Privacy

GCS Privacy Policy

Last updated July 27, 2026 · Version 2026-07-27-ca-1
Issued by Grizzly Asset Holdings Inc., doing business as Grizzly Client Services.

Who we are

This Privacy Policy describes how Grizzly Asset Holdings Inc., doing business as Grizzly Client Services ('GCS'), collects, uses, discloses, retains, and protects personal information in connection with the GCS platform, the Revenue Desk, website-first intake, subscriptions, support, and billing. It is written to meet the Personal Information Protection and Electronic Documents Act (PIPEDA) and its ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use, disclosure, and retention, accuracy, safeguards, openness, individual access, and challenging compliance.

Applicable law

PIPEDA applies to personal information GCS handles in the course of commercial activity. Where a client or individual is in British Columbia, Alberta, or Québec, the private-sector privacy law of that province — the BC Personal Information Protection Act, the Alberta Personal Information Protection Act, or Québec's Act respecting the protection of personal information in the private sector as modernized by Law 25 — may apply in addition to or instead of PIPEDA. Where these laws differ, GCS applies the stricter requirement.

What we collect

GCS collects only what it needs to run the services:

  • account and business information — business name, owner and user names, emails, phone numbers, service area, and business type;
  • the submitted website address and the extracted business profile, with the public source page addresses kept as evidence;
  • customer intake records entered into or captured by the workspace — names, phone numbers, emails, service requests, quotes, and follow-up history;
  • login and security data — hashed passwords, two-step verification enrolment, session and activation events, and salted one-way hashes (never raw values) of IP addresses and browser details on legal acceptance and security records;
  • payment status and subscription metadata from the payment processor — never full card numbers or card security codes;
  • call data where voice features are configured — caller details, recordings, transcripts, summaries, and routing metadata;
  • email and message metadata — delivery, bounce, unsubscribe, and suppression status;
  • support communications, usage logs, provider configuration status, audit logs, and the cookies described in the Cookie Policy.

Website-first intake

When a business submits its website during onboarding, GCS scans public pages of that website to build the business profile used to configure the account. GCS stores what was extracted and the source page addresses, and asks the business to confirm the profile before activation. The scan is limited to public pages of the submitted site — never login, admin, or other private areas — as described in the Website Intake and Public Site Scan Disclosure.

Why we collect it

GCS uses personal information to:

  • operate the Revenue Desk and the client workspace;
  • create and administer the account and the client file;
  • provide AI and automation features that prepare work for owner review;
  • process subscription payments and maintain billing records;
  • send transactional messages such as activation, billing, security, and support notices;
  • maintain security, prevent abuse, and investigate incidents;
  • provide support and troubleshoot problems;
  • improve reliability and service quality; and
  • comply with legal obligations.

Who we share it with

GCS shares personal information only with the service providers needed to run the platform and only for the purposes above:

  • payment processing — Stripe (subscription billing and checkout);
  • email delivery — Postmark (transactional and approved messages);
  • voice and telephony — Vapi and Telnyx, only where voice features are configured for the account;
  • hosting, database, and infrastructure providers that store and serve the platform;
  • local business data for lead research — Foursquare (business listings; not used to disclose customer personal information);
  • security, logging, and diagnostic tooling used to keep the service safe; and
  • courts, regulators, or law enforcement where disclosure is required by law.

No sale of personal information

GCS does not sell personal information and does not disclose it to third parties for advertising. If GCS is ever party to a business transaction such as a financing or sale, personal information would be handled under confidentiality terms and this policy would be updated with notice.

Cross-border processing

Some providers process or store information outside Canada, including in the United States. While information is in another jurisdiction, it is subject to the laws of that jurisdiction and may be accessible to its courts, government, and law-enforcement agencies. GCS uses contractual and technical safeguards with providers to require protection comparable to this policy, and GCS remains accountable for personal information it transfers for processing.

Retention

GCS keeps personal information only as long as needed for the purposes described here: while the account is active; afterwards for the periods needed for billing, tax, legal, audit, dispute, and security records; and in routine encrypted backups until those cycle out. Call Files and legal acceptance records follow the Account Lifecycle, Archive, and Data Retention Policy. Personal information used to make a decision about an individual is kept long enough for the individual to request access to it.

Your rights

A person may request access to their personal information under GCS's control, request correction of inaccurate or incomplete information, withdraw consent subject to legal and contractual consequences, and request deletion subject to the retention needs above. Requests go to [email protected] and are answered within the time allowed by the applicable law.

Where a request concerns Customer Data controlled by a client business, GCS will refer the request to that business or assist it as described in the Data Processing Addendum. Anyone who is not satisfied with GCS's response may complain to the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner.

Safeguards

GCS protects personal information with safeguards appropriate to its sensitivity: account scoping and role-based access controls, hashed passwords, two-step verification for administrators and available to client users, session and CSRF protections, salted one-way hashing of IP and browser identifiers on acceptance records, audit logs, least-privilege internal access, and encrypted transport. No safeguard is perfect, but GCS reviews and improves these controls over time.

Breach handling

GCS assesses and contains suspected security incidents. Where a breach of security safeguards creates a real risk of significant harm to an individual, GCS reports the breach to the Office of the Privacy Commissioner of Canada, notifies affected individuals as soon as feasible, notifies client businesses whose Customer Data is involved, and keeps records of every breach as the Breach of Security Safeguards Regulations require. Provincial notification duties (for example under Alberta PIPA or Québec Law 25) are met where they apply.

Children

The services are business tools and are not directed to children. GCS does not knowingly collect personal information from minors, and clients should not enter information about minors unless it is necessary for a lawful business purpose.

Cookies

GCS uses cookies mainly for sign-in sessions and security. The Cookie Policy at /cookies lists each category in use and how to control them. GCS does not run third-party advertising trackers.

Automated processing and AI

AI Services prepare summaries, scores, and recommended actions from workspace data. Under the Client's configured autonomy policy, routine customer-facing actions may execute automatically within consent, compliance, and frequency limits, while exceptional actions are held for owner review. GCS does not make purely automated decisions that have a legal or similarly significant effect on an individual.

Privacy contact

Privacy questions, access and correction requests, and complaints: [email protected], attention Privacy Officer, Grizzly Asset Holdings Inc., doing business as Grizzly Client Services. The corporate mailing address is available on request.

Support / Contact

Questions about this privacy record may be sent to [email protected].