Privacy Policy
This policy explains what personal information the practice collects, why, who it goes to, how long it is kept, and how to see it, correct it or have it deleted. It is written under Quebec's Law 25 and the federal Personal Information Protection and Electronic Documents Act, and the person responsible for the protection of personal information is named in it.
Quebec's Law 25 requires a second document alongside this one. The rules governing how the practice ensures this policy is followed are published at governance of personal information.
This policy covers personal information handled by Canadian Wealth Creation Centre Inc., trading as IBC Financial, whether it reaches the practice through this website, a conversation, a form, or an insurance application.
It is written under Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25, and under the federal Personal Information Protection and Electronic Documents Act. Those are the frameworks that apply to a practice based in Quebec dealing with clients across several provinces. It is not written against the European regime, and it does not reuse European wording, because the obligations differ in ways that matter.
The person responsible
One person carries this responsibility here, and both her name and the means of reaching her appear below. A name published without a way of reaching it is not a contact detail, and it is not what the legislation asks for.
Law 25 requires that a named person be responsible for the protection of personal information within the organisation, and that the name and contact details be published.
Mona Haddad, Canadian Wealth Creation Centre Inc., 203-3899 Autoroute des Laurentides, Laval, Quebec H7L 3H7. Telephone 514-875-9444.
A request may be made in writing or by telephone. No reason is required for any request described in this policy, and none will be asked for.
The three groups of people this policy covers
The information handled differs greatly depending on which of these you are, and grouping them together is how privacy policies become unreadable.
A visitor to this website who reads and leaves. Almost no information is handled. See the section on website visitors below.
A person who makes an enquiry, requests a meeting, or has a first conversation. Contact details and whatever is discussed.
A client, meaning someone for whom an insurance application is prepared or a policy is placed. Substantially more, because a suitability assessment and an insurance application both require it.
What is collected: website visitors
The consent record. Your choice about what may load in your browser, stored on your own device, never transmitted. Described in full in the cookie and consent policy.
Server logs. The server records the address a request came from, the page requested, the time, and the browser identifier your software sends. This happens at the network level on every website and no consent notice can prevent it. These records exist for security and for diagnosing faults, are not used to build a profile of any individual, and are not combined with anything else.
Nothing else is collected from a visitor who does not submit anything. There is no analytics running at present, which is stated in the cookie policy and is verifiable from your own browser.
What is collected: enquirers
From the form on the discovery meeting page:
- your name
- your email address
- your telephone number, if you provide one
- whether you currently live in Canada
- whether you are a licensed insurance professional
- anything you write in the message field
The two questions are asked for stated reasons that appear beside them on the form. Residency determines whether a conversation can usefully happen, because these contracts are available to residents of Canada and the advisor is licensed in three provinces. The professional question determines which of two different conversations applies.
Citizenship and immigration status are not collected. They are neither necessary for the purpose nor appropriate to ask, and the residency question establishes what is actually needed.
What is collected: clients
Before any recommendation can be made, a suitability assessment is required. This is a regulatory obligation rather than a commercial preference, and it is the reason the information requested is more detailed than a first conversation suggests.
Identity and contact information. Name, date of birth, address, telephone, email, and identification where an insurer requires it.
Financial circumstances. Income, assets, liabilities, expenditure, existing insurance coverage, registered contribution room, and corporate structure where relevant.
Objectives and circumstances. What the money is for, time horizon, family situation, dependants, and business arrangements where relevant.
Health and lifestyle information, where an insurance application is made. This is collected by, and for, the insurer as part of underwriting. It may include medical history, current treatment, family medical history, occupation, travel, and activities the insurer prices for. An insurer may also request records from a physician or arrange an examination.
Health information is sensitive information under both Law 25 and PIPEDA. It is collected only where an application is being made, it is used only for that application, and it is not used for marketing under any circumstances.
Why it is collected
Each purpose is stated separately, because consent is meaningful only against a stated purpose.
