEDA compliance
  • Conduct audits of organizational privacy practices
  • Make findings and recommendations
  • Publicize findings of non-compliance
  • Refer matters to Federal Court for enforcement

12.5 No Retaliation

The Company prohibits retaliation against any individual who:

  • Submits a privacy complaint in good faith
  • Participates in a privacy investigation
  • Reports privacy concerns to management or regulators
  • Exercises their privacy rights under PIPEDA

13. Privacy Breach Management

13.1 Breach Identification and Assessment

The Company has implemented protocols to identify and assess breaches of security safeguards involving personal information, including:

  • Loss of devices or records containing personal information
  • Unauthorized access to systems or databases
  • Unauthorized disclosure or sharing of personal information
  • Theft of personal information
  • Hacking, ransomware, or other cyber incidents
  • Employee misconduct or negligence resulting in privacy breaches
  • Third-party security failures

13.2 Breach Response Procedures

Upon discovering a potential breach, the Company will:

  • Contain the breach immediately to prevent further unauthorized access or disclosure
  • Investigate the nature and scope of the breach
  • Determine what personal information was affected and how many individuals
  • Assess the causes and contributing factors
  • Document the breach investigation and response actions

13.3 Real Risk of Significant Harm Assessment

The Company assesses whether a breach creates a real risk of significant harm by considering:

Sensitivity of Information: Whether the information could be used for identity theft, fraud, financial loss, or reputational harm (financial records, identification numbers, passwords are highly sensitive).

Probability of Misuse: The likelihood that the information will be misused, considering:

  • Who had or may have access to the information
  • Whether safeguards were in place (encryption, password protection)
  • The nature of the incident (malicious vs. inadvertent)
  • Whether the information has been or will be recovered

Significant Harm: Potential harm includes bodily harm, humiliation, damage to reputation or relationships, loss of employment or business opportunities, financial loss, identity theft, negative credit impacts, damage to or loss of property.

13.4 Breach Notification to Privacy Commissioner

If the Company determines a breach creates a real risk of significant harm, the Company will notify the Office of the Privacy Commissioner of Canada (OPC) as soon as feasible using the PIPEDA Breach Report Form.

The report to the OPC includes:

  • Description of the circumstances of the breach
  • Date or time period when the breach occurred
  • Description of the personal information involved
  • Number of affected individuals (or estimate)
  • Steps taken to reduce risk of harm
  • Steps taken to notify affected individuals
  • Contact information for inquiries

13.5 Notification to Affected Individuals

If a breach creates a real risk of significant harm, the Company notifies affected individuals as soon as feasible after determining the breach occurred.

Notification to individuals includes:

  • The Company's name and contact information
  • Description of the breach and when it occurred
  • Description of the personal information involved
  • Steps the Company has taken to reduce risk of harm or mitigate harm
  • Steps individuals can take to reduce risk of harm or protect themselves (for example, monitoring accounts, changing passwords, fraud alerts)
  • Contact information for inquiries about the breach

Method of Notification: Direct notification to individuals (email, telephone, mail) unless:

  • Direct notification would cause further harm to individuals
  • Direct notification would cause undue hardship to the Company (for example, prohibitive cost or Company lacks contact information)
  • The Company does not have contact information and cannot reasonably obtain it

If direct notification is not feasible, the Company provides indirect notification through public communication (website notice, media announcement) that is reasonably likely to reach affected individuals.

13.6 Notification to Other Organizations

If another organization or government institution may be able to reduce the risk of harm or mitigate harm resulting from the breach, the Company notifies that organization as soon as feasible, which may include:

  • Payment institutions that can freeze accounts or issue fraud alerts
  • Credit bureaus to place alerts on credit files
  • Identity theft protection services
  • Law enforcement agencies
  • Other payment service providers or networks affected by the breach

13.7 Breach Record-Keeping

The Company maintains records of all breaches (regardless of whether they meet the real risk of significant harm threshold), including:

  • Date or time period of the breach
  • General description of circumstances
  • Affected personal information and number of individuals
  • Whether the breach was reported to the OPC and individuals were notified
  • Explanation of why the real risk threshold was or was not met

Breach records are retained for a minimum of 24 months and are made available to the Privacy Commissioner upon request.

