How Orbiq is governed
A personal finance app is asking you to hand over the most detailed record of your life that exists. These are the documents that say what happens to it — written before launch, kept current, and published here in full.
None of this is a badge or a logo we bought. A Record of Processing Activities is the list of every kind of data handled and every third party that ever sees it. A Privacy Impact Assessment is the written analysis of what an AI feature actually risks. A Vendor Risk Assessment is the review of a company we depend on. They are unglamorous, they take months, and a product assembled last weekend does not have them. That is exactly why they are worth showing you.
Published in full
Each of these is rendered from the source document in the repository. The version and effective date on every page come from that file, so this site cannot quietly drift out of step with the record it is publishing.
-
Record of Processing Activities
The full list of every kind of personal data Orbiq handles, why it handles it, who else ever sees it, whether it leaves Canada, and how long it is kept. If a company cannot produce this document, it does not actually know the answer.
-
Data Classification Policy
Which data is treated as most sensitive, and what protection each tier is required to get. Your transactions and any credential that can read your bank sit in the top tier, which is the one with mandatory encryption.
-
AI Privacy Impact Assessment
What is actually sent to an AI model when Orbiq categorizes a transaction, what is stripped out first, and what the provider is contractually forbidden from doing with it. Short version: merchant structure goes, your raw rows do not.
-
Vendor Risk Assessment — Groq
The review of the AI provider: what it receives, where it processes, and the no-store / no-train terms that make that acceptable.
-
Vendor Risk Assessment — Plaid
The review of the bank-connection provider used for Canada and the US, including how the access token is protected and what happens to it when you disconnect.
-
Vendor Risk Assessment — LunchFlow
The review of the bring-your-own-key sync path. It says out loud that Orbiq has no contract with this vendor and has therefore NOT vetted their processing on your behalf — which is the honest position, and not the flattering one.
-
Privacy Officer Designation
The named human who is accountable for all of the above, and how to reach them.
-
Claims → evidence map
Every privacy claim on this website, mapped to the document or the line of code that backs it — plus a list of the claims deliberately not made, and why. A claim with no row here gets deleted rather than softened.
Exists, reviewed, deliberately not published
Two documents are attested to rather than published. Saying so directly is the point — an omission you have to notice is worse than a refusal you can read.
-
Incident Response Playbook
What it covers. Detection, containment, assessment of real risk of significant harm (RROSH), and the commitment to notify the Office of the Privacy Commissioner of Canada within 72 hours of establishing that a breach poses real risk. Covers the specific case of an aggregator token compromise.
- Exists and is in force
- Compliance mapping: PIPEDA · CSA STAR CCM-SEF-04 · CyberSecure Canada
- 72-hour OPC notification commitment
- RROSH assessment framework applied to every incident
Why it is not published. The containment sequence — which edge to disable, which credentials to rotate, which logs to preserve first, in what order — is an operational map. Publishing it would hand an attacker the runbook for staying ahead of the response. It is reviewed, it is dated, and it is not on this page.
-
Business Continuity & Disaster Recovery Plan
What it covers. Recovery point and recovery time objectives, a multi-layer backup posture with geographic separation, and a fixed testing cadence so the plan is exercised rather than assumed.
- Backups exist in more than one layer, with geographic separation
- RPO and RTO targets are defined and in force
- Tested on a fixed cadence: quarterly tabletop, six-monthly technical restoration
- Compliance mapping: CSA STAR BCR · PIPEDA
Why it is not published. Region names, storage paths, provider topology and the recovery command sequence are withheld: together they describe exactly where the backups live and how to reach them. The targets and the testing cadence are the parts a reader can actually hold us to, so those are stated.
Who is accountable
Orbiq is operated by FINARO CAPITAL SERVICES INC., Toronto, Ontario, Canada. The Privacy Officer is named in the designation document above and is reachable at [email protected]. Full address provided on request for service of legal process. Access, correction and erasure requests go to the same address and are handled under the Data Retention & Deletion Policy.