Privacy Policy
Effective September 1, 2026
1. Effective Date
This Privacy Policy is effective as of September 1st, 2026 and applies to the Dynamic Needs Analysis application at https://app.dynamicneedsanalysis.com, our website at https://dynamicneedsanalysis.com, and any related services we provide (collectively, the "Services").
Most of what this Policy describes concerns the application, which is where advisors and their client information are. Where something applies only to the website, or only to the application, we say so.
By accessing or using the Services, you acknowledge that you have read this Privacy Policy and understand how we collect, use, and disclose your personal information.
2. Who We Are
Dynamic Needs Analysis Inc. ("DNA," "we," "us," or "our") is a Canadian software company headquartered at:
Dynamic Needs Analysis Inc.609 Granville St, Suite 1592
Vancouver, BC V7Y 1G5
Canada
For privacy law purposes:
- Under the General Data Protection Regulation ("GDPR"), we act as a data controller for personal data we collect from, or about, users of our Services.
- Under the California Consumer Privacy Act ("CCPA"), we act as a business.
- Under Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA"), British Columbia's Personal Information Protection Act ("BC PIPA"), and substantially similar provincial statutes, we act as an organization.
3. Contacting Us
If you have any questions, concerns, or complaints regarding this Privacy Policy or our privacy practices, you may contact us at:
- Privacy email (requests & questions): privacy@dynamicneedsanalysis.com
- Data Protection Officer (DPO): Robert McCurdy – robert@dynamicneedsanalysis.com
Please do not include sensitive personal information in unencrypted emails.
4. Key Definitions
Personal Data / Personal Information ("PII")
Any information that can reasonably identify, relate to, describe, or be linked to an individual.
User / Data Subject
An individual advisor, client, or website visitor whose data is processed by DNA.
Processor / Service Provider
A third party that processes data on DNA's behalf and according to our instructions.
Account
The secure profile an advisor or organization creates to access the Services.
Capitalized terms not defined here have the meanings given in applicable privacy laws.
5. Information We Collect
We collect different categories of personal information depending on how you use the Services.
Identifiers
Examples: name, postal address, email address, phone number, IP address, unique device identifiers.
Source: provided by you; some collected automatically.
Advisor-Generated Data
Examples: case notes, compliance checklists, needs-analysis inputs, uploaded client documents.
Source: you or your organization.
Payment Data
Examples: cardholder name, last 4 digits of card number, expiry date (handled by a PCI-certified payment processor).
Source: you; payment processor.
Usage Data
Examples: browser type, operating system, pages viewed, features used, session duration, referring URLs.
Source: collected automatically.
Location Data
Examples: approximate geolocation derived from IP address. DNA is a web application and does not collect precise GPS location.
Source: collected automatically.
AI Inputs and Outputs
Examples: prompts, instructions, and other content you submit to AI Advisor features, and the generated responses.
Source: provided by you; generated by the model.
Special Categories
DNA does not intentionally request or require sensitive categories of personal data (such as health information, racial or ethnic origin, religious beliefs, or union membership). If you believe such data has been uploaded inadvertently, please contact us so we can evaluate and, where appropriate, delete or de-identify it.
6. How We Use Personal Information
We use personal information for the following purposes:
- To deliver the Services
- Creating and maintaining your Account
- Generating needs-analysis reports and automated compliance documents
- Providing dashboards, analytics, and AI-based advisor guidance
- To improve and secure the platform
- Monitoring performance and reliability
- Debugging and incident response
- Fraud detection and prevention
- Capacity planning and scaling
- To process transactions
- Managing subscriptions and billing
- Processing payments and issuing invoices
- Handling refunds and account adjustments
- To communicate with you
- Service-related messages (e.g., feature updates, maintenance notices)
- Security alerts and important account notices
- Marketing and product updates, where permitted by law and with the ability to opt out at any time
- To develop new features
- Using de-identified or aggregated data to analyze usage patterns
- Enhancing AI models and advisor insights while avoiding direct use of identifiable client data whenever possible
- To comply with legal obligations
- Maintaining business and tax records
- Responding to lawful requests from regulators or law enforcement
- Enforcing our Terms of Service and other agreements
Legal Bases (GDPR)
Where GDPR applies, we rely on one or more of the following legal bases when processing personal data:
- Performance of a contract (for example, providing the Services you or your organization subscribed to)
- Legitimate interests (for example, improving and securing the platform, preventing fraud)
- Your consent (for example, for marketing communications)
- Compliance with legal obligations (for example, record-keeping and regulatory reporting)
7. AI Processing
Parts of the Services use artificial intelligence to read documents you provide, size insurance need, and draft recommendations and supporting documents for your review.
