Paranest Privacy Policy

Last updated: July 2026

1. Introduction and Scope

Paranest provides coworking and flexible workspace services in Ontario, Canada. This Privacy Policy explains what personal information we collect about you, why we collect it, who we share it with, how long we keep it, and what choices and rights you have.

This Policy applies to you if you are:

(a) a visitor to our websites or a user of our mobile or web applications;
(b) a prospective member, for example if you book a tour, request a quote, or start an application;
(c) an active member, or an individual authorized to use a membership held by a company;
(d) a guest, visitor, contractor, or delivery person who enters one of our locations; or
(e) a guest under the age of 18 brought into one of our locations by a member or authorized user.

It covers all Paranest websites, applications, and member portals, and all Paranest locations.

What this Policy does not cover. It does not cover the privacy practices of third party websites, apps, or services that we link to or that you choose to connect to your account. It also does not cover our handling of employee or job applicant information, which is addressed separately.

Throughout this Policy, "personal information" means information about an identifiable individual, as that term is defined under Canadian privacy law.

2. Who We Are

2.1 Legal entities. Paranest operates through Paranest Inc. and/or its affiliates.

2.2 Who is responsible for your information. All Paranest online applications, websites, and mobile apps are licensed and operated by Paranest Inc., and is the organization responsible for the personal information described in this Policy. This means Paranest Inc. determines why and how your personal information is collected and used, and is accountable for it under Canadian privacy law. Where this Policy says "Paranest," "we," "us," or "our," it refers to Paranest Inc. and/or its affiliates.

2.3 Where we operate. We operate only in Ontario, Canada.

2.4 Which law applies. Our handling of personal information is governed by the federal Personal Information Protection and Electronic Documents Act (PIPEDA). Ontario does not have its own general private sector privacy law, so PIPEDA applies to our commercial activities in the province. Our commercial electronic messages are also subject to Canada's Anti-Spam Legislation (CASL).

2.5 Our privacy contact. All privacy questions, complaints, consent withdrawals, and requests to exercise your rights should be directed to info@paranest.com. See Section 15 for full contact details.

3. Personal Information We Collect

We collect personal information in three ways: from you directly, automatically through our websites and apps, and automatically at our physical locations. Section 4 provides a separate and more detailed notice covering camera footage, access records, and Wi-Fi monitoring, because that information is more sensitive.

3.1 Information You Provide Directly

We collect this information when you contact us, book a tour, sign-up for a membership, sign an agreement, set up your account in our member app, make a payment, register a guest, or otherwise communicate with us.

Category Examples
Contact information Your name, email address, phone number, and mailing address.
Company information For corporate memberships: your company name, your role, and the names and contact details of authorized users on the account.
Payment and billing information Billing address, bank account and banking details provided under a pre-authorized debit agreement, credit or debit card details (entered into and processed by our payment providers), invoice history, and payment status.
Government issued identification If your membership includes a physical or dedicated office space, we collect and review a government issued ID to verify your identity before we grant access to that space.
Account information Your username, password, profile photo (if you choose to add one), home location, and notification preferences.
Bookings and requests Meeting room and desk bookings, guest registrations, mail and package handling instructions, support tickets, and event registrations.
Anything else you choose to send us The content of your emails, messages, survey responses, and feedback.

If you do not provide it. Some of the information above is necessary for us to provide our services. If you choose not to provide it, we may not be able to open your account, grant you access, process your payments, or respond to your request.

Information about other people. If you give us personal information about someone else, for example when you register a guest (including a guest under the age of 18) or add an authorized user to a corporate account, you confirm that you have the appropriate permission or authority to do so and that you have made this Policy available to them or their parent or guardian, as applicable.

3.2 Information Collected Automatically Online

When you visit our websites or use our apps, we and our service providers automatically collect:

(i) Device and technical information. IP address, approximate location derived from your IP address, device type and identifiers, operating system, browser type and settings, and language preferences.

