Legal

Privacy Policy

What is collected, why, who else sees it, how long it is kept, and how to get it back or have it deleted. Written to be read rather than to be defensible.

Last updated
15 August 2026
Applies to
This website and everything sold through it
Governing law
Ontario, Canada

01Who is responsible for your information

Lumineer, the professional practice of Aneta Kosinska is the organisation accountable for the personal information described here. In Canadian law it is the organisation under the Personal Information Protection and Electronic Documents Act (PIPEDA). Where the General Data Protection Regulation applies, it is the controller.

Aneta Kosinska, Privacy Officer is the individual accountable for this policy and for answering requests about it, as PIPEDA’s first principle requires. Contact details are at the foot of this page.

The practice is a single-practitioner consultancy. There is no marketing department and no data broker relationship. In practice, the person reading your enquiry is the person who wrote this policy.

02What this policy covers

This policy covers this website, the forms and free tools on it, the email you receive from the practice, and the administration of paid engagements — the Business Momentum Sprint, the e-book and the monthly room.

It does not cover:

  • Anything you tell a third-party platform directly, such as LinkedIn or Instagram. Their own policies govern that.
  • Confidential material discussed inside a paid engagement, which is governed by the engagement agreement and the confidentiality terms in the purchase and engagement terms. Those terms are stricter than this policy, not looser.

03What is collected, why, and on what basis

Only what is needed for the stated purpose, which is PIPEDA’s fourth principle and the GDPR’s minimisation requirement. There is no field on this website that exists to profile you.

Collected whenWhat exactlyWhyLawful basisKept for
Enquiry formName, email address, role and business, team size, which engagement you are looking at, timing, format, how you found the practice, and what you write in “what has stopped moving”To answer your enquiry, judge whether the Sprint would help, and prepare for the callSteps taken at your request before a contract, and legitimate interests in respondingThree years from the last contact, then deleted
Business Momentum ScoreYour eighteen answers, and — only if you ask for the written read — your name and email addressTo calculate and return your score, and to send the written breakdown you requestedConsent, which you can withdraw at any timeAnswers are not stored unless you request the written read. Where you do, three years from the last contact
Booking a callName, email address, time zone and anything you add to the booking formTo hold the appointment and send you the invitation and remindersSteps taken at your request before a contractAs long as the booking record is needed, then deleted on request
Buying the e-bookName, email address, billing address and order detailsTo deliver the file, provide support, and meet tax and bookkeeping dutiesPerformance of a contract, and legal obligation for the recordsSeven years, because Canadian tax law requires it
Email you receiveDelivery, open and click events for messages sent to youTo confirm delivery, and to understand at an aggregate level what is worth sendingLegitimate interests, and consent where the message is marketingTwo years, then deleted
Server logs and abuse preventionIP address, request headers and timestamps. IP addresses used for rate limiting are held in memory only and are never written to a databaseTo keep the site available and stop automated abuse of the formsLegitimate interests in the security of the serviceTransient. Hosting logs are kept by the host for a short operational period

Sensitive information

The enquiry form and the Sprint invite you to describe what is not working. People sometimes volunteer information about health, stress, burnout or personal circumstances in that answer. None of it is requested, none of it is required, and it is never used to make a decision about you beyond deciding whether the work would help.

If the GDPR applies to you, any special category information in a free text answer is processed only on the basis of your explicit consent, given by choosing to write it. You are welcome to keep your answer to the business facts and to raise anything personal on the call instead.

04Where the information comes from

Almost all of it comes from you, directly. The exceptions are:

  • Your email provider, which reports whether a message was delivered, opened or clicked.
  • Your browser and network, which necessarily reveal an IP address and request headers in order to load a page at all.
  • A person who refers you, where a client or contact passes on your name and email so an introduction can be made. If that happens and you would rather not be contacted, say so and the record is deleted.

Nothing is bought from a list broker, scraped, or enriched from a third-party data provider.

06Email, and Canada's anti-spam law

Canada’s Anti-Spam Legislation (CASL) governs commercial electronic messages sent from Canada. It is stricter than the rules in most countries, and the practice follows it for everyone rather than keeping two standards.

That means:

  • Every commercial message identifies the sender, gives a mailing address, and carries a working unsubscribe link that is honoured within ten business days — in practice, immediately.
  • Express consent is obtained before marketing email is sent, and a record of when and how it was given is kept.
  • Implied consent is relied on only where CASL allows it, such as an existing business relationship, and only for the period the statute permits.
  • Transactional messages — a reply to your enquiry, your Momentum Score, a booking confirmation, an invoice, the e-book download — are not marketing and are sent because you asked for them.

