Velcord

Velcord Logo

Privacy Statement

At Velcord, the information you share with us isn't just data—it's trust. We've built our approach around that idea, structuring how we receive, handle, and protect what you entrust to us with the seriousness it deserves.

Effective: February 10, 2026

What We Receive and When

Information arrives at different moments throughout your relationship with us. When you first register with Velcord, we ask for identification fundamentals: your name, email address, and country of residence. This occurs before any investment activity begins.

Registration Phase

During account setup, you provide your legal name, contact email, residential jurisdiction, and create authentication credentials. We derive your IP address and browser configuration automatically during this interaction.

As you move deeper into our services—submitting investment preferences, adjusting portfolio settings, or reaching out through support channels—additional details emerge. Transaction history builds naturally from your actions. Communication records develop when you contact our team. Device fingerprints get captured through standard web protocols whenever you access your dashboard.

Operational Phase

Once active, your account generates investment selections, risk tolerance indicators, contribution patterns, withdrawal requests, and support correspondence. We also record session metadata: login timestamps, page navigation sequences, and feature usage patterns.

Financial verification happens when regulatory requirements demand it. Depending on your jurisdiction and investment volume, we may request government-issued identification documents, proof of address, or source-of-funds documentation. This intake occurs only when legally mandated, not as a standard procedure for every client.

Information We Don't Actively Seek

We deliberately avoid gathering details beyond operational necessity. Social connections, browsing habits outside our platform, and personal preferences unrelated to financial planning remain outside our scope. If you voluntarily share such information through support messages, we don't systematically record or analyze it.

Why Each Element Matters

Every piece of information we request serves a defined function. Nothing gets collected "just in case" or for undefined future purposes.

Identity Verification

Names and documents establish that you are who you claim to be, meeting anti-fraud regulations and protecting your account from unauthorized access attempts.

Service Delivery

Contact details enable us to send investment updates, respond to inquiries, and notify you of account events. Without them, the service simply cannot function.

Legal Compliance

Financial services operate under strict regulatory frameworks. Transaction records, jurisdiction data, and verification documents satisfy obligations imposed by Canadian securities law and tax authorities.

Security Monitoring

IP addresses and device patterns help detect suspicious login attempts and account takeover efforts, forming part of our intrusion prevention approach.

Investment preferences—risk tolerance, time horizons, sector interests—directly shape the portfolio recommendations and asset allocation strategies we present. Support conversations create records that prevent repeated explanations and enable continuity when different team members assist you over time.

How Information Moves Internally and Externally

Within Velcord, access follows a principle of operational necessity. Not everyone sees everything. Our investment advisors view portfolio data and preferences. Customer support personnel access communication history and account status. Technical staff monitor system logs and security events. Finance teams handle transaction records and payment processing. Each group reaches only what they require to perform their specific function.

Third-Party Involvement

Certain functions cannot be performed entirely in-house, which means selective information disclosure to external partners. Payment processing services receive transaction amounts and account identifiers to execute transfers. Cloud infrastructure providers host encrypted databases containing your records. Email delivery systems transmit messages you've requested. Identity verification vendors analyze documents you submit during compliance checks.

These external entities operate under contractual restrictions. They cannot repurpose your information, cannot combine it with data from other sources, and must delete it when our business relationship ends. We select partners based partly on their own privacy practices and security certifications.

Velcord does not sell client information to marketing firms, data brokers, or advertising networks. Your details never appear in commercial databases sold to third parties.

Legal demands occasionally force disclosure. Court orders, regulatory investigations, or law enforcement requests backed by proper legal authority may compel us to provide specific records. When this occurs, we verify the legitimacy of the demand and narrow the scope to only what the legal instrument requires.

Business Transitions

Should Velcord undergo acquisition, merger, or asset sale, your information would transfer to the successor entity. Such transitions require the new organization to honor existing privacy commitments, though future handling might differ if they provide proper notice and choice.

Protection Measures and Remaining Risks

Security at Velcord combines technical controls, procedural discipline, and architectural choices designed to reduce exposure. We encrypt data both during transmission and while stored in databases. Access credentials undergo hashing with cryptographic algorithms that prevent reverse computation. Network traffic passes through monitored firewalls. System logs capture access attempts and administrative actions for audit review.

Employee access requires multi-factor authentication and gets reviewed quarterly. We maintain separate development, testing, and production environments to prevent accidental data exposure during software updates. Regular vulnerability scans and penetration tests identify weaknesses before attackers can exploit them.

Despite these measures, absolute security doesn't exist. Sophisticated attacks, human error, or unknown vulnerabilities could lead to unauthorized access. We maintain incident response protocols and commit to prompt notification should a breach occur that materially affects your information.

You bear responsibility for protecting your own credentials. Weak passwords, credential sharing, or accessing your account from compromised devices creates risks outside our control. We recommend unique passwords, password manager usage, and avoiding public computers for financial activities.

Your Control Options

Canadian residents—and in certain cases, residents of other jurisdictions—possess specific rights regarding their information. You can request to view what we hold about you. You can ask us to correct inaccuracies. You can demand deletion of your records, subject to legal retention requirements that may prevent immediate removal. You can object to certain processing activities or request that we restrict handling to specific purposes only.

Access Requests

Submit a formal request through email to our privacy contact. We respond within thirty days with a structured report of your information or an explanation of any delays.

Correction Procedures

Identify the specific incorrect details and provide supporting documentation. We update records within fifteen days once verification is complete.

Deletion Requests

Understand that financial regulations require us to retain certain records for seven years. We delete what law permits and anonymize what must remain.

Portability Options

Request a machine-readable export of your investment history and account data to transfer to another provider. Format depends on technical feasibility.

Marketing communications can be stopped at any time through the unsubscribe mechanism in each message or by contacting support directly. Operational messages—account notifications, security alerts, regulatory disclosures—cannot be opted out of while you maintain an active account.

Retention Duration

Active account information remains accessible throughout your relationship with Velcord. After account closure, we retain transaction records for seven years per securities regulations, then permanently delete them. Communication logs get purged three years post-closure. Marketing lists remove you immediately upon unsubscribe request.

If you believe we've mishandled your information, you can file a complaint with the Office of the Privacy Commissioner of Canada. Contact details for that office can be found on their official government website. We commit to working with regulatory authorities to resolve any concerns.

Legal Foundation and Jurisdiction

Velcord operates under Canadian federal privacy legislation and Ontario provincial securities law. Our processing relies on several legal bases depending on the activity: contractual necessity for service delivery, legal obligation for regulatory compliance, legitimate interest for fraud prevention and system security, and explicit consent for marketing communications.

We do not specifically target European Union residents, but if you access our services from the EU, certain GDPR protections may apply. Cross-border data transfers outside Canada occur only with partners maintaining adequate safeguards through standard contractual clauses or equivalent mechanisms.

This statement governs information handling by Velcord exclusively. Third-party sites linked from our platform operate under their own policies. We recommend reviewing those separately before sharing information with external services.

Changes to this privacy statement occur when legal requirements shift, business practices evolve, or new services launch. Material revisions trigger email notification to active account holders thirty days before taking effect. Continued use of Velcord services after that period constitutes acceptance of the updated terms.

Privacy Questions and Formal Requests

Email: contact@velcord.com
Mail: 185 Doe Rd, Carleton Place, ON K7C 0C4, Canada
Phone: +1 519 988 0050

For tracking purposes, our reference code is available upon request. Include "Privacy Inquiry" in your subject line to ensure proper routing to our compliance team.