Legal

Privacy Policy

Effective date: [DATE] · The plain-English boxes and the formal text mean the same thing; if they ever seem to differ, the formal text controls.

DRAFT — pending review by counsel. Not yet in force. Entity name, effective date, and jurisdiction to be confirmed.

1. Who we are

CanyonOps ("CanyonOps," "we," "us"), a product of Canyon Strategic Wealth, provides a practice-management platform for financial advisory firms. Our customer is the advisory firm ("Customer" or "firm"); information about the firm's clients ("Client Data") is submitted by the firm and processed on the firm's behalf and instructions.

Plain EnglishYour firm is our customer. Your clients' data belongs to your firm — we process it to run the service, nothing else.

2. Information we collect

  • Account data — names, work email addresses, and roles of the firm's users.
  • Client Data — household records, tasks, notes, meeting transcripts and the suggestions derived from them, and documents the firm submits.
  • Usage data — log and device information collected for security, reliability, and product improvement.
  • Billing data — processed by our payment processor; we do not store full card numbers.

3. How we use information

We use information to provide and secure the service; to generate AI-assisted suggestions for the firm's review; to provide support; to send service communications; and to comply with law. We do not sell personal information. We do not use Client Data to train AI models.

Plain EnglishYour data runs your account. It isn't sold, and it isn't training material.

4. AI processing

Meeting transcripts and related records are processed to draft suggestions (tasks, notes, logged meetings) that firm users review. Suggestions trace to their source content, and nothing becomes part of the firm's records until a firm user approves it. Sub-processors involved in AI processing appear in our sub-processor list, available on request.

5. Sharing

We share information only with: sub-processors operating under contractual data-protection obligations (list available on request); our professional advisers; parties to legal process, with notice to the firm where lawful; and a successor entity in a corporate transaction, with notice.

6. Retention & deletion

Client Data is retained according to the firm's instructions and applicable recordkeeping obligations — advisory firms frequently must retain records under SEC Rule 204-2 and similar rules. Deletion requests are executed with dual-control holds designed to prevent improper destruction of required records. Upon termination, data is made available for export to the firm and subsequently deleted on a defined schedule.

Plain EnglishWe keep what your regulators require you to keep, delete carefully on purpose, and hand everything back if you leave.

7. Security

We maintain administrative, technical, and physical safeguards including AES-256 encryption at rest, TLS in transit, per-firm data isolation, need-to-know access controls, and permanent audit logging. Details are on our Security page.

8. Your rights

Clients of advisory firms should direct privacy requests to their firm, which controls their data; we assist firms in honoring such requests. Firm users may contact us directly about their account data. Where state privacy laws apply (for example, California), we honor the rights they provide.

9. Cookies & analytics

Our marketing site uses minimal analytics to understand aggregate usage. We do not run advertising trackers on the marketing site.

10. Children

The service is not directed to children under 16, and we do not knowingly collect their information.

11. Changes

We will notify firms in advance of material changes to this policy.

12. Contact

Questions about this policy: hello@canyonops.ai.