This Privacy Policy applies to the platform, website, and services operated by SILICON SILK LTD., a corporation registered as a Money Services Business under MSB Registration No. C100000527.
SILICON SILK LTD. is registered with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) and processes personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), applicable provincial privacy legislation, and the record-keeping and reporting obligations imposed by the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA).
Registered address: 5307 Victoria Drive, Suite 851, Vancouver, BC V5P 3V6, Canada.
For the purposes of this Policy, SILICON SILK LTD. acts as the entity accountable for the personal information under its control.
01Introduction
SILICON SILK LTD. ("Silicon Silk", the "Company", "we", "us", or "our") is committed to protecting the privacy and confidentiality of the personal information entrusted to us. As a regulated money services business, we are required to collect and verify certain information about our clients and their transactions; we treat that information as a matter of trust and handle it with care.
This Policy describes what personal information we collect, why we collect it, how we use and disclose it, how long we keep it, how we protect it, and the rights available to individuals. It applies to visitors to siliconsilk.ca, applicants for an account, clients and their authorised representatives, beneficial owners, directors, signatories, and counterparties involved in transactions processed through the platform.
This Policy should be read together with our Terms of Service. Additional or product-specific privacy notices may be provided where relevant.
02Information We Collect
The categories of information we collect depend on your relationship with us and the services you use.
2.1 Identity and Verification Information
- Full legal name, date of birth, nationality, and residential address;
- Government-issued identification details, including passport, driver's licence, or national identity document numbers, expiry dates, and images;
- Occupation or role, and details of directorship, signing authority, or beneficial ownership;
- Verification results and risk-screening outcomes, including sanctions, politically exposed person, and adverse media checks.
2.2 Business Information
- Legal and trading names, incorporation or registration numbers, jurisdiction and date of incorporation;
- Registered and operating addresses, ownership and control structure, and corporate constitutional documents;
- Nature of business activity, industry, expected transaction volumes and corridors, source of funds and source of wealth information;
- Licences, tax registrations, and financial statements where relevant.
2.3 Transaction Data
- Payment and collection instructions, amounts, currencies, value dates, and reference details;
- Payer and beneficiary details, including names, addresses, and account or payment identifiers;
- Purpose of payment, supporting commercial documentation such as invoices, contracts, and shipping documents;
- Balances, statements, fees, and settlement records.
2.4 Device and Technical Information
- IP address, approximate location derived from IP address, browser type and version, operating system, and device identifiers;
- Login timestamps, authentication events, session activity, and security logs;
- Pages visited, referring URLs, and interaction data collected through cookies and similar technologies.
2.5 Communications
- Email, web form, and portal messages, including enquiries submitted through our contact page;
- Records of support requests, complaints, and, where applicable and permitted, call records or notes of conversations.
2.6 Information from Third Parties
We may receive information about you from identity verification and screening providers, credit and business information agencies, banking and payment partners, corporate registries, public databases, sanctions and watch lists, and your own representatives or counterparties.
03How We Use Your Information
We use personal information for the following purposes:
- Onboarding and account administration — assessing applications, establishing and maintaining accounts, and authenticating users;
- Service delivery — processing payments, collections, and settlement, and providing statements and reporting;
- KYC, AML/CTF, and sanctions compliance — verifying identity, identifying beneficial owners, conducting due diligence and enhanced due diligence, screening, transaction monitoring, and preparing and filing regulatory reports;
- Fraud prevention and security — detecting, investigating, and preventing fraud, unauthorised access, and misuse of the platform;
- Legal and regulatory obligations — record keeping, responding to regulators, law enforcement, tax authorities, and courts, and managing audits and regulatory examinations;
- Risk management — client risk rating, credit and counterparty assessment, and limit setting;
- Service improvement — analysing usage in aggregate to improve platform functionality, reliability, and user experience;
- Communications — responding to enquiries, providing service notices and operational updates, and, where permitted, sending information about products and services relevant to your business.
