Privacy Policy

Privacy Policy

Effective Date: August 12, 2026

Advisor Terminal Inc. ("Advisor Terminal", "we", "us", "our") provides a practice management platform for financial advisors (the "Platform"). This Policy explains what personal information we collect, why, where it is held, how long we keep it, and how to reach us.

We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.

1. Accountability

Advisor Terminal is responsible for personal information under its control. We have designated a Privacy Officer accountable for our compliance with this Policy, reachable at support@advisorterminal.com.

We remain accountable for personal information transferred to third parties for processing, and use contractual means to require a comparable level of protection.

2. Identifying Purposes

We collect personal information in order to:

  • Create and administer accounts and authenticate users
  • Provide the Platform, including client records, documents, tasks, planning tools, and meeting recording, transcription, and AI-assisted summarization
  • Communicate with users about their account, support, and security matters
  • Process subscription payments
  • Secure, monitor, and improve the Platform
  • Meet our legal, regulatory, and audit obligations

We identify the purpose at or before the time of collection. If we intend to use personal information for a new purpose, we will identify it and obtain consent first.

3. Consent

Users consent to the collection, use, and disclosure described in this Policy when they create an account and accept our Terms of Service.

Advisors using the Platform enter information about their own clients. Those advisors are responsible for obtaining any consent required from their clients, including consent to record and transcribe a meeting. We act as a service provider to the advisor in respect of that information.

Consent may be withdrawn at any time, subject to legal and contractual restrictions and reasonable notice. Withdrawing consent may mean we can no longer provide some or all of the Platform.

4. Limiting Collection

We limit collection to what is necessary for the purposes above, and collect by fair and lawful means.

We do not collect, and the Platform provides no fields for, credit card or banking credentials, Social Insurance Numbers, or bank login credentials. Subscription payments are handled by our payment processor and card details are not stored by us.

We do not track users across other websites and we do not sell personal information.

5. Limiting Use and Disclosure

We use personal information only for the purposes identified at collection, for a consistent purpose, or as permitted or required by law.

We disclose it only to service providers processing it on our behalf under contract, where required by law or legal process, in connection with a merger or sale of the business with appropriate safeguards, or with consent.

We do not sell, rent, or trade personal information, and we do not use customer content for advertising.

6. Retention

We retain personal information for the duration of the customer relationship and for seven (7) years after it ends, after which it is securely destroyed. This reflects the record retention obligations applying to the financial services professionals who use the Platform, and our own legal, tax, and audit requirements.

Audio recordings are the exception. They are deleted immediately after transcription and are not retained. See Section 9.

Operational data is held for shorter periods: system and access logs are retained for security and investigation purposes, and product usage telemetry is short-lived and carries no personally identifying information.

Users may delete individual records within the Platform at any time. A deleted record is removed from the Platform immediately and permanently erased within 180 days. A user may also request deletion of their account and its contents, which we will action subject to anything we are required by law to retain.

Where litigation or a regulatory investigation is pending or reasonably anticipated, retention periods are suspended for the relevant information.

7. Accuracy

We keep personal information as accurate and complete as is necessary for the purposes for which it is used. Users can review and correct information in their account at any time through the Platform.

8. Safeguards

We protect personal information with physical, organizational, and technological safeguards appropriate to its sensitivity, including:

  • Encryption in transit using TLS 1.2 or higher, and encryption at rest
  • Mandatory multi-factor authentication for all users and for administrative access to production systems
  • Role-based access, with each practice's data isolated so one practice cannot access another's
  • Access to production systems limited to named personnel on a need-to-know basis
  • Platform access restricted to connections originating in Canada and the United States
  • Monitoring, audit logging, and documented incident response procedures
  • Security awareness training for all personnel, and confidentiality obligations in every employment and contractor agreement

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Meeting Recordings, Transcription, and Artificial Intelligence

The Platform includes optional meeting recording, transcription, and AI-assisted summarization.

How it works. When a user records a meeting, audio is captured and held in temporary encrypted storage, transcribed by a third-party speech-to-text provider, and the transcript is then summarized by a third-party AI provider to produce a title, summary, and drafted notes.

Recording is optional; what follows is not. Users choose whether to record. Once a recording is made, transcription and summarization run automatically as part of processing it and cannot be disabled for that recording.

Audio is not retained. It is deleted immediately after transcription completes, is not backed up, and is not accessible to our personnel.

What is kept. The transcript, the AI-generated title and summary, and speaker labels are retained under Section 6. Users can edit or delete them at any time.

Content is not used to train AI models. We do not develop, train, or fine-tune AI models, and our providers are contractually bound not to use content submitted through our account for training.