We do not train models on your data
We do not use your personal information, your advisor-generated data, or your clients' information to train or fine-tune AI models. This applies to our own models and to any model shared with other customers. Your inputs are used to produce your output, and for nothing else.
Our AI service providers
This processing runs on Microsoft Azure AI Foundry, using models provided by OpenAI and Anthropic. We may change which of those models we use as better ones become available, and everything in this section applies whichever one is in use. Our full list of sub-processors is maintained in our Trust Center.
These providers act on our instructions under contract, may use the information only to return a result to us, and may not use it to train, fine-tune, or improve their own models.
A provider may keep a limited record of a request for a short period, for operating the service, security, and abuse monitoring, under the business terms that govern our use of it. That record is subject to the same restriction: it is not used to train, fine-tune, or improve any model.
Human oversight
AI output in the Services is a draft for a licensed advisor to review, amend, and approve. It is not a recommendation to any individual on its own, and it does not by itself determine any outcome for a client.
Where it runs
Storage and processing are separate, and they are in different places. Your account data and the client information you enter into the application are stored in Canada, as described in Section 10. AI processing is not: to produce a result, the content needed for that request is sent to our AI service provider, processed in a United States processing region, and the result returned to us and stored in Canada.
We do not process your information anywhere other than Canada and the United States. If we change which model we use, the replacement runs in the United States on the same terms. We will not move AI processing to any other country without first updating this Policy, as described in Section 10.
While information is being processed in the United States it is subject to the laws of that country, and may be available to government authorities there under lawful orders, in the same way information held in Canada is subject to Canadian legal process. See Section 10 (Data Residency).
What is retained
Prompts and generated responses are retained for up to 90 days so that the assistant can refer to earlier context in a case, after which they are de-identified or deleted. See Section 11 (Data Retention).
10. Data Residency
Your data is stored in Canada, but some of it may be processed in the United States. Storage and processing are different things, and this section explains which is which.
What is stored in Canada
DNA hosts all production application servers, databases, document storage, and encrypted backups exclusively in Canadian data centres. Your account data, the client records you create, the documents you upload, and everything the Services generate for you are stored there and stay there. We do not transfer or remotely access that stored information from outside Canada in the ordinary course of business.
What is processed in the United States
Two things are processed outside Canada, and this is the complete list.
- AI processing. To produce AI output, the content needed for a request is sent to Microsoft Azure AI Foundry and processed in a United States processing region, then returned to us and stored in Canada. This is described in Section 7. Where a document you uploaded is the subject of the request, its contents are part of what is sent.
- Our public website. What you submit through a form on our website (for example your name, email address, and firm) is received by HubSpot, which operates in the United States. This is not optional, because delivering the form to us is the purpose of submitting it. Analytics and advertising identifiers are also processed in the United States, but only if you grant the matching consent described in Section 8; if you decline, nothing is sent.
While personal information is being processed in the United States, it is subject to the laws of that country, and may be available to government authorities there under lawful orders. This is not unique to the United States: information held in Canada is subject to Canadian legal process in the same way. We use contractual and technical measures appropriate to the sensitivity of the information, including terms requiring a comparable level of protection to the one it receives in Canada, and we say this plainly rather than imply that a contract can override the law of the place where information is processed.
Canada and the United States, and nowhere else
Your personal information is processed only in Canada and the United States. We do not process it in any other country. This holds across the Services, and it holds regardless of which AI model we use. If, in the future, we contemplate processing in any other country, we will:
- Update this Policy to describe the new processing
- Obtain any required consents
- Ensure an equivalent level of protection, including through Canadian adequacy decisions or contractual safeguards
11. Data Retention
We retain personal information only for as long as reasonably necessary to fulfill the purposes for which it was collected, or as required by law.
