Effective Date: March 2026

Last Updated: March 2026

AION Global Inc. (“AION Global,” “we,” “us,” or “our“) is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our website at aionglobalinc.com (the “Site“), use our AION Nexus platform, or otherwise interact with our services.

AION Global Inc. is a corporation incorporated under the Canada Business Corporations Act (corporation number 1546101-4), with its registered office at 100 King St W, Suite 5600, Toronto, Ontario M5X 1C9, Canada. We provide business management consulting services and develop AION Nexus, a customer relationship management platform for regulated financial businesses. We are subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada’s Anti-Spam Legislation (CASL), and we respect the rights of data subjects under the General Data Protection Regulation (GDPR) and other applicable privacy laws.

By accessing or using our Site or services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not use our Site or services.

1. Information We Collect

1.1 Information You Provide Directly

We collect personal information that you voluntarily provide to us, including when you:

  • Fill out a contact form or request a consultation
  • Subscribe to our newsletter or mailing list
  • Request a demo of AION Nexus
  • Communicate with us via email, telephone, or other channels
  • Apply for employment with us

The types of personal information we may collect include:

  • Identification information: Name, job title, company name
  • Contact information: Email address, phone number, mailing address
  • Business information: Industry, company size, business needs, and related details you provide when requesting our services
  • Communications: Any messages, inquiries, or feedback you send to us

1.2 Information Collected Automatically

When you visit our Site, certain information is collected automatically through cookies and similar technologies, including:

  • Device information: Browser type and version, operating system, device type, screen resolution
  • Usage data: Pages visited, time spent on pages, links clicked, referring URL, access times, and date of visit
  • Network information: IP address (which may be anonymized), approximate geographic location derived from IP address, Internet service provider

For detailed information about the cookies and tracking technologies we use, please see our Cookie Policy.

1.3 Information from Third Parties

We may receive information about you from third-party sources, including:

  • Publicly available business information (e.g., LinkedIn profiles, company websites)
  • Referrals from business partners or existing clients
  • Analytics providers (such as Google Analytics)

2. How We Use Your Information

We use the personal information we collect for the following purposes:

  • Providing services: To deliver our consulting services and AION Nexus platform, fulfill your requests, and manage our business relationship with you
  • Communication: To respond to your inquiries, send service-related notifications, and provide customer support
  • Marketing: To send you newsletters, promotional materials, and information about our services, where you have provided consent or where permitted by applicable law
  • Improvement: To analyze how our Site and services are used, identify trends, and improve our offerings
  • Security: To detect, prevent, and respond to fraud, unauthorized access, and other security threats
  • Compliance: To comply with applicable laws, regulations, and legal processes
  • Business operations: To manage our internal business operations, including record-keeping, auditing, and reporting

2.1 Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data on the following legal bases:

  • Consent: Where you have given us explicit consent to process your personal data for specific purposes (e.g., marketing communications, non-essential cookies)
  • Contractual necessity: Where processing is necessary to perform a contract with you or to take steps at your request prior to entering into a contract
  • Legitimate interests: Where processing is necessary for our legitimate business interests, such as improving our services, ensuring security, and conducting analytics, provided these interests do not override your fundamental rights
  • Legal obligation: Where processing is necessary to comply with a legal obligation to which we are subject

3. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties. We may share your information in the following limited circumstances:

  • Service providers: We engage trusted third-party service providers who perform services on our behalf, such as website hosting, analytics, email delivery, and customer relationship management. These providers are contractually obligated to use your information only as necessary to provide services to us and to maintain appropriate security measures.
  • Legal requirements: We may disclose your information if required to do so by law, in response to valid legal process (such as a court order or subpoena), or when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
  • Business transfers: In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your personal information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.
  • With your consent: We may share your information with third parties when you have given us explicit consent to do so.

4. Third-Party Services

Our Site and services use the following third-party services that may collect or process personal information:

Service Provider Purpose Privacy Policy
Google Analytics 4 Google LLC Website analytics and traffic analysis Google Privacy Policy
Gravity Forms Rocketgenius, Inc. Contact and demo request forms Gravity Forms Privacy Policy
Cloudflare Cloudflare, Inc. Content delivery network (CDN) and security Cloudflare Privacy Policy
CookieYes CookieYes Limited Cookie consent management CookieYes Privacy Policy
Hostinger Hostinger International Ltd. Web hosting Hostinger Privacy Policy
WordPress Automattic Inc. Content management system Automattic Privacy Policy

We encourage you to review the privacy policies of these third-party services. We are not responsible for the privacy practices of third-party websites or services.

5. Cookies and Tracking Technologies

Our Site uses cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and understand user behavior. We categorize cookies as follows:

  • Essential cookies: Required for the Site to function properly (e.g., session management, security)
  • Analytics cookies: Help us understand how visitors interact with our Site (e.g., Google Analytics)
  • Functional cookies: Enable enhanced functionality and personalization
  • Marketing cookies: Used to deliver relevant advertisements and track their effectiveness

We use CookieYes to manage cookie consent. When you first visit our Site, you will be presented with a cookie consent banner that allows you to accept or reject non-essential cookies. You can change your cookie preferences at any time by clicking the cookie settings link in the footer of our Site.