To answer an enquiry and arrange a meeting. Contact details, used for the thing you asked for.
To assess suitability. A licensed advisor may not recommend an insurance product without establishing that it suits the client's circumstances. This is the purpose behind most of what is asked of a client.
To prepare and submit an application. An insurer requires the information it requires, and an application cannot proceed without it.
To service a policy in force. Annual reviews, changes, claims support, and correspondence about a contract you own.
To meet legal and regulatory obligations. Record keeping, regulatory inspection, and obligations under anti-money-laundering legislation where they apply.
To send educational material by email, and only where you have separately and expressly agreed to that. It is a distinct purpose with a distinct consent, and it is never bundled with any of the above.
Consent, and how it is obtained
Express consent is obtained where information is sensitive, where it is used for marketing, and where it is shared beyond what a client would reasonably expect. It is obtained separately for each purpose rather than through a single acceptance.
Implied consent is relied upon only for the obvious: replying to a message you sent, using a telephone number you provided to telephone you about the thing you asked about.
Consent for marketing is always separate. On the discovery meeting form, asking to be contacted about a meeting and agreeing to receive educational material are two distinct checkboxes, and the second is not required to submit the first. Bundling them would be simpler and would not be valid.
Withdrawing consent. Marketing consent may be withdrawn at any time, using the link in any message or by contacting the person named above. Withdrawal takes effect promptly and does not affect communications necessary to service a policy you own, which are not marketing.
Consent to the collection required for a suitability assessment cannot meaningfully be withdrawn while a recommendation is being sought, because the recommendation cannot lawfully be made without it. It can be withdrawn by ending the process, at which point retention rules below apply.
Who information is shared with
The recipients relevant to your own file are named to you on request, including the insurer holding your contract and any managing general agency involved in placing it. The categories below set out who may receive information about you, and on what footing they receive it.
Insurers. Where an application is made, information goes to the insurer issuing the contract. The insurer becomes responsible for it under its own policy, which is a separate document from this one and worth reading.
A managing general agency, where one is involved in placing business.
Reinsurers and the industry information exchange, where an insurer uses them as part of underwriting. This is standard practice in Canadian life insurance and is disclosed on the application you sign.
Service providers who support the practice, such as those providing email, document storage, scheduling or file management. Each acts on instruction and not for its own purposes.
Your other professionals, meaning your accountant or legal advisor, only on your instruction and only to the extent you direct.
Regulators and authorities, where required by law, by a regulator exercising its powers, or by a court.
Information is not sold. It is not traded, not rented, and not provided to anyone for their own marketing.
Information handled outside Quebec
Personal information is not communicated outside Quebec without an assessment of privacy factors carried out first. That is the rule this section states, and it applies to a service provider storing or processing information elsewhere as much as to anything else.
Law 25 requires an assessment before personal information is communicated outside Quebec, and requires that this be disclosed. Where a provider operates outside the province, the assessment considers the sensitivity of the information, the purpose, the protections in place, and the legal framework applying where it is held.
The arrangements that apply to your own file are identified to you by the person responsible on request, rather than described in general terms, because a general description tells a reader nothing they can act on.
Automated processing
This is a question worth putting directly to any practice, because the answer is rarely volunteered and the right to ask for a human review depends on it.
Law 25 requires that a person be informed where a decision is based exclusively on automated processing, and gives them the right to submit observations and to request a review by a person.
Where an insurer uses automated underwriting, that is the insurer's process and its own policy governs. Where anything of that kind operates within this practice, it will be described here specifically, including what it does, what it does not do, and how to ask for a human review.
No automated system makes a recommendation at this practice at the date of this policy. Recommendations are made by a licensed advisor who has read the file.
Retention
Personal information is retained only for as long as the purpose it was collected for requires, and for the periods set by insurance regulation and by professional obligation. The period applied to your own file is stated to you on request rather than left behind a phrase such as "as long as necessary".
