Coaching For Change

privacy Policy

1. Purpose and Scope

This Privacy Policy (“Policy”) describes how Accountability Intelligence (“we”, “us”, “our” or the “Company”) collects,

uses, discloses, retains, and disposes of personal information in connection with the Accountability Intelligence

platform (the “Services”). This Policy applies to all individuals who access or use the Services, including registered users,

organizational customers, and visitors to our website, and is administered in accordance with the Personal Information

Protection and Electronic Documents Act (PIPEDA) and any applicable provincial privacy legislation. This Policy governs

personal information collected in connection with the Services regardless of the jurisdiction from which the Services are

accessed, provided the Company’s operations and data storage are presently limited to Canada.

2. Notice of Privacy Practices

We are committed to providing clear and timely notice of our privacy practices. This Policy is made available to all users
prior to or at the time personal information is collected, is accessible at all times on our website, and is referenced
during account registration. Where we make a material change to how we collect, use, retain, or disclose personal
information, we will provide advance notice in accordance with Section 19 (Changes to This Policy) before the change
takes effect.

3. Personal Information We Collect

We collect only the personal information reasonably necessary to achieve the purposes described in this Policy. We do
not collect personal information beyond what is needed to provide, secure, and improve the Services.

3.1 Information You Provide Directly

  • Full name
  • Email address
  • Phone number (if provided)
  • Company name and job title (if applicable)
  • Billing and payment information (for paid subscriptions)

3.2 Information Collected Through Use of the Services

  • Device information – IP address, browser type, operating system, device model, and unique device identifiers
  • Login and session details – timestamps, session duration, pages visited, referral sources, and interaction patterns
  • Assessment and performance data – responses to accountability assessments, progress tracking, engagement
    metrics, and usage trends
  • Cookies and tracking technologies – used to monitor usage, detect issues, and optimize platform performance
  • Error reports and debugging information – data on crashes, errors, and technical failures
  • Approximate geolocation data (if enabled) – derived from IP address or device settings

 

Cookies and similar tracking technologies are used to improve user experience, analyse site traffic, and personalize
content. You shall manage cookie preferences through your browser settings and, where applicable, through any
in-platform cookie preference controls made available to you.

4. Consent

4.1 Obtaining Consent

We obtain your consent before collecting, using, retaining, or disclosing your personal information, except where an
exception under PIPEDA or applicable law permits collection, use, or disclosure without consent (for example, legal or
regulatory compliance, or the investigation of fraud). Consent shall be express (e.g., ticking a consent checkbox, agreeing to Terms during registration) or implied through your continued use of the Services where the purpose is
reasonably obvious and non-sensitive.

4.2 Withdrawing Consent

You shall withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice, by using the
details in Section 20. Withdrawing consent shall limit or prevent our ability to provide certain features or the Services
generally, and we will explain any such impact at the time of your request.

4.3 Sensitive Information

Where we collect information of a sensitive nature – including assessment responses that shall reveal information about
workplace conduct, performance evaluations, or other information that could cause harm if disclosed inappropriately –
we obtain your explicit, opt-in consent prior to collection, separate from general acceptance of the Terms and
Conditions. We do not infer consent to collect sensitive information from general platform use alone.

5. Use of Personal Information

We use personal information only for the purposes for which it was collected, or for a purpose reasonably compatible
with that original purpose, unless you separately consent to an additional use or the use is required or authorized by
law. Stated purposes include:

  • Providing and maintaining the Accountability Intelligence™ platform
  • Processing account registration and managing user profiles
  • Processing billing and payment for paid subscriptions
  • Delivering personalized insights and recommendations based on assessments
  • Improving platform functionality, security, and user experience
  • Sending service updates, notifications, and support communications
  • Detecting and preventing fraud, abuse, and unauthorized access
  • Complying with legal obligations and enforcing our Terms and Conditions

 

We do not sell personal information, and we do not disclose personal information to third parties for their own
independent marketing purposes.

6. Retention of Personal Information

We retain personal information only for as long as necessary to fulfil the purposes described in this Policy, including the
following retention criteria:

  • Account and profile information: retained for the duration of the active account, plus agreed business needs or
    legal/contractual requirements following account closure to address legal, accounting, or dispute-resolution
    needs
  • Billing and payment records: retained for agreed business needs or legal/contractual requirements to meet tax
    and financial regulatory obligations
  • Usage, device, and log data: retained for contractually discussed months for security monitoring and
    troubleshooting, after which it is aggregated or deleted
  • Assessment and performance data: retained for timeline agreed with the organizational customer under a data
    processing agreement

 

During the retention period, personal information is protected using the safeguards described in Section 11 and internal
security controls, including encryption of sensitive data, restricted access controls, and regular security audits.
Retention periods are reviewed periodically and updated as legal, or business requirements change.

7. Secure Disposal of Personal Information

Once personal information is no longer required for the purposes described in this Policy and no legal or regulatory
requirement obliges continued retention, we securely destroy, erase, or anonymize it. Electronic records are
permanently deleted or rendered unrecoverable using secure deletion methods; physical records, if any, are shredded
or otherwise destroyed to prevent reconstruction. Where you request account deletion, we will remove your personal
data from active systems within a reasonable period, except where retention is required by law.

8. Access to Personal Information

You have the right to request access to the personal information we hold about you, including confirmation of its
existence, the purposes for which it is used, and the parties to whom it has been disclosed. To submit an access
request, contact our Privacy Officer using the details in Section 20.

  • We will respond to access requests within 30 calendar days, or provide written notice of an extension where permitted by law, including the reason for the extension.
  • Copies of personal information will be provided in an understandable and, where reasonably feasible, structured and portable format.
  • Where a request is denied in whole or in part, we will provide the reasons for the denial, the specific provision of law relied upon, and information about your right to challenge the denial with our Privacy Officer or, if unresolved, with the Office of the Privacy Commissioner of Canada.