Unsubscribing from marketing does not stop transactional messages about something you have actually bought or requested.

07The Momentum Score and automated scoring

The Business Momentum Score is calculated by a formula, with no human involvement at the moment it is produced. Transparency about how it works matters more than mystique, so:

  • Your eighteen answers are scored across six dimensions. Each dimension is weighted; direction and inner load count for slightly more than the others because they sit upstream of the rest.
  • The score is recalculated on the server from your raw answers, so the number cannot be forged by editing the page.
  • Your result travels in the page address. That is what lets you bookmark or forward it — and it means anyone you send the link to can see the same result. Treat the link as you would the result.
  • If you do not ask for the written read, your answers are not stored at all. They are scored in the request and discarded.

The score has no legal or comparable significant effect on you. It does not price anything, decide whether you can buy anything, or feed a credit, employment or insurance decision. For GDPR purposes it is not automated decision-making of the kind Article 22 restricts. You can still ask for a human read of your result — that is what the call is for.

08Who else handles your information

The practice runs on a small number of established services. Each is bound by a written data processing agreement, may use your information only to provide the service, and may not use it for their own purposes.

Services marked planned are listed for transparency and are not processing anything today. This page is updated before any of them goes live.
ServiceWhat it doesWhat reaches itWhereTransfer basisStatus
Vercel Inc.Website hosting and content deliveryIP address and request headers, transiently, to serve pages and protect the serviceUnited States, with edge delivery worldwideStandard Contractual ClausesIn use
Brevo (Sendinblue SAS)Transactional email, the mailing list and contact recordsName, email address, enquiry answers, assessment results, and email delivery and engagement eventsFrance and the European UnionNot applicable — processed within the EEAIn use
Cal.com, Inc.Booking the discovery callName, email address, time zone and anything typed into the booking formUnited StatesStandard Contractual ClausesIn use
Stripe, Inc.Card payments for the e-book and the AI Anonymous Series, and for the Sprint where it is paid by card rather than invoiceName, email address, billing details and payment metadata. Card numbers are collected by Stripe directly and never reach this websiteUnited States and IrelandStandard Contractual ClausesIn use
Google Analytics (Google Ireland Ltd)Aggregate traffic measurement, only where consent is givenPage path, referrer, approximate location, device and browser, and a first-party cookie identifying the browser across visitsIreland, with transfers to the United StatesEU-US Data Privacy Framework and Standard Contractual ClausesIn use
Vercel Web AnalyticsAggregate traffic measurement, only where consent is givenPage path, referrer, country, and coarse device type. No cookies and no cross-site identifierUnited StatesStandard Contractual ClausesIn use

Payment information

Card numbers are never received, seen or stored by the practice or by this website. Card data is collected directly by the payment provider on their own infrastructure, which is certified to PCI DSS. What comes back is a confirmation and the last four digits.

Other disclosures

Your information may also be disclosed where the law requires it — a court order, a lawful demand from a regulator, or a tax audit — and to professional advisers such as an accountant or lawyer under a duty of confidence. If the practice were ever sold or reorganised, records could transfer to the successor, who would be bound by this policy or by terms no less protective.

09Sending information outside Canada

The practice is in Toronto and its clients are international, so some information is processed outside Canada. The table above names where.

PIPEDA permits transfers for processing provided the information receives a comparable level of protection by contract, and provided you are told it happens — which is the purpose of this section. It also means that while your information is in another country, the courts and law enforcement of that country may be able to compel access to it under their own law. That is true of any organisation using international infrastructure, and it is stated here plainly rather than buried.

Where the GDPR applies, transfers outside the EEA or the UK rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision — including the Commission’s finding that Canada offers adequate protection for commercial organisations. A copy of the clauses relied on for any given service is available on request.

10How long it is kept

Information is kept only as long as the purpose requires, or as long as the law demands, and then deleted. The schedule is:

RecordRetention
Enquiries and call notesThree years from our last contact
Momentum Score answers, where the written read was requestedThree years from our last contact
Momentum Score answers, where it was notNot stored at all
Mailing list membershipUntil you unsubscribe, then a suppression record only
Invoices, receipts and tax recordsSeven years, as Canadian tax law requires
Sprint working material and boardsTwo years from the Sprint, unless you ask for deletion sooner
Signed agreementsSeven years from the end of the engagement

Where you unsubscribe or ask to be deleted, a minimal suppression record — effectively your email address and the fact you asked — is kept indefinitely. That is deliberate: it is the only way to guarantee you are not contacted again, and keeping it is a legitimate interest recognised under both PIPEDA and the GDPR.

