Privacy Policy

Solomon Financial Privacy Policy & Compliance Program

Purpose

To establish Solomon Financial’s privacy governance, accountability, consent, collection, use, disclosure, safeguarding, retention, individual access, complaint handling and breach-response expectations for personal information handled in the course of insurance, segregated fund/IVIC, client service, advisor support, employment, marketing, technology, compliance and business operations.

Area of Impact

This policy applies to Solomon Financial Corporation, its Advisors, Staff, contractors, sub-contractors, authorized assistants, service providers and anyone who collects, uses, discloses, accesses, stores, transmits, receives, reviews or disposes of personal information on behalf of Solomon Financial or under the Solomon Financial banner.

Source Alignment

  • Solomon Financial Best Practices format, privacy/data breach procedure, advisor-to-client data transfer requirements, cloud storage requirements, clean desk, email, password, AI and marketing controls.
  • HUB Financial audit feedback requiring a complete Privacy Policy and Privacy Compliance Program, reviewed at least every two years and properly documented.
  • PIPEDA fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access and challenging compliance.
  • Alberta PIPA and substantially similar provincial privacy laws, including Alberta OIPC resources for private-sector organizations and breach response.
  • Quebec private-sector privacy obligations where Solomon, Advisors or service providers carry on business in Quebec or handle Quebec-resident information.
  • Applicable insurance, segregated fund, insurer, HUB Financial, AML/ATF, CASL and data-retention requirements.

Guiding Principle: Client and employee personal information must be treated as confidential, collected only for reasonable identified purposes, used or disclosed only as authorized, protected according to sensitivity, retained only as required, and disposed of securely when no longer required.

Definitions:

Term Meaning
Personal Information Information about an identifiable individual, including direct identifiers and information that can reasonably identify a person when combined with other information.
Sensitive Information Information requiring enhanced protection, such as SIN, date of birth, financial account details, health/medical information, insurance applications, beneficiary information, government ID, void cheques, banking information, tax/legal documents, vulnerability indicators and client file notes.
Client Personal Information Personal information about clients, prospects, beneficiaries, policyholders, applicants, attorneys, trustees, authorized representatives and related persons.
Employee / Advisor Personal Information Personal information about Staff, Advisors, contractors and applicants collected for employment, affiliation, licensing, contracting, compliance, payroll, security or operational purposes.
Privacy Incident Any event where personal information may have been lost, accessed by, disclosed to, used by or retained by an unauthorized person.
Privacy Breach A confirmed privacy incident involving unauthorized access to, use, disclosure, loss, theft or compromise of personal information.

Privacy Governance and Accountability

  • Solomon Financial will designate a Privacy/Compliance Officer or Privacy Compliance Lead with authority to oversee privacy compliance, breach response, privacy complaints, privacy training, vendor/privacy reviews and periodic policy updates.
  • The Privacy/Compliance Officer may delegate operational tasks, but Solomon remains accountable for personal information under its control, including information handled by service providers or authorized assistants.
  • Advisors remain individually responsible for handling client information in accordance with applicable law, insurer/HUB requirements, Solomon Best Practices, client consent and professional obligations.
  • Privacy governance records must include policy versions, annual/two-year reviews, incident logs, access requests, complaint records, training registers, vendor review evidence and implemented corrective actions.
  • Material privacy issues must be escalated to Solomon leadership and, where required, HUB Financial, insurer compliance, legal counsel, privacy regulators, E&O carrier or applicable regulators.

Privacy Principles

Principle Solomon Requirement
Accountability Assign privacy responsibility, maintain policies/procedures, train personnel and monitor compliance.
Identifying Purposes Identify why information is collected before or at the time of collection.
Consent Obtain meaningful consent unless collection, use or disclosure is permitted or required by law.
Limiting Collection Collect only what is reasonably necessary for identified purposes.
Limiting Use, Disclosure and Retention Use, disclose and retain information only for the purpose collected, a compatible authorized purpose, or as otherwise permitted/required by law.
Accuracy Keep personal information as accurate, complete and current as required for its use.
Safeguards Protect information using physical, organizational and technological safeguards appropriate to sensitivity.
Openness Make privacy practices available to clients and other individuals on request and through approved public notices.
Individual Access Provide access and correction rights subject to legal, regulatory, confidentiality and privilege limits.
Challenging Compliance Maintain a process to receive, investigate and respond to privacy complaints.

