Privacy Policy
Effective Date: June 14, 2026 · Approved by Jason Pereira, Privacy Officer
This Privacy Policy explains how Woodgate Financial Inc. ("Woodgate", "we", "us", or "our") collects, uses, discloses, retains, and protects personal information — both in the delivery of our advisory services and through this website, BusinessOwnerFP.ca — in accordance with PIPEDA, Quebec's Law 25, and all other applicable privacy legislation.
1. Introduction and Purpose
Woodgate Financial Inc. ("Woodgate," "we," "our," or "us") is a financial planning firm serving clients across Canada, including Quebec. Investment services are offered through IPC Securities Corporation, a member of the Canadian Investment Regulatory Organization (CIRO) and the Canadian Investor Protection Fund (CIPF). Jason Pereira is approved by CIRO as a Portfolio Manager and provides discretionary portfolio management through IPC Securities Corporation. Our advisors hold Certified Financial Planner (CFP) and Qualified Associate Financial Planner (QAFP) designations.
We are committed to protecting the privacy and confidentiality of the personal information entrusted to us by our clients, prospective clients, and other individuals. This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector (Law 25), and all other applicable provincial and federal privacy legislation.
This policy is structured around the ten Fair Information Principles set out in Schedule 1 of PIPEDA, which form the backbone of our privacy practices.
Privacy Officer: Jason Pereira, jason.pereira@woodgate.com
2. Definitions
Personal Information: Information about an identifiable individual, including but not limited to name, address, date of birth, Social Insurance Number, financial account information, investment holdings, income, employment details, health information relevant to financial planning, and any other information that identifies or could reasonably be used to identify an individual.
Business Information: Information that relates to an organization in its business capacity and does not identify an individual, including corporate financial statements, business registration information, and publicly available company data. Business information is not subject to this policy.
3. Principle 1 — Accountability
Woodgate Financial Inc. is responsible for all personal information in its possession or control, including information transferred to third parties for processing.
- Jason Pereira is the designated Privacy Officer, accountable for Woodgate's compliance with this policy and applicable legislation.
- The Privacy Officer can be reached at jason.pereira@woodgate.com for any privacy-related inquiries, access requests, or complaints.
- All employees and authorized agents of Woodgate are required to comply with this policy and receive training on their privacy obligations.
- Where personal information is transferred to third-party service providers for processing, Woodgate requires contractual protections to ensure a comparable level of protection (see Section 11).
4. Principle 2 — Identifying Purposes
We collect and use personal information for the following purposes:
- Identity Verification: To verify your identity as required by applicable securities regulatory requirements and anti-money laundering legislation (PCMLTFA).
- Know Your Client (KYC) and Suitability: To understand your financial situation, investment knowledge, risk tolerance, and objectives in order to provide suitable investment advice.
- Financial Planning: To develop comprehensive financial plans covering retirement, tax, estate, insurance, and other planning areas.
- Service Delivery: To administer your accounts, execute transactions, provide ongoing advice, and communicate with you about your investments.
- Technology-Assisted Analysis: To use software tools, including artificial intelligence and machine learning systems, to support investment analysis, financial planning, conversation analysis, and internal tool development in furtherance of client service delivery (see Section 9).
- Regulatory and Legal Compliance: To comply with securities regulations, tax reporting, anti-money laundering obligations, and other legal requirements.
- Complaint and Dispute Resolution: To investigate and resolve complaints or regulatory inquiries.
- Client Protection: To protect clients from suspected financial exploitation or diminished capacity (see Section 10).
5. Principle 3 — Consent
Woodgate obtains meaningful consent for the collection, use, and disclosure of personal information in compliance with the Office of the Privacy Commissioner (OPC) Guidelines for Obtaining Meaningful Consent.
5.1 Implied Consent
By entering into an advisory relationship with Woodgate, you provide implied consent for the collection, use, and disclosure of your personal information for all purposes reasonably necessary to deliver the advisory services described in your client agreement. This includes:
- All purposes identified in Section 4, including technology-assisted analysis and AI-supported service delivery.
- Processing of your information through software tools and systems used in the ordinary course of service delivery, as described transparently in this policy.
Implied consent is appropriate for these uses because they fall within the reasonable expectations of a client engaging a financial advisory firm and are necessary for the performance of our services.
