📞 780-905-3766 ✉️ heidi@eidon.ca
Eidon Policies

Privacy & Data Governance Policy

Effective Date: August 2026

Jurisdiction: Alberta, Canada (Personal Information Protection Act — PIPA)

At Eidon Practice System Inc. ("Eidon"), I treat client operational and financial data with the same rigor a bank applies to a credit file. Because I handle sensitive financial metrics, tax filings, internal balance sheets, and ownership details, maintaining absolute confidentiality and statutory compliance under Alberta's Personal Information Protection Act (PIPA) is non-negotiable.

1. Collection & Purpose Limitation

What I Collect

I collect financial statements, debt schedules, corporate ownership details, tax returns, operating reports, and personal contact details required for Capital Readiness Assessments and System.

Purpose

Data is collected solely to diagnose capital gaps, build bank-ready financial architecture, normalize financials for commercial lender underwriting, and conduct strategic quarterly oversight. I do not collect data beyond what is strictly necessary to execute these services.

2. Mandatory Cross-Border & Foreign Storage Disclosure

Notice of Foreign Processing

In compliance with Alberta PIPA, notice is hereby given that Eidon utilizes secure, industry-standard cloud-based software platforms to store, analyze, and manage engagement data.

Jurisdiction Risk

These service providers operate cloud infrastructure and servers hosted outside of Canada, primarily in the United States. Consequently, your data may be accessible to foreign courts, law enforcement, and national security authorities under the laws of those foreign jurisdictions.

Consent

Engagement terms and Tier 1 Intake forms explicitly outline and require client consent for this necessary operational cross-border data routing prior to data collection.

Data Security & AI Privacy

Client data is strictly encrypted and protected by industry-standard security protocols. Furthermore, I ensure that engagement data is not utilized for the training of external AI models or algorithms.

3. Data Retention & Destruction Schedule

PIPA mandates that personal information be retained only as long as necessary to fulfill the business or legal purpose for which it was collected, while ensuring records used to make decisions about an individual are retained for at least one year.

Record TypeRetention PeriodJustification / Statutory Rule
Active Engagement Audits & Intake Data (Tier 1) Duration of active project + 1 year Ensures clients can access records used during the assessment/system build under PIPA.
Strategic Oversight Financials (Tiers 2 & 3) Duration of active retainer + 1 year Maintained to track quarterly trajectory and story consistency.
Financial Transaction & Billing Records (All Tiers) 6 years from end of relevant tax year Mandated by the Canada Revenue Agency (CRA) under the Income Tax Act and corporate recordkeeping standards.
Raw AI Queries & Working Files (All Tiers) Deleted upon final deliverable handoff Anonymized during analysis; unredacted working notes purged after the Capital Readiness Brief is issued.

Destruction Standard

When the retention period expires or an engagement concludes without ongoing retention requirements, all digital files hosted in Google Workspace and QuickBooks are permanently deleted. Cloud trash bins are manually purged, and platform permissions granted to Eidon by the client are formally revoked and audited.

4. Client Rights & Privacy Contact

Clients have the right to request access to or correction of their personal data held by Eidon, or to withdraw consent (subject to legal and contractual limitations).

  • Privacy Officer: Heidi Schurman, Founder & Capital Readiness Strategist
  • Contact: Written requests can be submitted directly via official Eidon communication channels. Response times will strictly adhere to PIPA's statutory 45-day window.