This is a public document. It is not a terms-of-service page buried in a footer. It is not a press release. It is a plain-language description of exactly how MVP Condominium Property Management uses artificial intelligence — what we do, what we refuse to do, how we check ourselves, and why we hold ourselves to a standard that goes well beyond what Canadian law currently requires.
You deserve to know this. The people in your community — owners, residents, board members — did not sign up to have their information handled by AI tools. They signed up to live in a well-managed condominium. Their trust in us is not abstract. It is personal. And we take it seriously.
Our standard is simple: human judgment at the beginning, human oversight throughout, and human approval before anything reaches you.
Everything in this policy flows from that standard.
Why we published this
Most organizations that use AI do not tell you much about it. They may mention it in a privacy policy, or reference it in a terms-of-service update you never read. We think that is not good enough — especially in property management, where the information involved touches people's homes, finances, and daily lives.
We published this policy because we want to be held accountable to it. If you read it and believe we are falling short, we want to hear from you. That is not a formality. It is how we get better.
We also published it because we hope it is useful to others. If another management company, a condo board, or an organization in a different industry reads this and decides to adopt a similar standard, that is a good outcome. The communities they serve will be better protected for it.
How we use AI in our communications
Our people use AI tools to help them write more clearly. That is the honest summary.
Here is what that means in practice: before an employee uses AI to help with a message, they must first do the thinking themselves. They must understand the question, check the relevant facts, decide what needs to be said, and consider what action is appropriate. They must prepare their own draft or substantive notes that capture those decisions.
Only then may AI help with the writing — spelling, grammar, punctuation, clarity, tone, and length. It can make a complicated explanation easier to follow. It can remove unnecessary repetition. It can soften a sentence that came out harsher than intended. But it cannot decide what the message says. That is the employee's job, and it stays that way.
Pasting an incoming email into an AI tool, asking it to generate a reply, and sending that reply does not meet our standard. A quick review before hitting send does not replace the thinking that should have happened first.
AI tools may also help our people locate and summarize records — declarations, contracts, meeting minutes, maintenance reports. Before relying on any AI-assisted summary, the employee must check the original document and its context. Anything that requires professional advice goes to the appropriate qualified adviser. AI does not replace that.
Every outgoing message is the responsibility of the employee who sends it. AI does not send messages on our behalf. AI does not make commitments on our behalf. The person whose name is on the message is the person who owns it.
How we use AI in software development
MVP builds and maintains digital tools — systems that support owner communication, maintenance tracking, financial reporting, and other operational functions. AI assists in that development work. Here is how.
Before any AI-assisted development begins, a responsible person at MVP establishes the purpose of the system, the requirements it must meet, the information it will handle, and the limits on what it may do. Qualified technical professionals assess the design and potential risks before implementation starts.
During development, AI may help produce code, explore approaches, prepare tests, and support troubleshooting. The developers using those tools must understand what the AI has produced. They must be capable of reviewing it, correcting it, and explaining it. A system that works in a demonstration is not a system that is ready for use — it must be tested for what happens when things go wrong, not only when they go right.
Before any system is released, qualified developers and security professionals review the implementation. They oversee functional tests, vulnerability checks, and threat assessments appropriate to the system. Privacy requirements are assessed. Asking AI to approve its own output is not sufficient — and we do not do it.
After release, every system has an identified owner at MVP who is responsible for maintenance, updates, security findings, and incident response. That responsibility does not end at launch.
We follow the NIST Secure Software Development Framework as a baseline for our development security practices. NIST SSDF
What we do — and do not do — with your information
This section matters most to the people in the communities we manage. Please read it carefully.