(ii) Usage information. Pages and screens you view, links you click, referring website, search terms used to find us, dates and times of access, and features you use in the member app.

(iii) Cookie and tracking information. Information collected through cookies, pixels, tags, and similar technologies. Section 6 explains these and how to control them.

(iv) Email interaction information. Whether you opened an email we sent and whether you clicked a link in it.

3.3 Information Collected at Our Locations

When you enter or use one of our locations as a member, authorized user, guest, or visitor, we collect:

(i) Building access and keycard information. Records generated when you use a keycard, badge, fob, or mobile key at an entry point, including the door or reader used and the date and time. We also keep front desk visitor logs where guests sign in.

(ii) Video and audio surveillance footage. Images, video, and audio recorded by security cameras in common areas, entrances, corridors, and other shared spaces. Signs are posted at every entry door notifying you that recording is in progress. Cameras are not installed inside private offices, washrooms, or phone booths.

(iii) Wi-Fi and network information. When you connect a device to a Paranest Wi-Fi network, our network management system records connection and usage information about that device. Section 4.3 sets this out in detail.

(iv) Space usage information. Meeting room and desk bookings, printer usage, and general occupancy counts used for capacity planning.

4. Cameras, Access Records, and Wi-Fi Monitoring

4.1 Video and audio surveillance

What we collect. Continuously recorded video and audio from cameras in entrances, exits, common areas, corridors, and other shared spaces at our locations.

Why we collect it. To protect the safety of members, guests, and staff. To deter and investigate theft, vandalism, trespass, unauthorized entry, and damage to property. To investigate accidents and insurance claims. To meet obligations under our leases and building agreements.

Our basis for collecting it. We rely on your implied consent. Signs are posted at every entry door notifying you that video and audio recording is in operation before you enter, and this Policy provides further detail.

How long we keep it. Video and audio footage is retained for as long as necessary, after which it is automatically overwritten or deleted, unless it has been flagged as part of an active security, insurance, or legal matter, in which case it is retained until that matter is resolved.

Who can access it. Access is limited to authorized Paranest management and security personnel, and law enforcement or other authorities where we are legally required or permitted to disclose it.

If you prefer not to be recorded. Cameras cover the shared and common areas of our locations and cannot be switched off for individuals. Recording does not extend into private offices, washrooms, or phone booths. If you have concerns, please contact us at info@paranest.com.

4.2 Building access and keycard records

What we collect. A record each time you use a keycard, badge, fob, or mobile key at one of our access points, including the reader location and the date and time.

Why we collect it. To control and administer access. To confirm who was on site during a security or safety incident. To account for occupancy in an emergency such as a fire evacuation. To administer memberships that include limited or after hours access.

Our basis for collecting it. Access records are necessary to perform our agreement with you and to keep our locations secure. Your consent is implied by your use of the access credential we issue you, and this Policy provides notice of the practice.

How long we keep it. Access records are retained for as long as necessary, unless retained longer as part of an active security, insurance, or legal matter.

Who can access it. Access to building access and keycard records is limited to Paranest personnel who need it to administer access and security, and to the landlord or property manager of the relevant location where necessary to operate base building security systems.

4.3 Wi-Fi and network monitoring

What we collect. Our Wi-Fi networks are operated using enterprise network management equipment that records detailed information about each connected device. This includes:

  • the device's hardware address (MAC address), device name, and device type;
  • the IP address assigned to the device;
  • the access point the device is connected to, which indicates your approximate location within the building;
  • connection and disconnection times, session duration, and signal strength;
  • the volume of data uploaded and downloaded; and
  • information about the network destinations your device communicates with, including the names of the sites and services it connects to and the categories of applications in use.

Where a device is associated with your member account, this information can be linked to you.

Why we collect it. To operate and maintain the network, allocate bandwidth, diagnose connectivity problems, protect against network abuse and security threats, and support investigations into misuse of our network.