What Information may be Colletcted

Category Examples
Identity and contact Name, address, telephone, email, date of birth, government ID as required, occupation, employer.
Financial and insurance Income, assets, liabilities, banking, policy/account numbers, investment objectives, risk tolerance, source of funds, tax and estate information.
Health and underwriting Medical, lifestyle and underwriting information required for insurance applications or servicing.
Family / beneficiary / estate Beneficiary details, dependants, family relationships, attorney/trustee/executor information where relevant.
Compliance and suitability KYC, KYP/Reasons Why, replacement analysis, disclosure acknowledgements, complaint notes, vulnerability indicators, consent records.
Technology and communications Emails, Teams/business messages, meeting notes, e-signature logs, audit trails, IP/device/security logs where collected through approved systems.
Advisor/Staff records Licensing, E&O insurance, contracts, CE/training, payroll, performance administration, access permissions and compliance/audit records.

Permitted Purposes for Collection, Use, and Disclosure

  • Confirm identity, licensing authority, eligibility, suitability and client instructions.
  • Assess needs, prepare recommendations, process applications, service policies/accounts, support claims, process transactions and maintain client relationships.
  • Meet insurance, segregated fund/IVIC, insurer, HUB Financial, MGA/dealer, regulatory, AML/ATF, tax, accounting, complaint handling, privacy, cybersecurity and record-retention obligations.
  • Communicate with clients, authorized representatives, insurers, HUB Financial, service providers and regulators as required for legitimate business purposes.
  • Administer Advisor/Staff contracts, payroll, licensing, E&O, training, compliance monitoring, audits and access controls.
  • Detect, prevent and investigate fraud, privacy incidents, cybersecurity issues, suspicious transactions, misconduct, complaints and regulatory inquiries.
  • Send marketing or educational communications only where permitted by CASL, consent, Solomon marketing policies and applicable privacy requirements.

Consent Requirements

  • Consent must be meaningful, informed and documented in a way that is appropriate to the sensitivity of the information and reasonable expectations of the individual.
  • Express consent is required for sensitive information, new uses, disclosures outside the original purpose, marketing where required, and sharing with third parties not reasonably expected by the client unless permitted or required by law.
  • Implied consent may be used only where the purpose is obvious, the information is less sensitive, and the individual voluntarily provides the information for that purpose.
  • Consent language must explain what information is collected, why it is needed, who it may be shared with, consequences of refusing consent, and how consent may be withdrawn subject to legal/contractual limitations.
  • Where a client withdraws consent, the Advisor or Staff member must escalate to determine whether the service can continue and what legal, insurer, regulatory or retention obligations remain.
  • Clients must not be asked to provide personal information through unapproved channels where a secure approved method is available.

Disclosure and Information Sharing Rules

  • Share information only on a need-to-know basis and only for an authorized purpose.
  • Confirm authority before disclosing information to family members, assistants, attorneys, trustees, accountants, lawyers or other third parties.
  • Use Solomon-approved secure systems for transmitting sensitive information, including approved SharePoint/OneDrive/client file structures, approved e-signature processes and secure file transfer methods.
  • Do not use personal email, unapproved cloud storage, personal devices, consumer messaging applications, USB/external drives or public AI tools to collect, store, process or transmit client personal information unless expressly approved and documented by Solomon leadership.
  • When information is shared with a service provider, the relationship must include confidentiality, security, limited-use, breach reporting and return/destruction requirements appropriate to the information involved.
  • Information may be disclosed without consent where permitted or required by law, including specific AML/ATF, fraud, regulatory, court, insurer, E&O, complaint, cybersecurity or emergency circumstances.

Safeguards and Security Controls

Control Area Minimum Requirement
Physical safeguards Clean desk, locked cabinets, secure shredding, no unattended documents, secure printer/fax handling.
Administrative safeguards Need-to-know access, privacy training, confidentiality agreements, access reviews, incident escalation, vendor oversight.
Technical safeguards MFA, strong passwords/password manager, approved cloud storage, device lock, encryption/security settings where available, audit logs and remote wipe where applicable.
Transmission safeguards Validate recipient identity/email, avoid sensitive information by text, use approved secure folders or e-signature/file transfer methods.
AI safeguards No client personal, financial, health, policy/account or identifying information in AI tools unless explicitly authorized under Solomon policy and enterprise controls.
Mobile/remote safeguards Avoid public Wi-Fi for business, tether to cellular when appropriate, upload sensitive information to approved storage and delete local copies.

Retention, Accuracy, and Secure Disposal

  • Personal information must be retained only as long as necessary for the identified purpose and applicable legal, regulatory, insurer/HUB, complaint, AML/ATF, tax, corporate, audit or litigation requirements.
  • Client and compliance records must follow Solomon’s Record Retention Process & Schedule and any applicable litigation/regulatory hold instructions.
  • Advisors and Staff must keep information accurate and current enough for the purpose being served; material changes must be documented in the client file.
  • Secure disposal must be documented where required and must use approved shredding or electronic deletion/destruction processes after confirming no hold or retention requirement applies.
  • Personal information must not be retained in personal email, personal cloud storage, unapproved CRM systems, downloaded local folders, USB/external drives or shadow client lists.

