Privacy Policy
Brook Wagman Wealth Management & Financial Planning
Effective Date: May 3, 2026
Last Updated: May 3, 2026
1. Introduction & Regulatory Positioning
Brook Wagman Wealth Management & Financial Planning (“Brook Wagman,” “we,” “our,” or “us”) operates in a regulatory environment where privacy is inseparable from fiduciary responsibility, client trust, and financial compliance. The information we collect is not incidental—it is required to deliver appropriate, compliant, and defensible financial advice.
- Our privacy practices are governed by a combination of Canadian federal and provincial legislation, including PIPEDA and applicable provincial laws such as Québec Law 25, Alberta PIPA, and BC PIPA, all of which impose strict requirements around consent, transparency, and accountability in the handling of personal information.
- Because our communications and digital systems may interact with individuals outside Canada, we also align our practices with GDPR requirements for EU residents and CAN-SPAM obligations for U.S.-based communications, ensuring that cross-border engagement does not create compliance gaps.
- In addition to privacy-specific legislation, we operate under financial regulatory frameworks that require the collection, verification, and retention of personal information, including KYC, AML, and audit obligations that cannot be waived even if a client relationship ends.
- This policy reflects the actual operational reality of how data is collected, processed, stored, and governed across our systems, rather than serving as a high-level or marketing-oriented summary.
2. Definition & Classification of Personal Information
Personal information within Brook Wagman extends beyond basic identifiers and includes any data that contributes to understanding an individual’s financial position, behavior, or advisory profile.
- Personal information includes foundational identifiers such as name, contact details, and date of birth, but also extends to highly sensitive financial disclosures, including income, assets, liabilities, and investment account details, all of which are required to construct appropriate financial strategies.
- We collect and maintain tax-related and regulatory information, including identifiers such as SIN where legally required, as well as tax residency and reporting data necessary to meet compliance obligations with governing authorities.
- Behavioral and digital interaction data, such as website usage, email engagement, and communication history, is treated as personal information when it can be associated with an identifiable individual and used to inform communication or advisory decisions.
- Inferred data, including segmentation categories and advisory insights derived from client inputs, is also considered personal information because it reflects conclusions about an individual’s financial situation or preferences.
- Information is managed using a tiered sensitivity model, where financial and tax data are subject to heightened safeguards, restricted access, and stricter consent requirements due to the potential impact of misuse or unauthorized disclosure.
3. Methods of Collection
The collection of personal information is conducted deliberately and through defined channels to ensure relevance, accuracy, and compliance with legal requirements.
- Information is primarily collected through direct interactions with clients and prospective clients, including consultations, onboarding processes, and ongoing advisory engagements, where individuals provide information necessary to assess their financial position and objectives.
- These interactions are documented in secure systems, including CRM platforms and internal records, to ensure continuity, accuracy, and compliance with regulatory documentation requirements over time.
- Digital interactions contribute additional layers of data, including technical information such as IP address, device type, and browsing behavior, which help us understand how individuals engage with our website and digital content.
- CRM and marketing automation systems are used to capture and organize interaction data, including communication history, engagement with emails and resources, and consent status, enabling structured relationship management and the delivery of relevant communications.
- In certain cases, information is obtained from third parties such as financial institutions, custodians, or referral partners, but only where appropriate consent has been obtained or where collection is required for regulatory or operational purposes.
- Publicly available sources may be used to verify or supplement information in specific contexts, such as compliance or due diligence, but are not used as a primary method of data collection.
- At all times, collection is limited to what is necessary for defined purposes, and we do not gather information speculatively or without a clear connection to service delivery, compliance, or legitimate business operations.
4. Purpose of Use & Processing
Personal information is used in a controlled and purpose-driven manner, with each use tied to a defined operational or regulatory requirement.
- Information is used to deliver core financial advisory services, including the development of financial plans, construction and management of investment portfolios, and ongoing monitoring to ensure that recommendations remain suitable as circumstances evolve.
- Regulatory compliance requires the use of personal information to verify identity, assess risk, monitor transactions, and maintain records that may be subject to audit or review by governing bodies, and these obligations persist regardless of the status of the client relationship.
- Communication functions rely on personal information to provide updates, reports, and responses to inquiries, ensuring that clients receive timely, relevant information about their financial situation and advisory relationship.
- Marketing and educational communications are delivered using personal information in a structured, consent-based manner, enabling targeted outreach aligned with individual interests and engagement history, rather than broad, untargeted messaging.
- Internal business operations may use personal information to analyze performance, identify trends, and improve services, with appropriate controls in place to ensure that such use remains aligned with the original purpose of collection.
- Personal information is not used for purposes incompatible with the original purpose unless additional consent is obtained and the individual is fully informed of the new use.
5. Consent & Control
Consent is treated as a continuous and meaningful process rather than a one-time event, ensuring that individuals remain aware of and in control of how their information is used.