Our basis for collecting it. Basic connection and performance information is necessary to provide and secure the network you have asked to use, and your consent to that is implied by connecting. For the more detailed traffic information described above, we rely on the notice given in this Policy.

What we do not do. We do not read the content of your communications, and traffic sent over encrypted connections cannot be read by us. We do not sell or disclose network information for advertising purposes. We do not review individual browsing records except where necessary to investigate a specific security incident, a suspected breach of our network terms, or a legal request.

How long we keep it. We retain Wi-Fi and network records for as long as necessary to support the purposes described above, such as maintaining the network and investigating security incidents, after which the information is deleted or de-identified. We have not fixed a specific retention period for this information, and the length of time we keep it may vary depending on operational and security needs.

Your choices. You are not required to use our Wi-Fi. You may use your own mobile data connection instead.

5. How We Use Personal Information

5.1 Our purposes
Purpose What this involves
Providing our services Setting up and administering your account, providing workspace access, managing desk and meeting room bookings, handling mail and packages, providing Wi-Fi, and running member events.
Billing and payments Issuing invoices, processing payments and pre-authorized debits, collecting overdue amounts, issuing refunds, and maintaining accounting records.
Verifying identity Confirming who you are before we grant access to a private or dedicated office space, and reducing the risk of fraud and unauthorized access.
Security and incident investigation Operating cameras, access control, network monitoring, and visitor management, and investigating security and safety incidents, unauthorized access, theft, and property damage.
Support and communication Responding to your questions, providing technical support, and sending service messages such as booking confirmations, invoices, access notices, building announcements, and changes to our terms.
Marketing Sending you newsletters, promotions, event invitations, and information about our services and locations, and measuring how our marketing performs.
Improving our business Understanding how our websites, apps, and spaces are used, planning capacity, developing new services, and producing internal reports, usually using aggregated or de-identified information.
Legal and compliance Meeting our legal, tax, accounting, and regulatory obligations, enforcing our agreements, and establishing, exercising, or defending legal claims.
5.2 Consent and our legal basis under PIPEDA

Under PIPEDA we generally need your consent to collect, use, or disclose your personal information. The form that consent takes depends on how sensitive the information is and what you would reasonably expect.

(a) Express consent. We ask for your clear, specific agreement where the information is sensitive or where the use would not be obvious from the circumstances. This currently includes marketing emails.

(b) Implied consent. We rely on implied consent where the purpose is obvious and you would reasonably expect it. This includes using your contact details to respond to an enquiry you sent us, using your booking details to provide the space you booked, recording video and audio in monitored common areas where signs are posted, and recording basic connection information when you join our Wi-Fi.

(c) Necessary to provide the service you asked for. Some information is required for us to perform our agreement with you, for example your billing details and your access credentials. By entering into a membership agreement with us, you consent to the collection and use of the information needed to deliver it.

(d) Permitted or required without consent. PIPEDA allows organizations to collect, use, or disclose personal information without consent in limited circumstances, for example to investigate a breach of an agreement or a contravention of the law, to comply with a subpoena, warrant, or court order, in an emergency threatening someone's life, health, or security, or in connection with certain business transactions. We rely on these exceptions only where the law permits.

(e) Reasonable business purposes. Where we handle information for our own business purposes such as network security, fraud prevention, internal reporting, and service improvement, we limit ourselves to what a reasonable person would consider appropriate in the circumstances, and we use de-identified or aggregated information wherever we can.

5.3 New purposes

If we want to use your personal information for a purpose that is not described in this Policy and is not compatible with the purpose it was collected for, we will tell you and, where required, obtain your consent first.

6. Cookies and Tracking Technologies

6.1 What they are

Cookies are small text files placed on your device when you visit a website. We also use similar technologies including pixels, tags, web beacons, local storage, and software development kits in our apps. Some are set by us and some by third parties.

Cookies may be session cookies, which are deleted when you close your browser, or persistent cookies, which stay on your device until they expire or you delete them.

