Privacy
Privacy Policy
Last updated 25 August 2026
CONTANNUITY™ records where the things that matter are kept, not the things themselves. This policy explains exactly what that means for your data: what we hold, where it lives, who else can see it, how long we keep it, and how to make us change or delete it.
Who we are, and who is accountable
CONTANNUITY™ is operated by 49Maple Inc., carrying on business as Etc. Projects, from Alberta, Canada. This policy covers the CONTANNUITY™ application at contannuity.ca and the transactional email we send you.
One named person is accountable for our handling of personal information and for answering questions and complaints about it. Their name and address are below, and again at the end of this document. This is the person Quebec’s Law 25 calls the person in charge of the protection of personal information.
We are the organization that decides what is collected and why. The companies listed under “Who else touches your data” process it on our instructions and for no purpose of their own.
Vaughn W-S
Person in charge of the protection of personal information, 49Maple Inc. o/a Etc. Projects
What we collect, and what we do with it
We collect only what the product needs to do its job. Nothing here is bought from a data broker, enriched from another source, or inferred about you.
- Your account — your name, email address, firm name, and the MGA, dealer or network you arrived through, if any. Used to sign you in, to address you correctly, and to connect you to your sponsoring organization. Your password is held by our authentication provider as a cryptographic hash; we never see it and cannot recover it.
- Your assessment and plan — your answers to the 28 readiness questions, any notes you add, your gap-review responses, your readiness score and tier, and every field you fill in across the plan itself: emergency contacts, the 24-hour checklist, where systems and documents are kept, revenue and operations figures, and your action plan. This is the substance of the product and it is stored so you can come back to it.
- Your consent decisions — every choice you make about sharing, recorded with the date and the organization it applies to. Refusals are recorded as carefully as agreements, so the product stops asking and so you have a record of what you decided.
- Your payment record — whether you have purchased, how many plans, and the customer identifier our payment processor assigns you. Card numbers never reach our servers: checkout happens on the processor’s own pages.
- Messages you send us — the name, email address and message you submit through the support form or an access request, along with the page you were on when you sent it, so a reply can start from where you got stuck.
- Error diagnostics — when something in the product fails, we record what broke: the error message, the point in the code it came from, the page or API path involved, and the time. Email addresses are stripped out before the record is written. These stay in the same Canadian database as everything else, and the alert we send ourselves goes through the same Canadian email provider. No monitoring vendor is involved.
What we deliberately do not collect
A continuity plan is a map of where things are, not a copy of them. The product is designed around that distinction, and it is the single most important thing to understand about how your data is held here.
Every field that asks about credentials, client lists or documents is asking where they live, not what they are — “the client list is in the CRM, access held by the office manager”, not the client list itself. The interface says so at the point of entry, and we ask you to keep it that way.
So we do not collect, and ask you never to enter: passwords, PINs or access codes for any system; client names, account numbers or policy numbers; social insurance numbers; or copies of client documents. If you have entered something of this kind by mistake, tell us and we will remove it.
We also do not collect location data, we do not build advertising profiles, and we do not use your plan content to train machine-learning models. The plan narrative the product generates is produced by a deterministic program from your own answers — there is no third-party model involved and your content is not sent to one.
Where your data lives, and when it leaves Canada
Your account, your assessment and your plan are stored in a database hosted in Canada, in the ca-central-1 region. Transactional email is sent through a Canadian provider from Canadian servers.
Two things do leave the country, and we would rather say so plainly than bury it. The application itself runs on servers in Washington, D.C., which means your data passes through the United States in transit whenever you use the product, even though it comes to rest in Canada. And payments are processed in the United States by our payment processor, which holds your billing details there.
Data held in or passing through the United States is subject to lawful access by United States authorities, and that is a risk no contractual term fully removes. We assess each transfer before we make it, as Quebec’s Law 25 requires, and we contract with each processor to restrict them to our instructions and to hold the data no longer than they need to.
If you would like the assessment we hold for a particular transfer, ask the privacy officer and we will provide it.
Who else touches your data
These are every third party that processes personal information on our behalf, what each one does, and where it holds the data. Each is bound by contract to process it only on our instructions.
We do not sell your personal information, we do not rent it, and we do not share it with anyone outside this list except with your consent or where the law requires it.
