TRUST

How we handle your data

Do you handle patient or medical records?

No. We market the practice. We do not receive, store or process patient records, appointment data, or clinical information. If a healthcare client offers us that data we decline it. Keeping that line means the rules governing medical records never apply to us or to the work, which is safer for you than any promise we could make about protecting it.

How do you decide who you are allowed to email?

Every business we might contact carries a recorded lawful basis: what the basis is, where the address was published, when we recorded it, and when it expires. No recorded basis means our own software refuses to draft the message. That is a hard check in the system, not a guideline someone might skip on a busy day.

Canada's anti-spam law is the strictest of its kind anywhere, and the penalties run to $10 million with personal liability for directors. We would rather send fewer emails than defend a bad one.

Does AI send emails on your behalf without review?

No. Drafting is automated. Sending is not.

Every message waits in an approval queue until a person reads it and approves it. The decision is recorded with who made it and when. That record is also useful to you: we can show you exactly what went out in your name, to whom, and on what date.

Automation widens only when the numbers say it should. We measure how often the system's judgment matches a human's, and the gate stays shut until that agreement is high and the expensive kind of error is rare. Nobody here decides the software is ready by feel.

Is my data used to help your other clients?

Your data is never shown to another client and never pooled into a shared benchmark. What improves across clients is the scoring model itself, in the same way a spam filter gets better without anyone reading your mail. If we ever could not honour that separation for a piece of work, we would not take the work.

What happens to my data if we stop working together?

Ask us to delete it and we do, within 30 days, confirmed in writing. Consent for us to route your needs to suppliers is recorded separately from the marketing work, so you can withdraw that on its own without ending anything else.

What we keep, and why

We keep these because they are the only honest way to answer the questions above. An agency that cannot show you its record is asking you to take its word.

What we do not have yet

We are not SOC 2 or ISO 27001 certified. We are a small firm and those audits are a later step. What we do have is the underlying evidence those audits look for, kept from the start rather than reconstructed afterwards. If your procurement process needs a security review, ask and we will send what we have, including the gaps.