11How it is protected

Safeguards are proportionate to the sensitivity of the information, as PIPEDA’s seventh principle requires. Concretely:

  • The whole site is served over TLS. Form submissions are encrypted in transit.
  • API credentials are held as server-side environment variables and are never included in anything sent to your browser.
  • No payment card data is handled, so none can be lost.
  • Forms are rate limited and carry a hidden honeypot field to blunt automated abuse. IP addresses used for rate limiting stay in memory and are never written to a database.
  • Accounts on the underlying services use unique credentials and multi-factor authentication where the service supports it.
  • Access is limited to the practitioner and, where strictly necessary, a contracted developer under a confidentiality obligation.

No safeguard is perfect and nobody honest claims otherwise. What is promised is a proportionate standard of care, prompt action if something goes wrong, and the notifications described below.

12Cookies and tracking

This website sets no cookies of its own unless you allow traffic measurement, stores nothing in your browser’s local storage beyond the record of that choice, and runs no advertising or social tracking pixels. The typeface is served from this domain rather than from a font network, so loading a page does not tell a third party that you did.

Two embedded third parties can set their own cookies once you interact with them, and traffic measurement runs only where you allow it. All of it is set out in the cookie policy, including what will change and what consent will be asked for before it does.

13The short version

Two things qualify that, and both are set out below in full: an embedded booking calendar and a checkout on another domain can set their own cookies once you interact with them, and two further tools are planned.

15What this website itself does

Three specifics, because “we respect your privacy” is not information:

  • The typeface is served from this domain. It is downloaded at build time and delivered with the site, so loading a page does not tell a font network that you visited.
  • The Momentum Score keeps nothing on your device. Your answers and your result live in the page address itself. That is what lets you bookmark or forward the result — and it is why closing the tab loses it, because there is no cookie remembering you.
  • Nothing remembers you between visits unless you allow it. There is no login and no basket. Decline traffic measurement and a second visit is indistinguishable from a first.

Your IP address is necessarily visible to the server in order to send a page back to you, and is used briefly to rate limit the forms against automated abuse. That is not storage on your device and is covered in the privacy policy.

16Third parties that can set cookies

These are not controlled by this practice. Where a cookie is set, it is set by them, under their policy, and they are the ones who can read it.

ServiceWhen it can set anythingPurposeWhose policy applies
Cal.comOnly on the booking page, once the calendar loads in its frameKeeping your place in the booking flow, and preventing abuse of the calendarCal.com's own cookie and privacy policies
StripeOnly after you click through to pay, and then on Stripe's own checkout page rather than this oneTaking the payment, issuing the receipt, and fraud preventionStripe's own cookie and privacy policies
VercelNot at all in normal useThe host may use a strictly necessary cookie for load balancing or to protect the service against attackVercel's privacy policy

If you never open the booking calendar and never click through to the checkout, none of the above happens.

17What is planned, and what will be asked first

One tool is intended and is not in place yet. It is named here in advance so this page is never behind the site.

ToolWhat it will doStorage on your deviceConsent needed
Traffic measurement (Vercel Web Analytics)Count page views, referrers and countries in aggregateNone. It is cookieless and sets no cross-site identifierNo cookie consent required, and it is disclosed here regardless

18Controlling cookies yourself

You do not have to take anyone’s word for this. Open your browser’s developer tools, look at the Application or Storage panel, and read what is actually there while you browse this site.

Every major browser lets you block or delete cookies, block third-party cookies specifically, and run a private window that discards everything on close. Those controls are in your browser’s privacy settings.

Blocking third-party cookies will not break anything on this site. It may affect the embedded booking calendar, in which case you can book directly on Cal.com or simply email aneta@lumineer.partners and arrange a time that way.

19Do Not Track and Global Privacy Control

Some browsers send a Do Not Track header or a Global Privacy Control signal. Because this site does not track you across sites and does not sell or share personal information, there is nothing for either signal to switch off — the outcome they ask for is already the default.

If cookie-based analytics is ever introduced, a Global Privacy Control signal will be treated as a valid refusal of consent without your having to interact with a banner at all.

21Your rights in Canada

Under PIPEDA you may:

  • Ask what is held about you, how it is used and to whom it has been disclosed, and receive a copy.
  • Correct it where it is inaccurate or incomplete.
  • Withdraw consent, subject to legal and contractual limits.
  • Challenge how the practice handles it, and receive a substantive answer.

