PRIVACY POLICY

Our Privacy Policy

We value the trust that you have placed in Stonebridge Financial Corporation (“Stonebridge”, “we”, “our”, or “us”) and protecting your personal information is our priority. This Privacy Policy (“Policy”) discloses the practices of Stonebridge, including its subsidiaries and affiliates, regarding the collection, use, safeguard, disclosure, transfer, access, disposal and other processing (collectively, “Processing”) of personal information of individuals who engage with Stonebridge for our support, services or otherwise, or visits our website(s) (“Website”) or contributes to Stonebridge’s social media platforms. For the purposes of this Policy, personal information (“Personal Information”) shall mean information that can identify an individual directly or indirectly through reasonably available information, but does not include information that is used solely for the purpose of communicating or facilitating communication with an individual in relation to their employment, business, or profession.

This Policy is Stonebridge’s way of making sure you are fully informed and affirms our commitment to maintaining the accuracy, confidentiality, and security of Personal Information. Stonebridge respects your privacy and is committed to protecting your Personal Information in line with all applicable laws and regulations governing the Processing of Personal Information.

Acceptance of Privacy Policy

By providing Personal Information to Stonebridge and visiting the Website and clicking “I Agree to Stonebridge’s Privacy Policy”, engaging with our social media or otherwise, you are consenting to our Processing of your Personal Information in accordance with the terms of this Policy. 

This Policy is effective as of the date “Last Updated”, above, and will remain in effect except with respect to any of its provisions that are changed in the future. We reserve the right to change this Policy at any time and we will notify you of any material changes. Notifications of material changes may be made by posting the changes on our Website, or otherwise notifying you using other means of contact we have on you (such as email address, text messaging or direct messaging). Changes, modifications, additions, or deletions will be effective immediately upon their posting to the Website or upon you being otherwise notified. Your continued use of the Website after we post any such modifications, and provide notifications to the extent required, will constitute your acknowledgement of the modified Policy and your agreement to abide and be bound by the modified Policy. We will also revise the “Last Updated” date found at the beginning of this Policy when we post changes to it. 

Subject to certain legal and contractual limitations, you have the right to withdraw your consent from us Processing your Personal Information. This may limit our ability to provide you with our services, act on your behalf or engage with you as you would like. To withdraw your consent to certain Processing by Stonebridge, you may declare to the Chief Operating Officer (“COO”) (contact information provided below) in writing, at any time, of your desire to withdraw consent. Stonebridge will inform you of the implications of such withdrawal within thirty (30) days of your written request. Any withdrawal of consent will apply thereafter and not to information handling practices that have been previously undertaken based on prior consent.

Stonebridge will not knowingly obtain consent from those individuals who are minors under 18 years of age, seriously ill, or mentally incapacitated and we shall therefore obtain consent from a parent, legal guardian or person having power of attorney of such an individual. If you are an individual under the age of 18 years, you must access or use the Website only with the permission and involvement of your parent or guardian.

Collection and Processing of your Personal Information

Types of Personal Information Collected and Processed

The Personal Information which Stonebridge may collect includes, but is not limited to:

1) Contact and identifying information including your name, mailing address, country of residence, email address, telephone number, gender and date of birth.

2) Banking and payment information such as credit card details, bank account numbers, transaction data, and payment methods. 

3) Income statements such as pay stubs, T4 forms, asset declarations such as real estate holdings or investment portfolios, and debt liabilities. 

4) Social insurance number and government-issued identification such as passport numbers or driver’s license details. 

5) Taxpayer identification numbers, tax residency, and filings. 

6) Login information including username and password.

7) Marketing and communications information including your preferences in receiving marketing from us and third parties, and your communication preferences.

8) Computer information including device type, device identifiers, IP address, MAC address, location, browser type, operating system and platform, protocol, sequence information, cookies, beacons, pixel tags, browser language and type, and domain name system requests.

9) Internet or other electronic network activity including browsing, session, interaction, search history, duration of use, frequency of use, material and pages viewed, time and date of access, number of bytes transferred, number of clicks per visit and other user behaviour related to our website.

10) Other information which you voluntarily provide to us, our employees, or our contractors.