5.2 Express Consent
Woodgate will seek express opt-in consent before using your personal information for any purpose beyond the direct delivery of advisory services. If we identify future uses of personal information that go beyond serving you as a client — such as any commercial use unrelated to your advisory relationship — we will notify you and seek your express consent before proceeding.
5.3 Mandatory vs. Optional Processing
Certain processing activities are mandatory for the delivery of advisory services and regulatory compliance. You may not opt out of these activities while maintaining an active advisory relationship. Any future optional processing activities will be clearly distinguished and subject to separate express consent.
5.4 Withdrawal of Consent
You may withdraw consent for non-mandatory processing at any time by contacting the Privacy Officer. Please note that withdrawal of consent for mandatory processing may require termination of the advisory relationship. We will explain the consequences of withdrawal upon request. Withdrawal of consent does not affect the lawfulness of any processing conducted prior to such withdrawal.
6. Principle 4 — Limiting Collection
We collect only the personal information necessary for the purposes identified in this policy. Information is collected by fair and lawful means, directly from the client where possible, and from third parties only where authorized by the client or permitted by law.
Woodgate does not knowingly collect personal information from individuals under the age of 18. Our advisory services are not directed to minors. If we become aware that personal information has been collected from an individual under the age of 18 without appropriate legal authorization, we will take steps to delete that information. If you have reason to believe that a minor under the age of 18 has provided personal information to us, please contact the Privacy Officer to request deletion.
7. Principle 5 — Limiting Use, Disclosure, and Retention
Personal information will not be used or disclosed for purposes other than those for which it was collected, except with the consent of the individual or as required or permitted by law.
7.1 Retention Periods
Client records are retained for the legally mandated minimum periods, including:
- Seven (7) years following the end of the client relationship, as required under applicable securities regulatory requirements.
- Periods required under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) for transaction and identification records.
- Any additional periods required by applicable securities, tax, or other regulatory requirements.
7.2 Secure Destruction
Upon expiry of the applicable retention period, personal information is destroyed using methods appropriate to the sensitivity of the information, including cryptographic wiping for electronic records and secure shredding for physical records.
8. Principle 6 — Accuracy
We take reasonable steps to ensure that personal information is accurate, complete, and up to date for the purposes for which it is used. Clients are encouraged to notify us of any changes to their personal information. We update client records as part of our regular KYC review process.
9. Principle 7 — Safeguards
Woodgate protects personal information with security safeguards appropriate to the sensitivity of the information.
9.1 Cybersecurity Controls
We are committed to maintaining robust cybersecurity protections, including:
- Encryption of personal information at rest and in transit using industry-standard protocols.
- Multi-factor authentication for access to systems containing personal information.
- Principle of least privilege access controls, limiting access to personal information to authorized personnel who require it for their duties.
- Regular security assessments of third-party vendors and service providers.
- Ongoing monitoring of systems for unauthorized access or anomalous activity.
While Woodgate is committed to maintaining robust security safeguards, you acknowledge that no method of transmission over the Internet or method of electronic storage is completely secure. Woodgate cannot guarantee the absolute security of personal information transmitted to or stored by us, despite our best efforts. You are responsible for safeguarding your login credentials, using strong passwords, and notifying us immediately if you become aware of any unauthorized access to or use of your account.
9.2 Data Residency
Woodgate is committed to Canadian data residency for client personal information where operationally feasible. All internally developed systems and tools are hosted on servers located within Canada. Where third-party service providers store or process data on servers located outside Canada, we ensure contractual safeguards are in place and conduct Privacy Impact Assessments prior to any cross-border transfer (see Section 12).
9.3 AI and Technology Use in Service Delivery
Woodgate uses modern technology, including artificial intelligence and machine learning tools, to enhance the quality and efficiency of our advisory services. We are committed to transparency about these practices.
9.3.1 Permitted Uses of Personal Information in Technology Systems
Personal information may flow through AI and technology systems for the following service delivery purposes:
- Querying and extraction of relevant information from client records.
- Analysis of financial data to support planning and investment recommendations.
- Conversation analysis to improve service quality and compliance documentation.
- Internal tool development to enhance service delivery capabilities.
All software development activities use client data for service delivery as the primary purpose. Any secondary commercial application is subordinate to and dependent upon the service delivery function.
9.3.2 Prohibition on AI Training with Raw Personal Information
Woodgate explicitly prohibits the use of raw, identifiable personal information to train any artificial intelligence or machine learning model, whether internal or operated by a third party. This prohibition applies without exception.