We do not sell personal information. We do not use personal information for automated decision-making that produces legal effects without human involvement in the review of that decision.
04Legal Basis for Processing
We process personal information only where we have a lawful basis to do so. Depending on the circumstances and the applicable legal framework, our bases include:
- Compliance with legal obligations — including obligations under the PCMLTFA and FINTRAC guidance to identify clients, keep records, monitor activity, and file reports; sanctions legislation; and tax and reporting requirements;
- Performance of a contract — where processing is necessary to provide the services requested under our Terms of Service;
- Consent — where you have provided knowledge and consent to the collection, use, or disclosure of your information, which you may withdraw subject to legal and contractual restrictions;
- Legitimate interests — including fraud prevention, platform security, risk management, and the establishment or defence of legal claims, where such interests are not overridden by your privacy rights;
- Legally permitted collection without consent — where Canadian privacy legislation permits collection, use, or disclosure without consent, for example in the context of investigating a breach of an agreement or a contravention of law, or in complying with a lawful order.
Where you decline to provide information that we are legally required to obtain, we may be unable to open or maintain your account or process your transactions.
05Information Sharing and Disclosure
We disclose personal information only as described below, and only to the extent necessary:
- Regulators and authorities — FINTRAC, other financial regulators, law enforcement, tax authorities, and courts, where required or permitted by law. Where we file a suspicious transaction report, we are prohibited by law from disclosing that fact;
- Banking and payment partners — correspondent banks, beneficiary banks, licensed payment institutions, and payment networks that execute or settle your transactions. Payment messages necessarily include payer and beneficiary information;
- Service providers — identity verification and screening vendors, cloud hosting and infrastructure providers, security and monitoring services, communication platforms, and professional advisers, each engaged under contractual confidentiality and data-protection obligations;
- Auditors and examiners — internal and external auditors, and independent reviewers of our compliance program;
- Corporate transactions — prospective purchasers, investors, or successors in the context of a merger, acquisition, financing, or reorganisation, subject to appropriate confidentiality protections;
- With your direction — to parties you instruct us to share information with, such as your accountants or authorised representatives.
Service providers are authorised to use personal information only for the purposes for which it was provided to them, and are required to maintain safeguards comparable to our own.
06Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against loss, theft, unauthorised access, disclosure, copying, use, or modification. These measures include:
- Encryption of data in transit using TLS, and encryption of sensitive data at rest;
- Role-based access controls, least-privilege provisioning, and multi-factor authentication for administrative and client access;
- Network segregation, firewalls, intrusion detection, and continuous monitoring and logging;
- Secure development practices, change control, vulnerability management, and periodic security testing;
- Confidentiality obligations, background screening where appropriate, and mandatory privacy and security training for personnel;
- Documented incident response procedures, including assessment of any breach of security safeguards and notification to affected individuals and regulators where required by law.
While we apply safeguards appropriate to the sensitivity of the information, no method of transmission or storage is completely secure. You are responsible for safeguarding your own credentials and for using secure devices and networks when accessing the platform.
07Data Retention
We retain personal information only as long as necessary to fulfil the purposes for which it was collected and to satisfy legal, regulatory, accounting, and reporting requirements.
- Client identification and account records — retained for at least five (5) years following the closure of the account or the end of the business relationship, as required under the PCMLTFA and FINTRAC record-keeping requirements;
- Transaction records and supporting documentation — retained for at least five (5) years from the date of the transaction;
- Compliance records — including risk assessments, monitoring alerts, and reports, retained for the periods prescribed by Applicable Law;
- Applicant information — where an application is declined or abandoned, retained for a limited period to evidence our assessment and to prevent duplicate or evasive applications;
- Technical and security logs — retained for a period appropriate to security investigation and incident response purposes.
Where information is subject to a legal hold, investigation, audit, or litigation, retention may be extended accordingly. When information is no longer required, it is securely deleted, destroyed, or anonymised.
