privacy policy
How we collect, use, disclose, and protect personal information in connection with our website and our consulting engagements.
- Entity
- 2557345 Alberta Inc., operating as “Rockwell Group”
- Effective
- August 20, 2026 (Version 1.0)
- Privacy Officer
- privacy@rockwellgroup.xyz
- Mailing address
- 430-2339 Highway 97 North
Kelowna, BC V1X 4H9, Canada
1About this policy
Rockwell Group (“Rockwell,” “we,” “our,” “us”) is a professional consulting firm. We provide fractional CFO and CCO advisory, financial and capital advisory, AML and regulatory compliance consulting, and AI and automation implementation services to businesses.
We are not a software vendor. We do not sell, license, or operate a product that stores your customers’ data on an ongoing basis. The information we handle comes from people who contact us, people who subscribe to our insights, and the materials our clients give us to do the work they hire us to do.
This Privacy Policy explains how we collect, use, disclose, safeguard, and retain personal information in connection with our website at rockwellgroup.xyz (the “Website”) and our consulting engagements (together, the “Services”).
Applicable law. We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act(Canada) (“PIPEDA”) and, where they apply to our activities, Alberta’s Personal Information Protection Act(“Alberta PIPA”) and British Columbia’s Personal Information Protection Act(“BC PIPA”). Where the requirements differ, we apply the standard that is most protective of the individual.
2Who this policy applies to
This policy applies to:
- Visitors to our Website.
- Prospective clients who contact us, submit an inquiry, or use the AI intake assistant on our Website.
- Subscribers to our insights emails.
- Client personnel — the directors, officers, employees, and contractors we deal with during an engagement.
- Individuals whose personal information appears in materials a client provides to us during an engagement (see Section 3.4).
- Suppliers, subcontractors, referral partners, and candidates.
- Former clients and former contacts.
3Information we collect
3.1 Information you provide directly
- Inquiry information: Name, email address, company name, company stage or size, and the content of the message you submit through our contact form.
- Intake assistant conversations:If you use the AI intake assistant on our Website, we collect the messages you send, any name, email, and company you choose to provide, and a structured summary of the project you describe that is generated from the conversation. A randomly generated session identifier is stored in your browser’s local storage so your conversation persists across page loads.
- Subscription information: Your email address and the page or topic you subscribed from.
- Booking information:When you book a call through our scheduling link, the name, email address, and details you enter are collected through Google’s appointment scheduling.
- Engagement information: Information exchanged in the course of an engagement, including names, titles, and contact details for your team; financial statements, forecasts, models, and accounting records; corporate, governance, and ownership documents; compliance policies, procedures, risk assessments, and training records; systems and process documentation; and any other business records you provide to us.
- Billing information: Billing contact, business address, invoices, and payment records. We do not collect or store full payment card numbers.
- Communications: Emails, messages, meeting notes, and correspondence between us.
- Feedback: Responses to requests for feedback, references, or case-study participation.
3.2 Meetings, calls, and AI note-taking
We use AI note-taking tools to record, transcribe, and summarize calls and meetings, so that we have an accurate record of what was discussed and can produce internal notes and action items. This policy is your notice that calls and meetings with us may be recorded and transcribed. If you do not want a particular call recorded, tell us before or during the call and we will turn the tool off. Recordings, transcripts, and summaries are used only for the purposes described in Section 4, are accessible only to Rockwell personnel working on the matter, and are retained in accordance with Section 10.
3.3 Information collected automatically
Our Website is a statically generated site. We do not use advertising cookies, cross-site behavioural tracking, third-party analytics cookies, session recording, or heatmaps, and we do not sell or share personal information for advertising purposes.
- Technical logs: Our hosting and backend providers generate standard technical logs — IP address, browser user agent, timestamp, requested URL, referrer, and error diagnostics — which we use for security, abuse prevention, rate limiting, and reliability.
- Local storage:The intake assistant stores a randomly generated session identifier in your browser’s local storage. It is not an advertising identifier and is not shared with third parties for marketing. You can remove it by clearing site data in your browser; doing so will start a new conversation.
- Rate-limiting records: We keep short-lived records tied to session identifiers to prevent abuse of the intake assistant and our forms.
If we add website analytics in the future, we will update this policy and the provider list in Section 8 before doing so.
3.4 Information we receive from clients about other people
During an engagement, we may receive personal information about individuals other than our direct contacts. Depending on the engagement, this can include:
- Your employees’ roles, compensation, training records, and compliance attestations.
