Last updated: September 2026
Advisor Privacy Policy
Oltre Financial Inc. operates under the trademark OPTIML FINTECH SOLUTIONS™ ("Optiml™") and provides an online platform for personalized lifetime tax and estate optimization, including a workspace for financial advisory firms and their personnel (the "Advisor Workspace"). OPTIML™ IS A SOFTWARE PROVIDER. WE DO NOT PROVIDE FINANCIAL, INVESTMENT, TAX OR LEGAL ADVICE.
This Advisor Privacy Policy explains how we collect, use, disclose and protect personal information in connection with the Advisor Workspace. It applies to advisory firms and other organizations that use the Advisor Workspace (each an "Organization"), to the individuals who access it under an Organization's account (each an "Authorized User"), and to the information those Organizations enter about the individuals they serve (their "Clients"). Capitalized terms not defined here have the meaning given in our Advisor Terms of Service.
Individual consumer accounts, including accounts held by an Organization's Clients, remain governed by our Privacy Policy and Terms of Use. To the extent of any conflict concerning the Advisor Workspace, this Advisor Privacy Policy prevails.
"Personal information" means information about an identifiable individual. It does not include information that has been de-identified so that it can no longer be associated with a specific individual, or business contact information used to reach someone in their professional capacity. We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and the substantially similar provincial privacy laws that apply to us. Our representatives are trained on our privacy policies and practices. Unless compelled to do so by law, or as part of a sale of all or part of our business, we never sell personal information and never use it for purposes not described in this policy.
Our two roles
The Advisor Workspace holds two kinds of personal information, and our responsibility differs for each.
- Information about Authorized Users. The account, profile and billing information of the advisors, administrators and other personnel who use the workspace. We are the organization accountable for this information, and we collect it directly from the individual or from the Organization that invites them.
- Client Data. Personal and financial information about an Organization's Clients (including a Client's spouse or family members) that the Organization enters into, uploads to, or generates within the workspace. As between the parties, the Organization owns and controls Client Data. We collect, use and disclose it only as a service provider acting on the Organization's instructions: to provide, maintain, secure and improve the Service, and as otherwise required by law.
What we collect about Authorized Users
Depending on how an Authorized User joins and what they do in the workspace, we collect some or all of the following:
- Account details: name, email address, telephone number, and the Organization name and approximate team size provided at signup.
- Professional profile: role within the Organization, office, title, designations, professional photo and the sign-off block that appears on reports and emails sent to Clients.
- Organization details entered by its administrators: legal or trade name, address, telephone number, website, logo and brand colours.
- Billing information: payment card details are collected and held by our payment processor, not by us. We receive the card brand, its last four digits, its expiry date, the billing address and a record of invoices and payments.
- Usage and technical information: pages and features used, actions taken on Client records (kept as an activity history visible to the Organization), device and browser type, IP address, approximate location derived from it, and error and performance reports.
- Communications: messages you send us for support, and your email preferences.
When an administrator invites a teammate, they give us that person's name and email address so we can send the invitation. By doing so, the administrator confirms that they are entitled to share it with us for that purpose. The Advisor Workspace is intended for adults working in a professional capacity and is not directed to anyone under the age of 18.
How we use information about Authorized Users
- To create and administer the Organization's workspace, including team membership, roles, offices and access controls.
- To bill the Organization for its subscription, including seat counts, and to prevent fraud and abuse.
- To identify the Authorized User on the plans, reports and emails their Organization sends to Clients through the Service.
- To provide support, respond to requests and send service messages such as invitations, security notices, billing notices and changes to our terms or policies.
- To send product news, onboarding guidance and other communications about the Service, which you may opt out of at any time (see Communications below).
- To monitor, secure and improve the Service and to develop new features, using aggregated or de-identified information wherever possible.
- To comply with legal obligations and enforce our agreements.
