OZELO Engine ← Back to site

Compliance & Privacy Policy

OZELO™ Engine  ·  Effective date: July 6th, 2026  ·  Last updated: July 9th, 2026

This policy explains how OZELO Inc. ("OZELO™", "we", "us") approaches privacy and compliance for the OZELO™ Engine Software and the myozelo.com website. It describes our zero-cloud, local-processing model, the roles of the parties, the limited information we collect, and how the design is built to support advisors' obligations under Quebec's Law 25 and PIPEDA.

The short version. OZELO™ is built so that a child's personal information never leaves the advisor's machine. There is no central database of family or child data. OZELO™ never holds it. The advisor remains the party responsible for that information; OZELO™ provides the software and does not collect, host, or have access to it.

Contents

  1. Scope of this policy
  2. Our privacy philosophy
  3. Roles & responsibilities
  4. How the software handles personal information
  5. Children's information & parental consent
  6. Information OZELO™ collects
  7. Website privacy & cookies
  8. How we use information
  9. Service providers & disclosure
  10. Data retention
  11. Security
  12. Your rights (Law 25 / PIPEDA)
  13. Privacy incidents
  14. Data location & transfers
  15. Changes to this policy
  16. Contact & privacy officer
  17. Revision history

1. Scope of this policy

This policy covers two things: (a) the way the OZELO™ Engine Software is designed to handle the personal information advisors process within it, and (b) the limited personal information OZELO™ itself collects from advisors and website visitors. It does not replace the privacy notices an advisor provides to their own clients, nor an advisor's own obligations as the party responsible for client and child information. Capitalized terms used in this policy, such as "Software" and "Curriculum," have the meaning given to them in the OZELO™ Engine End User License Agreement (the "EULA").

2. Our privacy philosophy

OZELO™ follows a zero-cloud, local-first design. The personal information of client families and children is entered and processed on the advisor's own device and is not transmitted to or stored on OZELO™'s servers. Our view is simple: the safest place for a child's data is nowhere — so we built the product not to hold it.

3. Roles & responsibilities

As between the advisor and OZELO™:

Advisors remain responsible for their own privacy notices, consents, records, and regulatory obligations.

4. How the software handles personal information

5. Children's information & parental consent

The Curriculum is delivered to families that include minors, which calls for heightened care. The Software includes a consent gate: Curriculum cannot be delivered to a child until the advisor records that consent from a parent or legal guardian has been obtained. Canadian privacy laws generally require parental or guardian consent before the personal information of a minor can be collected or used, though the specific rules and age thresholds vary by province. In Quebec, for example, Law 25 provides that consent to process the personal information of a minor under 14 is given by the person having parental authority. The advisor is responsible for identifying and meeting the consent standard that applies under the law of their own province or territory; the consent gate is a workflow control that supports — but does not replace — that obligation.

6. Information OZELO™ collects

OZELO™ collects a limited set of information directly from advisors and visitors, which does not include the client or child Curriculum data processed locally in the Software:

7. Website privacy & cookies

When you visit myozelo.com we may collect limited technical information (such as IP address, browser type, and pages viewed) and use privacy-respecting analytics provided by Cloudflare to understand site usage. The site also uses Cloudflare's security features, including bot detection and abuse monitoring, to protect against malicious traffic; these operate automatically and do not involve advertising or tracking. We only use strictly necessary cookies, for site security and core functionality, so a cookie consent banner is not required. If you submit a contact or access request, we use the information you provide to respond.

8. How we use information

We use the information we collect to provide, secure, and improve the Software and website; to process subscriptions and billing; to provide support; to communicate about your account and service; and to meet legal and regulatory obligations. We do not sell personal information.

9. Service providers & disclosure

We share information only as needed with service providers who help us operate — Stripe for payment processing; Cloudflare for website hosting, security, and privacy-preserving analytics; Web3Forms for handling website contact-form submissions; and Google Workspace for business email — under contracts that require them to protect it. We may disclose information where required by law or to protect rights and safety. If OZELO™ is involved in a merger or acquisition, information may be transferred subject to this policy.

10. Data retention

We keep the information OZELO™ collects only as long as needed for the purposes described here or as required by law, after which it is deleted or de-identified. As a general schedule: account and licence records are retained for the duration of the subscription plus seven (7) years, aligned with Canadian tax record-retention obligations; billing and subscription-status records are retained for the same seven-year period; and support communications are retained for two (2) years after the matter is closed, unless a longer period is required for a specific matter. Client and child information processed locally in the Software is retained on the advisor's device under the advisor's control and is governed by the advisor's own retention practices.

11. Security

We use reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including the on-device AES-256 encryption and access controls built into the Software. No method of storage or transmission is perfectly secure, but the local-processing model is designed to minimize the information at risk by not centralizing it.

12. Your rights (Law 25 / PIPEDA)

Subject to applicable law, you may have the right to access, correct, or update the personal information OZELO™ holds about you, to withdraw consent, and — under Law 25 — to request portability of certain information and to be informed of automated processing. To exercise these rights for information OZELO™ holds, contact us using Section 16. For client or child information processed in the Software, requests should be directed to the responsible advisor, since OZELO™ does not hold that information. You may also contact the Commission d'accès à l'information du Québec or the Office of the Privacy Commissioner of Canada with a complaint.

13. Privacy incidents

OZELO™ maintains procedures to assess and respond to confidentiality incidents involving information it holds, and will notify affected individuals and regulators where required by Law 25, PIPEDA, or other applicable law. Because the Software does not transmit client or child information to OZELO™, incidents involving information held locally by an advisor are assessed and reported by that advisor as the responsible party.

14. Data location & transfers

Client and child information processed in the Software remains on the advisor's device, in the advisor's location. The licence key installed on the advisor's device is likewise stored locally on that device and is not transmitted to OZELO™ during use. Information OZELO™ collects (Section 6) may be processed by our service providers; where information is processed outside Quebec or Canada, we take steps intended to provide an appropriate level of protection.

15. Changes to this policy

We may update this policy from time to time. We will post the updated version with a new "last updated" date and, where appropriate, provide additional notice. Your continued use after changes take effect constitutes acceptance.

16. Contact & privacy officer

The person responsible for the protection of personal information at OZELO™ is Bryan Goldsman, Director and Privacy Officer. For privacy questions or requests, contact info@myozelo.com, OZELO Inc., Montreal, Quebec.

Revision history

v1.2 — July 9, 2026. Section 4 expanded with a bullet on the advisor-held recovery passphrase (OZELO™ holds no vault decryption keys). Section 9 updated to name service providers (Stripe, Cloudflare, Web3Forms, Google Workspace). Section 10 updated with a concrete retention schedule.

v1.1 — July 6, 2026. Updated to reflect the introduction of local, offline licence-key verification in the Software. Section 4 expanded with a bullet on local licence verification. Section 6 expanded with a bullet on licence and activation information collected by OZELO™. Section 14 clarified to note that the licence key is stored locally on the advisor's device.

v1.0 — June 1, 2026. Initial version.