- Your customers’ identification information and transaction records, where we test files as part of an AML effectiveness review, compliance program build, FINTRAC readiness assessment, or similar work.
- Beneficial ownership, related-party, and corporate structure information.
- Screening results, including politically exposed person (PEP) and sanctions determinations, and suspicious transaction analysis.
- Third parties named in documents, contracts, board materials, or investigation files you provide to us.
We collect this information only as necessary to perform the engagement, and we handle it as described in Section 5.
3.5 Sensitive information
Some engagement materials are sensitive — government-issued identification, financial account and transaction data, screening and suspicious-activity records, and compensation information. We ask clients to provide only what the engagement actually requires, and to provide redacted, sampled, or de-identified material where that is sufficient for the work.
4How we use information
We use personal information to:
Respond and scope: respond to inquiries and requests for information; understand a prospective engagement, assess fit, and identify conflicts; and prepare proposals, scopes of work, and engagement letters.
Deliver the Services: perform the advisory, compliance, financial, and implementation work you engage us to do; communicate with you and your team about the engagement; prepare deliverables, reports, models, policies, and recommendations; and maintain professional working papers and engagement records supporting our work.
Operate our business: issue invoices, process payments, and collect amounts owing; maintain accounting, tax, insurance, and corporate records; manage subcontractors and referral relationships; conduct quality assurance and improve how we deliver services; and evaluate, negotiate, and complete business transactions.
Protect and comply: secure our Website and systems, prevent fraud and abuse, and investigate incidents; comply with legal, regulatory, professional, and record-keeping obligations; and establish, exercise, or defend legal claims.
Communicate: send insights emails, updates, and event invitations where you have consented (see Section 13), and send transactional and engagement communications, which are not marketing and continue regardless of marketing preferences.
We do not sell, rent, or trade personal information. We do not use client engagement materials to train AI models, and the AI providers we use process content under commercial terms that do not permit training their general-purpose models on it.
We will not use personal information for a materially different purpose without your consent or as otherwise permitted or required by law.
5Client information and our role
Where you engage us and provide personal information about your customers, employees, or other individuals, you remain the organization accountable for that information under privacy law. We act as your service provider and handle it only to perform the engagement.
Your responsibilities as our client
- Ensure you have lawful authority and any necessary consents to disclose the information to us.
- Provide only the information the engagement requires, redacted or sampled where sufficient.
- Tell us in advance of any restrictions, legal holds, or handling requirements that apply.
- Give your own customers and personnel any privacy notices required by law, including with respect to service providers and cross-border processing.
- Respond to privacy requests you receive from those individuals.
Our commitments
- We use client information only to perform the engagement, and not for any secondary purpose.
- Access is limited to Rockwell personnel and subcontractors who need it, all of whom are bound by confidentiality obligations and, where applicable, professional standards of confidentiality.
- We do not disclose client information except as described in Section 7.
- On request at the end of an engagement, we will return or securely dispose of client materials, subject to the working papers and records we are required or reasonably need to retain under Section 10.
6Consent and legal bases
We collect, use, and disclose personal information with your consent, except where the law permits or requires otherwise.
- Express consent is obtained where the information is sensitive or where the purpose would not be obvious — for example, marketing subscriptions.
- Implied consent applies where the purpose is obvious from the circumstances, or where we have given notice of a practice in this policy and you continue to deal with us — for example, submitting an inquiry so we can respond to it, or continuing with a call after the notice in Section 3.2.
- Business contact information — your name, title, business address, business phone, and business email, used solely to communicate with you in relation to your role — is not subject to consent requirements under PIPEDA, Alberta PIPA, or BC PIPA.
- Without consent, where permitted by law — for example, where collection is necessary to perform or enforce a contract, to investigate a breach of an agreement or a contravention of law, to comply with a subpoena, warrant, court order, or regulatory requirement, in an emergency threatening life, health, or security, or where the information is publicly available in a form prescribed by the applicable statute.
- Business transactions — as permitted under PIPEDA and provincial legislation, personal information may be used and disclosed in connection with a prospective or completed business transaction, subject to the safeguards in Section 7.
Withdrawing consent. You may withdraw consent at any time on reasonable notice, subject to legal and contractual restrictions. Contact privacy@rockwellgroup.xyz. Withdrawing consent may mean we cannot continue to provide some or all of the Services, and we may still retain information where we have another legal basis or obligation to do so. You cannot withdraw consent with retroactive effect for processing already completed, for information we must retain by law, or for information necessary to complete a transaction already underway.