Records relating to insurance advice and placement are retained for periods required by applicable regulation, which are measured in years after a relationship ends rather than months. Records relating to an enquiry that did not proceed are retained for a much shorter period.
When a period ends, information is destroyed or anonymised. It is not archived indefinitely on the grounds that storage is inexpensive.
The consent record on your own device is not held by the practice at all and is removed when you clear your browser storage.
Security
Information is protected by measures appropriate to its sensitivity, which for health and financial information means the higher end of that range.
Transmission of anything submitted through this website is encrypted. Access within the practice is limited to those who need it for a stated purpose. Paper records, where they exist, are held securely. Service providers are selected with their security arrangements in mind, and are bound to use information only on instruction.
No arrangement is perfect and a policy claiming otherwise would be worth distrusting. What can be said is that the measures are proportionate, that they are reviewed, and that a failure would be handled as described in the next section rather than concealed.
If something goes wrong
Law 25 uses the term confidentiality incident: unauthorised access, use or communication of personal information, or its loss.
Where an incident occurs and presents a risk of serious injury, the practice will notify the Commission d'accès à l'information and the individuals concerned promptly, take reasonable measures to reduce the risk, and maintain a register of incidents as required.
Notification will describe what happened, what information was involved, what is being done, and what you can do. It will not be written to minimise.
Your rights
Each of these is exercised by contacting the person named at the top of this page. No reason is required and none will be requested.
Access. You may ask what personal information is held about you and receive a copy. A response is provided within thirty days.
Correction. You may have inaccurate, incomplete or ambiguous information corrected. If a correction is refused, you are told why and how to challenge it.
Withdrawal of consent. For anything relying on consent, including marketing.
Deletion. You may ask for information to be deleted where it is no longer needed for the purpose it was collected for and where no legal or regulatory requirement obliges its retention. Where a request cannot be granted in full, the reason is given.
Portability. Since September 2024, Law 25 gives a right to receive computerised personal information you provided in a structured, commonly used technological format, or to have it communicated to another organisation.
Ceasing dissemination. You may request that information be de-indexed or that its dissemination cease, in the circumstances the legislation provides for.
Complaint. Described below.
Complaints
Raise it with the person named at the top of this page first, in writing or by telephone. A complaint is acknowledged, examined, and answered with reasons.
If the answer does not resolve it, the right to go further is unaffected by anything in this policy:
In Quebec, the Commission d'accès à l'information du Québec.
Elsewhere in Canada, the Office of the Privacy Commissioner of Canada.
Regarding insurance conduct rather than privacy, the applicable regulator: the Autorité des marchés financiers in Quebec, the Financial Services Regulatory Authority of Ontario, or the Insurance Council of British Columbia.
Nobody can sign away a right to complain to a regulator, and this policy does not ask you to.
Children
Services described on this website are directed to adults, and no part of this site is aimed at children. Information about a child is collected only in the context of an application in which a child is an insured or a beneficiary, and only from a parent or guardian entitled to provide it.
The French property
The practice's French-language property is a separate website with its own privacy notice, written for Quebec rather than translated from this one. Where you have dealt with the practice in French, the French version applies.
Changes to this policy
This policy may be amended. The version in force is the one published here, and the review date is shown on this page. Where a change materially affects how information is handled, it will be brought to the attention of those affected rather than published quietly.
What happens at each stage of the relationship
The clearest way to understand what is held about you is to follow the stages, because the answer changes at each one.
You read the site and leave
The consent record sits on your device. A server log entry exists. Nothing identifies you, nothing is retained about you by the practice, and there is nothing to request access to.
You submit the form
Six fields, listed above, arrive at the practice. They are used to arrange and prepare for a conversation. If no meeting happens and you do not respond further, they are deleted after the short retention period stated above.
If you ticked the marketing box, your email address is also held for that separate purpose until you withdraw.
You have a discovery meeting
Notes of the conversation are made. They record what you said you were trying to do, what already exists, and whether the approach appeared to fit. If the conversation concludes that it does not fit, the file closes there.