In addition, if you contact us, we may keep a record of your communication to help solve any issues you might be facing. 

Purposes for Collection and Processing of Personal Information

Personal Information may be collected by Stonebridge for purposes that include, but are not limited to:

1) Maintaining and improving our services and otherwise running and managing our business in the ordinary course, and keeping our records up to date, including without limitation, facilitating a financing transaction.

2) For your use of our services and the Website, including in support of a financing transaction.

3) Receiving communications from us in regard to e-news, emails, bulletins, notifications, newsletters, programs, events and activities.

4) Assisting you when you contact our support services, including to direct your questions to appropriate individuals, investigate and address any of your concerns, and to improve and monitor our customer support responses.

5) Administering and protecting our business and Website, including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data. 

6) Marketing and advertising to be presented on the Website. 

7) Administering surveys, offer tailored content, and other promotional materials to you based on your interests.

8) Using data for business development and market research to understand demographics, interests, and to track and analyze trends and patterns.

9) Complying generally with all laws and applicable statutory requirements, and meeting regulatory reporting requirements, including without limitation, “Know Your Customer” requirements, Canada’s Criminal Code, National Instrument 31-103 – Registration Requirements, Exemptions and Ongoing Registrant Obligations, and Proceeds of Crime (Money Laundering) and Terrorist Financing Act. 

Methods of Collection of Personal Information

1) General – Personal Information may be collected by Stonebridge in a number of ways, including in person, our website, by mail, by email, and from third parties whom you have authorized to disclose Personal Information to us. We also collect Personal Information under contract when an individual, serving as an officer, director, or in another capacity, consents to share such Personal Information to support a financing request. In certain cases, Stonebridge obtains consent to collect, use, or share Personal Information through third parties under a contract to support their financing request. If you provide information about a third party or authorize a third party to do so, we will assume you have taken proper measures to obtain informed consent.

2) Phone Calls – For the purpose of maintaining quality service, telephone calls to Stonebridge’s customer services lines may be recorded. If your call is subject to a quality assurance program, you will be advised prior to speaking to a representative.

3) Cookies and Web Beacons – Stonebridge may collect Personal Information through cookies on our Website. Cookies are small text files inside your computer that contain a unique identifier, allowing us to recognize you when you visit our Website again. This helps us to understand your preferences based on previous or current Website activity, allowing us to provide you with improved services, tailor our content to meet your needs and for advertising purposes. We also use cookies and navigational data to gather information regarding the date and time of your visit and the information for which you searched and viewed, or on which of the advertisements displayed on our Website you clicked. 

The Website may use retargeting ads to advertise online. Retargeting uses cookies from third party vendors like Google to track visitors. This tracking enables the third-party vendors to display our ads to people on various sites across the internet based on their visits to our Website. 

We may also use web beacons (small pieces of data that are embedded in images on the pages of our Website) and auditing software to track page views and entry and exit points to and from our Website. We may use web beacons, cookies, customized links and/or similar technologies to determine whether electronic newsletters sent by us to those who have requested them from us have been opened and which links are clicked. Any data collected will only be used in an aggregate form and will not contain any Personal Information.
Some cookies are automatically deactivated upon your access and use of the Website. However, unless you activate cookies, you may be unable to fully utilize and access all areas and features of the Website. You may activate cookies by visiting our Website and clicking “Activate Cookies”. Some third-party service providers may also place their own cookies on your browser. Note that this Policy only covers Stonebridge’s use of cookies and does not include use of cookies by such third parties.

4) Clickstream Data – When you visit the Stonebridge Website, we may also collect clickstream data (e.g. server address, domain name, device type, browsing software) which may be stored on the Website’s server. This information can be combined with information you have provided to us which will enable us to analyze and better customize your visits. We may use clickstream data for traffic analysis or e-commerce analysis of the Website, to determine which features of the Website are most or least effective or useful to you.

5) Mobile and Location Information – Stonebridge’s Website features may be accessible from web-enabled mobile devices. The intent is to provide screens that are optimized for the size of the screen and operating systems. On some devices, functionality may be limited. If you use mobile-enabled services provided by our Website, we may receive information about you from your mobile device. This may also include information about your precise location if you have enabled location-based services on your mobile device. Some devices may allow you to opt-out of this collection or access, and in those cases, you may be able to subsequently stop the collection or access. Please review your device settings for more information.