7Disclosure of information
We may disclose personal information:
- To service providers who support our business, as listed in Section 8, under contracts requiring them to protect the information and use it only for the purposes we specify.
- To subcontractors and associates we engage to help deliver an engagement, under written confidentiality obligations, with client notice where the engagement agreement requires it.
- To professional advisors — our lawyers, accountants, auditors, and insurers — who are bound by confidentiality obligations.
- To recipients you direct — for example, where you ask us to share a deliverable or correspond with your auditor, lender, counsel, or regulator on your behalf.
- As required or authorized by law — including in response to a court order, subpoena, warrant, regulatory demand, or lawful request from a government authority, and to cooperate with privacy commissioners. Where we are legally permitted to do so, we will notify the affected client before responding.
- To enforce our agreements — including for billing, collections, and the establishment, exercise, or defence of legal claims.
- To protect rights and safety — of Rockwell, our clients, our personnel, or the public, including to prevent or address fraud, security threats, or criminal activity.
- In a business transaction — in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar transaction. Information disclosed before a transaction closes is limited to what is necessary to evaluate it, is subject to a confidentiality agreement restricting its use to that purpose, and must be returned or destroyed if the transaction does not close. If a transaction closes, the acquiring party will be required to use the information only for the purposes for which it was collected and to provide notice where the law requires it.
- With your consent, or for a purpose disclosed to you at the time of collection.
We do not sell, rent, or trade personal information, and we do not disclose it to third parties for their own marketing purposes. We limit each disclosure to the minimum information reasonably necessary.
8Service providers
We use the following third-party service providers. Each is bound by contractual terms requiring appropriate safeguards, and each is engaged only for the purposes described.
| Service provider | Purpose | Information processed | Location / jurisdiction |
|---|---|---|---|
| Netlify, Inc. | Website hosting and content delivery | Request logs: IP address, user agent, requested URL, timestamps | United States (global CDN) |
| Convex, Inc. | Backend database for inquiries, intake conversations, and subscriptions | Inquiry details, conversation content, project summaries, email addresses, session identifiers, rate-limit records | United States |
| Resend, Inc. | Transactional and notification email delivery | Recipient names and email addresses, message content | United States |
| Anthropic, PBC | AI model powering the website intake assistant | Conversation content you submit to the assistant | United States |
| OpenAI, L.L.C. | AI model used for conversation titling and project summary generation | Conversation content you submit to the assistant | United States |
| Tavily | Web search tool available to the intake assistant | Search queries generated from your conversation (product and platform names, not your contact details) | United States |
| Google LLC (Workspace, Calendar appointment scheduling, Drive) | Business email, document creation and storage, meeting scheduling | Correspondence, engagement documents and deliverables, booking details | United States and global |
| Granola Labs, Inc. | AI note-taking and call transcription, where enabled for a call | Call audio, transcripts, summaries, participant names | United States |
| Accounting, invoicing, and payment providers | Billing, payment processing, bookkeeping, and tax filing | Billing contact details, invoices, payment and transaction records | Canada and United States |
Our AI providers process content submitted through their commercial APIs under terms that prohibit using it to train their general-purpose models.
We review this list as our providers change and will update it accordingly. Material changes are communicated in accordance with Section 18.
9Storage and cross-border processing
9.1 Storage locations
Most of the information we hold is stored with the providers listed in Section 8, whose infrastructure is located primarily in the United States. Engagement working papers and deliverables are stored in our Google Workspace environment and on encrypted company devices.
9.2 Notice regarding service providers outside Canada
Canadian privacy legislation — including section 13.1 of Alberta’s Personal Information Protection Act, and the equivalent transparency requirements under PIPEDA and BC PIPA — requires us to tell you the following:
- (a) We use service providers located outside Canada, as listed in Section 8, to collect, use, store, disclose, or otherwise process personal information on our behalf, for the purposes described in that table.
- (b) You may obtain information about our policies and practices with respect to the use of service providers outside Canada, including how those providers handle personal information, by contacting our Privacy Officer.
- (c) The person able to answer your questions about the collection, use, disclosure, or storage of personal information by service providers outside Canada is our Privacy Officer, reachable at privacy@rockwellgroup.xyz or at 2557345 Alberta Inc., 430-2339 Highway 97 North, Kelowna, BC V1X 4H9.
9.3 Foreign jurisdiction risk
While information is protected by contract and by the safeguards described in Section 11, personal information stored or processed outside Canada is subject to the laws of the jurisdiction where the service provider operates, and may be accessible to courts, law enforcement, national security authorities, and other government bodies of that jurisdiction under their laws. Those legal processes may not provide the same privacy protections, procedural safeguards, or judicial oversight as Canadian law. Physical storage location and legal jurisdiction are not the same thing: a United States company can be compelled under United States law even where the data itself sits on Canadian infrastructure.
