This policy explains how Grizzly Asset Holdings Inc., doing business as Grizzly Client Services ('GCS'), handles commercial electronic messages and outbound communications under Canada's Anti-Spam Legislation (CASL) and Canadian telemarketing rules, and how responsibility is divided between GCS and the client business.
A commercial electronic message (CEM) is a message sent to an electronic address — email or SMS, for example — that encourages participation in a commercial activity: promoting services, recovering a quote, seeking a booking, or reactivating an old customer. CASL requires three things for a CEM: consent, sender identification, and a working unsubscribe mechanism.
Express consent must be sought clearly and separately — never through a pre-checked box — with the sender identified and the purpose stated, and the sender bears the burden of proving it. Implied consent exists in limited windows: an existing business relationship (for example a purchase within the last two years or an inquiry within the last six months) or conspicuous publication of an address relevant to the message. Consent tied to a relationship expires when its window closes.
Messages that facilitate an existing transaction or relationship — providing a quote the person requested, confirming an appointment, delivering account or safety information — can be sent without CEM consent, but still require accurate sender identification and an unsubscribe mechanism where they are electronic messages.
Every CEM prepared or sent through GCS identifies the business on whose behalf it is sent, and where GCS sends its own CEMs, GCS identifies Grizzly Asset Holdings Inc., doing business as Grizzly Client Services, with a current mailing address and a contact method. Sender identity must never be deceptive.
Every CEM includes an unsubscribe mechanism that works for at least 60 days after sending. Unsubscribe requests take effect promptly and no later than 10 business days after they are made, without fees or hurdles.
Unsubscribes, bounces, complaints, and do-not-contact requests are recorded as suppression status, and suppressed addresses are excluded from prepared and sent messages. Clients must not bypass suppression or ask GCS to message people who have opted out.
The client business owns its customer relationships and keeps the records that prove consent: when and how consent was obtained, or what relationship supports implied consent. GCS stores the consent evidence the client records in the workspace and enforces it in the workflow, but GCS cannot invent consent the client does not have.
The client is responsible for the lawful basis of its recipient lists, the truth of its message content, and its autonomy-policy configuration. GCS is responsible for the mechanics it controls: identification blocks, unsubscribe links, suppression enforcement, policy and consent gates on every send, and honest provider states. Both parties can be liable under CASL for a violating message, which is why GCS refuses work that lacks a lawful basis.
GCS does not send spam, does not accept harvested or purchased lists without verifiable consent, does not disguise sender identity, and does not disable compliance controls on request.
Customer-facing messages send according to the account's configured autonomy policy. Routine in-policy messages may send automatically; exceptional or out-of-policy messages are held for owner review; and sending can be switched off per capability. Every send — automatic or approved — additionally requires configured provider credentials, consent and suppression checks, and account-level sending rules. Until those exist, prepared messages stay internal.
Messages can be blocked by GCS compliance checks or rejected by the email provider (Postmark) under its own anti-abuse policies. Blocked and failed sends are shown honestly in the workspace rather than silently dropped or silently retried forever.
Outbound calling, where configured, follows the Canadian telemarketing framework: National Do Not Call List scrubbing and registration where required, internal do-not-call lists, permitted calling hours, caller identification, and prior express consent for automated calls that deliver a solicitation. Outbound call tasks are approval-gated and logged.
Questions about this messaging & casl record may be sent to [email protected].