6.2 Categories we use
Category What it does
Strictly necessary Enables core functions such as signing in, keeping you signed in, load balancing, and security.
Functional and preference Remembers choices such as language, home location, and display settings.
Analytics and performance Helps us understand how many people visit, which pages they use, and where errors occur, so we can improve the site and app.
Advertising and targeting Used by us and our advertising partners to show you Paranest ads on other websites and social platforms, limit how often you see them, and measure whether they worked.
6.3 Your choices

(a) Cookie consent banner. When you first visit our website, a cookie banner lets you accept cookies and provide a link to this Privacy Policy.

(b) Browser controls. Most browsers let you see what cookies are stored, delete them, and block some or all of them. These controls are usually found under Settings, Preferences, or Privacy. Blocking all cookies, including strictly necessary ones, may stop parts of our website and member portal from working.

  • Chrome: Settings, then Privacy and security, then Third party cookies
  • Safari: Settings, then Privacy
  • Firefox: Settings, then Privacy and Security
  • Edge: Settings, then Cookies and site permissions

(c) Analytics opt out. You can install the Google Analytics Opt-out Browser Add-on at https://tools.google.com/dlpage/gaoptout.

(d) Advertising opt outs. You can opt out of interest based advertising from participating companies through the Digital Advertising Alliance of Canada at https://youradchoices.ca.

(e) Mobile devices. Your device settings allow you to reset or limit the use of your advertising identifier.

(f) Contact us. You can also email info@paranest.com with questions.

6.4 Do Not Track

Browsers may offer a "Do Not Track" setting. There is no common industry standard for how websites should respond to these signals, and we do not currently respond to them. You can control tracking using the options in Section 6.3.

7. Third Party Service Providers

7.1 How we use service providers

We use third party companies to help us run our business. These companies act as processors, which means they handle personal information on our instructions, only to provide services to us, and are not permitted to use it for their own purposes.

7.2 Categories of service providers and the information they receive
Category of provider Purpose Categories of information received
Member management and workspace platform Operating our member facing app and portal, including accounts, bookings, member directory, invoicing workflows, and support Contact information, company information, account information, booking and usage information, billing information
Payment processing and pre-authorized debit Taking card payments, processing pre-authorized debits, managing recurring billing and refunds Name, email, billing address, bank account details, card details, transaction records
Financial institutions Settling payments and operating our bank accounts Name, bank account details, transaction records
Accounting and bookkeeping Invoicing, financial records, tax and audit Name, company name, billing address, email, invoice and payment records
Access control and camera systems Operating keycards and mobile keys, and video and audio recording and storage Name, credential identifiers, access records, video and audio footage
Network, Wi-Fi, and IT infrastructure Providing connectivity, hosting our systems, backups, and security monitoring Device and network information, and other categories depending on the system
Analytics and marketing Understanding website and app usage, sending email campaigns, and running advertising Device and usage information, cookie identifiers, email address, marketing preferences and engagement
Professional advisors Legal, accounting, insurance, and audit services Any category, as needed for the specific matter
7.3 Dealing with providers directly

For certain functionality you may be dealing with a provider directly as well as with us. For example, when you enter card details into a payment form, those details go to our payment processor rather than to us. In those situations the provider's own privacy policy also applies to how they handle your information for their own purposes. We are not responsible for their independent practices, and we encourage you to review their policies.

7.4 Pre-authorized debit

If you pay by pre-authorized debit, you enter into a pre-authorized debit agreement with Paranest and provide us with your banking details. We submit that agreement and those details to our payment processors and our financial institution so that they can collect payments from your account. Pre-authorized debits are handled in accordance with the rules of Payments Canada, which give you the right to receive advance notice of the amount and date of each debit, to revoke your authorization on notice, and to dispute a debit that was not drawn in accordance with your authorization. Details of these rights, including how to obtain a sample cancellation form, are available from your financial institution or at www.payments.ca. To change or cancel a pre-authorized debit arrangement, contact us at info@paranest.com.

