Lexedge ConsultingLexedge ConsultingLEGAL CENTRE
Legal centrePrivacyTermsCookies
Back to Lexedge

PRIVACY POLICY

Your information should have a clear purpose.

This policy explains what Lexedge Consulting and Vanteloq handle, why it is needed, and the choices available to website visitors, account holders, and other individuals.
Last updated
August 26, 2026
Operator
Lexedge Consulting
Have a question?

For help understanding these documents or a question about your information, contact Lexedge directly.

Email Hussien Issa
LEGAL DOCUMENTSPrivacy PolicyTerms of ServiceCookie NoticeLegal Centre

1. Scope and accountability

This Privacy Policy applies when you visit lexedgeconsulting.com or vanteloq.com, create or use a Vanteloq account, administer a workspace, connect a supported service, submit a form, schedule a call, or contact us.

LexEdge Consulting, operating as Vanteloq, is responsible for personal information under its control. The privacy contact is the Vanteloq Privacy Officer at hussienissa@lexedgeconsulting.com.

Vanteloq follows Alberta’s Personal Information Protection Act and Canada’s Personal Information Protection and Electronic Documents Act where each law applies.

2. Information we collect

Account and workspace information

We collect information you provide, such as your name, email address, password credentials handled by the authentication provider, business name, legal name, business contact details, role, location information, operating hours, and workspace settings.

Connected business information

When an authorized workspace user connects a supported provider or imports records, Vanteloq may receive sales, payment, refund, product, inventory, customer, supplier, location, purchasing, finance, and operational records. The exact fields depend on the source, the permissions granted, and the import selected by the user.

Google and Meta connections

A Google or Meta connection remains unavailable for measurement until an authorized user selects the exact eligible account, property, or owned business location, assigns it organization-wide or to an owned workspace location, and approves a warning-free sample. Vanteloq may retain encrypted authorization credentials while the connection is active, the selected provider and resource identifiers, the chosen workspace scope, connection and sync status, and derived daily measurements with source and freshness details. We use that information only to provide the connected reporting and operational features requested by the workspace.

For a selected Google Business Profile location, an authorized user may request the current review response queue. Review text, ratings, reviewer details, and reply content are fetched directly from Google for that request, are sent with a no-store response, and are not inserted into Vanteloq's database or aggregated into a customer profile. Vanteloq sends a reply to Google only after a user with marketing-management permission enters the reply and provides a separate, specific confirmation. Google remains the system of record for the review and reply.

Connected financial account information

When an authorized workspace owner chooses a bank connection, Vanteloq may use Plaid as a service provider to connect selected business accounts. Depending on the connection and consent shown, Vanteloq may receive account and institution names, masked account identifiers, account type, balances, transactions, transaction descriptions, pending or posted status, currency, provider item and account identifiers, and connection or sync status.

Bank sign-in information entered in Plaid Link is handled by Plaid and the financial institution. Vanteloq does not receive the online banking credentials entered in that flow. When a Plaid connection is configured and an authorized workspace user completes the provider consent flow, the connection uses only the read-only data products disclosed in that flow and does not allow Vanteloq to move money. We use connected records for bookkeeping review, reconciliation, supported cash context, connection support, security, and audit evidence.

Gemini Advisor information

When an authorized user chooses to ask the Gemini Advisor a question, Vanteloq sends Google Gemini the question, a dated summary of verified aggregate sales and profit metrics, connected-source status and freshness, aggregate cash available only when the user has permission to view it, and up to six recent messages from that user's conversation. The current Advisor flow excludes raw provider credentials, full account numbers, customer names, invoice or receipt files, and raw transaction records.

Vanteloq stores the question, the generated explanation, a limited evidence summary, the model identifier, and conversation timestamps so the authorized user can continue the conversation. Advisor records are scoped to that user and workspace.