13.8 Post-Breach Review and Remediation

Following a breach, the Company conducts a post-incident review to:

  • Identify root causes and contributing factors
  • Determine whether security safeguards were adequate
  • Implement corrective actions to prevent recurrence
  • Update policies, procedures, and training as needed
  • Report findings to senior management and the Board

14. Consumer Rights and Protections

14.1 Right to Clear Information

All consumers have the right to receive clear, accurate, and timely information about:

  • Services offered and how they function
  • All fees, charges, and exchange rates
  • Terms and conditions of service
  • Privacy practices and how personal information is handled
  • Rights and responsibilities
  • How to file complaints and access dispute resolution

14.2 Right to Fair Treatment

The Company commits to:

  • Treating all consumers fairly, objectively, and without discrimination
  • Ensuring accessibility for vulnerable consumers and persons with disabilities
  • Avoiding unfair, deceptive, or misleading practices
  • Providing reasonable accommodations when requested
  • Respecting consumer privacy and confidentiality

14.3 Right to Complaint Resolution

Consumers have the right to:

  • Submit complaints about services, fees, or treatment free of charge through multiple accessible channels
  • Receive timely acknowledgment and investigation of complaints
  • Escalate unresolved complaints internally and to external bodies
  • Receive fair redress and compensation when appropriate

14.4 Right to Accessible Services

The Company ensures services are accessible by:

  • Providing multiple communication channels (in-person, phone, email, online)
  • Offering services in English and French where required
  • Accommodating persons with disabilities under the AODA
  • Supporting consumers with varying levels of technological proficiency
  • Providing alternative formats for communications upon request

15. Disclosure and Transparency

15.1 Fee Disclosure

The Company provides clear disclosure of all fees before services are rendered, including:

  • Transaction fees and service charges
  • Currency conversion rates and margins
  • Third-party fees that may apply
  • Any changes to fee structures with appropriate advance notice (typically 30–60 days)

15.2 Terms and Conditions

Service agreements and terms of use must:

  • Be written in plain, understandable language
  • Clearly outline consumer rights and obligations
  • Specify service limitations and exclusions
  • Detail cancellation and refund policies
  • Include privacy notices and consent provisions
  • Be readily accessible on the Company website and upon request

15.3 Cross-Border Transfer Disclosure

Privacy notices clearly disclose that:

  • Personal information may be transferred to third-party processors outside Canada
  • The countries where information may be processed
  • That information processed in foreign jurisdictions may be subject to lawful access by foreign government authorities
  • That contractual and technical safeguards protect transferred information
  • That the Company remains accountable for information transferred to third parties

16. Complaints Handling Procedure

16.1 Complaint Submission Channels

Consumers may submit service complaints (non-privacy) through:

  • Email: complaints@blupqy.com
  • Mail: Complaints, Blu Pqy Inc., 130 Spadina Avenue, Unit 807, Toronto, Ontario, M5V 2L4, Canada
  • In-app: the Support section of the Blu Pqy application

16.2 Complaint Acknowledgment and Resolution

The Company:

  • Acknowledges receipt of complaints within 5 business days
  • Assigns a unique complaint reference number
  • Investigates complaints objectively and impartially
  • Resolves complaints within 56 days (8 weeks) of receipt
  • Escalates unresolved complaints to the Senior Complaints Officer
  • Provides written decisions with reasoning

17. Error Resolution and Unauthorized Transactions

17.1 Error Notification Process

Consumers may report errors or unauthorized transactions immediately through any complaint channel. The Company does not require written confirmation to begin an investigation, though supporting documentation may be requested.

17.2 Investigation Requirements

Upon receiving an error notice, the Company:

  • Begins investigation immediately
  • Provides written acknowledgment within 10 business days
  • Reviews transaction records, system logs, and consumer documentation
  • Considers all relevant factors before determining fault
  • Completes investigation within a reasonable timeframe

17.3 Refund and Reimbursement

If an error or unauthorized transaction is confirmed:

  • Full refund is provided within 15 days of determination
  • All associated fees and charges are reversed
  • Interest or other financial impacts are compensated
  • Written explanation of resolution is provided

18. Anti-Money Laundering and Consumer Disclosure

18.1 Regulatory Disclosure Requirements

The Company informs consumers that:

  • Identity verification is legally required under the PCMLTFA for MSBs
  • Certain transaction information must be reported to FINTRAC
  • Reporting occurs without consumer consent or notification
  • These requirements exist for anti-money laundering and counter-terrorism financing purposes
  • Failure to cooperate with verification may prevent service delivery

18.2 Client Identification and Verification

The Company verifies identity when:

  • Opening accounts or establishing service agreements
  • Conducting transactions over specified thresholds
  • Any transaction is suspicious regardless of amount

Verification methods include government-issued photo ID, credit file verification, or dual-process methods as prescribed by FINTRAC.