The information we hold on behalf of condominium corporations and their owners is not ours to use freely. It was shared with us for a specific purpose — managing the property — and we treat that boundary as absolute. Here are the rules we follow, most of which go beyond what Canadian privacy law currently requires:
Owner information does not go into general-purpose AI tools. Personal information about unit owners, residents, or board members — names, contact details, financial records, maintenance history, dispute files — is never entered into a general-purpose AI tool such as a public chatbot or consumer writing assistant. These tools may use submitted content to improve their models. We do not accept that risk with information that belongs to the people in your community.
We use the minimum information necessary. When AI tools are used for internal drafting or analysis, employees use only what is needed for the specific task. A question about a maintenance process does not require attaching an owner's name or unit number. Our people are trained to strip identifying details before any AI interaction where they are not strictly required.
Every AI tool we use is reviewed and approved before use. Before any AI tool is authorized at MVP, we assess where data goes, who can access it, how long it is retained, whether it is used for model training, and how it can be deleted. We require contractual protections — data processing agreements, confidentiality terms, and deletion rights — before any tool is authorized. That approval is documented and reviewed at least annually, and whenever a tool's terms, ownership, or capabilities change.
Your information is used for one purpose: managing your property. Information collected for property management is used for property management. It is not used to train internal models, build owner profiles, or inform decisions outside the scope of the original purpose without explicit authorization.
We do not keep AI outputs indefinitely. AI-generated drafts, summaries, and logs that contain or reference personal information are subject to the same retention and disposal rules as other records. They are not kept simply because a tool produced them.
You can ask us what we did with your information. Any owner or resident may ask what information about them has been used in connection with an AI tool, and what the result was. We will answer that question honestly and completely. This is not a courtesy — it is a commitment.
These rules are stricter than PIPEDA requires. We adopted them because the people in the communities we manage deserve more than the legal floor.
Third-party assessment: we do not just take our own word for it
Self-assessment is not enough. We do not believe any organization — including MVP — should be the sole judge of whether its AI practices are sound. Here is how we verify our own work.
Annual independent privacy review. Each year, MVP engages a qualified privacy professional — external to MVP — to review our AI-related data practices. That review covers the tools we use, the data they touch, the contractual protections in place, and whether our internal practices match this written policy. Findings are reported to MVP leadership and addressed in writing. We will confirm to any board or owner that the review has been completed and describe its scope.
Security assessment for AI-integrated systems. Any system we develop or deploy that incorporates AI is subject to independent security assessment before release and on a scheduled basis thereafter. We follow the NIST Secure Software Development Framework as a baseline. NIST SSDF
Vendor claims are verified, not trusted. When an AI platform or tool provider makes claims about their security, privacy, or compliance posture, we verify those claims through published documentation, third-party certifications such as SOC 2 Type II or ISO 27001 where applicable, and contractual representations. A vendor's marketing materials are not a substitute for documented evidence. We ask for that evidence and keep it on file.
Any board can ask us directly. The condominium boards we serve may ask us, at any time, to describe what AI tools are in use in connection with their corporation, what data those tools have accessed, and what assessments have been completed. We will answer those questions fully and without delay.
Compliance: what the law requires, and where we go further
MVP's AI practices comply with applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, provincial privacy legislation. We comply with the Condominium Act, 1998 (Ontario) and the regulations under it, including obligations related to records, disclosure, and the handling of owner information.
We align voluntarily with Ontario's Responsible Use of Artificial Intelligence Directive, which sets expectations for provincial ministries and agencies and identifies its principles as a model for other organizations. Ontario's responsible-use directive Those principles — useful and proportionate AI use, privacy and safety, fairness and human rights, transparency, and continuing human accountability — are reflected throughout this policy.
We follow the guidance of the Office of the Privacy Commissioner of Canada on generative AI. Canadian privacy principles for generative AI
We also follow Ontario's trustworthy AI framework as a guide for our own work. Ontario's trustworthy AI framework
Compliance with these frameworks is the floor, not the ceiling. In several areas, our internal rules are stricter:
- PIPEDA permits certain uses of personal information without consent where a legitimate business purpose exists. Our policy does not rely on that flexibility for AI use. We require a clear, documented purpose and minimize data regardless of whether consent is technically required.
