Short versionOptional site analytics is off until you choose. Prior research-improvement tracking is disabled and cannot be enabled. We do not sell personal information or use advertising, remarketing, session replay, or personalized ads.
Regional research collection is pausedKaizen is not accepting new responses, saved drafts, report requests, or journey events for the Northern BC readiness project while its methodology, scope, and public presentation are reviewed with Statistics Canada. Existing records are preserved under this policy so privacy rights, security, retention, and any approved research decision can be handled responsibly.
1. Scope and accountability
This Privacy Policy applies to Kaizen Strategic AI and information handled through kaizenstrategic.ai, related forms, article and standards comments, email workflows, and records previously collected through the Northern BC readiness project. It is designed for practical alignment with Canadian and British Columbia private-sector privacy requirements, including British Columbia's Personal Information Protection Act and PIPEDA where applicable.
Questions, access requests, corrections, deletion requests, or complaints can be sent to the privacy contact at info@kaizenstrategic.ai.
2. Information needed to provide requested services
Depending on what you choose to use, or used before the research pause, we may collect or hold:
- Contact form information, including name, organization, email, optional phone number, service area, message, delivery status, and follow-up records.
- Article or standards comment information, including display name, optional organization, private email address, comment text, and moderation records. For new comment submissions, network information is used transiently to create a short-lived, purpose-specific abuse-prevention key; raw network addresses, stable network hashes, and full browser user-agent strings are not added to the comment record. Approved article comments publish the display name, comment, and calendar date. Approved standards comments may also publish the optional organization. Email addresses remain private.
- Prior research organization-profile categories, question answers, readiness score, pillar scores, selected regional context factors, recommendations, and—only when supplied for a requested report or follow-up—business contact details.
- Security-session information needed to prevent forgery, spam, unauthorized access, and abuse.
- A bounded prior research progress draft may have been kept on Kaizen's server for no more than 24 hours when save-and-resume was available. Contact details were excluded from that draft. The browser held only an opaque security cookie and did not store the profile, answers, contact details, or edit credential.
Current requested forms and security functions are separate from optional analytics. Declining analytics does not block them. Research scoring and saved progress are not currently offered.
The same transient abuse-prevention approach applied to prior research submissions and applies to new contact submissions. Short-lived, purpose-specific request keys are kept only in rate-limit records and expire with the applicable rate-limit window. Older service records may contain limited network hashes or browser information collected under an earlier implementation; this policy does not claim those legacy fields have already been deleted.
3. Optional site analytics
If you turn on Site analytics, Kaizen's first-party system records a page path with its query string removed, referring origin, intentionally supplied UTM campaign identifiers (ID, source, medium, and campaign only), coarse browser, device, country and region categories, performance measurements, and broad actions such as a contact-form start or successful submission. UTM term and content values are not collected.
A random per-tab analytics session value is created only after consent and hashed before database storage. Network information is used transiently for abuse prevention and a rotating daily visitor count; raw network addresses and full browser user-agent strings are not stored in site analytics. Form contents, names, email addresses, phone numbers, organization names, submission identifiers, form free text, full URLs, query strings, outbound destinations, search terms, and prior research answers are not intentionally collected. Campaign identifiers are restricted to short code-like values and values resembling email addresses or phone numbers are discarded.
The administrative view shows aggregate consented traffic. It is not a count of every visitor because declined visits are not measured.
4. Paused research-improvement insights
Kaizen previously offered a separate Census improvement insights choice for first-party journey events. That purpose is now disabled, the current privacy interface cannot enable it, and the endpoint does not accept new events.
Historical journey records, where separately permitted, used bounded step, progress, and completion information with hashed session and network values. Contact fields were blocked from event metadata. Those records remain subject to the retention and privacy rights below.
5. Cookies and similar browser storage
- __Host-kaizen_privacy_consent — necessary in production; remembers your choices for up to 180 days. A matching local browser record stores the policy version and choice time.
- __Host-kaizen_contact_session — necessary for contact-form security and expires after two hours. The paused research endpoint no longer issues a __Host-kaizen_census_session cookie and expires old Census session cookies when contacted.
- __Host-kaizen_admin_session — necessary only for the private administrative area; expires after 30 minutes.
- kaizen:site-analytics-session — optional per-tab session storage created only after site-analytics consent. It closes with the tab and is removed when consent is withdrawn; only its server-side hash is stored.
