1. Who we are
NorthLake Advisory provides business consulting services focused on AI adoption, analytics foundations, and executive-ready reporting for organizations in Canada. This Privacy Policy applies to our website and related communications that originate from this site, including when you contact us about consulting engagements or request information about our services.
For the purposes of this policy, NorthLake Advisory is the organization responsible for determining how and why personal information is processed through this website. If you have any questions about this policy, your rights, or our data practices, you can contact us using the information in the Contact section below.
4. Consent requirements
Our cookie consent banner offers three options: Accept All, Reject Non-Essential, and Manage Preferences. Analytics and marketing cookies are not activated until you provide consent. Your choice is stored in localStorage for 12 months and can be changed at any time using the footer link.
By clicking 'Accept All Cookies', you consent to the storing of cookies on your device for analytics and advertising purposes, including personalized advertising delivered by Google and Meta. You may withdraw consent at any time through the cookie preferences panel without affecting the lawfulness of processing that occurred before withdrawal.
Users in the European Economic Area and the United Kingdom receive this consent notice in compliance with the General Data Protection Regulation (GDPR) and UK GDPR. Marketing and analytics cookies are activated solely after explicit, informed, freely given consent under GDPR Article 6(1)(a). Consent is recorded with a timestamp and may be audited upon request.
You may withdraw consent at any time by clicking 'Manage cookie preferences' in the website footer, or by clearing cookies via your browser settings. Withdrawal does not affect processing that occurred while consent was valid.
6. Lead Forms and Contact Requests
When you submit a contact form, request a quote, or register interest in our services, we collect the information you provide. This typically includes: full name, email address, phone number, and your message.
Legal basis: consent (GDPR Art. 6.1.a) and, where a service relationship exists, performance of a contract (GDPR Art. 6.1.b).
Retention: form submission data is retained for up to 2 years from the date of submission, unless a longer period is required by applicable law.
You may request deletion of your data at any time by contacting us at the email address in this policy.
A link to this Privacy Policy appears adjacent to every submission button on this site. Submitting a form constitutes acknowledgment of this policy.
7. Google Services and Advertising
This website uses the following Google services:
Collects anonymized usage data, device info, and behavioral signals. IP anonymization is enabled. Data retention is set to 14 months. Users may opt out via the Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout
Records when a user completes a defined action (form submission, call, purchase) after clicking one of our ads. This data is used solely for measuring ad campaign performance.
Allows us to show ads to previous visitors across Google's network. Remarketing lists are not created from sensitive data categories (health, finance, religion, sexual orientation).
Deploys tracking tags on our behalf. No personal data is collected by GTM itself; it acts as a container for the tags listed above.
Google's advertising products are governed by: https://policies.google.com/technologies/ads
8. Meta Advertising Services
This website uses the Meta Pixel to measure the effectiveness of our advertising on Facebook and Instagram. The pixel may record:
- Page views and time on site
- Specific conversion events (form submissions, purchases)
- Custom audience membership for retargeting purposes
We do not use the Meta Pixel to collect sensitive personal data, nor to target users based on health status, financial situation, religion, political views, sexual orientation, or any other special-category attribute prohibited under Meta's advertising policies.
Meta acts as an independent data controller for data collected via its Pixel and processed within its own platform. Refer to Meta's Data Policy: https://www.facebook.com/privacy/policy
To manage your ad preferences on Meta platforms, visit: https://www.facebook.com/adpreferences/
9. Prohibited Content Self-Declaration
This website does not promote, sell, or facilitate access to prohibited product or service categories including but not limited to: weapons, controlled substances, counterfeit goods, gambling services (unlicensed), adult content, or services that make misleading health or financial claims. All advertising conducted through Google Ads and Meta Ads complies with the respective platform policies in full.
10. Landing Page Integrity Statement
The content of this website accurately represents the products and services advertised. No bait-and-switch practices are employed. The experience delivered to users arriving from paid advertisements is identical to the experience for all other visitors. Cloaking, automatic redirects, and content variation by traffic source are not used on this website.
11. Children's Privacy
This website is not directed at individuals under the age of 16. We do not knowingly collect personal data from minors. If we discover that data has been collected from a person under 16 without verifiable parental consent, we will delete it promptly. Contact us at the address in this policy if you believe we have received data from a minor.
12. International Data Transfers
Personal data collected through this website may be transferred to and processed in countries outside the European Economic Area, including the United States, where Google LLC and Meta Platforms, Inc. are based.
These transfers are conducted under Standard Contractual Clauses (SCCs) approved by the European Commission, which provide appropriate safeguards for personal data. A copy of the applicable SCCs can be requested by contacting us directly.
13. User Rights (GDPR Articles 15-22)
If you are located in the EEA or UK, you have the following rights:
- Access (Art. 15): request a copy of data we hold about you
- Rectification (Art. 16): correct inaccurate or incomplete data
- Erasure (Art. 17): request deletion ('right to be forgotten')
- Restriction (Art. 18): limit how we process your data
- Portability (Art. 20): receive your data in a structured, machine-readable format
- Objection (Art. 21): object to processing based on legitimate interest
- Withdraw consent (Art. 7.3): revoke consent at any time without penalty
To exercise any right, email us at the contact address provided in this policy. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority:
- EU users: https://edpb.europa.eu
- UK users: https://ico.org.uk
14. What Data We Collect
Depending on how you use the site and your cookie preferences, we may collect the following categories of information:
- Full name
- Email address
- Phone number
- IP address
- Browser type and version
- Device type and operating system
- Cookies and tracking identifiers
- Usage data (pages visited, time on site, click paths)
- Form submission content
- Conversion events (form submits, calls, purchases)
We do not intend to collect sensitive personal data through this website. If you choose to include sensitive details in a message to us, you provide that information voluntarily.
15. Legal Basis for Processing (GDPR Art. 6)
- Contact form data: consent (Art. 6.1.a) and contract performance (Art. 6.1.b)
- Analytics data: consent (Art. 6.1.a)
- Marketing/remarketing data: consent (Art. 6.1.a)
- Security and fraud prevention: legitimate interest (Art. 6.1.f)
Where consent is the legal basis, you can withdraw consent at any time using the cookie preferences panel. Withdrawing consent does not affect prior processing while consent was valid.
16. Retention Periods
We retain information for only as long as needed to provide services, meet legal obligations, and maintain appropriate records. The periods below describe typical retention:
- Contact form submissions: 2 years
- Analytics data (GA4): 14 months
- Marketing cookies (Google Ads): up to 540 days
- Email communications: duration of relationship + 1 year
- Server logs: 90 days
- Cookie consent records: 3 years (audit requirement)
17. Contact
If you want to ask a privacy question, request access or deletion, or report a concern about this policy, contact us using the details below. For faster handling, include your name and a description of your request.
You can also review our Terms for additional information about website use.