Grove Wealth YYC

Privacy policy

Andy Turney, insurance and segregated investment solutions.

We collect and keep information about you, which is needed to provide the products and services you request. This information is collected either directly or through our Independent Advisor Representatives. We may also provide the basic information to a third-party medical service company so they may contact you to arrange any underwriting requirements. These requirements are sent directly to private labs and the insurance companies who will underwrite your application. We do not receive or maintain any copies of this medical information. We may also maintain a database and record the following information. This information is used to assist in the underwriting process and maintain information that is required by various federal regulations which includes PIPEDA in Canada, ALPIPA in Alberta, BCPIPA in British Columbia where Grove Wealth YYC follows their rules and regulations.

Type of information we maintain

  • Marital status
  • Date of birth
  • Citizenship status
  • Occupation
  • Health information (only during the underwriting process)
  • Net worth
  • Gender
  • Social insurance number
  • Income
  • Name, home address, and phone number

We need the individuals or companies written consent to maintain this information and also when any new use of the personal information is to be used. We securely remove and dispose of any Personal Information that does not have a specific purpose or no longer fulfills its intended purpose.

If your Independent Advisor Representatives requests information concerning the status of your insurance policies or information on coverage amounts, beneficiary designations or any values this information will be provided unless another Independent Advisor Representatives is appointed and has obtained a signed release from you.

You as an individual or a company have a right to make a written request to access any personal information we have on file. This information must be provided within 30 days of receipt of the request.

You may withdraw your consent in writing at any time but this will not allow us to provide service on your policies as it would result in us removing your data and we would not be able to answer your inquiries.

The Insurance or Investment Company you have applied to will have similar privacy policies with the exception that they will keep copies of your application and all information obtained to underwrite your application. This information may include medical and financial data that is used to make an underwriting decision, or to process claims in the case of Insurance applications. Investment companies will keep copies of any financial data you have supplied.

The Independent Advisor Representatives who is submitting this application on your behalf will also be required to maintain files which will include copies of your applications and any presentations they have used to assist in the transaction. The Independent Advisor Representatives are also required to provide you with an Advisors Disclosure or Engagement document, complete a needs analysis and send a reason why letter or email.

Your right to access your information

You have a right to access the personal information that we, the Insurance company, the Investment company and the Associate Advisor have about you in your file. If any of them have information that is not correct, you can have it corrected.

Email aturney@grovewealthyyc.caor call 780-604-7735 and speak to our Compliance Officer.

Computer security

If you are sending us financial or personal information, you should know how it is protected. Business we process is stored on a separate secured system atcustomplan.virtgate.carather than on this website. This website itself does not store your application data.

Encrypted communications

Traffic between your browser and our systems is protected in transit by Transport Layer Security, the current standard for encrypted web connections. TLS replaced the older SSL protocols, which are no longer considered secure and are not used. Data is encrypted before it leaves your device and decrypted only at the destination, which prevents it being read or altered along the way.

Connections are authenticated with a certificate from a publicly trusted certificate authority, so your browser can confirm it is talking to the site it expects. Your browser's padlock indicates the connection is encrypted and the certificate is valid. Certificates and protocol versions are maintained by our hosting providers and are updated as standards change, so we do not publish specific cipher or key details here.

Other internet security

Where a session is required, session state is held in short-lived cookies and validated on each request, so a session cannot be forged or altered by editing what is stored on the device. Comparable checks are applied to form submissions to prevent tampering in transit.

The systems holding client business are operated by our providers with continuously monitored firewalls and intrusion detection, with unnecessary network access closed by default and unusual traffic investigated as it arises.

Website analytics

We use Google Analytics to understand how visitors use this site, pages viewed, how people arrive here, and general engagement. Analytics is not active until you accept it in the banner shown on your first visit; declining keeps it off for that visit. This data is aggregate and behavioural. It is kept separate from, and never combined with, the personal or underwriting information described above, and is automatically deleted after two months.

Physical security

The servers are housed at a major international data centre rather than in an office. Access is controlled: visitors provide identification and are escorted, and must pass through corridors where the first door locks before the next opens. The servers themselves are in locked secure cages with video surveillance.

Operational resilience

The data centre runs multiple servers in the locked cage, any one of which could handle the entire load alone, so a site can be moved between servers in minutes. Network connections are redundant and diversely routed, and there is no single router representing a point of failure.

Power comes through separate redundant links to two different sub-stations, with multiple layers of backup generation, battery backup, and uninterruptible power supplies sufficient to run the centre for several days without refuelling. Environmental systems are monitored continuously, including water, temperature, cooling, heating, and fire suppression.

Each server uses hot-swappable storage, so a drive can fail and be replaced while the server is running with no loss of data or service. Replaced drives are retained and wiped of data before being returned to the manufacturer. Full backups of all data are performed nightly at a secondary location, which are in turn backed up to separate storage media.