Accuracy. AI-generated summaries and notes are drafting aids, may contain errors, and should be reviewed before being relied on.

10. Where Your Data Is Processed

Some processing is performed by service providers outside Canada, including in the United States, as described in Section 11.

While personal information is outside Canada it is subject to the laws of that country and may be accessible to its courts, law enforcement, and national security authorities. We use data processing agreements or equivalent contractual protections to require comparable protection wherever processing occurs.

11. Service Providers

We engage third-party service providers for cloud hosting and storage, real-time synchronization, meeting capture, speech-to-text transcription, AI summarization, payment processing, email and SMS delivery, logging, monitoring and product analytics, caching and rate limiting, and background processing.

Before engaging a provider with access to customer data we assess its security posture, review its SOC 2 report or complete a security questionnaire, and put a data processing agreement or equivalent contractual protection in place. We reassess these providers periodically.

A current list of the specific providers we use, including the data each accesses and where it is processed, is available to customers on request to support@advisorterminal.com.

12. Openness

This Policy is published at advisorterminal.com and available to all users at any time. We will provide further information about our privacy practices on request.

13. Individual Access and Your Rights

Subject to the limits set out in PIPEDA, you have the right to know what personal information we hold about you and how it has been used and disclosed, to access and receive a copy of it, to correct it, and to withdraw consent.

In addition to those rights, we allow you to request deletion of your account and its contents, and to export your data from the Platform at any time.

We will respond to a request within thirty (30) days, or tell you if an extension is required and why. We may decline access in the limited circumstances PIPEDA permits, including where doing so would reveal another individual's personal information or compromise an active security investigation; where we decline, we will explain why.

Requests go to support@advisorterminal.com.

If you are an advisor's client: where an advisor has entered your information into the Platform, that advisor controls the record. Please direct requests to your advisor first. If you cannot reach them, contact us and we will assist.

14. Security Incident and Breach Notification

We maintain a documented Incident Response Policy governing how we detect, classify, contain, investigate, and report security incidents.

Where we confirm a breach of security safeguards involving personal information, we will notify affected customers within twenty-four (24) hours of confirmation. Where a material incident affects your data or service without constituting such a breach, we will notify you within seventy-two (72) hours. Notice is given by email to the account's primary contact and by in-application notice, and describes what happened, what was affected, what we have done, and what if anything you should do.

Where a breach creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, in accordance with PIPEDA. Where an advisor's clients are affected we will notify the advisor so they can meet their own obligations. We maintain a record of every breach of security safeguards for at least twenty-four (24) months.

15. Reporting a Security Incident or Compliance Concern

You do not need to be a customer to report a problem. Every report goes to the same place: support@advisorterminal.com. To help us route it, put one of the following at the start of the subject line.

What You Want to ReportSubject Line
A suspected security incident, vulnerability, or misuse of the PlatformSecurity
A privacy question, access or correction request, or a complaint about how we handled personal informationPrivacy
A concern about our compliance with this Policy or applicable lawPrivacy Officer

Security reports are triaged by our Chief Information Security Officer, assigned a severity, and handled under our Incident Response Policy. Privacy and compliance concerns are investigated by the Privacy Officer. We will tell you the outcome unless we are legally prevented from doing so.

16. Challenging Compliance

You may challenge our compliance with this Policy or with applicable privacy law by contacting the Privacy Officer at support@advisorterminal.com.

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada:

Office of the Privacy Commissioner of Canada

30 Victoria Street, Gatineau, Quebec, K1A 1H3

Toll-free: 1-800-282-1376

priv.gc.ca

17. Cookies and Similar Technologies

We use cookies necessary for the Platform to function, including maintaining your authenticated session and preferences, and limited analytics that involve no personally identifying information and do not track you across other websites.

We do not use advertising cookies and do not permit third-party advertising trackers.

Most browsers allow you to refuse or delete cookies. Disabling cookies necessary for authentication will prevent you from signing in.

18. Third-Party Links

The Platform and our website may link to third-party sites. We are not responsible for the privacy practices or content of those sites.

19. Updates to This Policy

We review this Policy at least annually and whenever there is a material change to the Platform, our service providers, or applicable law. We will notify account holders of material changes. Other changes take effect when posted. The effective date appears at the top of this Policy, and previous versions are available on request.

20. Contact Us

Privacy Officer

Advisor Terminal Inc.

401 Bay Street, Suite 1600

Toronto, Ontario M5H 2Y4

Canada

All enquiries, including privacy questions, access requests, complaints, and security reports: support@advisorterminal.com