We cannot prevent lawful foreign government access to information held by our service providers. We select providers with strong privacy and security practices, require contractual protections, minimize what we transmit, and will challenge inappropriate requests where we are able and legally permitted to do so.
If cross-border processing is not acceptable for a particular engagement, tell us before the engagement begins and we will discuss what alternative handling arrangements are workable.
10Data retention
We retain personal information only as long as necessary for the purposes for which it was collected, to meet legal, tax, professional, and regulatory obligations, and to establish, exercise, or defend legal claims.
| Category | Retention |
|---|---|
| Inquiry and intake assistant conversations that do not lead to an engagement | Up to 24 months from last activity, then deleted or anonymized |
| Insights subscriber information | Until you unsubscribe; we keep a minimal suppression record afterward so we do not re-add you |
| Engagement records, deliverables, and working papers | Seven years after the end of the engagement, consistent with professional practice, limitation periods, and tax requirements |
| Billing, accounting, and tax records | Seven years, as required for tax and accounting compliance |
| Call recordings, transcripts, and AI-generated notes | Twelve months, unless they form part of an engagement record, in which case they follow the engagement retention period |
| Technical and diagnostic logs | Up to 12 months, then deleted or anonymized |
| Correspondence | For the life of the business relationship and the applicable limitation period |
Legal holds and exceptions. We may retain information longer where it is subject to a legal hold, litigation, regulatory inquiry, or investigation; where retention is required or permitted by law; or where you have asked us to retain it.
Your own record-keeping obligations are yours. Retention by Rockwell is not a record-keeping service. If you are a reporting entity, you remain responsible for meeting your own retention obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and its regulations, and for maintaining your own copies of everything we produce for you.
Anonymized information. Information that has been aggregated or de-identified so that it cannot reasonably be used to identify an individual or organization is no longer personal information, and we may retain and use it — for example, to describe engagement patterns or publish market observations — without restriction.
11Safeguards
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including:
- Encryption in transit and at rest across the providers listed in Section 8.
- Multi-factor authentication on business accounts, and full-disk encryption on company devices.
- Access on a need-to-know basis, limited to personnel and subcontractors working on the relevant engagement.
- Written confidentiality obligations for all personnel and subcontractors, in addition to applicable professional obligations of confidentiality.
- Rate limiting and abuse prevention on public Website endpoints.
- Secure disposal of physical and electronic records at the end of the retention period.
- Review of service provider security and privacy practices before engagement.
Limitations. No system is completely secure and we cannot guarantee absolute security. Ordinary email is not a secure channel — if you need to send us sensitive materials, ask and we will arrange a secure transfer method. You are responsible for the security of your own systems, accounts, and devices.
12Your rights
Subject to applicable law, you have the following rights with respect to personal information we hold about you.
12.1 Access
You may request access to the personal information we hold about you, how it has been used, and to whom it has been disclosed. We will respond within 30 days of receiving a request that includes enough information to identify you and locate the records. If we need more time, we will notify you of the extension, the reason, and the new timeline. Most requests are free; where a request requires significant resources and the law permits a fee, we will provide an estimate in advance and proceed only with your agreement.
12.2 Exceptions to access
We may be unable to provide access where the information is subject to solicitor-client privilege; where providing it would reveal personal information about another individual or confidential commercial information of a client or third party; where it was generated in the course of a formal dispute resolution process or an investigation into a breach of an agreement or a contravention of law; where disclosure is prohibited by law or court order; or where the request is frivolous or vexatious. If we refuse a request in whole or in part, we will tell you why, to the extent we are permitted to, and how you may challenge that decision.
12.3 Correction
You may request correction of personal information that is inaccurate or incomplete. Where a record cannot be altered without compromising its integrity — for example, a dated working paper, a signed deliverable, or an audit log — we correct it by annotation rather than alteration. Where appropriate, we will pass the correction on to third parties who received the inaccurate information from us.
12.4 Withdrawal of consent and deletion
You may withdraw consent as described in Section 6, and you may ask us to delete personal information we hold about you. We will do so where we no longer need it for the purpose for which it was collected, where consent was the only basis for holding it and you have withdrawn it, or where deletion is required by law. We may be unable to delete information that is subject to a legal or regulatory retention requirement, a legal hold, a limitation period, or a professional record-keeping obligation, or that we need to enforce an agreement or defend a claim.