You complete a suitability record
This is the largest single expansion in what is held, and it is the point at which it is worth asking questions rather than after.
You decide what to provide. Providing less is permitted and produces a narrower recommendation, because a recommendation can only be made against what is established. What you provide is used to assess suitability and for nothing else, and it is not shared outside the practice at this stage.
A recommendation is made
The recommendation, the reasoning behind it, and the information relied upon are recorded together. That record protects you as much as it protects the practice: if a question arises years later about why something was recommended, the answer exists in writing rather than in somebody's memory.
An application is submitted
Information now goes to the insurer, including health information collected for underwriting. From this point the insurer holds it under its own privacy policy, and the insurer's policy governs what it does with it. That is a separate document and it is worth reading rather than assuming.
The practice retains its own copy of what it submitted.
A policy is in force
Contract details, correspondence, review notes and any changes are retained for as long as the policy exists and for the regulatory period after it ends.
The relationship ends
Whether because a policy lapses, is surrendered, is transferred to another advisor, or because you simply stop, the regulatory retention period begins to run. At its end, records are destroyed or anonymised.
Ending the advisory relationship does not affect a policy in force, and does not affect your right to request access to what is still held.
Questions worth asking any practice about privacy
These are worth asking here and worth asking anywhere else you are considering, because the answers vary more than most people expect.
Who is the named person responsible? Law 25 requires one and requires the name to be published. A practice that cannot name theirs has not done the work.
How long is my information kept after I leave? A specific number of years, or an evasion.
Which third parties receive it, by name? Categories are easy. Names are the test.
Is anything held or processed outside Quebec, or outside Canada? If so, what assessment was done.
Is any part of the assessment automated? And if so, how do I ask for a human review.
What happens if there is a breach? Whether the answer mentions the Commission d'accès à l'information and notification, or stays general.
This policy answers all six in the sections above, and where an answer turns on your own file the person responsible gives it by name and in writing. That is itself the answer to a seventh question nobody asks: whether anyone here will put it in writing at all.
How this policy relates to the insurer's
Two organisations hold information about a client, and they are governed separately.
This practice holds what it collected: contact details, the suitability record, notes, correspondence, and a copy of what was submitted.
The insurer holds the application, the underwriting file including health information, the contract, and everything arising from it. The insurer's privacy policy governs that, and its retention periods, its service providers and its cross-border arrangements are its own.
A request to this practice reaches this practice's records. A request about an insurer's file goes to the insurer, and the practice will tell you where to send it rather than leaving you to find out.
This distinction matters most at a claim, when a beneficiary is dealing with an insurer rather than with an advisor, and it is worth understanding before it arises.
Marketing, in specific terms
Because this is where most complaints originate.
No email is sent for marketing without express consent obtained separately, as Canada's anti-spam legislation requires.
Every marketing message identifies the sender and carries an unsubscribe mechanism that works and is honoured promptly.
Withdrawal is honoured across the practice, not only for the particular message it came from.
Service messages are not marketing. An annual review reminder, a notice about a contract you own, or an answer to a question you asked are communications about your own affairs, and they continue after a marketing withdrawal because they are not the same thing.
Your information is not used to target advertising elsewhere, and no advertising technology is running on this website at present, which the cookie policy describes and which you can verify yourself.
Referral to another professional is not a transfer of your information. If you are given a name, you are given a name. Nothing about you goes to them unless you ask for it to.
How to make a request, step by step
Written out because a right that is difficult to exercise is a right in name only.
Step one. Write or telephone. Use the name and contact details at the top of this page. A letter, an email or a telephone call are equally valid. There is no form to complete and no template to follow.
Step two. Say what you want. Access, correction, deletion, withdrawal of consent, portability, or a complaint. If you are unsure which applies, describe the outcome you want and it will be identified for you.
Step three. Identity. Enough information to establish that you are who you say you are, which protects you rather than the practice. Where information is sensitive, the check is correspondingly careful.