Client Data entered by your Organization
We use Client Data only to provide the Service to the Organization: to store it, to generate the projections, analyses and reports the Organization requests, to answer the Organization's questions about a Client's plan through our AI assistant, to deliver invitations and plan links the Organization sends to a Client, and to secure and support the workspace. We do not use Client Data to market to Clients, to build profiles of them, or for any purpose of our own beyond operating and improving the Service.
Because the Organization decides what Client Data is collected and why, the Organization is responsible for:
- having a lawful basis, including any consent its Clients' circumstances require, before entering Client Data into the Service;
- telling its Clients that it uses Optiml™ to prepare their plans and how their information will be handled;
- the accuracy of the Client Data it enters; and
- responding to its Clients' requests to access, correct or delete their information held in the Organization's workspace. We will assist the Organization with such requests on reasonable notice.
Client Data may include information about a Client's spouse, dependants and beneficiaries, some of whom may be minors, such as a child named on an education savings plan. The Organization enters that information under its own relationship with the Client, and the responsibilities above apply to it in the same way.
Emails the Service sends to a Client on the Organization's behalf, such as an invitation or a shared plan, are sent from Optiml™ and carry the Organization's name and logo and the sending advisor's name and reply-to address, so the Client can see who contacted them and respond to that person directly.
Clients who hold their own Optiml™ account
An Organization may invite a Client to create their own Optiml™ account, and a Client who already holds one may link it to their Organization. That account belongs to the Client and is governed by our consumer Terms of Use and Privacy Policy. Where a plan is shared between an Organization and a Client:
- plans the Organization releases to a Client become visible in the Client's account, and plans a Client chooses to share with the Organization become visible in the Organization's workspace;
- the Client can see, in their own account, which Organization and which advisor they are linked to; and
- when the relationship ends, the Organization's access to the Client's shared information ends, and the Client keeps their own account and the plans in it.
The AI assistant in the Advisor Workspace
The Service includes an AI assistant (EVA) that lets an Authorized User ask questions about a Client's plan while working on it. It uses retrieval-augmented generation powered by Google's paid Generative AI API. The same safeguards that apply to consumer accounts apply here:
- Last names are removed before plan data is processed by the AI. First names are retained so the assistant can refer to the Client and their spouse naturally; where a first name is unavailable, generic labels are used instead.
- Because we use a paid API, plan data is not used to train Google's models.
- The AI has access to a Client's plan data only while an Authorized User is interacting with the assistant about that Client.
- Questions and answers are stored with the Client's workspace so the conversation can continue later, and are deleted with that workspace. They are not used for profiling, advertising or marketing.
The assistant is optional. An Organization that does not wish Client Data to be processed this way should instruct its Authorized Users not to use it.
Service providers and where information is held
We use third-party service providers to operate the Service, and remain responsible for personal information handled by them on our behalf. Each is bound by contract to use the information only to perform services for us and to protect it at least as well as we do. They include providers of:
- cloud hosting, storage and computing;
- identity and login services, including invitation and password emails;
- payment processing, invoicing and sales tax calculation;
- transactional and product email delivery;
- address lookup when an Organization enters its own address;
- generative AI for the assistant described above; and
- error monitoring and usage analytics.
We may also share personal information with our own professional advisers, such as lawyers, accountants, auditors and insurers, where needed to run our business, and they are bound to keep it confidential.
Client Data and plan data are stored on servers located in Canada. Some of our service providers, including our identity, payment and email providers, process information in the United States, where it may be accessible to the authorities of that jurisdiction under its laws. Before we allow personal information to be handled outside Canada, we assess the privacy risks of doing so and require the provider by contract to protect it to a standard comparable to this policy. We do not otherwise transfer personal information outside Canada.
We may also disclose personal information where required by law, to protect the rights, property or safety of Optiml™, our users or the public, or in connection with a sale, merger or financing of our business, in which case the successor will be bound by this policy.
Security and breach notification
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the information we hold, including encryption in transit and at rest, role-based access within the workspace, audit history on Client records, and the practices described in our Security Policy. Access by our own personnel is limited to those who need it to support, secure or improve the Service, and they are bound by confidentiality obligations. Each Organization is responsible for the credentials and devices of its Authorized Users, for assigning roles appropriately, and for removing personnel who leave.