- Consent is obtained through clear and transparent mechanisms at the point of collection, including onboarding documentation, digital forms, and subscription processes, each of which explains what information is being collected and how it will be used.
- Express consent is required for the collection and use of sensitive financial information, as well as for marketing communications where no existing business relationship establishes implied consent under CASL.
- Implied consent may be relied upon in situations where an ongoing client relationship exists and the use of information is reasonably expected, but this is applied conservatively and does not extend to unrelated or secondary uses.
- For individuals subject to GDPR, processing may also be based on legal obligations, contractual necessity, or legitimate interests, provided that such interests are balanced against the rights and expectations of the individual.
- Individuals have the right to withdraw consent at any time, and mechanisms are provided to facilitate this, including unsubscribe options and direct communication channels, although withdrawal may limit our ability to provide certain services or meet regulatory obligations.
6. Marketing Communications & Automation
Marketing communications are managed within a strict compliance framework that prioritizes consent, transparency, and relevance.
- All commercial electronic messages are sent in compliance with CASL, ensuring that consent is obtained and documented, sender identification is clear, and recipients are provided with a functional, easily accessible unsubscribe mechanism that is processed within the required timelines.
- Communications that may reach U.S.-based individuals are structured to comply with CAN-SPAM requirements, including accurate sender identification, non-deceptive subject lines, and prompt honoring of opt-out requests.
- For individuals in GDPR jurisdictions, marketing communications are based on explicit opt-in consent, and individuals are informed of any profiling or segmentation used to tailor communications, with the ability to object at any time.
- Marketing automation systems are used to manage communication delivery, segment audiences, and track engagement, allowing for more relevant and efficient communication while maintaining full visibility into consent status and communication history.
- Engagement data, such as email opens, clicks, and content interactions, may be used to refine communication strategies and improve relevance, but is always handled within the boundaries of disclosed purposes and applicable regulations.
- Automated processes are designed and monitored to ensure that they do not result in excessive, intrusive, or inappropriate communication, and all marketing activities are subject to oversight and periodic review.
7. Data Security & Safeguards
The protection of personal information is implemented through a layered approach that addresses technical, operational, and physical risks.
- Technical safeguards include encryption of data in transit and at rest, access controls that restrict information based on role and necessity, and system monitoring designed to detect and prevent unauthorized access or activity.
- Operational safeguards involve staff training, confidentiality agreements, and clearly defined policies governing the handling, use, and disclosure of personal information, ensuring that all personnel understand their responsibilities.
- Access to systems and data is controlled through authentication protocols and permissions that limit exposure to only those individuals who require access to perform their duties.
- Physical safeguards, where applicable, include secure storage of documents, controlled access to office environments, and procedures for the secure disposal of physical records.
- Security measures are regularly reviewed and updated to address evolving risks, technological changes, and regulatory expectations, ensuring that protection remains aligned with current standards.
8. Data Retention & Lifecycle Management
Personal information is retained only for as long as necessary to fulfill its intended purpose and meet regulatory obligations.
- Financial services regulations require that certain records be retained for defined periods, even after the end of a client relationship, and these requirements take precedence over deletion requests where applicable.
- Outside regulatory requirements, retention is assessed on operational necessity, ensuring information is not retained longer than required for service delivery, communication, or analysis.
- When personal information is no longer needed, it is either securely deleted or anonymized, removing any ability to link the data to an identifiable individual.
- Disposal methods are aligned with the data format, ensuring that digital records are permanently removed and physical documents are destroyed in a manner that prevents reconstruction or unauthorized access.
9. Accountability & Governance
Privacy accountability is formally structured and actively managed within Brook Wagman to ensure that responsibilities are clear and enforceable.
- A designated Privacy Officer is responsible for overseeing compliance with this policy, managing access requests, handling complaints, and ensuring that privacy practices are consistently applied across the organization.
- Internal policies, procedures, and training programs are implemented to ensure that all staff understand and adhere to privacy requirements, with ongoing education to address changes in regulations or practices.
- Regular reviews and assessments are conducted to evaluate compliance, identify gaps, and implement improvements, ensuring that privacy practices remain effective and aligned with expectations.
- Third-party service providers are subject to due diligence and ongoing oversight, including contractual requirements that mandate the protection of personal information and adherence to applicable privacy standards.
10. Contact & Access Requests
Individuals have the right to access their personal information, request corrections, and raise concerns regarding how their data is handled.
- Requests for access or correction will be reviewed and responded to in accordance with applicable legal requirements, including identity verification and adherence to required timelines.
- Concerns or complaints related to privacy practices will be investigated and addressed in a manner that reflects both regulatory obligations and our commitment to maintaining client trust.
- All inquiries should be directed to the designated Privacy Officer using the contact information provided below.
Privacy Officer:
Brook Wagman Wealth Management & Financial Planning
80 Richmond St W, Suite 508
Toronto, Ontario
M5H 2A4, Canada