Who we are
This Privacy Policy describes how Grizzly Asset Holdings Inc., doing business as Grizzly Client Services ('GCS'), collects, uses, discloses, retains, and protects personal information in connection with the GCS platform, the Revenue Desk, guided website-reference intake, subscriptions, support, and billing. It is written to meet the Personal Information Protection and Electronic Documents Act (PIPEDA) and its ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use, disclosure, and retention, accuracy, safeguards, openness, individual access, and challenging compliance.
Applicable law
PIPEDA applies to personal information GCS handles in the course of commercial activity. Where a client or individual is in British Columbia, Alberta, or Québec, the private-sector privacy law of that province — the BC Personal Information Protection Act, the Alberta Personal Information Protection Act, or Québec's Act respecting the protection of personal information in the private sector as modernized by Law 25 — may apply in addition to or instead of PIPEDA. Where these laws differ, GCS applies the stricter requirement.
What we collect
GCS collects only what it needs to run the services:
- account and business information — business name, owner and user names, emails, phone numbers, service area, and business type;
- the submitted website address and the business profile fields the Client reviews and approves;
- customer intake records entered into or captured by the workspace — names, phone numbers, emails, service requests, quotes, and follow-up history;
- login and security data — hashed passwords, two-step verification enrolment, session and activation events, and salted one-way hashes (never raw values) of IP addresses and browser details on legal acceptance and security records;
- payment status and subscription metadata from the payment processor — never full card numbers or card security codes;
- call data where voice features are configured — caller details, recordings, transcripts, summaries, and routing metadata;
- email and message metadata — delivery, bounce, unsubscribe, and suppression status;
- support communications, usage logs, provider configuration status, audit logs, and the cookies described in the Cookie Policy.
Website reference and optional scan
The current public build and checkout forms save a submitted website address as an optional setup reference; they do not trigger a scan. GCS uses the business profile fields the Client submits and approves. If an optional scan is offered later, it requires separate authorization before any request is made.
Why we collect it
GCS uses personal information to:
- operate the Revenue Desk and the client workspace;
- create and administer the account and the client file;
- provide AI and automation features that prepare work for owner review;
- process subscription payments and maintain billing records;
- send transactional messages such as activation, billing, security, and support notices;
- maintain security, prevent abuse, and investigate incidents;
- provide support and troubleshoot problems;
- improve reliability and service quality; and
- comply with legal obligations.
Consent and legal bases
In Canadian terms, GCS collects, uses, and discloses personal information with consent — express or implied as appropriate to the sensitivity of the information and the reasonable expectations of the individual — for purposes a reasonable person would consider appropriate in the circumstances: delivering the contracted service, operating a business account, securing access, processing payment, and preparing the workflows the client asked for. GCS may also process information where necessary to meet legal obligations or for permitted investigation and security purposes. Consent can be withdrawn as described under 'Your rights'; withdrawal may limit what services GCS can provide.
No sale of personal information
GCS does not sell personal information and does not disclose it to third parties for advertising. If GCS is ever party to a business transaction such as a financing or sale, personal information would be handled under confidentiality terms and this policy would be updated with notice.
Cross-border processing
Some providers process or store information outside Canada, including in the United States. While information is in another jurisdiction, it is subject to the laws of that jurisdiction and may be accessible to its courts, government, and law-enforcement agencies. GCS uses contractual and technical safeguards with providers to require protection comparable to this policy, and GCS remains accountable for personal information it transfers for processing.
Retention
GCS keeps personal information only as long as needed for the purposes described here: while the account is active; afterwards for the periods needed for billing, tax, legal, audit, dispute, and security records; and in routine encrypted backups until those cycle out. Call Files and legal acceptance records follow the Account Lifecycle, Archive, and Data Retention Policy. Personal information used to make a decision about an individual is kept long enough for the individual to request access to it.
Your rights
A person may request access to their personal information under GCS's control, request correction of inaccurate or incomplete information, withdraw consent subject to legal and contractual consequences, and request deletion subject to the retention needs above. Requests go to [email protected] and are answered within the time allowed by the applicable law.
Where a request concerns Customer Data controlled by a client business, GCS will refer the request to that business or assist it as described in the Data Processing Addendum. Anyone who is not satisfied with GCS's response may complain to the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner.
Safeguards
GCS protects personal information with safeguards appropriate to its sensitivity: account scoping and role-based access controls, hashed passwords, two-step verification for administrators and available to client users, session and CSRF protections, salted one-way hashing of IP and browser identifiers on acceptance records, audit logs, least-privilege internal access, and encrypted transport. No safeguard is perfect, but GCS reviews and improves these controls over time.
Breach handling
GCS assesses and contains suspected security incidents. Where a breach of security safeguards creates a real risk of significant harm to an individual, GCS reports the breach to the Office of the Privacy Commissioner of Canada, notifies affected individuals as soon as feasible, notifies client businesses whose Customer Data is involved, and keeps records of every breach as the Breach of Security Safeguards Regulations require. Provincial notification duties (for example under Alberta PIPA or Québec Law 25) are met where they apply.
Children
The services are business tools and are not directed to children. GCS does not knowingly collect personal information from minors, and clients should not enter information about minors unless it is necessary for a lawful business purpose.
Automated processing and AI
AI Services prepare summaries, scores, and recommended actions from workspace data. Under the Client's configured autonomy policy, routine customer-facing actions may execute automatically within consent, compliance, and frequency limits, while exceptional actions are held for owner review. GCS does not make purely automated decisions that have a legal or similarly significant effect on an individual.
Privacy contact
Privacy questions, access and correction requests, and complaints: [email protected], attention Privacy Officer, Grizzly Asset Holdings Inc., doing business as Grizzly Client Services. The corporate mailing address is available on request.
Support / Contact
Questions about this privacy record may be sent to [email protected].