ReachFlare Comp
Privacy

Privacy Policy.

How ReachFlare Comp Inc. collects, uses, discloses, and protects personal information under Canadian privacy law — including our use of AI-assisted tools with human oversight.

Last updated: 21 July 2026

1. Introduction and scope

ReachFlare Comp Inc. ("ReachFlare Comp," "we," "us," or "our") is a business-to-business marketing agency incorporated in Ontario, Canada. We respect your privacy and handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation where it applies to our activities.

This Privacy Policy describes how we collect, use, disclose, retain, and safeguard personal information when you visit reachflarecomp.pro, contact us, engage our services, or otherwise interact with us. It applies to website visitors, prospective clients, current and former clients, suppliers, and other individuals whose personal information we process in the course of our business.

This policy does not apply to third-party websites, platforms, or services that we do not control, even when linked from our site or used in client campaigns. Those services have their own privacy practices, and we encourage you to review them separately.

2. Accountability and Privacy Officer

ReachFlare Comp Inc. is accountable for personal information under our control. We have designated a Privacy Officer responsible for our compliance with PIPEDA and for responding to privacy enquiries and complaints.

Privacy Officer
ReachFlare Comp Inc.
297 Geary Avenue, Suite 200
Toronto, ON M6H 2C3
Email: [email protected] (subject line: "Privacy")
Telephone: +1 (416) 849-2736

Our Privacy Officer oversees privacy training, policy review, breach response, and coordination with the Office of the Privacy Commissioner of Canada where appropriate. Questions about this policy, access requests, or complaints should be directed to the Privacy Officer using the contact details above.

3. Identifying purposes

We identify and document the purposes for which personal information is collected before or at the time of collection. We do not use or disclose personal information for purposes other than those identified in this policy, except with your consent or as permitted or required by law.

Our primary purposes for collecting personal information include: responding to enquiries and booking reach reviews; delivering marketing strategy, media planning, and campaign services under contract; managing client accounts and billing; operating and improving our website; meeting legal, regulatory, and contractual obligations; and protecting our business, clients, and website users from fraud or misuse.

When we collect personal information, we will explain the purpose in plain language — for example, in a contact form notice, engagement letter, or verbal briefing at the start of a client relationship.

4. Consent under PIPEDA

PIPEDA requires meaningful consent for the collection, use, and disclosure of personal information, except where the law permits collection without consent. We obtain consent in context: implied consent may be appropriate for obvious purposes such as responding to an email you send us, while express consent is required for more sensitive uses or where PIPEDA demands it.

On our website, cookie and analytics preferences are managed through a consent banner that stores your choice in browser localStorage under the key rfc_consent for six months, with a corresponding cookie for server-side reference. Essential cookies run regardless of analytics consent because they are necessary for basic site operation and security. Analytics cookies are activated only after you choose "Accept all" or an equivalent analytics-enabled option. You may withdraw consent at any time by clearing stored preferences, using the banner when it reappears, or contacting our Privacy Officer.

For client engagements, consent for processing personal information related to campaign audiences, CRM data, or platform integrations is typically documented in the statement of work, data processing addendum, or client onboarding materials. Where we process personal information on behalf of a client, the client remains responsible for obtaining lawful consent from data subjects unless otherwise agreed in writing.

You may refuse or withdraw consent, subject to legal or contractual restrictions and reasonable notice. Withdrawal of consent may limit our ability to provide certain services — for example, we cannot run a paid campaign without the contact details needed to manage the account.

5. What personal information we collect

The personal information we collect depends on how you interact with us. Categories may include:

  • Identity and contact data: name, job title, company name, business email, telephone number, mailing address, and similar professional identifiers.
  • Enquiry and communication data: messages, briefs, meeting notes, and correspondence you send through contact forms, email, or phone.
  • Account and billing data: invoicing details, purchase order references, payment status, and tax identifiers where required for Canadian business transactions.
  • Website and technical data: IP address, browser type, device information, pages viewed, referral source, and approximate location derived from IP — collected through server logs and, with consent, analytics tools.
  • Client campaign data: audience definitions, creative assets, performance metrics, and platform account identifiers supplied by clients or generated during engagements.
  • Employment and supplier data: résumés, contractor details, and vendor contact information where relevant to hiring or procurement.

We do not intentionally collect sensitive personal information such as health records, government identifiers unrelated to business billing, or financial account numbers through our public website forms. If such information is inadvertently provided, we will delete it unless retention is legally required.

