Connectability takes the security of its customers and of its customers’ data very seriously. As such, we have implemented a set of policies and controls to ensure that customer data is protected at all times.
These policies and controls include the following:
- Connectability stores customer and company information only in approved, access-controlled systems. These include customer-controlled environments and authorized cloud platforms such as Intuit QuickBooks Online, Microsoft 365, Microsoft Azure and Microsoft Power BI. Connectability does not ordinarily store this information on local office systems, except temporarily when required to provide an authorized service, such as equipment repair or troubleshooting.
- Customer or company data is copied or transferred from its source environment only when required to provide authorized services, security, backup, analytics or reporting. Any such data remains protected by Connectability’s security controls and is retained and deleted in accordance with the applicable business purpose, contractual requirements and the retention practices described below.
- Connectability’s offices maintain strict access control. During operating hours, there is always someone at our reception desk, and after hours our facilities are locked and equipped with a monitored intrusion alarm. All windows and doors are protected with bars and security film.
- All customer cloud data, including backups, is encrypted in transit and at rest.
- Customer access information is granted only to authorized individuals, and credentials are stored in a cloud repository requiring MFA authentication and using AES-256 encryption.
- Access credentials are removed immediately upon the resignation or termination of employees.
- Connectability employs all of the cyber security tools that we offer to our customers within our in-house environment. These include a Sophos next-generation firewall, advanced antivirus software, intrusion detection and remediation, zero-trust solutions, email filtering, and MDR.
- Remote access to all of our cloud portals is tightly controlled and reviewed regularly.
- Connectability performs a monthly vulnerability scan and penetration test on our internal networks.
Connectability Analytics Privacy Notice
Effective date: July 31, 2026
About the application
Connectability Analytics is a private, internal business-intelligence application operated by Connectability Inc. It retrieves accounting information from Connectability’s own QuickBooks Online company and combines it with operational information from Connectability’s other authorized business systems. The resulting reports are used by authorized Connectability personnel for financial analysis, client profitability reporting, operational planning and management decision-making.
The application is not offered or licensed to the public.
Information accessed
When an authorized QuickBooks Online company administrator connects the application, Connectability Analytics may access accounting information including:
- Company profile and configuration information
- Chart of accounts and account balances
- Customer and vendor records
- Invoices, credit memos, sales receipts and payments recorded in the accounting ledger
- Bills, purchases, expenses, deposits and journal entries
- Products and services, classes, departments and applicable tax information
- Transaction dates, amounts, references and related accounting metadata
Connectability Analytics does not request access to the QuickBooks Payments API and does not collect payment-card security codes, complete payment-card numbers or online-banking login credentials.
Although the QuickBooks Online authorization scope can support both reading and writing, Connectability Analytics is designed to make read-only accounting API requests. It does not create, modify or delete records in QuickBooks Online.
Purpose and use
Information obtained through the integration is used only for Connectability’s internal accounting, management and business-intelligence purposes, including:
- Revenue, expense and profitability reporting
- Client and service profitability analysis
- Labour-efficiency and utilization reporting
- Financial reconciliation and trend analysis
- Operational planning and executive reporting
QuickBooks information is not sold, rented or used for advertising. It is not used to train public or third-party artificial-intelligence models. Information from one organization is not shared with another organization.
Authorization and access
The connection must be authorized by an administrator of the applicable QuickBooks Online company. Access to the resulting information is restricted to authorized Connectability personnel with a legitimate business requirement.
The QuickBooks connection can be revoked through QuickBooks Online or through the application’s disconnection process. Revocation stops future data extraction and invalidates the application’s authorization credentials.
Storage and service providers
QuickBooks data extracted by Connectability Analytics is processed and stored within Connectability-controlled Microsoft services, including Microsoft Azure and Microsoft Power BI. Azure resources used for the integration are hosted in the Canada Central region.
OAuth credentials and other application secrets are stored separately in Microsoft Azure Key Vault. Accounting extracts are stored in private Azure storage containers and are not made publicly accessible.
Connectability uses Intuit and Microsoft as technology service providers necessary to operate this integration. These providers process information according to their respective contractual, privacy and security obligations.
Security safeguards
Connectability applies administrative, technical and physical safeguards appropriate to the sensitivity of the information. These safeguards include:
- Encryption in transit and at rest
- Multifactor authentication
- Role-based access controls and least-privilege permissions
- Separate secure storage for application credentials
- Security monitoring, vulnerability management and access reviews
- Removal of access when personnel no longer require it
- Incident-response and business-continuity procedures
Retention and deletion
Accounting data is retained while the integration remains active and while the information is reasonably required for authorized accounting, reporting, legal or operational purposes.
If the integration is permanently disconnected or decommissioned:
- Scheduled extraction from QuickBooks Online will stop
- OAuth access and refresh credentials will be revoked and removed promptly
- Raw and processed QuickBooks extracts will be deleted from active integration storage within 30 days, unless retention is required by law
- Residual copies in protected system backups will expire through the normal backup lifecycle, ordinarily within 90 days
- Financial reports or records subject to Canadian tax, corporate or other legal-retention requirements may be retained for the applicable statutory period
Connectability may also retain aggregated information that no longer identifies an individual or customer.
Access, correction and questions
Questions about this notice, requests concerning personal information, or requests to permanently disconnect the integration may be directed to:
Connectability Inc.
28 Eugene Street
North York, Ontario M6B 3Z4
Canada
Telephone: (416) 966-3306
Contact form: https://www.connectability.com/contact-us/
Connectability will review privacy-related requests and respond in accordance with applicable Canadian privacy requirements.
Changes to this notice
Connectability may update this notice when the application, its data practices or applicable legal requirements change. The effective date shown above will be updated whenever material changes are made.