18.3 Record Keeping Disclosure

Consumers are informed that:

  • Identification and transaction records are retained for a minimum of 5 years (PCMLTFA requirement)
  • Records may be produced to FINTRAC or law enforcement in accordance with legal obligations
  • Privacy rights are balanced against legal requirements for record retention

19. Accessibility and Vulnerable Consumers

19.1 Accessibility Standards

The Company commits to removing barriers for persons with disabilities by:

  • Ensuring physical accessibility of premises (ramps, accessible washrooms, door openers)
  • Providing digital accessibility (WCAG 2.0 Level AA compliance for website and applications)
  • Offering assisted services upon request
  • Training staff on accessibility and accommodation

19.2 Plain Language and Alternative Formats

All consumer-facing materials use plain language wherever feasible. Upon request, the Company provides reasonable accommodation that may include:

  • Large print documents
  • Audio recordings
  • Braille
  • Electronic formats compatible with screen readers
  • Translation services for languages other than English/French (where feasible)

19.3 Support for Vulnerable Consumers

The Company recognizes vulnerable consumers may include persons with disabilities, low-income individuals, seniors, newcomers to Canada, and persons with limited financial literacy.

Special accommodations include:

  • Extended time for decision-making
  • Additional explanation of terms and privacy practices
  • Flexibility in documentation requirements where permissible
  • Referrals to financial counseling or support services

20. Cancellation and Refund Rights

20.1 Cancellation Notice Requirements

Consumers may cancel service agreements by providing written notice (mail, email, or delivery). Notice of cancellation takes effect when sent by the consumer.

20.2 Refund Timelines

Upon receiving valid cancellation notice, the Company processes refunds within 15 calendar days, refunding all payments made by the consumer (except amounts permitted by law for services already consumed).

20.3 Ongoing Service Agreement Cancellation

For ongoing service agreements:

  • Consumers may cancel with appropriate notice (typically 30 days unless otherwise specified)
  • No penalty fees are charged for cancellation except as disclosed in the agreement
  • Outstanding transactions are completed or reversed as appropriate
  • Pro-rated refunds are provided for prepaid services

21. Governance and Oversight

21.1 Board Oversight

The Board of Directors:

  • Approves this Privacy and Consumer Protection Policy and all amendments
  • Reviews privacy and consumer protection performance annually
  • Receives reports on privacy breaches, complaints, and consumer outcomes
  • Ensures adequate resources for privacy and consumer protection compliance
  • Holds management accountable for privacy and consumer protection outcomes

21.2 Compliance Officer Responsibilities

Compliance Officer:

  • Oversees overall regulatory compliance (FINTRAC, RPAA, privacy and consumer protection)
  • Coordinates complaint handling and consumer protection
  • Monitors compliance with all applicable regulations
  • Reports compliance matters to the Board

21.3 Staff Training

All employees receive mandatory training on:

  • PIPEDA's 10 Fair Information Principles
  • Privacy rights and individual access requests
  • Privacy breach identification and reporting
  • Security safeguards and confidentiality
  • Consumer rights and protections
  • Complaint handling and fair treatment
  • Accessibility and serving vulnerable consumers

Training is provided upon hire and refreshed annually.

21.4 Policy Review and Updates

This Privacy and Consumer Protection Policy is:

  • Reviewed annually by the assigned Officer
  • Updated to reflect regulatory changes, Privacy Commissioner guidance, and emerging privacy issues
  • Tested for effectiveness through audits, complaint analysis, and breach reviews
  • Revised based on privacy trends and systemic issues identified

22. Record Keeping and Reporting

22.1 Retention Periods

Privacy-related records are retained as follows:

  • Consent records: Duration of relationship plus 1 year
  • Access requests: 1 year after access provided
  • Privacy complaints: 2 years after resolution
  • Privacy breach records: Minimum 24 months (or longer if litigation or investigation is pending)
  • Privacy impact assessments: Duration of system/project plus 3 years
  • Privacy training records: 3 years
  • Third-party agreements: Duration of agreement plus 7 years