6. How we collect personal information

We collect personal information directly from you when you fill out forms, email us, call our studio, attend meetings, or sign engagement documents. We may collect information indirectly from your employer or colleagues when they refer you as a contact for a B2B engagement.

We also collect limited technical information automatically when you browse our website, through essential server processes and — only with your cookie consent — analytics scripts that help us understand aggregate traffic patterns.

During client work, we may receive personal information from clients about their customers, prospects, or employees. Clients represent that they have authority to share that information and that appropriate consents or legal bases exist. We process such data only as instructed in our contract with the client.

7. Use of personal information

We use personal information for the purposes identified at collection, including:

  • Responding to enquiries, scheduling reach reviews, and communicating about our services.
  • Planning, executing, reporting on, and improving marketing campaigns for clients.
  • Managing contracts, invoicing in Canadian dollars, and maintaining business records.
  • Operating, securing, and improving reachflarecomp.pro and internal systems.
  • Complying with legal obligations, responding to lawful requests, and enforcing our terms.
  • Training staff and maintaining quality standards, using de-identified or aggregated data where possible.

We do not sell personal information. We do not use personal information to offer follower packages, bot engagement, or automated social manipulation — those activities are outside our business model and contrary to our stated practices.

8. AI and generative AI in our workflows

ReachFlare Comp uses artificial intelligence and generative AI tools as part of our internal marketing workflow — for example, to draft initial copy variants, summarise research, organise campaign notes, or suggest audience framing. AI is an assistive layer, not an autonomous decision-maker.

Every client-facing deliverable produced with AI assistance is reviewed, edited, and approved by a named human account lead before it is published, sent, or deployed on your behalf. We do not upload confidential client information to public AI tools without contractual safeguards, and we configure enterprise or privacy-oriented tool settings where available.

When AI tools process personal information — such as anonymised audience samples or redacted brief excerpts — we assess the vendor's data handling practices, limit inputs to what is necessary, and avoid submitting sensitive categories of data unless required and agreed in writing.

AI outputs may contain errors, biases, or outdated references. Our human review step exists specifically to catch those issues before they reach your audience. We document AI use in engagement materials where it materially affects deliverable production, and clients may request details about tools and review processes applicable to their account.

We monitor evolving guidance from Canadian regulators and industry bodies on AI and privacy. This section will be updated as standards and our practices develop.

9. Disclosure of personal information

We disclose personal information only as necessary for the identified purposes, with consent where required, or as permitted by law. Recipients may include:

  • Service providers: hosting providers, email platforms, analytics vendors (with consent), payment processors, and professional advisors bound by confidentiality obligations.
  • Advertising and analytics platforms: when running client campaigns or measuring site traffic, subject to platform terms and applicable consent requirements.
  • Client personnel: account contacts named in statements of work who need access to reports, creative, or campaign data.
  • Legal and regulatory authorities: when required by court order, subpoena, or applicable Canadian law.
  • Business transitions: in connection with a merger, acquisition, or sale of assets, with notice where practicable and continued protection of personal information.

We require service providers that handle personal information on our behalf to use it only for the contracted purpose and to apply appropriate security measures. A list of major subprocessors is available on request to clients and privacy enquirers.

10. Cross-border transfers

Some of our service providers and platform partners store or process data outside Canada, including in the United States and other jurisdictions. When personal information is transferred across borders, we assess the receiving organisation's privacy practices and use contractual clauses, vendor certifications, or other safeguards recognised under PIPEDA to protect the information.

Cross-border transfer may be subject to foreign laws that permit access by government authorities. We minimise the volume of personal information transferred and choose vendors with transparent privacy programmes where feasible. You may contact our Privacy Officer for more information about transfers relevant to your data.

11. Retention

We retain personal information only as long as necessary to fulfil the purposes for which it was collected, meet legal and regulatory requirements, resolve disputes, and enforce agreements. Retention periods vary by data type:

  • Website enquiry records: typically up to twenty-four months after last contact unless a client relationship continues.
  • Client project files: duration of engagement plus seven years for business and tax record requirements, unless a shorter period is agreed.
  • Cookie consent records: six months, aligned with our banner storage practice.
  • Server logs: typically ninety days unless needed for security investigation.

When personal information is no longer required, we securely delete or anonymise it. Anonymised aggregate data used for internal analytics may be retained longer without identifying individuals.

12. Safeguards

We protect personal information with security safeguards appropriate to its sensitivity, including access controls, password policies, encrypted connections (HTTPS) on our website, restricted access to client folders, and staff training on confidentiality and phishing awareness.