Typical retention periods include:
- Account data – while your subscription is active, plus 90 days following termination for audit, dispute resolution, and tax purposes
- Client information entered into the application by an advisor – deleted together with that advisor's account, on the same 90-day schedule. Advisors remain responsible for retaining whatever their own regulator requires them to keep outside the Services
- AI inputs and outputs – up to 90 days so the assistant can refer to earlier context in a case, after which they are de-identified or deleted. They are never used to train or fine-tune a model (see Section 7)
- Marketing consent records – up to 5 years to meet legal record-keeping obligations
- System logs – up to 24 months for security monitoring and diagnostics
You may request earlier deletion of certain data where permitted by law (see Section 12). In some cases, we may need to retain limited information to comply with legal obligations or to establish or defend legal claims.
12. Your Privacy Rights
Under PIPEDA and substantially similar provincial privacy laws in Canada, you have certain rights in relation to your personal information.
Access
What it means: obtain a copy of the personal information DNA holds about you.
How to exercise: email privacy@dynamicneedsanalysis.com with "Access Request" in the subject line.
Correction
What it means: challenge the accuracy or completeness of your information and have it amended.
How to exercise: specify the data you believe is inaccurate or incomplete and provide supporting documentation.
Withdrawal of consent
What it means: withdraw consent to optional processing where consent is the legal basis (for example, marketing emails).
How to exercise: use the unsubscribe link in marketing messages or contact us at the address above.
Accountability and complaints
What it means: raise concerns about DNA's privacy practices.
How to exercise: contact our DPO using the details in Section 3. If unresolved, you may contact the Office of the Privacy Commissioner of Canada.
Deletion / Right to Erasure
What it means: request that DNA delete personal information we hold about you, subject to legal retention obligations.
How to exercise: email privacy@dynamicneedsanalysis.com with "Deletion Request" in the subject line. We will verify your identity, action the request across production systems and backups within 30 days, and confirm completion in writing. Some data may be retained where required by law (e.g., tax records) or to establish/defend legal claims; we will tell you which categories and why.
We respond to verified requests within 30 days, unless an extension is permitted by law. Exercising your rights is generally free of charge; however, we may charge a reasonable fee for copies of large data sets, as allowed by PIPEDA.
Additional rights in other jurisdictions
If you are located in the European Economic Area (EEA), the United Kingdom, or California, you may have additional rights under local law (for example, the right to data portability or to restrict certain processing). You can contact us at privacy@dynamicneedsanalysis.com to exercise these rights, and we will handle your request in accordance with applicable law.
13. Children's Privacy
The Services are designed for professional financial advisors and are not directed to children under 13 years of age.
We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can take appropriate steps to remove the information and terminate any related access.
14. Security Measures
We take the security of your data seriously and implement a combination of organizational and technical safeguards, including:
- TLS 1.3 encryption for data in transit
- AES-256 encryption for data at rest
- Multi-factor authentication for internal administrative access
- Role-based access controls and regular access reviews
- Routine penetration testing and vulnerability scanning
Our security controls are independently audited and monitored continuously under SOC 2. Our current reports and monitoring status are available in our Trust Center.
No method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security. However, we follow industry best practices and continuously work to strengthen our defences.
15. Third-Party Sites and Services
The Services may contain links to websites, apps, or services that DNA does not own or control. This Privacy Policy does not apply to those third-party services.
We are not responsible for the privacy or security practices of any third party. We encourage you to review the privacy policies of every third-party service you use in connection with, or instead of, our Services.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, technology, or our business practices.
- Material changes will be communicated via email and/or an in-app notice at least 30 days before they take effect.
- The "Effective Date" at the top of this Policy indicates when it was last updated.
Your continued use of the Services after the effective date of any changes constitutes your acceptance of the revised Policy.
17. Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy or our privacy practices, please refer to the contact details in Section 3 (Contacting Us). We will do our best to respond promptly and address your concerns.