Privacy Policy

Effective Date: June 14, 2026 · Approved by Jason Pereira, Privacy Officer

This Privacy Policy explains how Woodgate Financial Inc. ("Woodgate", "we", "us", or "our") collects, uses, discloses, retains, and protects personal information — both in the delivery of our advisory services and through this website, BusinessOwnerFP.ca — in accordance with PIPEDA, Quebec's Law 25, and all other applicable privacy legislation.

1. Introduction and Purpose

Woodgate Financial Inc. ("Woodgate," "we," "our," or "us") is a financial planning firm serving clients across Canada, including Quebec. Investment services are offered through IPC Securities Corporation, a member of the Canadian Investment Regulatory Organization (CIRO) and the Canadian Investor Protection Fund (CIPF). Jason Pereira is approved by CIRO as a Portfolio Manager and provides discretionary portfolio management through IPC Securities Corporation. Our advisors hold Certified Financial Planner (CFP) and Qualified Associate Financial Planner (QAFP) designations.

We are committed to protecting the privacy and confidentiality of the personal information entrusted to us by our clients, prospective clients, and other individuals. This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector (Law 25), and all other applicable provincial and federal privacy legislation.

This policy is structured around the ten Fair Information Principles set out in Schedule 1 of PIPEDA, which form the backbone of our privacy practices.

Privacy Officer: Jason Pereira, jason.pereira@woodgate.com

2. Definitions

Personal Information: Information about an identifiable individual, including but not limited to name, address, date of birth, Social Insurance Number, financial account information, investment holdings, income, employment details, health information relevant to financial planning, and any other information that identifies or could reasonably be used to identify an individual.

Business Information: Information that relates to an organization in its business capacity and does not identify an individual, including corporate financial statements, business registration information, and publicly available company data. Business information is not subject to this policy.

3. Principle 1 — Accountability

Woodgate Financial Inc. is responsible for all personal information in its possession or control, including information transferred to third parties for processing.

4. Principle 2 — Identifying Purposes

We collect and use personal information for the following purposes:

5. Principle 3 — Consent

Woodgate obtains meaningful consent for the collection, use, and disclosure of personal information in compliance with the Office of the Privacy Commissioner (OPC) Guidelines for Obtaining Meaningful Consent.

5.1 Implied Consent

By entering into an advisory relationship with Woodgate, you provide implied consent for the collection, use, and disclosure of your personal information for all purposes reasonably necessary to deliver the advisory services described in your client agreement. This includes:

Implied consent is appropriate for these uses because they fall within the reasonable expectations of a client engaging a financial advisory firm and are necessary for the performance of our services.

5.2 Express Consent

Woodgate will seek express opt-in consent before using your personal information for any purpose beyond the direct delivery of advisory services. If we identify future uses of personal information that go beyond serving you as a client — such as any commercial use unrelated to your advisory relationship — we will notify you and seek your express consent before proceeding.

5.3 Mandatory vs. Optional Processing

Certain processing activities are mandatory for the delivery of advisory services and regulatory compliance. You may not opt out of these activities while maintaining an active advisory relationship. Any future optional processing activities will be clearly distinguished and subject to separate express consent.

5.4 Withdrawal of Consent

You may withdraw consent for non-mandatory processing at any time by contacting the Privacy Officer. Please note that withdrawal of consent for mandatory processing may require termination of the advisory relationship. We will explain the consequences of withdrawal upon request. Withdrawal of consent does not affect the lawfulness of any processing conducted prior to such withdrawal.

6. Principle 4 — Limiting Collection

We collect only the personal information necessary for the purposes identified in this policy. Information is collected by fair and lawful means, directly from the client where possible, and from third parties only where authorized by the client or permitted by law.

Woodgate does not knowingly collect personal information from individuals under the age of 18. Our advisory services are not directed to minors. If we become aware that personal information has been collected from an individual under the age of 18 without appropriate legal authorization, we will take steps to delete that information. If you have reason to believe that a minor under the age of 18 has provided personal information to us, please contact the Privacy Officer to request deletion.