9. Correction and Amendment of Personal Information

If you believe personal information we hold about you is inaccurate or incomplete, you shall request that we correct,
amend, or append it. Upon verifying the request, we will:

  • Correct, amend, or append the information as appropriate
  • Where the correction affects information previously disclosed to a third party, notify that third party of the correction where reasonable and feasible to do so
  • Notify you once the correction has been made, or provide reasons if we decline to make a requested correction,
    along with information about how to have a statement of disagreement noted on file

10. Disclosure to Third Parties

10.1 Disclosure with Consent

We disclose personal information to third parties only with your consent, except where disclosure without consent is
permitted or required by law (see Section 12). Third parties who shall receive personal information, with consent,
include:

  • Service Providers: hosting providers, payment processors, data analytics providers, and customer support
    platforms, engaged to support delivery of the Services
  • Business Transfer Parties: in connection with a merger, acquisition, financing, or sale of assets, subject to the
    successor entity honouring the commitments in this Policy

10.2 No Sale or Marketing Disclosure

We do not sell or share personal information with third parties for their own independent marketing purposes.

10.3 Disclosure Records

We create and retain a record of authorized disclosures of personal information to third parties, including the recipient,
the categories of personal information disclosed, the purpose of disclosure, and the date. These records support our
ability to provide an accounting of disclosures under Section 14 and to demonstrate accountability under PIPEDA.

11. Vendor and Third-Party Management

Before engaging a vendor or third-party service provider that will process personal information on our behalf, we obtain
a written privacy and confidentiality commitment covering, at minimum, use restricted to the contracted purpose,
confidentiality, security safeguards commensurate with the sensitivity of the information, breach notification to us
without undue delay, and secure disposal or return of information at the end of the engagement. We periodically assess
vendor compliance with these commitments, commensurate with the sensitivity of the personal information involved
and the nature of the engagement and take corrective action – including remediation requirements or termination of
the engagement – where a vendor fails to meet its commitments.

12. Disclosure to Regulators and Legal Authorities

We shall disclose personal information without consent where required or authorized by law, including in response to a
valid court order, subpoena, search warrant, or lawful request from a government or regulatory authority; to comply
with legal, regulatory, or audit requirements; or to protect the rights, property, or safety of the Company, our users, or
the public. Any such disclosure is limited to what is legally required and is documented internally.

13. Breach and Incident Management

13.1 Detection and Response

We maintain internal processes to detect, investigate, contain, and remediate incidents involving unauthorized access,
use, or disclosure of personal information.

13.2 Notification

Where we determine that a breach of security safeguards has occurred and creates a real risk of significant harm to an
individual, we will notify affected individuals and report the breach to the Office of the Privacy Commissioner of Canada
as soon as feasible, in accordance with PIPEDA’s mandatory breach reporting requirements. Where applicable law in an
affected individual’s province imposes additional or different notification obligations, we will comply with those
obligations as well. Notifications will describe, to the extent known, the circumstances of the breach, the personal
information affected, the steps taken to reduce the risk of harm, and steps the individual can take to protect
themselves.

13.3 Incident Records

We create and retain a record of all detected or reported incidents involving unauthorized access, use, or disclosure of
personal information, whether the incident met the threshold for external notification, including the nature of the
incident, the personal information involved, the response taken, and the outcome. These records are retained to
support regulatory reporting obligations and continuous improvement of our safeguards.

14. Accounting of Personal Information Held and Disclosed

Upon written request, and subject to identity verification, we will provide you with a general account of the personal
information we hold about you and the third parties to whom that information has been disclosed, drawing on the
disclosure records maintained under Section 10.3. This accounting is provided within the same response timelines
described in Section 8 for access requests.

15. Accuracy and Data Quality

We take reasonable steps to ensure that personal information used on an ongoing basis, or disclosed to third parties, is
accurate, complete, and up to date for the purposes for which it is used. Users are encouraged to keep account and
profile information current and shall update most information directly within the platform or by submitting a correction
request under Section 9.

16. Privacy Inquiries, Complaints, and Compliance Monitoring

We welcome questions and concerns about our privacy practices. You shall direct a privacy inquiry or complaint to our
Privacy Officer using the details in Section 20. We will:

  • Acknowledge receipt of the inquiry or complaint within a reasonable period
  • Investigate the matter, including reviewing relevant records and consulting relevant personnel
  • Communicate the outcome and any resulting remediation to the individual
  • Where the individual remains unsatisfied, inform them of their right to escalate the complaint to the Office of the Privacy Commissioner of Canada (or the applicable provincial regulator)

 

We monitor ongoing compliance with this Policy and applicable privacy law through periodic internal reviews of our
privacy practices, safeguards, and vendor commitments, and through tracking of inquiries, complaints, and incidents to
identify and address recurring issues.

17. International and Cross-Border Data Storage

Our servers and data centres are presently located in Canada, and personal information is stored and processed within
Canada. If our data storage or processing arrangements change to involve a jurisdiction outside Canada, we will update
this Policy in accordance with Section 19 and disclose the general data handling practices applicable in that jurisdiction
before the change takes effect.

18. Children's Privacy

The Services are not intended for individuals under the age of 18, and we do not knowingly collect personal information
from children. If we become aware that we have collected personal information from a minor without appropriate
consent, we will take reasonable steps to delete that information promptly.

19. Changes to This Policy

We shall update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or
other factors. Where a change is material, we will provide advance notice – such as by email or a prominent notice
within the Services – before the change takes effect. The “Last Reviewed” date at the top of this Policy indicates when it
was most recently updated. Continued use of the Services after a change takes effect constitutes acceptance of the
updated Policy.

20. Contact Us