Uploaded invoices, receipts, and other documents

When a user uploads a business document, we may collect the original file, file name, type, size, cryptographic duplicate-check value, uploader, upload time, document category, storage reference, review status, and links to related transactions or records. If document extraction is enabled, we may also process proposed supplier, customer, date, amount, tax, currency, line-item, confidence, and source-page fields. Extracted fields remain subject to human review.

Service and security information

We may collect device and browser details, IP address, timestamps, authentication events, audit events, integration status, request identifiers, error details, and records of actions taken inside a workspace. This information supports sign-in, fraud prevention, troubleshooting, access control, and service reliability.

Lexedge website inquiries

When you use the Lexedge Consulting inquiry form, we collect the name, contact information, and message you provide, together with the submission time and limited security information needed to prevent abuse and operate the form.

Optional website analytics

If you select “Allow analytics,” Google Analytics may receive information about visits to the Lexedge Consulting public website, including pages viewed, device and browser details, referring pages, interaction timing, and approximate location derived from network information. The Google Analytics tag remains inactive if you select “Essential only.” We do not use this site analytics configuration for advertising profiles.

Communications and billing information

We collect messages and support details that you send to us. If paid billing becomes available, the payment processor may provide subscription status, plan, billing contact, transaction identifiers, and limited payment details. Vanteloq does not need to store full card numbers.

3. How we use information

We use information to:

  • create, authenticate, secure, and administer accounts and workspaces;
  • import, organize, reconcile, display, and analyze records selected by authorized users;
  • store and review uploaded source documents, detect duplicate files, and support document extraction where that feature is enabled;
  • provide reports, calculations, alerts, audit context, and operational workflows;
  • use Google Gemini, after separate affirmative acceptance, to explain verified aggregate business evidence and identify missing inputs;
  • maintain integrations and show their connection or verification status;
  • respond to support requests and service communications;
  • review and respond to Lexedge Consulting website inquiries;
  • measure and improve the Lexedge Consulting public website when analytics permission has been provided;
  • protect the service, investigate misuse, and meet legal obligations;
  • improve reliability and usability using the service and security information described above; and
  • send commercial electronic messages only with express or implied consent, or when an applicable CASL exception permits the message, with the required sender information and unsubscribe method;

We do not sell personal information. We do not use workspace business data to create advertising profiles.

4. Consent and workspace authority

We obtain consent where required and identify the purpose before or when information is collected. You may withdraw consent, subject to legal, security, and contractual limits. Withdrawal may prevent features that need the information from continuing to operate.

Google Analytics is optional on the Lexedge Consulting public website. The tag loads only after you allow analytics. You can review the choice through the Cookie settings control in the site footer or delete the saved site preference in your browser.

A workspace customer decides which authorized users and supported sources are added. The customer is responsible for having the authority to provide business records and personal information to Vanteloq. If Vanteloq processes personal information for a customer, that customer remains responsible for its own notices, permissions, and legal obligations.

Financial-connection consent

Before Plaid Link opens, Vanteloq shows a separate financial-data authorization that names the requested data categories, each processing purpose, the read-only limitation, retention consequences, and withdrawal choices. The authorization is not preselected. An authenticated user must actively accept it, and Vanteloq records the workspace, user identifier, acceptance time, provider, data categories, purposes, and versions of this Privacy Policy and the authorization notice. Plaid then presents the eligible institutions, accounts, and provider-specific permissions in Plaid Link.

A financial connection begins only after both steps are completed. A workspace owner can disconnect the connection, which stops scheduled access and causes stored provider access credentials to be revoked or deleted. The owner can then use the protected Plaid deletion control to delete unreviewed imports and remove bank/provider identifiers from accounting records that must remain. Approved, reconciled, or posted accounting fields and limited audit evidence may remain when needed for legal recordkeeping or a documented retention requirement.