08Your Rights
Subject to Applicable Law and to legal and regulatory limitations, you may:
- Access — request confirmation of whether we hold personal information about you and obtain a copy of that information, together with information about how it has been used and to whom it has been disclosed;
- Correct — request correction of inaccurate or incomplete personal information;
- Withdraw consent — withdraw consent to certain uses or disclosures, including marketing communications, subject to legal and contractual restrictions;
- Request deletion — request deletion of personal information, which we will honour where we are not required to retain it under Applicable Law. Records held for AML/CTF, sanctions, tax, or other statutory purposes cannot be deleted before the end of the mandated retention period;
- Restrict or object — object to processing based on legitimate interests, or request restriction of processing, where such a right applies to you;
- Complain — submit a complaint about our handling of your personal information.
To exercise these rights, contact us at info@siliconsilk.ca. We may require verification of your identity before responding, and we will respond within the timeframe required by Applicable Law, generally within thirty (30) days. Where we refuse a request in whole or in part, we will explain the reason and the recourse available to you.
If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada or the applicable provincial privacy authority.
09International Data Transfers
Silicon Silk operates internationally and works with banking, payment, and technology partners located outside Canada. Personal information may therefore be transferred to, stored in, or accessed from jurisdictions other than your own, including for the purpose of executing cross-border payments and collections.
When personal information is held in another jurisdiction, or by a service provider operating in another jurisdiction, it may be subject to the laws of that jurisdiction and may be accessible to courts, law enforcement, and national security authorities there.
Where we transfer personal information across borders, we use contractual and organisational measures designed to provide a comparable level of protection to that required under Canadian privacy law, including data processing terms, confidentiality obligations, security requirements, and restrictions on onward transfer.
10Cookies and Tracking
Our website uses cookies and similar technologies to operate the site, maintain sessions, remember preferences, and understand how the site is used. The categories we use are:
- Strictly necessary cookies — required for security, session management, and core site functionality. These cannot be disabled without affecting the operation of the site;
- Preference cookies — remember settings such as language or display choices;
- Analytics cookies — help us understand aggregate traffic patterns and improve content and performance.
Most browsers allow you to block or delete cookies through their settings. Disabling cookies may limit certain features of the website or client portal. We do not use cookies to sell personal information, and we do not knowingly permit third-party advertising trackers on our client portal.
11Third-Party Links
Our website and communications may contain links to third-party websites, including regulator registries, partner institutions, and informational resources. These sites operate independently of Silicon Silk and are governed by their own privacy policies and terms.
We do not control and are not responsible for the content, security, or privacy practices of third-party websites. We encourage you to review the applicable privacy policy before providing personal information to any third party.
12Children's Privacy
The Silicon Silk platform is intended exclusively for businesses and for individuals acting in a business capacity. Our services are not directed to, and we do not knowingly collect personal information from, individuals under the age of eighteen (18).
If we become aware that we have inadvertently collected personal information from a minor other than as part of a legally required client record, we will take reasonable steps to delete that information, subject to any applicable retention obligation. If you believe a minor has provided us with personal information, please contact us at info@siliconsilk.ca.
13Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, service providers, or legal and regulatory requirements.
The current version is always published on this page with an updated effective date. Where a change is material, we will provide additional notice, which may include email notification or a notice within the client portal, before the change takes effect. Changes required for legal, regulatory, or security reasons may take effect immediately.
We encourage you to review this Policy periodically. Continued use of the platform after an update takes effect indicates your awareness of the revised Policy.
14Contact Us
For questions, access requests, or complaints regarding this Privacy Policy or our handling of personal information, please contact:
- Entity: SILICON SILK LTD.
- MSB Registration No.: C100000527 (registered with FINTRAC)
- Address: 5307 Victoria Drive, Suite 851, Vancouver, BC V5P 3V6, Canada
- Email: info@siliconsilk.ca
- Website: siliconsilk.ca
Please mark privacy-related correspondence for the attention of the Privacy Officer. Written requests should be sent to the registered address above, with a copy by email.
Last updated: July 2026
SILICON SILK LTD. · MSB No. C100000527