9.3.3 Vendor Safeguards for Technology Systems
All third-party technology vendors processing personal information are required to maintain:
- Zero-data-retention API terms, ensuring that personal information is not stored by the vendor beyond the duration of the processing request.
- Contractual prohibitions on using client data to train the vendor's own models or any third-party models.
- Walled garden or isolated processing environments that prevent commingling of Woodgate client data with other data sets.
9.3.4 De-identification Requirements
Before personal information enters any development pipeline that is separate from direct client service delivery, it must undergo irreversible de-identification. De-identified data is not subject to the consent requirements of this policy, as it no longer constitutes personal information.
9.3.5 Automated Decision-Making
Woodgate does not make material decisions affecting clients based exclusively on automated processing of personal information. AI tools used by Woodgate assist advisors in analysis and planning but do not make material decisions on behalf of clients without human involvement. All material recommendations and decisions are made by qualified human professionals holding appropriate designations (CFP, QAFP) and registered with the applicable securities regulator. Clients may request human review of any technology-assisted recommendation at any time by contacting the Privacy Officer.
10. Protection of Vulnerable Clients
Woodgate is committed to protecting clients who may be vulnerable due to age, diminished capacity, or susceptibility to financial exploitation, in accordance with the Canadian Securities Administrators (CSA) Client Focused Reforms and CSA Staff Notice 31-354.
10.1 Trusted Contact Person (TCP)
We collect the name and contact information of a Trusted Contact Person designated by the client. This information is collected solely to protect the primary client in situations involving suspected financial exploitation or diminished mental capacity.
Woodgate will only contact the TCP under narrow, defined circumstances:
- Where there is a reasonable basis to believe the client is being financially exploited.
- Where there are concerns about the client's mental capacity to make financial decisions.
- To confirm the client's contact information or the identity of a legal representative.
TCP information will not be used for any other purpose or shared with any third party except as required by law or securities regulation.
10.2 Temporary Holds and Internal Disclosure
Where financial exploitation is suspected, Woodgate may place a temporary hold on account transactions and share relevant personal information internally among compliance, legal, and advisory personnel on a need-to-know basis. These actions are taken under the emergency provisions of PIPEDA, which permit disclosure without consent where necessary to protect the individual from significant harm.
A written record of the basis for any temporary hold and associated internal disclosures is maintained for regulatory audit purposes.
11. Third-Party Service Providers
Woodgate does not sell, rent, or trade personal information to any third party.
Where personal information is transferred to third-party service providers for processing (including custodians, technology vendors, and professional advisors), we require:
- Written agreements that limit use of the information to the purposes specified by Woodgate.
- Obligations to protect the information with safeguards no less stringent than those described in this policy.
- Return or destruction of all personal information upon termination of the service relationship.
- Prompt notification to Woodgate in the event of any data breach or security incident affecting client personal information.
- For technology vendors: compliance with the AI and technology safeguards set out in Section 9.3.3.
Vendor compliance with the privacy safeguards described in this policy is verified through contractual provisions reviewed at onboarding and renewal, and through periodic review of vendor documentation, including SOC 2 reports, privacy attestations, or equivalent assurance mechanisms.
In the event of a merger, acquisition, reorganization, sale of assets, or similar business transaction involving Woodgate, personal information may be transferred to a successor entity as part of that transaction. Any successor entity will be bound to handle your personal information in accordance with this Privacy Policy and applicable privacy legislation. Where required by applicable law, we will notify you of any such transfer.
12. Cross-Border Transfers and Law 25 Compliance
Woodgate serves clients across Canada, including in Quebec, and complies with Law 25 (Act respecting the protection of personal information in the private sector) as a national baseline for privacy protections.
12.1 Privacy Impact Assessments
Woodgate conducts a Privacy Impact Assessment (PIA) prior to any project involving the development, acquisition, or redesign of an information system or electronic service delivery that involves personal information, as well as prior to any cross-border transfer of personal information outside of Canada. This includes AI-powered systems used in service delivery, such as document extraction, questionnaire scoring, and financial analysis tools. PIAs are conducted in accordance with guidance published by the Office of the Privacy Commissioner of Canada and the Commission d'accès à l'information du Québec.
- All internally developed products and systems are housed on Canadian servers.