No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security. We maintain an incident response process and will notify affected individuals and regulators of significant breaches as required by PIPEDA and applicable provincial breach notification rules.

13. Openness and transparency

We make information about our privacy practices readily available through this policy, our Cookie Policy, and our Legal page. We will explain our policies and practices on request in plain language. Material changes to this policy will be posted on this page with an updated "Last updated" date, and where appropriate we will provide additional notice to active clients.

14. Individual access

Upon written request, we will inform you whether we hold personal information about you and provide access to that information, subject to limited exceptions under PIPEDA — for example, where disclosure would reveal confidential commercial information of another party or is prohibited by law.

Access requests should be sent to our Privacy Officer at [email protected] with "Privacy" in the subject line. We may require verification of identity before releasing information. We will respond within thirty days or notify you if an extension is required under PIPEDA.

If you believe information we hold is inaccurate or incomplete, you may request correction. We will amend the record or annotate disputed information where appropriate and notify third parties who received incorrect data if required.

15. Challenging compliance

If you have concerns about our privacy practices, contact our Privacy Officer first. We will investigate complaints promptly and aim to resolve them within thirty days. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada:

Office of the Privacy Commissioner of Canada
30 Victoria Street
Gatineau, QC K1A 1H3
Toll-free: 1-800-282-1376
Website: priv.gc.ca

The Commissioner can investigate complaints about organisations subject to PIPEDA and recommend remedies. We cooperate fully with regulatory enquiries.

16. Marketing communications

We may send service-related emails, project updates, and — where permitted — occasional information about ReachFlare Comp services. B2B marketing messages are sent in compliance with Canada's Anti-Spam Legislation (CASL). You may unsubscribe from promotional emails using the link in the message or by contacting us. Unsubscribing from marketing does not affect transactional messages related to active engagements.

We do not purchase email lists for unsolicited outreach. Contacts in our CRM are typically individuals who have enquired, been referred in a business context, or met us at industry events with implied or express consent to follow up.

17. Children

Our website and services are directed at business professionals, not children. We do not knowingly collect personal information from anyone under the age of sixteen. If we learn that we have collected such information without appropriate parental consent, we will delete it promptly. Parents or guardians who believe we may have collected a child's information should contact our Privacy Officer.

18. Client data and role distinction

In many engagements, our clients determine the purposes and means of processing personal information about their own customers and prospects. In those cases, the client acts as the data controller (or organisation accountable under PIPEDA) and ReachFlare Comp acts as a service provider processing data on the client's instructions.

Clients are responsible for providing privacy notices to their audiences, obtaining valid consent, and honouring access requests from their customers. We assist clients with technical measures — such as audience suppression lists or platform configuration — as agreed in contract, but primary accountability for end-user privacy rests with the client unless we explicitly agree otherwise in writing.

19. Automated decision-making

We do not make decisions that produce legal or similarly significant effects on individuals based solely on automated processing without meaningful human involvement. Platform algorithms used in paid media (for example, ad delivery optimisation) operate under client and platform control; ReachFlare Comp configures and monitors those systems but does not replace human judgment on strategy, creative approval, or budget allocation.

20. Third-party links and embedded content

Our website may contain links to LinkedIn, advertising platforms, scheduling tools, and other third-party sites. Clicking those links may expose you to third-party tracking independent of our cookie banner. We are not responsible for the privacy practices of external sites and encourage you to read their policies before providing personal information.

21. Provincial privacy law

PIPEDA applies to our interprovincial and international activities. Where provincial privacy statutes apply to personal information in our custody — for example, in certain employee or health contexts — we comply with the applicable provincial requirements. Ontario does not have a substantially equivalent private-sector privacy statute to PIPEDA for most commercial activities; our primary framework remains PIPEDA for client and website data processed in Ontario.

22. Changes to this policy

We review this Privacy Policy periodically and update it to reflect changes in law, technology, and our business practices. The "Last updated" date at the top of this page indicates the most recent revision. Continued use of our website after changes are posted constitutes acknowledgment of the updated policy, subject to any additional consent requirements for new uses of personal information.

23. Contact

For privacy questions, access requests, consent withdrawals, or complaints, contact:

Privacy Officer, ReachFlare Comp Inc.
297 Geary Avenue, Suite 200, Toronto, ON M6H 2C3
Email: [email protected] (subject: "Privacy")
Phone: +1 (416) 849-2736
Business Number: 863417259 RC0001

Related documents: Cookie Policy · Terms of Service · Legal