advisoryaicontact
Legal

privacy policy

How we collect, use, disclose, and protect personal information in connection with our website and our consulting engagements.

Entity
2557345 Alberta Inc., operating as “Rockwell Group”
Effective
August 20, 2026 (Version 1.0)
Mailing address
430-2339 Highway 97 North
Kelowna, BC V1X 4H9, Canada

1About this policy

Rockwell Group (“Rockwell,” “we,” “our,” “us”) is a professional consulting firm. We provide fractional CFO and CCO advisory, financial and capital advisory, AML and regulatory compliance consulting, and AI and automation implementation services to businesses.

We are not a software vendor. We do not sell, license, or operate a product that stores your customers’ data on an ongoing basis. The information we handle comes from people who contact us, people who subscribe to our insights, and the materials our clients give us to do the work they hire us to do.

This Privacy Policy explains how we collect, use, disclose, safeguard, and retain personal information in connection with our website at rockwellgroup.xyz (the “Website”) and our consulting engagements (together, the “Services”).

Applicable law. We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act(Canada) (“PIPEDA”) and, where they apply to our activities, Alberta’s Personal Information Protection Act(“Alberta PIPA”) and British Columbia’s Personal Information Protection Act(“BC PIPA”). Where the requirements differ, we apply the standard that is most protective of the individual.

2Who this policy applies to

This policy applies to:

  • Visitors to our Website.
  • Prospective clients who contact us, submit an inquiry, or use the AI intake assistant on our Website.
  • Subscribers to our insights emails.
  • Client personnel — the directors, officers, employees, and contractors we deal with during an engagement.
  • Individuals whose personal information appears in materials a client provides to us during an engagement (see Section 3.4).
  • Suppliers, subcontractors, referral partners, and candidates.
  • Former clients and former contacts.

3Information we collect

3.1 Information you provide directly

  • Inquiry information: Name, email address, company name, company stage or size, and the content of the message you submit through our contact form.
  • Intake assistant conversations:If you use the AI intake assistant on our Website, we collect the messages you send, any name, email, and company you choose to provide, and a structured summary of the project you describe that is generated from the conversation. A randomly generated session identifier is stored in your browser’s local storage so your conversation persists across page loads.
  • Subscription information: Your email address and the page or topic you subscribed from.
  • Booking information:When you book a call through our scheduling link, the name, email address, and details you enter are collected through Google’s appointment scheduling.
  • Engagement information: Information exchanged in the course of an engagement, including names, titles, and contact details for your team; financial statements, forecasts, models, and accounting records; corporate, governance, and ownership documents; compliance policies, procedures, risk assessments, and training records; systems and process documentation; and any other business records you provide to us.
  • Billing information: Billing contact, business address, invoices, and payment records. We do not collect or store full payment card numbers.
  • Communications: Emails, messages, meeting notes, and correspondence between us.
  • Feedback: Responses to requests for feedback, references, or case-study participation.

3.2 Meetings, calls, and AI note-taking

We use AI note-taking tools to record, transcribe, and summarize calls and meetings, so that we have an accurate record of what was discussed and can produce internal notes and action items. This policy is your notice that calls and meetings with us may be recorded and transcribed. If you do not want a particular call recorded, tell us before or during the call and we will turn the tool off. Recordings, transcripts, and summaries are used only for the purposes described in Section 4, are accessible only to Rockwell personnel working on the matter, and are retained in accordance with Section 10.

3.3 Information collected automatically

Our Website is a statically generated site. We do not use advertising cookies, cross-site behavioural tracking, third-party analytics cookies, session recording, or heatmaps, and we do not sell or share personal information for advertising purposes.

  • Technical logs: Our hosting and backend providers generate standard technical logs — IP address, browser user agent, timestamp, requested URL, referrer, and error diagnostics — which we use for security, abuse prevention, rate limiting, and reliability.
  • Local storage:The intake assistant stores a randomly generated session identifier in your browser’s local storage. It is not an advertising identifier and is not shared with third parties for marketing. You can remove it by clearing site data in your browser; doing so will start a new conversation.
  • Rate-limiting records: We keep short-lived records tied to session identifiers to prevent abuse of the intake assistant and our forms.