Step four. A response within thirty days. Law 25 sets that period and it is adhered to. Where a request is complex, you are told so within the period rather than after it.
Step five. If refused. A refusal is given in writing, with the reason and the provision relied upon, and with information about how to challenge it. A request is not refused for being inconvenient.
There is no charge for a first request. Where a request is repetitive or requires substantial transcription, a reasonable fee may be indicated in advance, and you may decline it and withdraw the request at no cost.
Access requests, in practice
An access request produces more than people expect, and it is worth knowing what it looks like.
What you receive. The personal information held about you, in an intelligible form, together with an explanation of any term or code that would not be understandable on its own. That includes notes recording what was discussed and why something was recommended.
What may be withheld. Information about another identifiable person, where disclosing it would reveal something about them. Information subject to legal privilege. Information whose disclosure would be likely to interfere with a legal proceeding. Where anything is withheld, you are told that it has been and on what basis, rather than receiving a file with silent gaps.
What is not held. If the answer is that little or nothing is held, that is the answer, and it is given plainly rather than dressed up.
Correction requests, in practice
What can be corrected. Anything inaccurate, incomplete or ambiguous. A date of birth, an income figure, a note recording something you did not say.
What cannot simply be deleted. A record of advice given is a record of what happened, and it exists partly to protect you. Where you disagree with an opinion recorded rather than a fact, the response is to record your disagreement alongside it rather than to erase the original.
Where a correction has already been passed on. If inaccurate information was shared with an insurer before the error came to light, the correction is communicated to them too, and you are told that it has been.
Deletion, and its limits
Deletion is often assumed to be absolute and it is not, so the limits are stated here rather than discovered during a request.
What can be deleted. Enquiry records that did not proceed. Marketing contact details, on withdrawal. Information no longer needed for the purpose it was collected for, where no obligation requires keeping it.
What cannot, while an obligation subsists. Records of insurance advice and placement are subject to regulatory retention periods. Anti-money-laundering obligations apply their own periods where relevant. A request to delete such a record is refused with the reason and the period stated, and it is honoured when the period ends.
What is genuinely gone. When a retention period expires, records are destroyed or anonymised. Anonymised means the information can no longer be associated with you, and Law 25 sets a standard for that which is higher than simply removing a name.
A note on what a privacy policy cannot tell you
It cannot tell you whether it is being followed.
Every policy of this kind is a description of intended practice. The reader has no way to verify most of it from outside, which is precisely why so many are written in a way that says very little while appearing thorough.
Three things partially close that gap, and they are the reason this document is written the way it is.
Specificity. A policy naming recipients, stating retention in years, and identifying cross-border arrangements can be checked against reality by anyone inside the organisation and can be held to account by a regulator. A policy of generalities cannot be wrong, which is the problem with it.
A named person. A policy giving a name and the means of reaching it can be tested by anyone who uses them, and the answer comes back from someone who is answerable for it. A general enquiry form cannot be tested that way, because nobody in particular is answerable for what goes into it.
One verifiable claim. The statement that nothing third-party loads on this website before you consent is checkable from your own browser in about a minute, and the cookie policy explains how. It is the only claim in this whole area a visitor can independently confirm, which is why it is stated plainly and why it would be foolish to state it if it were not true.
The rest rests on the practice doing what it says. That is the honest position, and a policy claiming otherwise is claiming something no policy can deliver.
Information about people who are not you
Two situations arise regularly and neither is obvious.
A beneficiary. Naming someone as a beneficiary means providing their information to an insurer. They may not know. Where a designation is made, the person named acquires rights under the contract and their information is held by the insurer in connection with it. It is worth telling them, both because it is courteous and because a beneficiary who does not know a policy exists cannot claim on it, which is a more common problem than it should be.
A spouse, a business partner, or a child. A suitability assessment often involves information about people other than the client: a spouse's income, a partner's shareholding, a child's circumstances. Provide only what is needed, and be aware that you are providing information about someone else. Where that person is also a client, their own record is kept separately and their rights under this policy are their own.
