Scope and Application
This Privacy Policy ("Policy") explains how Prospera AI Inc. ("Prospera," "we," "us," or "our") collects, uses, discloses, and safeguards personal information processed through Sophie—our AI-powered wealth management platform (the "Platform" or "Service").
Prospera supplies technology to registered investment advisors, broker-dealers, insurance companies, and other professional wealth management firms (each, a "Customer"). Those Customers collect personal information from their own clients and provide it to Prospera so the Platform can generate data-driven insights.
Data Controller and Data Processor Roles: Under Canadian privacy laws (PIPEDA, Quebec Law 25) and U.S. privacy laws (CCPA, GDPR where applicable), our Customers are the "data controllers" / "businesses"; Prospera acts as their "data processor" / "service provider."
Information We Collect
2.1 Identifiers
- Name, postal address, email address, phone number
- Government-issued identification numbers
- Social insurance numbers, tax identification numbers
- Professional credentials and regulatory identifications
2.2 Financial Data
- Account numbers, financial holdings, investment portfolio details
- Income, assets, liabilities, net worth
- Risk tolerance, investment preferences, financial goals
- Transaction history, payment information, billing records
2.3 Demographic and Profile Data
- Age, date of birth, marital status
- Employment details, occupation, employer name
- Family information (dependents, beneficiaries)
- Financial goals, life events (retirement, education planning)
2.4 Sensitive Personal Information
We process certain categories of sensitive personal information only when necessary and with appropriate safeguards, including health status relevant to planning, biometric identifiers for verification, and precise geolocation for security controls.
2.5 Device and Usage Data
- IP address, browser type and version, operating system
- Timestamps, clickstream logs, pages viewed
- Device identifiers, session information
- In-product telemetry and usage analytics
2.6 Communications Data
- Messages, questions, and instructions provided to Sophie
- Support requests and correspondence
- Feedback and survey responses
How We Obtain Personal Information
3.1 From Customers
We receive personal information from our Customers (wealth management advisors) who have a lawful basis to collect and share it with us for processing through the Platform.
3.2 Directly from Data Subjects
In limited circumstances, we may collect personal information directly from website visitors, newsletter subscribers, and event attendees.
3.3 Automatically Through Technology
We automatically collect certain information through the Platform using cookies, log files, web beacons, and similar tracking technologies.
3.4 From Third-Party Service Providers
We may receive personal information from third-party data partners subject to contractual obligations or as instructed by the Customer.
Purposes and Legal Bases for Processing
4.1 Service Delivery (Contract Performance)
- Deliver, operate, and secure the Platform
- Process and analyze financial documents for insights
- Generate personalized recommendations and reports
- Maintain conversation context and behavioral profiles
- Store and retrieve client data securely with proper access controls
4.2 Legal and Regulatory Compliance
Comply with contractual, legal, and regulatory obligations under PIPEDA, Quebec Law 25, CCPA/CPRA, and other applicable laws.
4.3 Security and Fraud Prevention (Legitimate Interest)
Detect, investigate, and prevent fraud, cyber-threats, or misuse of the Platform.
4.4 Platform Improvement (Legitimate Interest)
Improve the Platform using de-identified or aggregated data that cannot reasonably identify any individual.
Important: We do NOT use identifiable personal information to train third-party AI models.
Automated Decision-Making and Profiling
The Platform produces predictive analytics, behavioral insights, and client personas to assist wealth management advisors, including risk tolerance profiling, investment suitability scoring, life event prediction, and behavioral pattern analysis.
Human Oversight: A qualified human advisor must review all recommendations before taking action. The Platform serves as a decision-support tool, not an autonomous decision-maker.
How We Disclose Personal Information
6.1 To Sub-processors and Service Providers
We engage carefully vetted sub-processors bound by contracts imposing equivalent privacy and security obligations. See our Subprocessors page for the current list.
6.2 To Corporate Affiliates
We may share personal information with corporate affiliates on a strict need-to-know basis.
6.3 For Legal Compliance and Protection of Rights
We may disclose personal information to regulators, courts, or law enforcement when legally required.
6.4 Business Transfers
In connection with a merger, acquisition, or sale, personal information may be transferred to the acquiring entity.
We Do Not Sell Personal Information. Prospera does NOT sell personal information, nor do we share it for cross-context behavioral advertising.
AI Model Training and Data Usage
7.1 Prospera's AI Training Policy
Definitive Answer: Prospera does NOT use identifiable personal information—yours or your clients'—nor any user-generated data or responses within the system to train our own AI models or any third-party models.
- Client data, financial documents, and conversational interactions are NEVER used to train or fine-tune AI models
- We do NOT build training datasets from identifiable personal information
- Personal information is used ONLY for inference and is immediately discarded after processing
7.2 Third-Party AI Provider Safeguards
- PII Scrubbing: All personally identifiable information is removed before transmission
- Zero Data Retention (ZDR): Enterprise agreements explicitly prohibit data retention beyond the API call lifecycle
- No Training Use: Contractual clauses prohibit using our API data for model training
- Audit Rights: Our DPAs include audit rights to verify compliance
7.3 How We Prove Compliance
- Executed DPAs available for review under NDA
- API keys configured for zero-retention enterprise tiers
- Immutable, append-only audit logs track every external API call
- SOC 2 Type II certification in progress
International and Inter-Provincial Data Transfers
Prospera's primary data centers are located in Canada (AWS ca-central-1). Certain sub-processors operate in the United States.
