Privacy and personal information

Aedis Portal Privacy Notice

Aedis Portal Privacy Notice

Effective date: August 6, 2026

Version: interim-2026-08-06

Aedis Appraisals Ltd. respects the privacy of clients, applicants, builders, developers, mortgage brokers, lenders, project contacts and Portal users. This Notice explains how Aedis collects, uses, discloses, protects and retains personal information in connection with the Portal and related appraisal services.

1. Scope and accountability

This Notice applies to personal information collected through the public order process, authenticated project workspaces, engagement-letter signing, payment administration, inspection scheduling, support communications and Aedis administrative functions.

Aedis is accountable for personal information under its control and will designate an Aedis Privacy Officer to oversee privacy compliance, questions, complaints, access requests and corrections.

Privacy contact: Aedis Privacy Officer, admin@multiplexappraisals.com, (844) 462-3347.

2. Information Aedis collects

- Identity and contact information, including names, roles, companies, titles, email addresses, telephone numbers and intended lender information.

- Applicant, builder, developer, mortgage broker, lender and authorized-signer information supplied for the project.

- Property and project information, including addresses, legal descriptions, unit details, plans, budgets, schedules, rents, income and expenses, permits, zoning, environmental and energy information, notes, photographs and supporting documents.

- Account and authentication information, such as the verified email address, authentication provider, sign-in timestamps and security events. Aedis does not receive a user's Google password.

- Fee, tax and payment-administration information, such as amounts, payment status, payer identity, provider transaction identifiers, receipts, refunds and approved offline-payment records. Aedis does not store payment-card numbers.

- Inspection and scheduling information, project status, delivery estimates, communications, support history, invitations, role changes, document versions, upload activity and report-download activity.

- Electronic-signature and audit information, including signer name, role, document version, consent record, date and time, IP address where permitted, user agent and tamper-evident document hash.

- Technical and security information, such as device/browser details, session data, logs, rate-limit events and information reasonably required to prevent fraud or unauthorized access.

3. Sources of information

Aedis may receive information directly from the person placing the order, other authorized project members, applicants, builders, developers, brokers, lenders, assigned appraisers, payment and authentication providers, public and municipal records, and other sources authorized or permitted by law.

A person who supplies another individual's information must be authorized to do so and must provide any required privacy notice or obtain any required consent.

4. Purposes

Aedis collects, uses and discloses personal information as reasonably required to prepare quotes, evaluate and accept orders, identify and communicate with project participants, verify authority, calculate and collect fees, generate and execute engagement letters, schedule and complete inspections, prepare and deliver appraisal reports, manage shared workspaces, request missing documents, provide support, maintain professional and business records, protect the Portal, prevent fraud, investigate incidents, enforce agreements and meet legal, tax, insurance, professional and regulatory obligations.

Aedis will seek additional consent before using personal information for a materially different purpose unless the use or disclosure is otherwise permitted or required by law.

Aedis does not sell or rent personal information. Aedis will not use project information for unrelated marketing without any consent required by law.

5. Consent and choices

By submitting information, joining an invited project, uploading documents, signing an engagement letter or otherwise using the Portal, a user consents to the collection, use and disclosure described in this Notice to the extent consent is the appropriate legal basis.

Consent may be withdrawn on reasonable notice, subject to legal, professional, contractual and record-retention requirements. Withdrawal does not invalidate prior authorized processing and may prevent Aedis from accepting, continuing or completing an appraisal or maintaining Portal access.

Aedis will explain material consequences of withdrawal when reasonably possible.

6. Sharing and project visibility

Aedis may disclose information to authorized Aedis personnel, assigned appraisers and contractors who need it for the assignment; authorized project members and intended users; and service providers supporting authentication, hosting, private storage, payment, email, calendar, document generation, security, analytics limited to Portal operations and technical support.

Aedis may also disclose information where required or permitted by law, to protect rights or safety, to investigate fraud or security incidents, to obtain professional advice, or in connection with a proposed business transaction subject to appropriate protections.

The shared project workspace is visible to authorized members according to role. Project owners should invite only people who require access and should remove access when it is no longer needed. Aedis records invitations and access changes.

7. Service providers and processing outside Canada

Some service providers may process or store personal information in Canada, the United States or other jurisdictions. Information processed outside Canada may be subject to the laws of the jurisdiction where it is processed and may be accessible to courts, law-enforcement or national-security authorities in that jurisdiction.

Aedis will assess relevant providers and use contractual, technical and organizational measures intended to require protection appropriate to the sensitivity of the information. Users may contact the Aedis Privacy Officer for information about relevant service-provider categories.

8. Safeguards

Aedis uses reasonable administrative, technical and physical safeguards appropriate to the sensitivity of the information. Portal controls are intended to include authenticated access, project-level authorization, private storage, time-limited authorized downloads, encryption in transit, secure session handling, file-type and size validation, malware-risk controls, rate limiting, role-based administration, audit logging and document version history.

No electronic system can be guaranteed completely secure. Users must protect their accounts, avoid sharing authentication links, use the secure workspace rather than unprotected email for sensitive documents, and report suspected unauthorized access promptly.

9. Retention and disposal

Aedis generally retains project records, uploaded documents, document versions, signed engagement letters, payment-administration records and audit records for 12 months after an assignment is completed or cancelled.

Aedis may retain particular records longer where reasonably required by applicable professional, legal, tax, insurance, contractual, security or dispute-resolution obligations. When information is no longer reasonably required, Aedis will securely delete, destroy or anonymize it using documented procedures. Deactivating an account does not necessarily delete records that Aedis must retain.

10. Access, correction and complaints

Subject to applicable exceptions, an individual may request access to personal information under Aedis's control and information about its use and disclosure, or request correction of inaccurate or incomplete personal information.

Requests must be made in writing to the Aedis Privacy Officer and include enough information to verify identity and locate the relevant records. Aedis will respond within the time required by applicable law and explain any lawful refusal.

A privacy concern or complaint may be directed to the Aedis Privacy Officer. If it is not resolved, the individual may have the right to contact the Office of the Information and Privacy Commissioner for British Columbia or the Office of the Privacy Commissioner of Canada, as applicable.

11. Cookies, sessions and updates

The Portal may use cookies or similar technologies that are necessary for authentication, security, session continuity, draft autosave and core functionality. Any optional analytics or marketing technology should be separately disclosed and consented to where required.

Aedis may update this Notice when practices, providers or legal requirements change. The Portal will display the effective date and version. A material change will be communicated and consent obtained where required.