If we add website analytics in the future, we will update this policy and the provider list in Section 8 before doing so.

3.4 Information we receive from clients about other people

During an engagement, we may receive personal information about individuals other than our direct contacts. Depending on the engagement, this can include:

  • Your employees’ roles, compensation, training records, and compliance attestations.
  • Your customers’ identification information and transaction records, where we test files as part of an AML effectiveness review, compliance program build, FINTRAC readiness assessment, or similar work.
  • Beneficial ownership, related-party, and corporate structure information.
  • Screening results, including politically exposed person (PEP) and sanctions determinations, and suspicious transaction analysis.
  • Third parties named in documents, contracts, board materials, or investigation files you provide to us.

We collect this information only as necessary to perform the engagement, and we handle it as described in Section 5.

3.5 Sensitive information

Some engagement materials are sensitive — government-issued identification, financial account and transaction data, screening and suspicious-activity records, and compensation information. We ask clients to provide only what the engagement actually requires, and to provide redacted, sampled, or de-identified material where that is sufficient for the work.

4How we use information

We use personal information to:

Respond and scope: respond to inquiries and requests for information; understand a prospective engagement, assess fit, and identify conflicts; and prepare proposals, scopes of work, and engagement letters.

Deliver the Services: perform the advisory, compliance, financial, and implementation work you engage us to do; communicate with you and your team about the engagement; prepare deliverables, reports, models, policies, and recommendations; and maintain professional working papers and engagement records supporting our work.

Operate our business: issue invoices, process payments, and collect amounts owing; maintain accounting, tax, insurance, and corporate records; manage subcontractors and referral relationships; conduct quality assurance and improve how we deliver services; and evaluate, negotiate, and complete business transactions.

Protect and comply: secure our Website and systems, prevent fraud and abuse, and investigate incidents; comply with legal, regulatory, professional, and record-keeping obligations; and establish, exercise, or defend legal claims.

Communicate: send insights emails, updates, and event invitations where you have consented (see Section 13), and send transactional and engagement communications, which are not marketing and continue regardless of marketing preferences.

We do not sell, rent, or trade personal information. We do not use client engagement materials to train AI models, and the AI providers we use process content under commercial terms that do not permit training their general-purpose models on it.

We will not use personal information for a materially different purpose without your consent or as otherwise permitted or required by law.

5Client information and our role

Where you engage us and provide personal information about your customers, employees, or other individuals, you remain the organization accountable for that information under privacy law. We act as your service provider and handle it only to perform the engagement.

Your responsibilities as our client

  • Ensure you have lawful authority and any necessary consents to disclose the information to us.
  • Provide only the information the engagement requires, redacted or sampled where sufficient.
  • Tell us in advance of any restrictions, legal holds, or handling requirements that apply.
  • Give your own customers and personnel any privacy notices required by law, including with respect to service providers and cross-border processing.
  • Respond to privacy requests you receive from those individuals.

Our commitments

  • We use client information only to perform the engagement, and not for any secondary purpose.
  • Access is limited to Rockwell personnel and subcontractors who need it, all of whom are bound by confidentiality obligations and, where applicable, professional standards of confidentiality.
  • We do not disclose client information except as described in Section 7.
  • On request at the end of an engagement, we will return or securely dispose of client materials, subject to the working papers and records we are required or reasonably need to retain under Section 10.

7Disclosure of information

We may disclose personal information:

  • To service providers who support our business, as listed in Section 8, under contracts requiring them to protect the information and use it only for the purposes we specify.
  • To subcontractors and associates we engage to help deliver an engagement, under written confidentiality obligations, with client notice where the engagement agreement requires it.
  • To professional advisors — our lawyers, accountants, auditors, and insurers — who are bound by confidentiality obligations.
  • To recipients you direct — for example, where you ask us to share a deliverable or correspond with your auditor, lender, counsel, or regulator on your behalf.
  • As required or authorized by law — including in response to a court order, subpoena, warrant, regulatory demand, or lawful request from a government authority, and to cooperate with privacy commissioners. Where we are legally permitted to do so, we will notify the affected client before responding.
  • To enforce our agreements — including for billing, collections, and the establishment, exercise, or defence of legal claims.
  • To protect rights and safety — of Rockwell, our clients, our personnel, or the public, including to prevent or address fraud, security threats, or criminal activity.
  • In a business transaction — in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar transaction. Information disclosed before a transaction closes is limited to what is necessary to evaluate it, is subject to a confidentiality agreement restricting its use to that purpose, and must be returned or destroyed if the transaction does not close. If a transaction closes, the acquiring party will be required to use the information only for the purposes for which it was collected and to provide notice where the law requires it.
  • With your consent, or for a purpose disclosed to you at the time of collection.