7. Principle 5 — Limiting Use, Disclosure, and Retention

Personal information will not be used or disclosed for purposes other than those for which it was collected, except with the consent of the individual or as required or permitted by law.

7.1 Retention Periods

Client records are retained for the legally mandated minimum periods, including:

7.2 Secure Destruction

Upon expiry of the applicable retention period, personal information is destroyed using methods appropriate to the sensitivity of the information, including cryptographic wiping for electronic records and secure shredding for physical records.

8. Principle 6 — Accuracy

We take reasonable steps to ensure that personal information is accurate, complete, and up to date for the purposes for which it is used. Clients are encouraged to notify us of any changes to their personal information. We update client records as part of our regular KYC review process.

9. Principle 7 — Safeguards

Woodgate protects personal information with security safeguards appropriate to the sensitivity of the information.

9.1 Cybersecurity Controls

We are committed to maintaining robust cybersecurity protections, including:

While Woodgate is committed to maintaining robust security safeguards, you acknowledge that no method of transmission over the Internet or method of electronic storage is completely secure. Woodgate cannot guarantee the absolute security of personal information transmitted to or stored by us, despite our best efforts. You are responsible for safeguarding your login credentials, using strong passwords, and notifying us immediately if you become aware of any unauthorized access to or use of your account.

9.2 Data Residency

Woodgate is committed to Canadian data residency for client personal information where operationally feasible. All internally developed systems and tools are hosted on servers located within Canada. Where third-party service providers store or process data on servers located outside Canada, we ensure contractual safeguards are in place and conduct Privacy Impact Assessments prior to any cross-border transfer (see Section 12).

9.3 AI and Technology Use in Service Delivery

Woodgate uses modern technology, including artificial intelligence and machine learning tools, to enhance the quality and efficiency of our advisory services. We are committed to transparency about these practices.

9.3.1 Permitted Uses of Personal Information in Technology Systems

Personal information may flow through AI and technology systems for the following service delivery purposes:

All software development activities use client data for service delivery as the primary purpose. Any secondary commercial application is subordinate to and dependent upon the service delivery function.

9.3.2 Prohibition on AI Training with Raw Personal Information

Woodgate explicitly prohibits the use of raw, identifiable personal information to train any artificial intelligence or machine learning model, whether internal or operated by a third party. This prohibition applies without exception.

9.3.3 Vendor Safeguards for Technology Systems

All third-party technology vendors processing personal information are required to maintain:

9.3.4 De-identification Requirements

Before personal information enters any development pipeline that is separate from direct client service delivery, it must undergo irreversible de-identification. De-identified data is not subject to the consent requirements of this policy, as it no longer constitutes personal information.

9.3.5 Automated Decision-Making

Woodgate does not make material decisions affecting clients based exclusively on automated processing of personal information. AI tools used by Woodgate assist advisors in analysis and planning but do not make material decisions on behalf of clients without human involvement. All material recommendations and decisions are made by qualified human professionals holding appropriate designations (CFP, QAFP) and registered with the applicable securities regulator. Clients may request human review of any technology-assisted recommendation at any time by contacting the Privacy Officer.

10. Protection of Vulnerable Clients

Woodgate is committed to protecting clients who may be vulnerable due to age, diminished capacity, or susceptibility to financial exploitation, in accordance with the Canadian Securities Administrators (CSA) Client Focused Reforms and CSA Staff Notice 31-354.

10.1 Trusted Contact Person (TCP)

We collect the name and contact information of a Trusted Contact Person designated by the client. This information is collected solely to protect the primary client in situations involving suspected financial exploitation or diminished mental capacity.

Woodgate will only contact the TCP under narrow, defined circumstances:

TCP information will not be used for any other purpose or shared with any third party except as required by law or securities regulation.

10.2 Temporary Holds and Internal Disclosure

Where financial exploitation is suspected, Woodgate may place a temporary hold on account transactions and share relevant personal information internally among compliance, legal, and advisory personnel on a need-to-know basis. These actions are taken under the emergency provisions of PIPEDA, which permit disclosure without consent where necessary to protect the individual from significant harm.

A written record of the basis for any temporary hold and associated internal disclosures is maintained for regulatory audit purposes.