For Google and Meta, authorization alone does not approve measurement collection. An authorized workspace user must complete the provider resource and owned-location selection described above before measurement sync can begin. Disconnecting stops scheduled access and removes the local authorization credential even if the provider's remote revocation service is temporarily unavailable.

Gemini Advisor data-use acceptance

Before Vanteloq sends an Advisor question or evidence summary to Google Gemini, the authenticated user must select a separate checkbox describing the data categories, purpose, exclusions, conversation memory, and link to this Privacy Policy. The checkbox is not preselected. Vanteloq records the workspace, user, provider, acceptance time, data categories, purposes, and versions of this Privacy Policy and the Advisor notice.

Commercial electronic messages require express or implied consent, or an applicable CASL exception. A purchase, transaction, customer profile, or imported contact does not automatically establish consent to receive those messages. Customers remain responsible for determining which rule applies and for their notices, sender identification, contact information, unsubscribe controls, consent evidence, and suppression lists.

5. When information is shared

We may disclose information:

  • to authorized users in the same workspace according to their roles and permissions;
  • to providers that support hosting, authentication, security, email delivery, payments, support, and connected services;
  • when an authorized user directs a connection, export, or disclosure;
  • to investigate security incidents or enforce the Terms of Service;
  • where required by law, court order, or lawful government request; or
  • as part of a business transaction, subject to appropriate confidentiality and legal protections.

Current infrastructure and product flows may involve Cloudflare for hosting and security, Google for optional Lexedge website analytics, Supabase for authentication, Stripe for billing or supported payment data where configured, Plaid for a bank connection selected by an authorized workspace owner, Google for a Gemini Advisor request affirmatively started by an authorized user, and the provider chosen by a workspace for another authorized integration. Plaid also provides information about its handling of connected account data in its End User Privacy Policy.

6. Processing outside Canada

Some service providers may process or store personal information outside Canada. Cloudflare may process web traffic through its global network for hosting, delivery, and security. Google may process optional website analytics and an authorized Gemini Advisor request in countries described in Google's service materials. Supabase processes authentication information in the configured project region and may use subprocessors in other countries. Stripe may process billing and supported payment information in the United States and other countries outside Canada when configured. Plaid may process authorized financial-connection information in the United States and other countries identified in its privacy materials when configured. A customer-selected integration may also process authorization and synchronized records in countries disclosed by that provider.

Information processed in another country may be subject to that country’s laws and lawful access rules. We assess providers and use contractual, technical, and organizational safeguards appropriate to the information and service. Contact the Privacy Officer at hussienissa@lexedgeconsulting.com to ask about a current service-provider location or safeguards relevant to a specific connection.

7. Retention and deletion

We keep information only as long as reasonably needed for the purposes described in this policy, to provide the service, protect the integrity of business records, meet legal requirements, resolve disputes, and maintain security or audit evidence.

Retention periods vary by record type. Account, transaction, audit, and accounting records may need different periods. When information is no longer required, we delete it, anonymize it, or securely isolate it until deletion is completed. Backup copies may remain for a limited period before being overwritten.

Lexedge website inquiries are retained only as long as reasonably needed to respond, manage the resulting business relationship, meet legal requirements, resolve disputes, and protect the service. Optional analytics information is retained according to the configured Google Analytics controls and Google's applicable service terms.

Provider access credentials are kept only while the connection is active and are revoked or deleted after disconnection. Scheduled collection then stops. After disconnecting Plaid, an owner can permanently delete unreviewed Plaid imports. For a transaction already approved, reconciled, or posted into a journal, the deletion workflow removes Plaid identifiers, pending links, and transaction descriptions while retaining the minimum accounting fields needed to preserve ledger integrity.

After a Google or Meta disconnection, Vanteloq removes the local access credential and stops collection. Selected resource identifiers, derived measurements, and limited audit evidence are deleted or retained only for the documented service, security, legal, or workspace recordkeeping purposes described in this policy.