12.5 Identity verification
We verify identity before responding to a request, and may ask for additional information to do so. For requests made by an agent or representative, we require proof of authorization. Information collected for verification is used only for that purpose.
12.6 If a client gave us your information
If your personal information was provided to us by one of our clients — for example, because you are their customer, employee, or counterparty — that client controls the information and we hold it as their service provider. Direct access, correction, and deletion requests to them. You may also contact us at privacy@rockwellgroup.xyz; we will verify your request, coordinate with the client, and respond directly where the law requires us to.
13Marketing communications
We send insights emails only to people who have subscribed or who have given us express or implied consent under Canada’s Anti-Spam Legislation (“CASL”) — for example, existing and recent clients, and people who have inquired about our services.
Every marketing email includes an unsubscribe link and our contact information. You may also unsubscribe by emailing privacy@rockwellgroup.xyz. We process unsubscribe requests within 10 business days.
Unsubscribing does not affect transactional or engagement communications — invoices, scheduling, deliverables, service notices, and correspondence about work in progress — which we will continue to send as necessary.
14Children
Our Services are directed to businesses and the professionals who run them. We do not knowingly collect personal information from individuals under 18. If you believe a minor has provided us with personal information, contact privacy@rockwellgroup.xyz and we will delete it.
15Third-party websites
Our Website links to third-party websites, including those of affiliated ventures. Those sites have their own privacy policies and practices, and we are not responsible for them. Review their policies before providing personal information.
16Breach response and notification
If we become aware of a breach of security safeguards involving personal information in our custody or control, we will contain the incident, secure affected systems, and investigate to determine what information and which individuals are affected.
- Notification to you.Where a breach creates a real risk of significant harm, we will notify affected individuals and, where the information belongs to a client engagement, the client’s primary contact, without undue delay. Our notification will describe the incident, the information involved, what we are doing about it, and steps you can take to reduce risk.
- Notification to regulators. Where required, we will report the breach to the Office of the Privacy Commissioner of Canada under PIPEDA, and to the Information and Privacy Commissioner of Alberta without unreasonable delay under section 34.1 of Alberta PIPA, and to any other commissioner with jurisdiction.
- Records. We maintain records of every breach of security safeguards involving personal information for at least 24 months, as required by PIPEDA, and will provide them to the Commissioner on request.
- Delay. We may delay notification where a law enforcement agency or regulator requires it, or where notification would compromise an ongoing investigation. We will notify as soon as we are permitted to.
- Your obligations. If you are a client, you may have independent notification obligations to your own customers and to regulators, including under PIPEDA, provincial legislation, or the PCMLTFA. We will provide the information and assistance you reasonably need to meet them. If you discover a security incident affecting information you have shared with us, notify us immediately at privacy@rockwellgroup.xyzwith the subject line “SECURITY INCIDENT.”
17Complaints and challenging our compliance
Step 1 — Contact us. Direct any question, concern, or complaint about how we handle personal information to our Privacy Officer at privacy@rockwellgroup.xyz or at the mailing address below. We will acknowledge your complaint, investigate it, and respond in writing with our findings and any corrective action taken.
Step 2 — Escalate. If you are not satisfied with our response, you may contact:
- Office of the Privacy Commissioner of Canada — priv.gc.ca — 1-800-282-1376
- Office of the Information and Privacy Commissioner of Alberta — oipc.ab.ca — 780-422-6860
- Office of the Information and Privacy Commissioner for British Columbia — oipc.bc.ca — 250-387-5629
Step 3 — Legal remedies. You may pursue any remedy available to you at law.
18Changes to this policy
We may update this Privacy Policy from time to time. The current version is always posted at rockwellgroup.xyz/privacy with its version number and effective date. Changes are effective when posted. Where a change materially affects how we handle personal information in an active engagement, we will notify the affected client directly by email. Continued use of the Website or the Services after a change takes effect constitutes acceptance of the updated policy.
19Governing law
This Privacy Policy is governed by the laws of the Province of Alberta and the federal laws of Canada applicable in Alberta, without regard to conflict of laws principles. Nothing in this policy limits any right you have under applicable privacy legislation or the jurisdiction of any privacy commissioner.
20Contact
Privacy Officer, Rockwell Group
2557345 Alberta Inc.
430-2339 Highway 97 North
Kelowna, BC V1X 4H9
Canada
Rockwell Group Privacy Policy, Version 1.0 — effective August 20, 2026. Questions about an engagement?