11. Third-Party Service Providers

Woodgate does not sell, rent, or trade personal information to any third party.

Where personal information is transferred to third-party service providers for processing (including custodians, technology vendors, and professional advisors), we require:

Vendor compliance with the privacy safeguards described in this policy is verified through contractual provisions reviewed at onboarding and renewal, and through periodic review of vendor documentation, including SOC 2 reports, privacy attestations, or equivalent assurance mechanisms.

In the event of a merger, acquisition, reorganization, sale of assets, or similar business transaction involving Woodgate, personal information may be transferred to a successor entity as part of that transaction. Any successor entity will be bound to handle your personal information in accordance with this Privacy Policy and applicable privacy legislation. Where required by applicable law, we will notify you of any such transfer.

12. Cross-Border Transfers and Law 25 Compliance

Woodgate serves clients across Canada, including in Quebec, and complies with Law 25 (Act respecting the protection of personal information in the private sector) as a national baseline for privacy protections.

12.1 Privacy Impact Assessments

Woodgate conducts a Privacy Impact Assessment (PIA) prior to any project involving the development, acquisition, or redesign of an information system or electronic service delivery that involves personal information, as well as prior to any cross-border transfer of personal information outside of Canada. This includes AI-powered systems used in service delivery, such as document extraction, questionnaire scoring, and financial analysis tools. PIAs are conducted in accordance with guidance published by the Office of the Privacy Commissioner of Canada and the Commission d'accès à l'information du Québec.

12.2 Data Portability

Clients have the right to receive their personal information in a structured, commonly used, and machine-readable format upon request. Requests should be directed to the Privacy Officer. A reasonable fee may be charged for the retrieval, reproduction, and transmission of personal information, as permitted by applicable law.

12.3 Privacy by Design

Woodgate applies the principle of Privacy by Design to all new systems, processes, and services. Personal information is afforded the highest level of confidentiality by default. Privacy protections are embedded into the design of technology systems and business processes from the outset, not applied as an afterthought.

13. Data Breach and Incident Response

Woodgate maintains a formal incident response procedure for addressing breaches of personal information security.

13.1 Federal Notification (PIPEDA)

Where a breach of security safeguards creates a real risk of significant harm (RROSH) to any individual, Woodgate will take the actions described below.

In assessing whether a breach creates a real risk of significant harm, Woodgate considers the following factors as required by PIPEDA Section 10.1(8):

Where RROSH is determined to exist, Woodgate will:

13.2 Provincial Notification (Law 25 — Quebec)

For incidents involving the personal information of Quebec residents, Woodgate will notify the Commission d'accès à l'information du Québec (CAI) promptly, targeting notification within seventy-two (72) hours of becoming aware of a confidentiality incident presenting a risk of serious injury.

13.3 General Commitments

13.4 Breach Record-Keeping

Woodgate maintains a record of all breaches of security safeguards involving personal information, regardless of whether the breach meets the threshold for notification under PIPEDA or Law 25. These records are retained for a minimum of twenty-four (24) months and are available to the Office of the Privacy Commissioner upon request, in accordance with SOR/2018-64. The procedures for maintaining these records are set out in Woodgate's companion Incident Response Procedure.

14. Principle 8 — Openness

Woodgate makes information about its privacy policies and practices readily available. This policy is provided to all new clients as part of the onboarding process and is available upon request at any time. The current version of this policy is also available on our website. Material changes to this policy will be communicated to clients in writing.

15. Principle 9 — Individual Access

Upon written request to the Privacy Officer, you have the right to:

Woodgate will respond to access requests within thirty (30) days, or such shorter period as may be required by applicable law. In exceptional cases, we may extend this period by an additional thirty (30) days with written notice and explanation of the reasons for the extension. Woodgate may deny or limit an access, correction, or deletion request where permitted or required by applicable law, including where:

16. Principle 10 — Challenging Compliance

You have the right to challenge Woodgate's compliance with this policy by contacting the Privacy Officer:

Jason Pereira, Privacy Officer
Email: jason.pereira@woodgate.com

All complaints will be investigated and responded to in writing. If you are not satisfied with our response, you have the right to file a complaint with:

17. Policy Review and Amendment

This policy is reviewed at least annually by the Privacy Officer to ensure continued compliance with applicable legislation and alignment with Woodgate's business practices. Amendments may be made at any time. Material amendments will be communicated to clients in writing prior to taking effect. Your continued use of Woodgate's services following any such communication constitutes your acknowledgment and acceptance of the amended policy.