- Where third-party service providers operate on US-based servers, Woodgate ensures contractual safeguards are in place, including data processing agreements, encryption requirements, and restrictions on further transfer.
- PIAs are retained and reviewed when material changes are made to the assessed system or when new personal information flows are introduced.
12.2 Data Portability
Clients have the right to receive their personal information in a structured, commonly used, and machine-readable format upon request. Requests should be directed to the Privacy Officer. A reasonable fee may be charged for the retrieval, reproduction, and transmission of personal information, as permitted by applicable law.
12.3 Privacy by Design
Woodgate applies the principle of Privacy by Design to all new systems, processes, and services. Personal information is afforded the highest level of confidentiality by default. Privacy protections are embedded into the design of technology systems and business processes from the outset, not applied as an afterthought.
13. Data Breach and Incident Response
Woodgate maintains a formal incident response procedure for addressing breaches of personal information security.
13.1 Federal Notification (PIPEDA)
Where a breach of security safeguards creates a real risk of significant harm (RROSH) to any individual, Woodgate will take the actions described below.
In assessing whether a breach creates a real risk of significant harm, Woodgate considers the following factors as required by PIPEDA Section 10.1(8):
- The sensitivity of the personal information involved in the breach;
- The probability that the personal information has been, is being, or will be misused;
- The number of individuals whose personal information is involved; and
- The breadth and scope of the breach, including the systems affected and the duration of the incident.
Where RROSH is determined to exist, Woodgate will:
- Notify the Office of the Privacy Commissioner of Canada (OPC) as soon as feasible after the determination of RROSH.
- Notify affected individuals as soon as feasible, providing a description of the breach, the types of information involved, steps taken, and contact information for further inquiries.
- Notify any other organization or government institution that may be able to reduce the risk of harm.
13.2 Provincial Notification (Law 25 — Quebec)
For incidents involving the personal information of Quebec residents, Woodgate will notify the Commission d'accès à l'information du Québec (CAI) promptly, targeting notification within seventy-two (72) hours of becoming aware of a confidentiality incident presenting a risk of serious injury.
13.3 General Commitments
- Woodgate will notify affected clients and all relevant regulatory authorities without unreasonable delay.
- Third-party vendors are contractually required to notify Woodgate promptly of any breach or security incident affecting personal information processed on Woodgate's behalf.
- An internal incident response procedure governs the investigation, containment, remediation, and documentation of all security incidents. This companion operational document is reviewed and tested at least annually.
13.4 Breach Record-Keeping
Woodgate maintains a record of all breaches of security safeguards involving personal information, regardless of whether the breach meets the threshold for notification under PIPEDA or Law 25. These records are retained for a minimum of twenty-four (24) months and are available to the Office of the Privacy Commissioner upon request, in accordance with SOR/2018-64. The procedures for maintaining these records are set out in Woodgate's companion Incident Response Procedure.
14. Principle 8 — Openness
Woodgate makes information about its privacy policies and practices readily available. This policy is provided to all new clients as part of the onboarding process and is available upon request at any time. The current version of this policy is also available on our website. Material changes to this policy will be communicated to clients in writing.
15. Principle 9 — Individual Access
Upon written request to the Privacy Officer, you have the right to:
- Be informed of the existence, use, and disclosure of your personal information.
- Access your personal information held by Woodgate, subject to limited exceptions permitted by law.
- Challenge the accuracy and completeness of your information and request corrections.
Woodgate will respond to access requests within thirty (30) days, or such shorter period as may be required by applicable law. In exceptional cases, we may extend this period by an additional thirty (30) days with written notice and explanation of the reasons for the extension. Woodgate may deny or limit an access, correction, or deletion request where permitted or required by applicable law, including where:
- retaining the information is necessary to complete a transaction or fulfill the terms of the advisory relationship;
- compliance with a legal, regulatory, or professional obligation, including securities regulatory record-keeping requirements and anti-money laundering legislation;
- detecting, investigating, or preventing fraud, security incidents, or other prohibited activities;
- establishing, exercising, or defending legal claims or regulatory proceedings; or
- where Woodgate denies or limits a request, we will provide written reasons for the denial and information about how to challenge the decision.
16. Principle 10 — Challenging Compliance
You have the right to challenge Woodgate's compliance with this policy by contacting the Privacy Officer:
Jason Pereira, Privacy Officer
Email: jason.pereira@woodgate.com
All complaints will be investigated and responded to in writing. If you are not satisfied with our response, you have the right to file a complaint with:
- The Office of the Privacy Commissioner of Canada (OPC).