8. How We Share and Disclose Personal Information

8.1 We do not sell your personal information

Paranest does not sell your personal information. We do not trade, rent, or otherwise make your personal information available to third parties for their own independent marketing purposes.

8.2 Who we share it with

(a) Service providers. As described in Section 7, and only as needed for them to provide services to us.

(b) Our affiliates. Between Paranest Inc. and its affiliates, for the purposes described in this Policy, including administering memberships and access across locations.

(c) Corporate account holders. If your membership is held and paid for by your employer or another organization, we may share account, booking, and billing information with that organization's administrators so they can manage the account.

(d) Landlords, building owners, and property managers. Where necessary to authorize your access through base building security systems, or to comply with our lease obligations.

(e) Professional advisors and insurers. Lawyers, accountants, auditors, and insurers, subject to confidentiality obligations.

(f) In a business transaction. If we are involved in a merger, acquisition, financing, reorganization, or sale of all or part of our business or assets, personal information may be reviewed and transferred as part of that transaction. We will require the parties involved to protect the information, to use it only for purposes related to the transaction, and to return or destroy it if the transaction does not proceed. If the transaction completes, we will notify you as required by law.

(g) Legal and safety reasons. We may disclose personal information where we believe in good faith that doing so is necessary to:

  • comply with a law, regulation, subpoena, warrant, court order, or other legal process;
  • respond to a lawful request from a government institution or law enforcement agency;
  • investigate a suspected breach of our agreements or a contravention of the law;
  • protect the rights, property, or safety of Paranest, our members, our staff, or others; or
  • respond to an emergency that threatens someone's life, health, or security.

(h) With your consent or at your direction. Including where you ask us to connect a third party integration to your account.

(i) Aggregated and de-identified information. We may share information that has been aggregated or de-identified so that it can no longer be used to identify you.

9. Data Retention

9.1 General approach. We keep personal information only as long as we need it for the purposes described in this Policy, or as long as we are required to keep it by law. When it is no longer needed, we securely destroy, erase, or de-identify it.

9.2 Indicative retention periods. We retain member account information for as long as your membership is active, and for a limited period afterward to respond to any billing disputes, complaints, or legal claims that may arise. Once that period has passed and the information is no longer needed for any purpose described in this Policy, we securely delete or de-identify it.

9.3 Legal holds. If information is relevant to an active legal claim, investigation, insurance matter, or regulatory request, we retain it until that matter is resolved, even if the period above has passed.

10. Security

We use physical, organizational, and technological safeguards to protect personal information against loss, theft, and unauthorized access, use, disclosure, copying, or modification. These safeguards include limiting access to personal information to staff and service providers who need it to do their jobs, requiring confidentiality commitments, using encryption for information in transit and for sensitive information at rest, securing our premises and records, and requiring our service providers to maintain comparable protections.

The level of protection we apply reflects how sensitive the information is. Banking details and government issued ID receive the highest level of protection we apply.

No method of transmitting or storing information is completely secure, and we cannot guarantee absolute security. If a privacy breach occurs that creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as PIPEDA requires, and we will keep a record of the breach.

Please help us protect your information by keeping your account password confidential, not sharing your access credentials with anyone, and telling us right away at info@paranest.com if you think your account or credential has been compromised.

11. Your Privacy Rights and Choices

11.1 Your rights

Subject to certain legal limits and exceptions, you have the right to:

(a) Know and access. Ask us whether we hold personal information about you, obtain a copy of it, and receive an account of how it has been used and to whom it has been disclosed.

(b) Correct. Ask us to correct personal information that is inaccurate or incomplete. If we disagree with a requested correction, we will note your disagreement in our records and, where appropriate, tell anyone we have disclosed the information to.

(c) Withdraw consent. Withdraw your consent to our collection, use, or disclosure of your personal information at any time, subject to legal and contractual restrictions and reasonable notice. If you withdraw consent for something necessary to provide our services, such as processing your payments or issuing you an access credential, we may not be able to continue providing those services, and we will explain the consequences before acting on your request.