22.2 Consumer and Transaction Records

Non-privacy record retention is governed by legal requirements:

  • Client identification and verification: Minimum 5 years (PCMLTFA)
  • Transaction records: Minimum 5 years (PCMLTFA)
  • Service agreements: Duration plus 5 years
  • Complaint records: 6 years
  • Corporate records: 7 years

23. Enforcement and Remediation

23.1 Monitoring and Auditing

The Company:

  • Conducts ongoing privacy compliance monitoring
  • Performs annual internal or external privacy audits
  • Tests access request and complaint handling procedures
  • Monitors breach response effectiveness
  • Tracks key privacy performance indicators

23.2 Systemic Issue Identification

When recurring privacy issues or systemic problems are identified:

  • Root cause analysis is conducted
  • Impact assessment determines affected individuals
  • Cross-functional review examines broader implications
  • Senior management and Board are notified
  • Corrective action plans are developed and implemented

23.3 Remediation and Redress

When individuals have been harmed by privacy breaches or policy violations:

  • The Company proactively identifies affected individuals
  • Provides appropriate redress (credit monitoring, identity theft protection, compensation)
  • Contacts all affected individuals, not only those who complained
  • Documents redress provided and completion
  • Reports significant privacy incidents and remediation to the Board and Privacy Commissioner

24. Complaints Handling and Escalation Processes

Blu Pqy is committed to handling customer complaints in a fair and timely manner. This next section will provide clear and accessible channels to raise concerns and submit complaints both internally and externally.

24.1 Internal Complaints Handling

If a customer has a question or complaint regarding Blu Pqy services, they may use the following points of contact:

  • Email: complaints@blupqy.com
  • Mail: Complaints, Blu Pqy Inc., 130 Spadina Avenue, Unit 807, Toronto, Ontario, M5V 2L4, Canada
  • In-app: the Support section of the Blu Pqy application

24.2 External Complaints Handling

Where a customer is not satisfied with the outcome of a complaint, or prefers to raise concerns externally, they may contact the following regulatory or oversight bodies where applicable.

24.2.1 Escalation to Privacy Commissioner

If an individual is not satisfied with the Company's response to a privacy complaint, they may escalate the matter to the Office of the Privacy Commissioner of Canada (OPC):

Privacy Commissioner of Canada

24.2.2 Consumer Protection Ontario

Customers may contact Consumer Protection Ontario for information regarding their rights and to file a complaint under Ontario's Consumer Protection Act.

  • Phone: 1-800-889-9768 or 416-326-8800 / TTY: 1-877-666-6545 or 416-229-6086
  • Mail: Manager, Marketplace Intelligence and Consumer Services, Ministry of Public and Business Service Delivery and Procurement, Consumer Services Operations Division, PO Box 450, Toronto ON M7A 2J6
  • Website: Complaint Form

24.2.3 Consumer Protection Ontario Complaints Form Steps

This next section is a step-by-step guide on how to fill out Consumer Protection Ontario's complaints form:

  1. Provide your name and mailing address
  2. Contact information (phone, email)
  3. Blu Pqy contact information (business name, address, phone, email)
  4. Contact information of the person you were dealing with at the business
  5. Information about your complaint (whether you have informed the business, date of agreement/transaction if applicable, amount in dispute, method of payment, details about the complaint and how you would like the complaint resolved)
  6. Provide any supporting documentation for your complaint (initial complaint to the business, any responses, terms and conditions of contract if applicable, record of payment)
  7. Provide some demographic questions (skip this section if you are completing on behalf of a business)
  8. Submit form

24.2.4 The Competition Bureau of Canada

For concerns about misleading advertising or anti-competitive practices, the Competition Bureau of Canada may also be contacted.

The Competition Bureau of Canada has several channels for general inquiries and feedback as well as reporting complaints and suspicious business activities which can be accessed through their website.

The Future of MEA Payments

Moving Money Where It Matters

Solutions

Business Payments

Cross-Border Transfers

Global Payouts

Multi-Currency Payments

Supplier & Vendor Payments

Contact

For partnerships and early access inquiries.

The Future of MEA Payments

Moving Money Where It Matters

Company

Moving Money Where It Matters

Moving Money Where It Matters

Solutions

Businesses

Businesses

Businesses

Businesses

Businesses

Who It's For

Global Payouts

Global Payouts

The Future of MEA Payments

Company

Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.

Company

Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.

Company

Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.

Company

Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.

Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.

Home