We do not sell, rent, or trade personal information, and we do not disclose it to third parties for their own marketing purposes. We limit each disclosure to the minimum information reasonably necessary.

8Service providers

We use the following third-party service providers. Each is bound by contractual terms requiring appropriate safeguards, and each is engaged only for the purposes described.

Service providerPurposeInformation processedLocation / jurisdiction
Netlify, Inc.Website hosting and content deliveryRequest logs: IP address, user agent, requested URL, timestampsUnited States (global CDN)
Convex, Inc.Backend database for inquiries, intake conversations, and subscriptionsInquiry details, conversation content, project summaries, email addresses, session identifiers, rate-limit recordsUnited States
Resend, Inc.Transactional and notification email deliveryRecipient names and email addresses, message contentUnited States
Anthropic, PBCAI model powering the website intake assistantConversation content you submit to the assistantUnited States
OpenAI, L.L.C.AI model used for conversation titling and project summary generationConversation content you submit to the assistantUnited States
TavilyWeb search tool available to the intake assistantSearch queries generated from your conversation (product and platform names, not your contact details)United States
Google LLC (Workspace, Calendar appointment scheduling, Drive)Business email, document creation and storage, meeting schedulingCorrespondence, engagement documents and deliverables, booking detailsUnited States and global
Granola Labs, Inc.AI note-taking and call transcription, where enabled for a callCall audio, transcripts, summaries, participant namesUnited States
Accounting, invoicing, and payment providersBilling, payment processing, bookkeeping, and tax filingBilling contact details, invoices, payment and transaction recordsCanada and United States

Our AI providers process content submitted through their commercial APIs under terms that prohibit using it to train their general-purpose models.

We review this list as our providers change and will update it accordingly. Material changes are communicated in accordance with Section 18.

9Storage and cross-border processing

9.1 Storage locations

Most of the information we hold is stored with the providers listed in Section 8, whose infrastructure is located primarily in the United States. Engagement working papers and deliverables are stored in our Google Workspace environment and on encrypted company devices.

9.2 Notice regarding service providers outside Canada

Canadian privacy legislation — including section 13.1 of Alberta’s Personal Information Protection Act, and the equivalent transparency requirements under PIPEDA and BC PIPA — requires us to tell you the following:

  • (a) We use service providers located outside Canada, as listed in Section 8, to collect, use, store, disclose, or otherwise process personal information on our behalf, for the purposes described in that table.
  • (b) You may obtain information about our policies and practices with respect to the use of service providers outside Canada, including how those providers handle personal information, by contacting our Privacy Officer.
  • (c) The person able to answer your questions about the collection, use, disclosure, or storage of personal information by service providers outside Canada is our Privacy Officer, reachable at privacy@rockwellgroup.xyz or at 2557345 Alberta Inc., 430-2339 Highway 97 North, Kelowna, BC V1X 4H9.

9.3 Foreign jurisdiction risk

While information is protected by contract and by the safeguards described in Section 11, personal information stored or processed outside Canada is subject to the laws of the jurisdiction where the service provider operates, and may be accessible to courts, law enforcement, national security authorities, and other government bodies of that jurisdiction under their laws. Those legal processes may not provide the same privacy protections, procedural safeguards, or judicial oversight as Canadian law. Physical storage location and legal jurisdiction are not the same thing: a United States company can be compelled under United States law even where the data itself sits on Canadian infrastructure.

We cannot prevent lawful foreign government access to information held by our service providers. We select providers with strong privacy and security practices, require contractual protections, minimize what we transmit, and will challenge inappropriate requests where we are able and legally permitted to do so.

If cross-border processing is not acceptable for a particular engagement, tell us before the engagement begins and we will discuss what alternative handling arrangements are workable.