An authorized user can use Clear conversation in the Gemini Advisor to permanently delete that conversation and its messages from the active application database. Advisor conversations that have not been updated for 90 days are deleted when that user next uses the Advisor. A limited deletion audit event remains without the deleted question or answer content.

The operational retention schedule is reviewed at least annually and after a material provider, product, infrastructure, or legal change. Quarterly reviews identify expired purpose, unresolved deletion requests, legal holds, and records eligible for deletion or de-identification. A verified legal hold suspends deletion only for the affected records and documented period.

Imported bank transactions, approved accounting records, original invoices and receipts, corrections, and review history may need a longer period because they support the customer’s books or legal obligations. Customers should export required records before closing an account and should confirm their retention duties with a qualified professional.

Unsubscribe and suppression information may be kept in a minimal form so that a prior marketing choice can continue to be honoured. Security, incident, and audit records may be kept for a documented period that is proportionate to the risk and any applicable legal requirement.

8. Safeguards

Vanteloq uses safeguards designed for the sensitivity of the information, including authenticated access, records separated and scoped by organization, role-based server permissions, protected provider authorization flows, encrypted credential storage, request controls, and recorded audit and security events for important actions.

Production browser, API, authentication, webhook, and provider traffic uses HTTPS. Vanteloq's production change control requires the managed edge to reject protocol versions below TLS 1.2 before Plaid production access is enabled. Stored application data is encrypted at rest by the managed database platform. Plaid access tokens and provider item identifiers receive an additional application-level AES-GCM encryption layer under a hosted key that is not stored with the database record. Vanteloq does not place raw Plaid credentials in browser storage, source control, ordinary connection-status responses, or application logs.

No online service can promise absolute security. Users must protect their credentials, use strong passwords, enable available account protections, and promptly report suspected unauthorized access.

9. Access, correction, and privacy requests

You may ask to access or correct personal information under our control, subject to legal exceptions. You may also ask about how information was used or disclosed, withdraw consent where applicable, or raise a privacy concern.

Workspace controls may also allow an authorized owner to export records, disconnect a provider, correct reviewable fields, or request account deletion. A disconnection is not the same as deleting legally retained accounting records. We will explain any applicable limitation when responding to a verified request.

Send a clear request to hussienissa@lexedgeconsulting.com. We may need to verify your identity and authority before responding. If information is controlled by a Vanteloq customer, we may direct the request to that customer.

If a concern is not resolved, you may contact the Office of the Information and Privacy Commissioner of Alberta or the Office of the Privacy Commissioner of Canada, depending on which law applies.

10. Analysis and human review

Vanteloq may organize records and produce calculations, alerts, or suggested next steps from available data. These outputs depend on the quality, completeness, timing, and definitions of the source records. Material business, financial, legal, tax, employment, or inventory decisions should be reviewed by an authorized person and, where appropriate, a qualified professional.

The Gemini Advisor explains a bounded evidence snapshot; it does not receive authority to post journals, send payments, change inventory, contact customers, or take another business action. The generated explanation can be inaccurate or incomplete. Vanteloq displays source dates and missing inputs, and an authorized person must review the explanation before relying on it.

Document extraction can misread text, numbers, tax, dates, pages, suppliers, or other fields. Vanteloq keeps extracted values provisional until an authorized reviewer compares them with the original document. An extracted value is not an approved accounting entry, payment instruction, tax position, or professional conclusion.

11. Business users and children

Vanteloq is a business service for people authorized to act for an organization. It is not directed to children, and we do not knowingly collect personal information from children for their own use of the service.

12. Changes to this policy

We may update this policy when the service, providers, or legal requirements change. We will post the revised policy with a new update date. If a change materially affects how personal information is used, we will provide additional notice or seek consent where required.

Lexedge ConsultingLexedge ConsultingIndependent consulting practice
HomeJournalPrivacyTermsCookies

Questions about these documents can be sent to hussienissa@lexedgeconsulting.com.