- Ontario's AI directive applies to government ministries. We have adopted it voluntarily because we believe its principles are right, not because we are required to.
- NIST's cybersecurity and software development frameworks are American federal guidance. We follow them because they represent sound practice, not because Canadian law compels us.
We track regulatory developments in Canada, Ontario, and internationally — including the proposed federal Artificial Intelligence and Data Act (AIDA) and the EU AI Act — and update our practices proactively as the landscape evolves. We do not wait for a law to pass before adopting a standard we believe is right.
How we audit ourselves
Policy without verification is aspiration. Here is how we confirm that this policy is being followed in practice.
Quarterly internal review. Each quarter, MVP leadership reviews a sample of AI-assisted communications and development outputs to confirm they meet this policy. The review checks whether employees are following the substance-first rule for communications, whether only approved tools are being used, and whether data-minimization practices are being applied. Findings are documented and addressed.
Tool authorization log. MVP maintains a current list of AI tools approved for use, the purposes for which they are approved, the data categories they may access, and the date of last review. Any tool not on this list may not be used for business purposes. The log is reviewed and updated at least annually and whenever a tool's terms, ownership, or capabilities change materially.
Incident tracking. Any suspected policy violation, inappropriate data disclosure, or AI-related error is logged, investigated, and resolved. Patterns are reviewed at the quarterly internal review. Significant incidents are reported to affected parties in accordance with applicable breach notification requirements — and, in our judgment, whenever an owner or board would reasonably want to know, even if the law does not require it.
Annual policy review. This policy is reviewed at least once a year and updated whenever our AI use changes materially, applicable law or guidance changes, or an audit finding identifies a gap. Owners and boards may ask when this policy was last reviewed and what changed.
Why we hold ourselves to a higher standard
I want to be direct about this.
The people in the communities we manage did not choose to share their information with an AI company. They chose to live in a condominium, and their information came to us as part of that relationship. That is a different kind of trust than a consumer signing up for a technology service. It deserves a different kind of care.
Condominium management involves sensitive information: financial records, maintenance histories, dispute files, insurance claims, and the details of people's daily lives in their homes. Some of those people are seniors. Some are families. Some are going through difficult circumstances. They have a right to expect that the organization managing their home is handling their information with genuine respect — not just technical compliance.
The legal minimum in Canada today does not fully reflect that responsibility. PIPEDA was written before generative AI existed. Ontario's AI directive applies to government, not to property managers. The rules that will eventually govern private-sector AI use in Canada are still being developed.
We are not waiting. We have adopted the standard we believe is right, documented it publicly, and committed to independent verification. If the law eventually catches up to where we already are, that is fine. If it requires more, we will meet it. But our standard is not set by what regulators currently require of us — it is set by what the people we serve deserve.
We also hope this policy is useful beyond MVP. If a condo board uses it to ask better questions of their current management company, that is a good outcome. If another management firm reads it and raises their own standard, that is an even better one. The communities they serve will be better protected for it.
A note on this website
This website uses an AI assistant named Sam. Sam is designed to answer questions about condominium management, help visitors understand their options, and connect people with our team. Sam does not have access to any owner records, financial data, or confidential corporation information. Conversations with Sam are not stored in a way that identifies individual users. Sam operates under the same human-oversight principles described in this policy — our team reviews Sam's design, tests its responses, and is responsible for how it behaves.
Questions and accountability
If you have a question about this policy, believe we are falling short of it, or want to know more about how we handle your corporation's information, please contact us directly. We will respond fully and without delay.
If AI-assisted work contributes to an error, we remain responsible for addressing it. That responsibility does not diminish because a tool was involved.
Our aim is to make everyday service clearer, more useful, and more responsive. The judgment behind that service — and the responsibility for it — remains with MVP.
Scott Hundey, CEO, MVP Condos
