Privacy & Data Governance Policy
At Eidon Practice System Inc. ("Eidon"), I treat client operational and financial data with the same rigor a bank applies to a credit file. Because I handle sensitive financial metrics, tax filings, internal balance sheets, and ownership details, maintaining absolute confidentiality and statutory compliance under Alberta's Personal Information Protection Act (PIPA) is non-negotiable.
1. Collection & Purpose Limitation
What I Collect
I collect financial statements, debt schedules, corporate ownership details, tax returns, operating reports, and personal contact details required for Capital Readiness Assessments and System.
Purpose
Data is collected solely to diagnose capital gaps, build bank-ready financial architecture, normalize financials for commercial lender underwriting, and conduct strategic quarterly oversight. I do not collect data beyond what is strictly necessary to execute these services.
2. Mandatory Cross-Border & Foreign Storage Disclosure
Notice of Foreign Processing
In compliance with Alberta PIPA, notice is hereby given that Eidon utilizes secure, industry-standard cloud-based software platforms to store, analyze, and manage engagement data.
Jurisdiction Risk
These service providers operate cloud infrastructure and servers hosted outside of Canada, primarily in the United States. Consequently, your data may be accessible to foreign courts, law enforcement, and national security authorities under the laws of those foreign jurisdictions.
Consent
Engagement terms and Tier 1 Intake forms explicitly outline and require client consent for this necessary operational cross-border data routing prior to data collection.
Data Security & AI Privacy
Client data is strictly encrypted and protected by industry-standard security protocols. Furthermore, I ensure that engagement data is not utilized for the training of external AI models or algorithms.
3. Data Retention & Destruction Schedule
PIPA mandates that personal information be retained only as long as necessary to fulfill the business or legal purpose for which it was collected, while ensuring records used to make decisions about an individual are retained for at least one year.
| Record Type | Retention Period | Justification / Statutory Rule |
|---|---|---|
| Active Engagement Audits & Intake Data (Tier 1) | Duration of active project + 1 year | Ensures clients can access records used during the assessment/system build under PIPA. |
| Strategic Oversight Financials (Tiers 2 & 3) | Duration of active retainer + 1 year | Maintained to track quarterly trajectory and story consistency. |
| Financial Transaction & Billing Records (All Tiers) | 6 years from end of relevant tax year | Mandated by the Canada Revenue Agency (CRA) under the Income Tax Act and corporate recordkeeping standards. |
| Raw AI Queries & Working Files (All Tiers) | Deleted upon final deliverable handoff | Anonymized during analysis; unredacted working notes purged after the Capital Readiness Brief is issued. |
Destruction Standard
When the retention period expires or an engagement concludes without ongoing retention requirements, all digital files hosted in Google Workspace and QuickBooks are permanently deleted. Cloud trash bins are manually purged, and platform permissions granted to Eidon by the client are formally revoked and audited.
4. Client Rights & Privacy Contact
Clients have the right to request access to or correction of their personal data held by Eidon, or to withdraw consent (subject to legal and contractual limitations).
- Privacy Officer: Heidi Schurman, Founder & Capital Readiness Strategist
- Contact: Written requests can be submitted directly via official Eidon communication channels. Response times will strictly adhere to PIPA's statutory 45-day window.