Individual Access, Correction and Privacy Questions

  1. Forward access, correction or privacy inquiries to the Privacy/Compliance Officer/designate promptly.
  2. Confirm identity and authority before releasing information.
  3. Review whether any legal, regulatory, confidentiality, privilege, third-party privacy, complaint, investigation or business-record limitation applies before disclosure.
  4. Provide access or correction response in a reasonable, documented manner consistent with applicable law and Solomon procedures.
  5. Document the request, response, records reviewed, exceptions applied and closure date.

Privacy Incident and Breach Response

  • Report any actual or suspected privacy incident immediately using Solomon’s Privacy/Data Breach Procedure.
  • Preserve evidence and do not delete, alter or overwrite emails, files, messages, logs, screenshots, drafts, affected documents or devices.
  • Contain the incident by changing passwords, disabling access, recalling messages, recovering documents, remote wiping compromised devices or suspending transmission where appropriate and directed.
  • Assess sensitivity of information, number of affected individuals, probability of misuse, real risk of significant harm, insurer/HUB obligations, regulator notification requirements and client notification requirements.
  • Maintain a privacy incident/breach register documenting all incidents, whether or not notifiable, including assessment, decision, corrective action and closure evidence.
  • Notify affected individuals, regulators, HUB Financial, insurers, E&O carrier or other parties where required by law, contract or risk decision approved by leadership/legal counsel.

Privacy Complaints

  • Privacy complaints must be handled under both this Privacy Policy and the Solomon Complaint Handling Process.
  • The subject of the complaint must not be the sole investigator or decision maker.
  • Investigations must preserve relevant evidence, review consent/authorization, confirm access logs and document findings/corrective action.
  • Where a privacy complaint reveals risk of harm, breach, fraud, misconduct, vulnerable-client concern or AML/ATF issue, the matter must be escalated under the applicable policy, and the MGA must be made aware of the complaint.

Website and Public Privacy Notice Requirements

  • Solomon’s public website must include a clear privacy notice explaining categories of information collected, purposes, consent, sharing, safeguards, retention, individual rights, complaint/access contact and breach/contact rights in plain language.
  • Advisor-branded websites must link to Solomon’s privacy notice and complaint process and must not publish inconsistent privacy language without approval.
  • Website forms must collect only necessary information and must avoid sensitive personal information unless the form and transmission method have been approved for that purpose.
  • Cookies, analytics, contact forms, newsletter sign-ups and marketing communications must be aligned with consent, CASL and privacy requirements.

Training and Monitoring Requirements

  • Privacy training is mandatory at onboarding for Advisors, Staff, contractors and authorized assistants with access to personal information.
  • Annual privacy and data-handling refresher training is required and must be recorded in the training register.
  • Additional training is required following a privacy incident, material policy change, audit finding, new technology implementation, new vendor/system or repeated non-compliance.
  • Solomon will review this Privacy Policy and Privacy Compliance Program at least every two years and more frequently when law, HUB/insurer expectations, technology, operations or risk changes warrant review.
  • Monitoring may include advisor audits, access reviews, file reviews, complaint/incident trend analysis, website review, marketing archive review and vendor/system review.

Recommended Tools and Resources

  • Solomon Privacy/Data Breach Procedure and Privacy Incident Report.
  • Solomon Advisor-to-Client Data Transfer, Cloud Storage, Email, Password, Clean Desk, AI Use, Record Retention, Complaint Handling and CASL policies.
  • Solomon Client Journey, Single Disclosure Consolidated, consent templates and website privacy notice.
  • HUB Financial compliance resources and privacy/CASL templates available through HUBLINK, as applicable.
  • Office of the Privacy Commissioner of Canada PIPEDA resources and Privacy Guide for Businesses.
  • Alberta OIPC PIPA resources and breach response guidance.
  • Quebec private-sector privacy law guidance where Quebec-resident information is handled.

Ramifications

Failure to protect personal information, obtain/maintain appropriate consent, follow approved transmission/storage practices, retain or dispose of records properly, report privacy incidents, complete privacy training or follow this policy may result in mandatory retraining, access restriction, enhanced supervision, suspension of business processing, insurer/HUB escalation, disciplinary action, termination of affiliation, regulatory complaint or investigation, civil liability, financial penalties, E&O involvement, reputational harm and/or reporting to applicable regulators.


© Copyright - Solomon Financial Corporation. All rights reserved. Unit 20, 5579 47th Street Red Deer, AB T4N 1S1

The articles and information provided on this website are intended to raise issues and help you find solutions and should not be construed as advice for any specific situation or individual. Always consult your representative and your tax or legal professional, as applicable, before taking personal action.


Website by iDreamDigital.