6) Social Media – If you post a review, make a comment, or otherwise submit Personal Information on a public forum such as social media accounts or public forums on our Website or other applications, your communications may be viewable by the public. When voluntarily disclosing Personal Information about yourself with other Stonebridge users, we are unable to control what may be done with that content. You should take all necessary precautions to protect your private information by not posting or publishing any information that you do not want in the public domain. While we strive to provide the highest level of confidentiality, you should review your personal privacy settings to further restrict any or all parts of your profile or other certain content or information. 

7) Other – Stonebridge may collect Personal Information when you interact with our Website, including when you access the Website, register or create or edit your account, sign up to receive newsletters and information, fill out online surveys or forms, send or respond to our emails, or otherwise communicate with us.

Sharing of Personal Information with Third Parties

Although you are entering into an agreement to disclose your Personal Information to Stonebridge pursuant to this Policy, we work with service providers to assist in Processing your Personal Information on our behalf to assist us with providing our services and administering our business, and for such other purposes contemplated herein. Without limiting the foregoing., we may transfer your Personal Information to a third party as follows:

1) Regulators and other third parties for purposes of complying with our anti-money laundering and legal compliance obligations.

2) Contractors and affiliates, including companies we use for storage, processing, and delivery of services.

3) Administrative and technical support, including cloud storage providers, IT support, and data analytics providers.

4) Public media and marketing, including companies we use for advertising, marketing, public relations, and press releases.

5) Parties in connection with proposed or actual financing, insuring, sale, securitization, assignment or other disposal of all or part of our business or assets.

6) We do not store your payment information for online purchases with debit/credit cards, this is shared directly with our third-party payment providers including financial institutions and payment processors.

We may also disclose Personal Information in situations where we are legally required or permitted to do so. These situations may include criminal investigations, government tax reporting requirements, court orders, or instances where we believe the rights and safety of others may be at risk. If you believe that a third party has inappropriately disclosed your Personal Information to us, please contact that third party directly. If the third party does not sufficiently respond to your inquiries, please let us know immediately.

Managing your Personal Information

Limiting the Collection and Processing of Personal Information

Stonebridge takes care to ensure that Personal Information you provide to us is accessed internally only by individuals that require access to perform their tasks and duties, and externally only by service providers with a legitimate purpose for accessing it. We do not sell, trade, rent or otherwise share for marketing purposes the Personal Information that we collect with third parties, unless you consent or authorize us to do so. We limit the Personal Information provided to the aforementioned affiliate and third-party service providers to the extent necessary for them to provide the services. We have contractual provisions in place to ensure that the third-party service providers to whom we transfer your information use it solely for purposes as we instruct, and to ensure such third party’s safeguard the Personal Information disclosed or transferred by us. 

Accuracy of Personal Information

Stonebridge takes all reasonable steps to keep your Personal Information as accurate, complete and up-to-date as necessary to fulfill the purpose for which your Personal Information has been collected. If desired, you may verify the accuracy and completeness of your Personal Information in our records with our COO. 

Despite our efforts, errors sometimes do occur. Should you identify any incorrect or out-of-date Personal Information in your file, we will remedy any such errors as soon as reasonably possible. You may request correction of the Personal Information we hold about you, though we may need to verify the accuracy of the new information you provide to us. If inaccurate Personal Information is mistakenly sent to a third party, we will communicate relevant changes to the third party where appropriate.

Retention of Personal Information

Stonebridge will store your Personal Information only for as long as is reasonably necessary to fulfill the purpose for which the Personal Information was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Once your Personal Information is no longer needed, we will securely and effectively dispose of it. To determine the appropriate retention period for Personal Information, we consider the amount, nature, and sensitivity of the Personal Information, the potential risk of harm from unauthorized use or disclosure of your Personal Information, the purposes for which we Process your Personal Information and whether we can achieve those purposes through other means, and the applicable legal requirements. In some circumstances we may anonymize your Personal Information (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this anonymized information indefinitely without further notice to you.