No security measures can provide absolute protection. If a breach of our security safeguards involving Client Data creates a real risk of significant harm, we will notify the affected Organization without undue delay, provide the information it reasonably needs to meet its own notification obligations, and cooperate with it. Where the breach concerns information for which we are directly accountable, we will notify the affected individuals and the Privacy Commissioner of Canada as the law requires.
Retention and deletion
- While the subscription is active, Client Data and workspace information are retained so the Organization can keep serving its Clients.
- When an Organization removes a Client, the Client's workspace data is permanently deleted 90 days after the removal. A Client who holds their own Optiml™ account keeps that account and the plans in it.
- When an Organization's subscription ends and is not renewed, the entire workspace, including every Client's data, Authorized User profiles and Organization details, is permanently deleted 90 days after the end date. We remind the Organization's owner before this happens. Resubscribing within those 90 days cancels the deletion.
- When an Authorized User leaves an Organization, their profile is removed from that workspace. Their login is retained only if they hold a personal Optiml™ subscription of their own.
- Records we are required to keep, such as invoices, payment records and records of acceptance of our terms, are retained for as long as applicable law requires (generally seven years for financial records) and are kept separate from workspace data.
Deletion removes the information from our systems and those of our service providers, other than backups that expire on their own schedule and the required records described above. We may keep information that has been de-identified and aggregated, so that it no longer relates to an identifiable individual or Organization, for research, modelling and product improvement after deletion.
Accessing, correcting and deleting personal information
Authorized Users can view and update their own profile and Organization administrators can update Organization details from within the workspace at any time. An Authorized User may also ask us to access, correct or delete the personal information we hold about them by contacting our Privacy Officer. We will respond within the time applicable law allows, we may need to verify your identity first, and if we cannot act on a request, for example because we must keep a record, we will explain why.
You may withdraw your consent to our collection, use or disclosure of your personal information at any time, subject to legal and contractual restrictions and reasonable notice. Because the Advisor Workspace cannot operate without an Authorized User's account information, withdrawing consent may mean we can no longer provide you access to it.
A Client who wishes to access, correct or delete information held in an Organization's workspace should contact that Organization, which controls the information. If a Client contacts us directly about such information, we will refer the request to the Organization and assist it in responding. Requests concerning a Client's own Optiml™ account are handled under our consumer Privacy Policy.
Complaints
If you believe we have not handled personal information in accordance with this policy, please contact our Privacy Officer. We will investigate every complaint promptly, tell you the outcome, and where a complaint is justified take appropriate steps to resolve it, including changing our practices where necessary.
Communications
We send service messages that are necessary to operate the workspace, such as invitations, security notices, billing notices, reminders before scheduled deletion, and changes to our terms or policies; these cannot be opted out of while the account exists. We may also send product news and guidance about the Service. You can opt out of those at any time using the unsubscribe link in the message or by contacting us.
Cookies and analytics
The workspace uses cookies and similar technologies that are necessary to keep you signed in and to keep your session secure. Our website and application also use analytics and error-monitoring tools to understand how the Service is used and to find and fix problems. These tools receive technical information such as pages viewed, browser type and approximate location; they do not receive Client Data. Our consumer Privacy Policy describes the analytics used on our website in more detail.
Changes to this policy
We may update this Advisor Privacy Policy from time to time. The current version is always posted at www.optiml.ca, and the date at the top shows when it last changed. If an Organization does not agree with a change, it may end its subscription. Continued use of the Advisor Workspace after a change takes effect constitutes acceptance of the updated policy.
Contacting Optiml™
If you have any questions or concerns about our privacy practices, or about personal information held in connection with the Advisor Workspace, please contact our Privacy Officer by email at privacy@optiml.ca or write to:
Optiml™
Attention: Privacy Officer
1107 South Park St
Halifax, NS B3H 2W6
