On this page
- Who is responsible
- What we keep
- Why we keep it
- Where it is kept
- Who can see it
- OneDrive and Google Drive
- Companies that help run Daykit
- Your browser
- How long we keep it
- Keeping it safe
- If something goes wrong
- What you can ask for
- Changes
Who is responsible
Daykit is made and run by Everyday Office Consulting Inc ("EOCO") in Nova Scotia, Canada. Our Privacy Officer is Bobby Gosbee, who is accountable for how Daykit handles personal information. Write to him at [email protected] about anything on this page.
There are two kinds of information in Daykit, and the responsibility is different for each:
- Your own account (your name, email and sign-in): EOCO is responsible for it.
- What a firm puts in about its clients (their names, contact details, onboarding answers, jobs, requests and files): the firm is responsible for it, the same as for its paper files. Daykit keeps and handles it for the firm, only to run the tools the firm uses. If you are one of a firm's clients, the firm is the place to start with any question; you are also welcome to write to us.
What we keep
| What | For example |
|---|---|
| Your account | Your name, email address and password (kept only in a scrambled form that can't be read back), your 2-step sign-in set-up, the devices you asked us to remember, and the firms you belong to. |
| Your firm | The business name, address, phone and logo, the people in the firm and their roles, and each tool's settings. |
| What you type into the tools | Clients and their contact details, onboarding answers (such as business and tax account numbers, year-end, software used), jobs and their steps, notes and messages, time entries, requests to clients, quotes, payments to government, loan schedules, and expense claims. |
| Your clients' secure page | The client's name and email, a password they choose (scrambled, never readable), the codes we email them to confirm it's them, and a list of what they sent and when. |
| Technical details | Sign-in records and the internet address a request came from, which our providers keep for a short time to run and protect the service. |
The demo and the Sample Company use made-up information. A demo visitor needs no name or email, and what they do is cleared within a day.
Why we keep it
Only to run Daykit for you: to sign you in, to let your firm's tools work, to send the emails you or your firm set up (invitations, requests to clients, reminders, expense approvals), to keep the service working and safe, and to help when you ask us to. We don't use it for advertising and we don't sell or rent it to anyone. By using Daykit you agree to this; you can withdraw at any time by closing your account (the tools can't work without the information they need).
Where it is kept
- Daykit's own information is kept in a database in Canada (Supabase's Montréal region), and the programs that send emails and talk to your drive run in Canada too.
- Client documents (files clients send, files you share with them, receipt photos, payment confirmations, loan schedules) go straight into your firm's own OneDrive or Google Drive. Where Microsoft or Google keeps them depends on your firm's account with them.
- Some companies that help run Daykit are outside Canada (below), so a little of your information, such as an email address on its way out, may pass through the United States or elsewhere and be subject to the laws there.
Who can see it
- People in your firm, as the firm's owner allows. The owner decides who joins the firm, each person's role, and what each level may see and do in each tool. Contractors only see their own clients.
- Other firms can't. The database itself refuses to show one firm's information to another, not only the screens.
- Your clients only see their own secure page: what you've asked them for, the files they've sent, the files you've shared with them, and your forms. Never your jobs, notes or other clients.
- EOCO: Daykit's developer account can see firms' information in Daykit, so that we can make backups, fix problems and help when you ask. We only look when that's needed, and never share what we see.
- Anyone else only if the law requires it (for example a court order), and then only what is required.
OneDrive and Google Drive
When a firm's owner connects a drive, Daykit asks for the smallest access those services offer:
- Microsoft OneDrive: only Daykit's own app folder (Apps → Daykit), plus the account's name and email to show which drive is connected.
- Google Drive: only the files and folders Daykit itself creates, plus the account's name and email. Daykit can't see anything else in the drive.
Daykit uses that access only to save, list, open, rename and remove files in that folder for the firm's own work. Daykit's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Nothing from the drive is used for advertising, sold, or shown to people outside the firm (apart from what the firm shares with a client).
The keys that let Daykit reach the drive are stored scrambled, in a part of the database the website itself can't reach, and they're left out of backups. The owner can press Disconnect on the Dashboard at any time: Daykit forgets its access straight away and the files stay in the drive. You can also remove Daykit's access from your Microsoft or Google account settings.
When a firm has Expense Approvals send approved claims to Dext or Hubdoc, the claim's PDF is emailed to the address the firm gave, and then removed from Daykit.
Companies that help run Daykit
| Company | What it does for Daykit |
|---|---|
| Supabase | The database and sign-in, in Canada. |
| Cloudflare | Delivers the website, and the robot check on the sign-in box (Turnstile). |
| Resend | Sends Daykit's emails. |
| Microsoft and Google | Your firm's own drive, when your firm connects one. |
| jsDelivr, cdnjs and Google Fonts | Deliver some of the code libraries and lettering the pages use. Your browser asks them for those files directly. |
| GitHub | Keeps the website's own code (no firm or client information). |
| YouTube or Vimeo | Only when an announcement has a video and you press play on it (YouTube in its privacy-enhanced mode). |
Each one only gets what it needs to do its part, and is bound by its own privacy and security terms.
Your browser
Daykit keeps a few small things in your browser so it works the way you left it: that you're signed in, dark mode, the order of your Tool tray, which sections you folded. A Job Tracker copy may be kept on your device for up to three days so you can look at it without a connection; signing out clears it. There are no advertising or tracking cookies, and no outside analytics.
How long we keep it
- Your account and your firm's information are kept for as long as you use Daykit.
- A firm can delete a client (and their jobs) at any time; that removes them from Daykit for good. Files in the firm's drive stay there until the firm removes them.
- Demo visitors and their copy are cleared within a day; a Sample Company copy is cleared when you leave it.
- Links in request emails run out, and a client can ask for a new one.
- When a firm or a person asks us to close their account, we delete their information from Daykit, apart from anything the law requires us to keep. Copies in Daykit's backups are replaced as new backups are made.
Keeping it safe
- Everything travels encrypted (https).
- Passwords are never stored in a readable form, for you or your clients.
- 2-step sign-in is required for every firm owner and admin, and anyone can turn it on.
- A robot check protects the sign-in box.
- The database checks who you are and what your firm allows on every request, so the rules can't be got around from the screen.
- A firm's owner can download a backup of the firm (with its files) from the Dashboard at any time.
No service can promise to be perfectly safe, but we work to keep Daykit as safe as we reasonably can.
If something goes wrong
If personal information in Daykit is lost, stolen or seen by someone who shouldn't see it, and that creates a real risk of significant harm, we will tell the firms and people affected as soon as we can, report it to the Office of the Privacy Commissioner of Canada, and keep a record of it, as Canadian privacy law requires. Where it's a firm's clients who are affected, we will work with the firm so they can tell their clients.
What you can ask for
Write to [email protected] and you can:
- ask what personal information Daykit holds about you, and get a copy;
- have anything that's wrong corrected (much of it you can change yourself on your Profile);
- have your account, or your firm's information, deleted;
- ask any question about how your information is handled.
We'll answer within 30 days. If you are one of a firm's clients, we may pass your request to the firm, since it decides what it keeps about you. If you're not happy with our answer, you can contact the Office of the Privacy Commissioner of Canada.
Daykit is made for businesses and isn't meant for children.
Changes
We may update this page as Daykit grows. The date at the top always shows the latest version, and we'll tell firms about any big change before it happens. See also the Terms & Disclaimer.