Where two people are advised together, each is entitled to access their own information. Neither is automatically entitled to the other's, and if that becomes a live question it is resolved before a recommendation is made rather than afterwards.
What happens to a file after a death
A subject rarely covered in a privacy policy and frequently needed.
On the death of a person insured, a beneficiary deals with the insurer for the claim. The practice will assist with the process where asked, and will provide a beneficiary with information necessary to make the claim.
A beneficiary is not automatically entitled to the deceased's whole file. What is provided is what relates to the contract and the claim. Broader access is a matter for the estate representative, in accordance with the applicable legislation, and the practice will follow that rather than deciding it informally.
Records relating to a deceased client are retained for the applicable regulatory period, which runs from the end of the relationship rather than from the death.
If the practice is sold or reorganised
No such arrangement is contemplated at the date of this policy. The paragraphs below state what would apply if one ever were.
Where a practice is transferred, personal information necessary to continue servicing existing contracts may be transferred with it. Clients would be notified. A transfer of that kind does not permit the recipient to use information for purposes beyond those it was collected for, and a marketing consent given to this practice does not transfer as a marketing consent to another.
A policy in force is unaffected by any of this. The contract is between the client and the insurer.
Contact, in one place
For any request, question or complaint under this policy:
Mona Haddad, person responsible for the protection of personal information Canadian Wealth Creation Centre Inc. 203-3899 Autoroute des Laurentides, Laval, Quebec H7L 3H7 Telephone 514-875-9444
Email: info@cwcc.ca. A request may be made by email, by telephone or by post, and all three reach the person responsible. A telephone number and a postal address are sufficient in law; an email address is what most people will actually use, which is why one is published here alongside them.
What this policy deliberately does not do
It does not claim rights over information you have not given. There is no clause permitting collection from other sources beyond what an insurer requires for underwriting, disclosed on the application you sign.
It does not reserve a right to sell or share for others' marketing. Many policies do. This one says the opposite in plain terms.
It does not use "as long as necessary" as a retention period. That phrase communicates nothing. Retention here is governed by the purpose, by insurance regulation and by professional obligation, and the period applied to your own file is given to you on request.
It does not describe categories of recipient without naming them. The recipients holding information from your own file are named to you on request by the person responsible.
It does not borrow European wording. Law 25 and PIPEDA are the applicable frameworks and this policy is written against them. Borrowed wording is easy to spot once you know the signs: references to a lawful basis, to legitimate interests, to a data protection officer rather than a person responsible, or to a supervisory authority rather than the Commission d'accès à l'information. None of those terms belongs in a Canadian policy, and a document using them was assembled rather than written.
It does not treat consent as a single event. Consent here attaches to a purpose, and there are several purposes, so there are several consents. A single acceptance covering everything is administratively convenient and is not what the legislation contemplates.
A privacy policy is one of the few documents where the gap between what is written and what is done is invisible to a reader. The only useful response to that is specificity, and a named person who answers for it in writing.
A thirty-minute discovery meeting
A first conversation establishes whether this fits. No illustration is prepared and nothing is arranged.
Often the answer is no, and you will hear it during the call rather than in a proposal afterwards.
This form reaches Canadian Wealth Creation Centre Inc. Any meeting, any advice and any insurance product is provided by Canadian Wealth Creation Centre Inc., through its representatives certified by the Autorité des marchés financiers. IBC Financial is the company's education platform: it distributes no product and no financial service, and it gives no individualised advice.
Common questions
Who is the person responsible for the protection of personal information?
What is the legal basis for collecting my personal information?
How is my personal information used?
How is my personal information protected?
How long is my personal information kept?
When is my information shared or disclosed?
How do I ask to see what is held about me?
Can I have my information deleted?
Is any decision about me made by an automated system?
Am I giving you information about other people?
How is information about my health handled?
Last reviewed 2026-08-21.
Get Started