10Data retention

We retain personal information only as long as necessary for the purposes for which it was collected, to meet legal, tax, professional, and regulatory obligations, and to establish, exercise, or defend legal claims.

CategoryRetention
Inquiry and intake assistant conversations that do not lead to an engagementUp to 24 months from last activity, then deleted or anonymized
Insights subscriber informationUntil you unsubscribe; we keep a minimal suppression record afterward so we do not re-add you
Engagement records, deliverables, and working papersSeven years after the end of the engagement, consistent with professional practice, limitation periods, and tax requirements
Billing, accounting, and tax recordsSeven years, as required for tax and accounting compliance
Call recordings, transcripts, and AI-generated notesTwelve months, unless they form part of an engagement record, in which case they follow the engagement retention period
Technical and diagnostic logsUp to 12 months, then deleted or anonymized
CorrespondenceFor the life of the business relationship and the applicable limitation period

Legal holds and exceptions. We may retain information longer where it is subject to a legal hold, litigation, regulatory inquiry, or investigation; where retention is required or permitted by law; or where you have asked us to retain it.

Your own record-keeping obligations are yours. Retention by Rockwell is not a record-keeping service. If you are a reporting entity, you remain responsible for meeting your own retention obligations under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act and its regulations, and for maintaining your own copies of everything we produce for you.

Anonymized information. Information that has been aggregated or de-identified so that it cannot reasonably be used to identify an individual or organization is no longer personal information, and we may retain and use it — for example, to describe engagement patterns or publish market observations — without restriction.

11Safeguards

We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including:

  • Encryption in transit and at rest across the providers listed in Section 8.
  • Multi-factor authentication on business accounts, and full-disk encryption on company devices.
  • Access on a need-to-know basis, limited to personnel and subcontractors working on the relevant engagement.
  • Written confidentiality obligations for all personnel and subcontractors, in addition to applicable professional obligations of confidentiality.
  • Rate limiting and abuse prevention on public Website endpoints.
  • Secure disposal of physical and electronic records at the end of the retention period.
  • Review of service provider security and privacy practices before engagement.

Limitations. No system is completely secure and we cannot guarantee absolute security. Ordinary email is not a secure channel — if you need to send us sensitive materials, ask and we will arrange a secure transfer method. You are responsible for the security of your own systems, accounts, and devices.

12Your rights

Subject to applicable law, you have the following rights with respect to personal information we hold about you.

12.1 Access

You may request access to the personal information we hold about you, how it has been used, and to whom it has been disclosed. We will respond within 30 days of receiving a request that includes enough information to identify you and locate the records. If we need more time, we will notify you of the extension, the reason, and the new timeline. Most requests are free; where a request requires significant resources and the law permits a fee, we will provide an estimate in advance and proceed only with your agreement.

12.2 Exceptions to access

We may be unable to provide access where the information is subject to solicitor-client privilege; where providing it would reveal personal information about another individual or confidential commercial information of a client or third party; where it was generated in the course of a formal dispute resolution process or an investigation into a breach of an agreement or a contravention of law; where disclosure is prohibited by law or court order; or where the request is frivolous or vexatious. If we refuse a request in whole or in part, we will tell you why, to the extent we are permitted to, and how you may challenge that decision.

12.3 Correction

You may request correction of personal information that is inaccurate or incomplete. Where a record cannot be altered without compromising its integrity — for example, a dated working paper, a signed deliverable, or an audit log — we correct it by annotation rather than alteration. Where appropriate, we will pass the correction on to third parties who received the inaccurate information from us.

12.4 Withdrawal of consent and deletion

You may withdraw consent as described in Section 6, and you may ask us to delete personal information we hold about you. We will do so where we no longer need it for the purpose for which it was collected, where consent was the only basis for holding it and you have withdrawn it, or where deletion is required by law. We may be unable to delete information that is subject to a legal or regulatory retention requirement, a legal hold, a limitation period, or a professional record-keeping obligation, or that we need to enforce an agreement or defend a claim.

12.5 Identity verification

We verify identity before responding to a request, and may ask for additional information to do so. For requests made by an agent or representative, we require proof of authorization. Information collected for verification is used only for that purpose.