- The Commission d'accès à l'information du Québec (CAI), for matters involving Quebec residents.
- Your applicable provincial privacy commissioner, if any.
17. Policy Review and Amendment
This policy is reviewed at least annually by the Privacy Officer to ensure continued compliance with applicable legislation and alignment with Woodgate's business practices. Amendments may be made at any time. Material amendments will be communicated to clients in writing prior to taking effect. Your continued use of Woodgate's services following any such communication constitutes your acknowledgment and acceptance of the amended policy.
Last reviewed: June 14, 2026
Next scheduled review: No later than May 2027
Website Data Collection — BusinessOwnerFP.ca
The sections below describe data collected specifically through this website (BusinessOwnerFP.ca), operated by Woodgate Financial Inc.
Who We Are
This website is operated by Woodgate Financial Inc., located at 5015 Spectrum Way, Suite 300, Mississauga, Ontario L4W 0E4, Canada.
Contact us at info@woodgate.com or +1 (416) 691-1944.
Information We Collect
We collect the following types of information:
Email Addresses: When you subscribe to our newsletter or use the subscribe form on this website, we collect your first name, last name, and email address.
We use PostHog to collect usage data including page views, clicks, and session recordings. This helps us understand how visitors interact with our content and improve the website experience. PostHog is not loaded until you accept analytics cookies through the consent banner, and you can withdraw that consent at any time using the Cookie preferences link in the site footer.
How We Use Your Information
Newsletter Delivery: Your name and email address are used to deliver newsletter content and updates about financial planning topics relevant to Canadian business owners, and to address you by name in that correspondence.
Website Improvement: Analytics data is used to improve the website experience, understand content effectiveness, and make informed decisions about future content.
Third-Party Services
Webflow. This website is built and hosted on Webflow. Newsletter and subscribe form submissions are stored in Webflow's form submission system, which is hosted in the United States, before being exported to our mailing list. Woodgate's cross-border transfer safeguards are described in Section 12.
Zapier and AdvisorStream (Newsletter Signup). Newsletter and subscribe form submissions are passed from Webflow to our email platform, AdvisorStream, through Zapier. They process the name and email address you submit. Zapier is hosted in the United States. Woodgate's cross-border transfer safeguards are described in Section 12.
Vidvisor (Video Playback). Every page of this site loads a video player script from Vidvisor. Loading the script transmits your IP address and the page you are viewing to Vidvisor. Woodgate Venture Holdings Inc., of which Jason Pereira is President, holds an investment in Vidvisor.
YouTube (Video Thumbnails and Embeds). Video thumbnail images on this site are loaded from YouTube, which transmits your IP address to Google in the United States when the page loads. Videos themselves are embedded through youtube-nocookie.com and only load when you click to play them.
PostHog (Analytics): We use PostHog for website analytics, including page views, click tracking, and session recordings. PostHog data is hosted in the United States. For more information, visit PostHog's privacy policy.
Acast (Podcast Hosting): Our podcast episodes are hosted through Acast. When you listen to episodes embedded on our site or through podcast platforms, Acast may collect listening data. For more information, visit Acast's privacy policy.
Cookies
PostHog uses cookies for session identification and analytics purposes. You can manage your cookie preferences through the cookie consent banner displayed on our website. You may also configure your browser to reject cookies, though this may affect certain website functionality.
Data Retention
Email Addresses: Your name and email address are retained for as long as you remain subscribed. When you unsubscribe, your subscription record is removed from our mailing list and the corresponding form submission is deleted from Webflow within 30 days.
Analytics Data: Website analytics data is retained per PostHog's standard data retention policies.
How to Opt Out
Email Communications: Click the unsubscribe link included at the bottom of any email you receive from us.
Cookies and Analytics: Use the cookie consent banner on our website to manage your tracking preferences.
Direct Contact: Email us at jason.pereira@woodgate.com to request access to, correction of, or deletion of your personal information.
Contact Us
If you have any questions about this privacy policy or our data practices, please contact us:
Woodgate Financial Inc.
5015 Spectrum Way, Suite 300
Mississauga, Ontario L4W 0E4
Email: info@woodgate.com
Phone: +1 (416) 691-1944