- __Host-kaizen_census_draft — an old opaque research-draft cookie that was Secure, HttpOnly, host-only, SameSite=Strict, and unavailable to page scripts. The retired route expires it and does not create a new draft.
- Prior research journey session — an optional random local identifier used only after separate research-improvement consent. The current site removes it and does not accept new journey-event payloads.
“Cookies” in the privacy interface includes cookies, local storage, pixels, and similar device technologies. Strictly necessary storage is used only for security, consent records, and features you request.
6. Consent and your choices
The first privacy notice offers equally available options to accept optional site analytics, reject it, or review the choice. Optional measurement starts off. You can reopen Privacy choices from the persistent control or site footers and withdraw consent as easily as it was given.
Withdrawal stops future optional collection and reloads the current page to sever the optional session. Site-analytics withdrawal removes its per-tab session value. The current site also removes prior research tracking and browser-progress keys. Previously collected records may remain until their stated retention period expires or a valid deletion request is completed.
The site honours browser Do Not Track as a refusal of all optional tracking. Global Privacy Control keeps site analytics off. These signals are also checked by the analytics endpoint. The absence of either signal is never treated as consent.
7. Existing research records and sensitive information
Existing responses are preserved while the methodology and scope are reviewed. Any future analysis or public reporting must stay within the approved methodology, this notice, and participant permissions, and must avoid identifying participants unless an appropriate permission or other lawful basis applies.
The paused project was not designed for confidential operational records. Do not submit client files, employee records, health information, passwords, payment information, trade secrets, detailed safety incidents, or other sensitive personal or confidential information.
8. How information is used
- Preserve and administer previously requested scores, reports, replies, and follow-up.
- Review and moderate comments while keeping private email fields out of public responses.
- Evaluate whether approved aggregated or de-identified research may be produced.
- Improve site usability, performance, and service design where consent permits.
- Prevent abuse, troubleshoot failures, maintain records, and meet legal obligations.
Personal information is not used for a new incompatible purpose without a new notice and, where required, a new choice.
9. Service providers and processing locations
Limited information may be processed by providers that operate the service: Vercel for website hosting, Neon for database hosting, and Resend for requested email delivery. First-party does not mean Canada-only: these providers may process information outside British Columbia or Canada, including in the United States, where it may be subject to the laws of that jurisdiction.
Kaizen does not sell participant or website information. Providers receive only the information reasonably needed for their stated role and may not be used here for personalized advertising.
10. Email delivery and engagement data
Prior requested research-report emails may have operational delivery records such as sent, delivered, delayed, bounced, or complained status. Kaizen's custom invisible email-open pixel is disabled, opened or clicked webhook events are ignored rather than stored, and the paused project does not accept or deliver new report requests. A future email-engagement feature would require a separate, specific disclosure and choice rather than relying on website analytics consent.
11. Safeguards and retention
Safeguards include restricted administrative access, encrypted transport, HttpOnly security cookies, request validation, rate limits, hashed analytics sessions and journey identifiers, rotating visitor counts, strict event allowlists, blocked contact keys in analytics metadata, and separation of public output from private contact fields.
- Consent choices: up to 180 days before a fresh decision is requested.
- First-party site analytics events: automatically deleted after 13 months.
- Prior first-party research journey events: a 13-month retention target.
- Security sessions: two hours for public forms and 30 minutes for private admin access.
- Prior research progress drafts: access ends no later than 24 hours. The authenticated retention process is designed to delete expired drafts in bounded batches. Physical deletion can lag if that operation fails or reports a backlog.
- Identifiable form, comment, prior research, and business records: only as long as reasonably needed for the stated service, moderation, reporting, legal, or administrative purpose.
De-identified or aggregated benchmark findings may be retained longer when they no longer reasonably identify a participant.
12. Access, correction, deletion, and complaints
You may ask to access, correct, or delete personal information Kaizen holds about you, or withdraw consent, subject to legal and practical limits. Email info@kaizenstrategic.ai. Kaizen may need to verify the request before acting. If information has already been irreversibly aggregated, it may not be possible to remove it from an aggregate report.
The retired research route expires old session and draft cookies and the current site removes old browser-only progress. That cleanup does not erase a response previously submitted. Use the privacy contact above to request access, correction, or deletion of an existing response.
13. Children and policy updates
The website and prior research project are designed for businesses and organizations, not for children under 13. Kaizen does not knowingly seek children's personal information through these services.
This policy may change when services, providers, purposes, or legal requirements change. A material change to optional collection will trigger a new choice rather than silently relying on an older decision.