Skip to content

Privacy, data and retention

Where your data lives, who can reach it, what the audit trail records, how long things are kept, and how to get your data out.

ForCouncilOwnersProperty managers

A strata corporation holds personal information about everyone who lives in the building. That comes with obligations under PIPA (BC and Alberta) and PIPEDA, and they belong to the corporation, not to its software vendor.

Where your data lives

Your corporation's data is hosted in a Canadian region, handled under PIPA and PIPEDA.

Some AI processing happens outside Canada

AI features — document Q&A, the Assistant, drafts, agents — send the relevant content to a language-model provider under contract, and that processing happens in the United States. This is a real limitation and worth knowing rather than glossing over.

If your corporation has taken a position that no personal information may leave Canada, don't use the AI features. Every core function — compliance, meetings, voting, the books, storage, maintenance — works without them. The full detail is in the privacy policy.

Names are swapped out before the AI sees them

When the Assistant answers a question or ManageStrata drafts minutes, every name on your corporation's roster — past and present — is replaced with a placeholder before anything is sent, and put back when the answer returns. The provider sees [P3], not a person.

It has limits worth knowing:

  • It covers the Assistant and minute drafts so far. Other AI features — asking questions of your documents, red-flag scans, filing uploads — send text as it's written.
  • A name that isn't on the roster — a tenant, a contractor, a neighbour mentioned in meeting notes — is sent as written.
  • Uploaded documents are indexed as they're written, names included.

Draft minutes name the lot, not the owner

Where minutes deal with a particular owner's or resident's arrears, a fine, a bylaw contravention, a complaint, a dispute, hardship or health, the AI draft identifies them by strata lot — "the owner of SL12" — or, where the lot isn't known, as "an owner" or "a resident", never by name. That follows the BC privacy commissioner's guidance for strata corporations. People acting in a role — council members, the chair, movers and seconders, and the attendance list — are still named. Minutes are a draft until council approves them, so check this holds in what you file.

Who else handles your data

The privacy policy lists every service provider ManageStrata uses — hosting, email, payments, the bot check on the sign-in forms, the AI providers and the rest — with what each one is given and the country it's processed in.

Who can see what

Access is enforced in the database itself, not just in the menus. Each query is filtered by who is asking.

Owners see their own account, and the building's shared records — the whole document library, the notice board, meetings. Not the corporation's finances, not other owners' accounts, not the roster's contact details. There is no council-only shelf in the library yet, so anything you wouldn't show an owner shouldn't be uploaded to it.

Council and managers see the corporation's records — that's the job.

Between corporations, nothing crosses. A manager with five buildings sees five separate workspaces.

Detail in roles and permissions.

The audit trail

SettingsRecords records who did what and when: money moved, invoices cancelled, roles changed, documents uploaded, notices sent, periods closed and reopened.

You'll rarely read it. It matters at the moments it matters a lot — an owner questioning a two-year-old charge, a handover to a new council, a tribunal.

Shared logins destroy it

The trail records the account that acted. Four people sharing one login turns every entry into "somebody on council", which answers nothing. Individual logins cost nothing. See invitations and logins.

Retention

Minutes, financial records, documents and the audit trail are never purged on a schedule, and the audit trail can't be edited or deleted by anyone. SettingsRecords shows how long each kind of record is kept.

The one exception is the communications log — the emails the corporation has sent, with the recipient, the subject and the body. It isn't a statutory record, and it holds owners' contact details, so it doesn't need keeping forever:

  • It's kept for 24 months by default. Council can shorten or lengthen that under SettingsRecords, anywhere from 1 month to 20 years.
  • Once a week, entries older than that window are erased automatically. Council can also press Purge expired entries to do it straight away; it previews what will go first.
  • What each message was about stays in the audit trail. The corporation keeps its record of having written to somebody, without keeping what it wrote or where it went.
  • Both the purge and any change to the window are recorded in the audit trail.

Purging is permanent. Corporation settings →

Beyond that, your legislation sets minimums, and they vary by record type — financial records and minutes are typically kept for years, some records longer where they touch major work or the reserve.

Practical guidance:

  • Meet your statutory minimum at least. Deleting something you were required to keep is the expensive mistake.
  • Keep minutes and financial statements indefinitely. They're small and they answer questions nothing else can.
  • Be more careful with personal information. Correspondence about an individual owner, a complaint file, a dispute — hold those no longer than you need. Holding personal information without a reason is its own problem.

Owners' access rights

Your province's legislation gives owners a right to certain corporate records, and that right exists regardless of what you've chosen to publish in the document library.

The library is a convenience. It is not a determination of what an owner is entitled to. When a formal records request arrives, check what your Act requires and produce it. If a request is unusual, take advice.

Handling personal information well

Councils get this wrong more often through carelessness than intent:

  • Never name an individual owner in an announcement. Arrears, complaints, disputes — direct to the person concerned.
  • Don't circulate the roster. Contact details are held for the corporation's purposes, not for the building's use.
  • Think before uploading. Legal advice, medical information, a complaint file — consider whether it belongs in a shared library at all.
  • Minute decisions, not personalities. Everything you write is disclosable.

Email preferences

Owners choose for themselves whether the corporation emails them, under Preferences in their portal. The council can't change it for them, and the date it last changed is kept. Statutory notices may still be sent where the law requires it. Notices go by email only — there's no text-message option.

ManageStrata's own product-update emails are separate, and only go to people who ticked the box for them at sign-up. Their unsubscribe link opens a page with an Unsubscribe button, so an email scanner or link preview opening it can't take anyone off the list by accident.

Getting your data out

Your data is yours. Financial statements, ledgers and documents can be exported, and your documents can be downloaded from the library.

If you're leaving ManageStrata, export before your paid period ends. Ask support if you need a full export.

Security basics

  • Individual logins, never shared.
  • Remove access promptly when someone leaves council or sells.
  • A strong, unique password. Nobody at ManageStrata can see or set it.
  • Reset it if you think someone else has it. Resetting through Forgot password? signs your account out on every device. How →
  • Review who has access yearly.
  • Support will never ask for your password. Anyone who does is not us.

Breaches

If something goes wrong at our end, we'll tell you. If something goes wrong at yours — a compromised council email account, a shared login used by someone who shouldn't have it — the corporation has its own notification obligations under PIPA/PIPEDA. Take advice quickly; the timelines are short.

Still stuck? Open Support in the top bar of the app, ask the Assistant, or contact us.