12.6 If a client gave us your information

If your personal information was provided to us by one of our clients — for example, because you are their customer, employee, or counterparty — that client controls the information and we hold it as their service provider. Direct access, correction, and deletion requests to them. You may also contact us at privacy@rockwellgroup.xyz; we will verify your request, coordinate with the client, and respond directly where the law requires us to.

13Marketing communications

We send insights emails only to people who have subscribed or who have given us express or implied consent under Canada’s Anti-Spam Legislation (“CASL”) — for example, existing and recent clients, and people who have inquired about our services.

Every marketing email includes an unsubscribe link and our contact information. You may also unsubscribe by emailing privacy@rockwellgroup.xyz. We process unsubscribe requests within 10 business days.

Unsubscribing does not affect transactional or engagement communications — invoices, scheduling, deliverables, service notices, and correspondence about work in progress — which we will continue to send as necessary.

14Children

Our Services are directed to businesses and the professionals who run them. We do not knowingly collect personal information from individuals under 18. If you believe a minor has provided us with personal information, contact privacy@rockwellgroup.xyz and we will delete it.

15Third-party websites

Our Website links to third-party websites, including those of affiliated ventures. Those sites have their own privacy policies and practices, and we are not responsible for them. Review their policies before providing personal information.

16Breach response and notification

If we become aware of a breach of security safeguards involving personal information in our custody or control, we will contain the incident, secure affected systems, and investigate to determine what information and which individuals are affected.

  • Notification to you.Where a breach creates a real risk of significant harm, we will notify affected individuals and, where the information belongs to a client engagement, the client’s primary contact, without undue delay. Our notification will describe the incident, the information involved, what we are doing about it, and steps you can take to reduce risk.
  • Notification to regulators. Where required, we will report the breach to the Office of the Privacy Commissioner of Canada under PIPEDA, and to the Information and Privacy Commissioner of Alberta without unreasonable delay under section 34.1 of Alberta PIPA, and to any other commissioner with jurisdiction.
  • Records. We maintain records of every breach of security safeguards involving personal information for at least 24 months, as required by PIPEDA, and will provide them to the Commissioner on request.
  • Delay. We may delay notification where a law enforcement agency or regulator requires it, or where notification would compromise an ongoing investigation. We will notify as soon as we are permitted to.
  • Your obligations. If you are a client, you may have independent notification obligations to your own customers and to regulators, including under PIPEDA, provincial legislation, or the PCMLTFA. We will provide the information and assistance you reasonably need to meet them. If you discover a security incident affecting information you have shared with us, notify us immediately at privacy@rockwellgroup.xyzwith the subject line “SECURITY INCIDENT.”

17Complaints and challenging our compliance

Step 1 — Contact us. Direct any question, concern, or complaint about how we handle personal information to our Privacy Officer at privacy@rockwellgroup.xyz or at the mailing address below. We will acknowledge your complaint, investigate it, and respond in writing with our findings and any corrective action taken.

Step 2 — Escalate. If you are not satisfied with our response, you may contact:

  • Office of the Privacy Commissioner of Canada priv.gc.ca 1-800-282-1376
  • Office of the Information and Privacy Commissioner of Alberta oipc.ab.ca 780-422-6860
  • Office of the Information and Privacy Commissioner for British Columbia oipc.bc.ca 250-387-5629

Step 3 — Legal remedies. You may pursue any remedy available to you at law.

18Changes to this policy

We may update this Privacy Policy from time to time. The current version is always posted at rockwellgroup.xyz/privacy with its version number and effective date. Changes are effective when posted. Where a change materially affects how we handle personal information in an active engagement, we will notify the affected client directly by email. Continued use of the Website or the Services after a change takes effect constitutes acceptance of the updated policy.

19Governing law

This Privacy Policy is governed by the laws of the Province of Alberta and the federal laws of Canada applicable in Alberta, without regard to conflict of laws principles. Nothing in this policy limits any right you have under applicable privacy legislation or the jurisdiction of any privacy commissioner.

20Contact

Privacy Officer, Rockwell Group

privacy@rockwellgroup.xyz

2557345 Alberta Inc.
430-2339 Highway 97 North
Kelowna, BC V1X 4H9
Canada


Rockwell Group Privacy Policy, Version 1.0 — effective August 20, 2026. Questions about an engagement?