Last reviewed: June 14, 2026
Next scheduled review: No later than May 2027

Website Data Collection — BusinessOwnerFP.ca

The sections below describe data collected specifically through this website (BusinessOwnerFP.ca), operated by Woodgate Financial Inc.

Who We Are

This website is operated by Woodgate Financial Inc., located at 5015 Spectrum Way, Suite 300, Mississauga, Ontario L4W 0E4, Canada.

Contact us at info@woodgate.com or +1 (416) 691-1944.

Information We Collect

We collect the following types of information:

Email Addresses: When you subscribe to our newsletter or use the subscribe form on this website, we collect your first name, last name, and email address.

We use PostHog to collect usage data including page views, clicks, and session recordings. This helps us understand how visitors interact with our content and improve the website experience. PostHog is not loaded until you accept analytics cookies through the consent banner, and you can withdraw that consent at any time using the Cookie preferences link in the site footer.

How We Use Your Information

Newsletter Delivery: Your name and email address are used to deliver newsletter content and updates about financial planning topics relevant to Canadian business owners, and to address you by name in that correspondence.

Website Improvement: Analytics data is used to improve the website experience, understand content effectiveness, and make informed decisions about future content.

Third-Party Services

Webflow. This website is built and hosted on Webflow. Newsletter and subscribe form submissions are stored in Webflow's form submission system, which is hosted in the United States, before being exported to our mailing list. Woodgate's cross-border transfer safeguards are described in Section 12.

Zapier and AdvisorStream (Newsletter Signup). Newsletter and subscribe form submissions are passed from Webflow to our email platform, AdvisorStream, through Zapier. They process the name and email address you submit. Zapier is hosted in the United States. Woodgate's cross-border transfer safeguards are described in Section 12.

Vidvisor (Video Playback). Every page of this site loads a video player script from Vidvisor. Loading the script transmits your IP address and the page you are viewing to Vidvisor. Woodgate Venture Holdings Inc., of which Jason Pereira is President, holds an investment in Vidvisor.

YouTube (Video Thumbnails and Embeds). Video thumbnail images on this site are loaded from YouTube, which transmits your IP address to Google in the United States when the page loads. Videos themselves are embedded through youtube-nocookie.com and only load when you click to play them.

PostHog (Analytics): We use PostHog for website analytics, including page views, click tracking, and session recordings. PostHog data is hosted in the United States. For more information, visit PostHog's privacy policy.

Acast (Podcast Hosting): Our podcast episodes are hosted through Acast. When you listen to episodes embedded on our site or through podcast platforms, Acast may collect listening data. For more information, visit Acast's privacy policy.

Cookies

PostHog uses cookies for session identification and analytics purposes. You can manage your cookie preferences through the cookie consent banner displayed on our website. You may also configure your browser to reject cookies, though this may affect certain website functionality.

Data Retention

Email Addresses: Your name and email address are retained for as long as you remain subscribed. When you unsubscribe, your subscription record is removed from our mailing list and the corresponding form submission is deleted from Webflow within 30 days.

Analytics Data: Website analytics data is retained per PostHog's standard data retention policies.

How to Opt Out

Email Communications: Click the unsubscribe link included at the bottom of any email you receive from us.

Cookies and Analytics: Use the cookie consent banner on our website to manage your tracking preferences.

Direct Contact: Email us at jason.pereira@woodgate.com to request access to, correction of, or deletion of your personal information.

Contact Us

If you have any questions about this privacy policy or our data practices, please contact us:

Woodgate Financial Inc.
5015 Spectrum Way, Suite 300
Mississauga, Ontario L4W 0E4
Email: info@woodgate.com
Phone: +1 (416) 691-1944