Requests are answered within 30 days, which is the statutory limit. There is no charge. Enough information will be asked for to be confident you are who you say you are, and no more. In the narrow cases where access must be refused — for example where granting it would reveal personal information about somebody else — the reason and your right to complain will be given in writing.

22Your rights in the EU and the UK

The practice takes clients in Europe, so the GDPR and the UK GDPR apply to those relationships. If you are in the EEA, the UK or Switzerland you additionally have the right to:

  • Access your information and receive a copy of it.
  • Have inaccurate information rectified.
  • Have it erased, where there is no overriding reason to keep it.
  • Restrict processing while a dispute about it is resolved.
  • Receive it in a portable, machine-readable form, and have it sent elsewhere.
  • Object to processing based on legitimate interests, and to direct marketing at any time and absolutely.
  • Withdraw consent at any time.
  • Lodge a complaint with your supervisory authority.

Where legitimate interests are relied on, the interest is the ordinary operation of a professional practice — answering enquiries, keeping the site secure, and understanding in aggregate what people read. A balancing assessment has been carried out in each case and is available on request.

23If you are in Quebec

Quebec’s Act respecting the protection of personal information in the private sector, as amended by Law 25, gives you rights beyond PIPEDA, including a right to the de-indexing of information in defined circumstances and a right to be informed before personal information is used for automated decision-making.

Those rights are honoured for Quebec residents. The Momentum Score is the only automated processing on this site, and section 07 above explains what it does and does not decide. Documents are available in English only at present; if you would prefer to correspond in French, write and it will be arranged.

24If you are in the United States

Several US states now give residents privacy rights, including California under the CCPA as amended by the CPRA, and Colorado, Connecticut, Virginia, Texas and others under comparable statutes. Where those laws apply you may request access to, correction of, deletion of, and a portable copy of your personal information, and you may appeal a refusal.

Two disclosures those statutes specifically require:

  • Your personal information is not sold, and is not shared for cross-context behavioural advertising. There is therefore nothing to opt out of, and no “Do Not Sell or Share” link is required.
  • You will not be discriminated against for exercising any of these rights. There is no different price or worse service for people who ask.

An authorised agent may make a request on your behalf with written proof of authority.

25Children

This is a business-to-business practice. Its services are directed at founders, owners and executives, and nothing on this site is intended for or marketed to children.

Personal information is not knowingly collected from anyone under 16. If you believe a child has submitted information, write and it will be deleted without delay.

26If something goes wrong

Under PIPEDA, a breach of security safeguards that creates a real risk of significant harm must be reported to the Office of the Privacy Commissioner of Canada and notified to the people affected as soon as feasible, and a record of every breach must be kept for two years. Those obligations are accepted and will be met.

Where the GDPR applies, notifiable breaches are reported to the lead supervisory authority within 72 hours of becoming aware of them, and to you without undue delay where the risk to you is high.

A notification will tell you what happened, what information was involved, what is being done about it, and what you can do to protect yourself. It will not be written to minimise the event.

27Complaints

Raise it directly first — write to Aneta Kosinska, Privacy Officer at aneta@lumineer.partners. You will get a substantive written answer, not an acknowledgement.

If the answer does not satisfy you, you can escalate:

  • Canada: the Office of the Privacy Commissioner of Canada, at priv.gc.ca, which can investigate independently.
  • Quebec: the Commission d’accès à l’information du Québec.
  • EU: the data protection authority of the member state where you live or work.
  • UK: the Information Commissioner’s Office, at ico.org.uk.

Going to a regulator does not cost you anything and does not affect any other legal remedy you have.

28Changes to this policy

This policy will change as the practice and its tools change. The date at the top is the date of the last substantive change.

Where a change materially affects how your information is used — a new purpose, a new category of recipient, or a new tool that tracks you — you will be told before it takes effect, by email if you are on the list, and fresh consent will be sought where the law requires it. Material changes are not made quietly and backdated.

This policy is drafted against Canadian federal privacy law, with the European, UK, Quebec and US state overlays that apply to an international practice. Where two regimes differ, the practice applies the more protective standard rather than the minimum it could defend.

Nothing here reduces a right you have under law that cannot be reduced by agreement.

Questions about this document

Write to Aneta Kosinska, Privacy Officer at aneta@lumineer.partners, or by post at 320 Bay Street, Toronto, Ontario, Canada.