8.1 Quebec Residents (Law 25 Compliance)
We support Customers in conducting Privacy Impact Assessments required under Quebec Law 25 for transfers outside Quebec, including Standard Contractual Clauses, encryption, and strict access controls.
8.2 European Economic Area Residents (GDPR)
For EEA transfers, we rely on European Commission's Standard Contractual Clauses (Module 2), transfer impact assessments, and additional safeguards including encryption and access controls.
Security Safeguards
9.1 Technical Safeguards
- Encryption: TLS 1.3 in transit; AES-256 at rest
- Key Management: AWS KMS with tenant-specific CMKs and automatic rotation
- Field-Level Encryption for highly sensitive PII
- Network Security: VPC isolation, firewalls, intrusion detection
- DDoS Protection: AWS Shield
9.2 Access Controls
- Multi-Factor Authentication (MFA) for all administrative access
- Role-Based Access Control (RBAC) with granular permissions
- Row-Level Security (RLS) for multi-tenant isolation
- Quarterly access reviews with automatic deprovisioning
9.3 Monitoring and Incident Response
- 24×7 monitoring of security events
- Comprehensive, immutable audit logs (retained 1+ years)
- Weekly automated vulnerability scanning
- Annual third-party penetration testing
- Breach notification within 72 hours as required by law
9.4 Business Continuity
- RTO: 6 hours; RPO: 2 hours
- Continuous backups with point-in-time recovery
- Cross-region replication with warm standby
- Annual disaster recovery drills
Data Retention and Deletion
10.1 Retention Periods
| Data Category | Retention Period | Basis |
|---|---|---|
| Active Client Data | Duration of service agreement | Service delivery |
| Financial Documents | 5–7 years | Legal compliance |
| Conversation Logs | 90 days after last interaction | Service improvement |
| Audit Logs | 1 year minimum | Security monitoring |
| Backups | Continuous PITR | Disaster recovery |
| De-identified Data | Indefinite | Platform improvement |
10.2 Deletion Procedures
Upon instruction, termination, or deletion request, we securely delete or return personal information within 30 days using cryptographic erasure, logical deletion, backup lifecycle management, and sub-processor confirmation.
Your Privacy Rights
11.1 Rights by Jurisdiction
| Jurisdiction | Your Rights |
|---|---|
| Canada (PIPEDA) | Access, correct, withdraw consent, challenge accuracy |
| Quebec (Law 25) | All PIPEDA rights plus automated processing info, incident notice, technological neutrality |
| California (CCPA/CPRA) | Know, access, correct, delete, limit sensitive data use, opt-out of sale/sharing |
| EEA/UK (GDPR) | Access, rectification, erasure, restriction, portability, object, withdraw consent |
11.2 How to Exercise Your Rights
Primary Contact: Please contact your financial advisor (the data controller) first. If unresponsive, contact our Privacy Officer at legal@myprospera.ai.
11.3 Response Timeline
- GDPR: 30 days (extendable by 60 days)
- PIPEDA: 30 days (extendable by 30 days)
- CCPA/CPRA: 45 days (extendable by 45 days)
11.5 Right to Lodge a Complaint
- Canada: Office of the Privacy Commissioner (priv.gc.ca)
- Quebec: Commission d'accès à l'information (cai.gouv.qc.ca)
- California: California Attorney General (oag.ca.gov/privacy)
- EEA: Your local Data Protection Authority
Cookies and Similar Technologies
12.1 Types of Cookies We Use
- Strictly Necessary: Required for website operation, security, and authentication
- Functional: Enable enhanced functionality like preferences and language
12.2 Cookie Consent
When you visit our website, you will see a granular cookie banner meeting Quebec's opt-in standard and CCPA Do-Not-Sell/Share requirements. You can accept all, reject non-essential, customize preferences, or withdraw consent at any time.
Children's Privacy
The Platform is not directed to individuals under 13. Prospera does not knowingly collect personal information from children under 13. If we become aware of such collection, we will delete it promptly.
Changes to This Privacy Policy
We may update this Policy from time to time. We will post the updated Policy with a new effective date, notify registered users via email at least 30 days before changes take effect, and provide enterprise customers with 60 days advance notice.
Third-Party Audit Rights
Enterprise customers have the right to audit Prospera's compliance. Audit rights include annual audits upon 30 days written notice and additional audits in response to suspected breaches. SOC 2 Type II reports are available under NDA as an alternative.
Data Processing Addendum
Enterprise customers may execute a Data Processing Addendum (DPA) including detailed processing descriptions, Standard Contractual Clauses, security measures, sub-processor management, and data return/deletion procedures. Contact legal@myprospera.ai to execute a DPA.
Compliance and Certifications
17.1 SOC 2 Type II
Status: Controls implemented; audit scheduled for Q2 2026. Covers Security, Availability, Confidentiality, and Privacy trust services criteria.
17.2 Other Frameworks
- GDPR: Full compliance for EEA resident data
- CCPA/CPRA: Compliance with California privacy requirements
- PIPEDA: Compliance with Canadian federal privacy law
- Quebec Law 25: Compliance in progress (Q3 2026)
- ISO 27001: On roadmap (expected Q4 2026 – Q1 2027)
Contact Information
Privacy Officer
Prospera AI Inc.
5343 Dundas St West, Toronto, ON M9B 6H8, Canada
- Email: legal@myprospera.ai
- General Inquiries: support@myprospera.ai
- Data Protection Officer: dpo@myprospera.ai
- Security Matters: security@myprospera.ai
This Privacy Policy was last updated on January 1, 2026.