(d) Deletion. Ask us to delete personal information we hold about you. We will do so where we are able to, but we may need to keep certain information to meet legal, tax, accounting, insurance, or security obligations, or to establish or defend a legal claim.

(e) Opt out of marketing. See Section 11.3.

(f) Complain. Raise a concern with us and, if you are not satisfied, with the Office of the Privacy Commissioner of Canada. See Section 11.4.

11.2 How to make a request

Email info@paranest.com with the subject line "Privacy Request." Please tell us what you are asking for and give us enough detail to locate your information.

To protect your privacy, we will take reasonable steps to verify your identity before acting on a request. We may ask for additional information for this purpose, and we will use that information only for verification.

We will respond within 30 days of receiving your request. If we need more time, we will tell you when to expect our response. Access requests are free in most cases. If a request would involve significant cost, we will tell you the estimated cost in advance and give you the chance to withdraw or narrow your request.

If we refuse a request in whole or in part, we will tell you in writing.

11.3 Marketing communications and how to opt out

You can opt out of marketing emails at any time by:

  • clicking the unsubscribe link at the bottom of any marketing email we send you;
  • changing your communication preferences in your account settings in the member app; or
  • emailing info@paranest.com and asking to be removed from our marketing list.

We will action your request promptly and in any event within 10 business days, as CASL requires.

Opting out of marketing does not stop service and transactional messages that we need to send you, such as invoices, booking confirmations, access notices, security alerts, building announcements, and changes to our terms or this Policy.

11.4 Complaints

If you have a concern about how we handle your personal information, please contact us first at info@paranest.com. We take complaints seriously, will investigate, and will tell you the outcome.

If you are not satisfied with our response, you can contact the Office of the Privacy Commissioner of Canada:

12. Children's Privacy

Our membership services are intended for use by adults. Memberships may only be held by, and access credentials issued to, individuals who are at least 18 years old.

Members and authorized users may bring guests under the age of 18 into our locations, for example, a client's child or a family member accompanying them. Guests under 18, like all guests, may be recorded by our video and audio cameras while in common and shared areas, and may be included in front desk visitor logs. Where a member or authorized user registers a guest under 18, that member or authorized user is responsible for confirming they have the appropriate authority to do so on the minor's behalf and for making this Policy available to the minor's parent or guardian, consistent with Section 3.1.

If you believe we have otherwise collected personal information directly from someone under 18 in a way that is not addressed above, please contact us at info@paranest.com and we will address it promptly.

13. Where Your Information Is Stored and Processed

We operate only in Ontario. However, some of our service providers, or their own sub-processors, may store or process personal information on servers located outside Canada, including but not limited to the United States.

When personal information is stored or processed in another country, it is subject to the laws of that country, and courts, law enforcement agencies, regulators, and national security authorities in that country may be able to obtain access to it under those laws.

Where a service provider handles personal information outside Canada, we:

  • use contractual and other measures to require a comparable level of protection to what the information would receive here; and
  • limit what is transferred to what the provider needs in order to deliver the service.

If you have questions about where your information is stored or the safeguards we use, contact us at info@paranest.com.

14. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, our services, or the law. When we do, we will change the "Last updated" date at the top of this page and post the revised Policy on our website and in our apps.

If we make a change that materially affects how we handle your personal information or your rights, we will give you additional notice, for example by email or through a notice in the member app, and where the law requires it we will ask for your consent before the change takes effect.

We encourage you to review this Policy periodically.

15. Contact Us

For any question, concern, complaint, or request relating to your personal information or this Policy, contact us:

Email: info@paranest.com
Mail: Paranest Inc. and/or its affiliates, 10 George St N, Brampton, ON L6X 1R2

Privacy matters are handled by our support team at the address above and are escalated internally to the person accountable for our compliance with this Policy.