If we add a processor, this list is updated before the change goes live. A processor marked as “committed” below is one we have contracted for and are in the course of integrating.
| Provider | What they do | Region | Country |
|---|---|---|---|
| Supabase | Hosts the database and manages sign-in. Holds your account, your assessment, your plan, and the usage records described under “Cookies and tracking”. | ca-central-1 | Canada |
| Vercel | Runs and serves the application. Processes your data in transit as pages and requests are handled; stores none of it. | iad1 (Washington, D.C.) | United States |
| Stripe | Processes payments. Holds your billing details and card data — we never receive or store a card number. | United States | United States |
| Cyberimpact | Sends transactional email — sign-in links, password resets, receipts. Holds your email address and the messages we send you. | Canada | Canada |
How long we keep it
Your account, your assessment and your plan are kept for as long as your account exists. We do not expire them on a timer: a continuity plan is a document you may not open for two years and then need urgently, and deleting it out from under you would defeat the point of keeping one.
When you ask us to delete your account, we delete your profile, your assessments, your plan content and every share you created.
Payment records are the exception, and this is the part worth reading twice. Canadian tax law requires business records to be kept for six years from the end of the tax year they relate to, so the record that a purchase happened — the amount, the date, and the customer identifier — survives the deletion of everything else. It is retained for that period and used for nothing but tax and accounting compliance.
Consent decisions are kept as the record that you gave or withdrew consent, for as long as your account exists and for a reasonable period afterwards, because the value of a consent record is precisely that it outlives the decision.
Messages you send us through the support form are kept while we deal with them and for a reasonable period after, so a follow-up has context.
Your rights, and how to use them
You can ask us for a copy of the personal information we hold about you, and we will tell you what we have, what we use it for, and who we have disclosed it to. You can ask us to correct anything inaccurate or incomplete.
You can withdraw any optional consent at any time, and withdrawing one does not affect your ability to use the product. The only consent required to use CONTANNUITY™ is consent to process the answers you enter in order to build your plan — without that there is nothing to build.
You can ask us to delete your account, subject to the payment-record carve-out described above. You can print or download your plan yourself at any time, and if you want a machine-readable copy of your data, ask and we will produce one.
To exercise any of these, write to the privacy officer at the address below. We will respond within 30 days. There is no charge, and we will not ask you why.
How we protect it, and what happens if we fail
Your data is encrypted in transit and at rest. Access is enforced at the database itself rather than only in application code: every table carries row-level policies, so a request can only ever reach rows belonging to the account that made it. The credential capable of bypassing those policies is held on the server, is used by exactly two internal operations, and is never sent to a browser.
No safeguard is perfect, and a policy that claims otherwise is not worth reading.
If a breach of our security safeguards creates a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada and notify you directly, as soon as feasible after we determine it has happened. Where a Quebec resident is affected we will also notify the Commission d’accès à l’information. We keep a record of every breach, whether or not it meets the reporting threshold, and provide those records to the Commissioner on request.
You have a part in this too. The plan you build records where your credentials and client data are kept — keep those things themselves in a secure, encrypted location outside this platform, and keep your own account password to yourself.
If your MGA, dealer or network sponsors your access
Some advisors reach CONTANNUITY™ through a sponsoring organization. If yours does, that organization can see a limited set of facts about you without any further consent from you: your name and firm, whether your plan is complete, your readiness score tier, and the date it was last updated. No plan content is included. That visibility exists to support their own continuity-oversight obligations.
Anything beyond that is yours to grant and yours to revoke. Sharing your actual plan content, being included in de-identified benchmarking statistics, and being identified to their business development team are three separate decisions, each with its own checkbox and its own record. None of them is required, none is pre-ticked, and each can be withdrawn on its own.
When you share plan content, your sponsor reads it inside this platform. It is not exported into their systems. If you withdraw, their access is removed within 48 hours. Withdrawal does not undo a disclosure that has already happened, which is why the decision is worth making deliberately.
Sponsoring organizations are bound by their agreement with us, by PIPEDA and by applicable provincial privacy legislation, and have agreed not to use your plan for marketing, profiling or compensation decisions. A data processing agreement is available to any sponsor on request — write to the privacy officer.
Contact, and how to complain
Questions, requests and complaints about your personal information all go to the same place: the privacy officer named at the top of this policy and again below. Write to them and you will get a person, not a queue.
If you are not satisfied with our answer, you can complain to a regulator. Federally, that is the Office of the Privacy Commissioner of Canada, at priv.gc.ca. If you live in Quebec, you may instead complain to the Commission d’accès à l’information du Québec, at cai.gouv.qc.ca. You do not need our permission to do either, and you do not need to come to us first — though we would rather you did, because we can usually fix it faster.
Vaughn W-S
Person in charge of the protection of personal information, 49Maple Inc. o/a Etc. Projects
Changes to this policy
The date at the top of this page is the date of the last substantive revision. We keep it accurate.
If we change something that materially affects how your personal information is handled — a new processor, a new purpose, a shorter or longer retention period — we will update this page before the change takes effect, and we will tell account holders by email rather than relying on you to notice.
This policy is under review by legal counsel. If that review changes anything, this page changes with it and the date above moves.