Request for Access to Personal Information and Processing

You may request access to your Personal Information. We may need to request specific information from you to help us confirm your identity and right to access your Personal Information. This is a security measure to ensure that Personal Information is not disclosed to any person who has no right to receive it. Stonebridge may not always be able to comply with your request for access to Personal Information for specific reasons which you will be notified of, if applicable.

Request for Deletion or Removal of Personal Information

In some circumstances you have the right to request that we delete or remove your Personal Information where there is no good reason for us to continue Processing it. You may also ask us to delete or remove your Personal Information where you have successfully exercised your right to object to Processing, where we may have processed your information unlawfully or where we are required by law to erase your Personal Information. We may not always be able to comply with your request for deletion of Personal Information for specific legal reasons which you will be notified of.

Protecting your Personal Information

Integrity and Security

Stonebridge uses industry standard measures, including administrative, organizational, technical, and physical safeguards, designed to protect Personal Information under its control from theft, loss, accidental release or other unauthorized access, use, disclosure or destruction. Such measures include: 

Technical Safeguards:

1) Cloud based Network server hosted at a SOC 2 Type II Security, Data Centre;

2) Network infrastructure protected by firewall technology with real time intrusion protection;

3) Site to Site Encrypted Virtual Private Network;

4) Network PCS and mobile devices are password protected; and

5) Network folders restricted to authorized users only.

Physical Safeguards:

1) Personal Information is stored in locked cabinets with restricted access. Negotiable instruments are stored in fireproof locked cabinets;

2) Building and premise access are restricted; and

3) All documentation for destruction, including Personal Information, are securely stored onsite and destroyed by a bonded Document Management Firm.

Administrative Safeguards:

1) Access to private, sensitive, and confidential information, including Personal Information, is restricted to authorized employees or contractors with legitimate business reasons.

2) Our employees and contractors are trained to properly use, store, destroy and otherwise Process Personal Information.
We regularly review our security and related policies to adapt the technology as new threats evolve and monitor our systems to help ensure the highest level of availability. If you have any questions about the security of our Website, you may contact our COO.

Confidentiality Incidents

Despite the foregoing security measures and significant steps Stonebridge has taken to protect your Personal Information, no company can fully eliminate all security risks associated with the Processing of Personal Information. With that in mind, we cannot guarantee the security of any Personal Information provided to or received by us. We encourage you to provide only the Personal Information you are comfortable with providing to a third party, keep watch for communications that are suspicious, and report any suspicious activity to us as soon as possible. In the event there has been a breach of our security safeguards which involve your Personal Information, including the unauthorized access, use or disclosure of your Personal Information, loss of your Personal Information, or other breach, Stonebridge will notify you as required by applicable laws. 

Third Party Websites and Linked Applications

Our Website and any of our applications available from our Website or third-party platforms are governed by the provisions and practices stated in this Policy. Our Website and such applications may contain links to third party sites or applications that are not governed by this Policy. Although we endeavour to only link to sites or applications that share our commitment to your privacy, please be aware that this Policy will no longer apply once you leave our Website or such applications, and that we are not responsible for the privacy practices of third party sites or applications. We therefore suggest that you closely examine the respective privacy policies of third-party sites and applications to learn how they collect, use and disclose your Personal Information.

Governing Law

This Policy and all related matters shall be interpreted and construed in accordance with the laws of the Province of Ontario and the applicable federal laws of Canada. 

Personal Information Outside of Canada

Personal Information provided to our service providers may be stored outside of Canada. You acknowledge and agree that, as a result, your Personal Information may be processed, used, stored or accessed in other jurisdictions and may be subject to the laws of those jurisdictions. For example, information may be disclosed in response to valid demands or requests from government authorities, courts, or law enforcement in other countries. 

Addressing your Inquiries and Concerns

Your privacy is very important to us. We are happy to provide you with a copy of this Policy and to discuss any of its contents with you. Stonebridge’s COO is responsible for the implementation of this Policy and monitoring our adherence to its terms and all applicable laws. The COO also handles questions and concerns about our Policy, as well as Personal Information access requests, opt out requests and complaints. The COO may be contacted at: Chief Operating Officer, Stonebridge Financial Corporation at Info@Stonebridge.ca.

LOGIN

CONTACT