This Privacy Policy describes how Grizzly Asset Holdings Inc., doing business as Grizzly Client Services ('GCS'), collects, uses, discloses, retains, and protects personal information in connection with the GCS platform, the Revenue Desk, website-first intake, subscriptions, support, and billing. It is written to meet the Personal Information Protection and Electronic Documents Act (PIPEDA) and its ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use, disclosure, and retention, accuracy, safeguards, openness, individual access, and challenging compliance.
PIPEDA applies to personal information GCS handles in the course of commercial activity. Where a client or individual is in British Columbia, Alberta, or Québec, the private-sector privacy law of that province — the BC Personal Information Protection Act, the Alberta Personal Information Protection Act, or Québec's Act respecting the protection of personal information in the private sector as modernized by Law 25 — may apply in addition to or instead of PIPEDA. Where these laws differ, GCS applies the stricter requirement.
GCS collects only what it needs to run the services:
When a business submits its website during onboarding, GCS scans public pages of that website to build the business profile used to configure the account. GCS stores what was extracted and the source page addresses, and asks the business to confirm the profile before activation. The scan is limited to public pages of the submitted site — never login, admin, or other private areas — as described in the Website Intake and Public Site Scan Disclosure.
GCS uses personal information to:
In Canadian terms, GCS collects, uses, and discloses personal information with consent — express or implied as appropriate to the sensitivity of the information and the reasonable expectations of the individual — for purposes a reasonable person would consider appropriate in the circumstances: delivering the contracted service, operating a business account, securing access, processing payment, and preparing the workflows the client asked for. GCS may also process information where necessary to meet legal obligations or for permitted investigation and security purposes. Consent can be withdrawn as described under 'Your rights'; withdrawal may limit what services GCS can provide.
GCS does not sell personal information and does not disclose it to third parties for advertising. If GCS is ever party to a business transaction such as a financing or sale, personal information would be handled under confidentiality terms and this policy would be updated with notice.
Some providers process or store information outside Canada, including in the United States. While information is in another jurisdiction, it is subject to the laws of that jurisdiction and may be accessible to its courts, government, and law-enforcement agencies. GCS uses contractual and technical safeguards with providers to require protection comparable to this policy, and GCS remains accountable for personal information it transfers for processing.
GCS keeps personal information only as long as needed for the purposes described here: while the account is active; afterwards for the periods needed for billing, tax, legal, audit, dispute, and security records; and in routine encrypted backups until those cycle out. Call Files and legal acceptance records follow the Account Lifecycle, Archive, and Data Retention Policy. Personal information used to make a decision about an individual is kept long enough for the individual to request access to it.
A person may request access to their personal information under GCS's control, request correction of inaccurate or incomplete information, withdraw consent subject to legal and contractual consequences, and request deletion subject to the retention needs above. Requests go to [email protected] and are answered within the time allowed by the applicable law.
Where a request concerns Customer Data controlled by a client business, GCS will refer the request to that business or assist it as described in the Data Processing Addendum. Anyone who is not satisfied with GCS's response may complain to the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner.
GCS protects personal information with safeguards appropriate to its sensitivity: account scoping and role-based access controls, hashed passwords, two-step verification for administrators and available to client users, session and CSRF protections, salted one-way hashing of IP and browser identifiers on acceptance records, audit logs, least-privilege internal access, and encrypted transport. No safeguard is perfect, but GCS reviews and improves these controls over time.
GCS assesses and contains suspected security incidents. Where a breach of security safeguards creates a real risk of significant harm to an individual, GCS reports the breach to the Office of the Privacy Commissioner of Canada, notifies affected individuals as soon as feasible, notifies client businesses whose Customer Data is involved, and keeps records of every breach as the Breach of Security Safeguards Regulations require. Provincial notification duties (for example under Alberta PIPA or Québec Law 25) are met where they apply.
The services are business tools and are not directed to children. GCS does not knowingly collect personal information from minors, and clients should not enter information about minors unless it is necessary for a lawful business purpose.
AI Services prepare summaries, scores, and recommended actions from workspace data. Under the Client's configured autonomy policy, routine customer-facing actions may execute automatically within consent, compliance, and frequency limits, while exceptional actions are held for owner review. GCS does not make purely automated decisions that have a legal or similarly significant effect on an individual.
Privacy questions, access and correction requests, and complaints: [email protected], attention Privacy Officer, Grizzly Asset Holdings Inc., doing business as Grizzly Client Services. The corporate mailing address is available on request.
Questions about this privacy record may be sent to [email protected].