For complete details about the specific cookies we use, please refer to our Cookie Policy.

6. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. Specifically:

  • Contact form submissions: Retained for up to 24 months after the last interaction, unless a business relationship is established
  • Client records: Retained for the duration of the business relationship and for up to 7 years thereafter, as required by Canadian tax and business laws
  • Analytics data: Google Analytics data is retained according to our GA4 configuration settings (currently set to 14 months)
  • Marketing consent records: Retained for as long as the consent is valid and for a reasonable period thereafter to demonstrate compliance with CASL and GDPR
  • Website server logs: Retained for up to 12 months for security and troubleshooting purposes

When personal information is no longer required, we will securely delete or anonymize it in accordance with our data retention procedures.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit using TLS/SSL
  • Access controls limiting who within our organization can access personal information
  • Regular security assessments and monitoring
  • Use of Cloudflare for DDoS protection and web application firewall (WAF)
  • Use of Wordfence for WordPress-specific security hardening
  • Secure hosting infrastructure with regular backups

While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee absolute security, but we are committed to maintaining industry-standard safeguards.

8. Your Rights and Choices

8.1 Rights Under PIPEDA (Canadian Residents)

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to:

  • Access: Request access to the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete personal information
  • Withdrawal of consent: Withdraw your consent to the collection, use, or disclosure of your personal information, subject to legal or contractual restrictions
  • Complaint: File a complaint with the Office of the Privacy Commissioner of Canada (www.priv.gc.ca) if you believe your privacy rights have been violated

We will respond to your access or correction request within 30 days, as required by PIPEDA.

8.2 Rights Under GDPR (EEA, UK, and Swiss Residents)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following additional rights under the GDPR:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request that we correct inaccurate personal data
  • Right to erasure (“right to be forgotten”): Request that we delete your personal data, subject to certain legal exceptions
  • Right to restriction of processing: Request that we restrict the processing of your personal data in certain circumstances
  • Right to data portability: Request that we provide your personal data in a structured, commonly used, and machine-readable format
  • Right to object: Object to the processing of your personal data based on our legitimate interests or for direct marketing purposes
  • Right to withdraw consent: Where processing is based on consent, withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal
  • Right to lodge a complaint: File a complaint with your local data protection authority

To exercise any of these rights, please contact us using the information provided in Section 14 below. We will respond to your request within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing your request.

8.3 CASL Compliance (Marketing Communications)

In compliance with Canada’s Anti-Spam Legislation (CASL), we will only send you commercial electronic messages (such as newsletters and promotional emails) with your express or implied consent. Every marketing email we send includes:

  • Clear identification of AION Global Inc. as the sender
  • Our contact information, including mailing address
  • A clear and prominently displayed unsubscribe mechanism

You may withdraw your consent to receive marketing communications at any time by clicking the “unsubscribe” link in any marketing email or by contacting us at privacy@aionglobalinc.com. We will process your unsubscribe request within 10 business days, as required by CASL.

8.4 Managing Cookies

You can manage your cookie preferences through our cookie consent banner (powered by CookieYes) or through your browser settings. Please see our Cookie Policy for detailed instructions.

9. International Data Transfers

AION Global Inc. is based in Canada. The European Commission has recognized Canada as providing an adequate level of data protection under PIPEDA for transfers of personal data from the EEA.

Some of our third-party service providers (such as Google and Cloudflare) may process personal data in the United States or other countries outside of Canada and the EEA. Where such transfers occur, we ensure that appropriate safeguards are in place, including:

  • Adequacy decisions by the European Commission or other competent authorities
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • The service provider’s certification under applicable data transfer frameworks
  • Other appropriate safeguards as required by applicable law

If you have questions about international data transfers, please contact us using the information in Section 14.

10. AION Nexus Platform

If you are a client using the AION Nexus platform, additional terms regarding data processing, data security, and data protection responsibilities may apply as outlined in your AION Nexus service agreement. AION Nexus processes data on behalf of our clients (as a data processor), and clients retain control over the personal data they input into the platform (as data controllers).

For fintech clients, AION Nexus incorporates security measures and access controls designed to protect financial data in accordance with applicable financial services regulations.

11. Children’s Privacy

Our Site and services are not directed at children under the age of 16 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child under the age of 16, we will take steps to delete such information promptly. If you believe that a child has provided personal information to us, please contact us at privacy@aionglobalinc.com.

12. Do Not Track Signals

Some web browsers transmit “Do Not Track” (DNT) signals. Because there is no uniform standard for how DNT signals should be interpreted, our Site does not currently respond to DNT signals. However, you can manage your tracking preferences through our cookie consent banner and your browser settings.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:

  • Update the “Last Updated” date at the top of this page
  • Post the revised Privacy Policy on our Site
  • Where required by law, notify you by email or through a prominent notice on our Site

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

AION Global Inc.
Privacy Inquiries
100 King St W, Suite 5600
Toronto, Ontario M5X 1C9
Canada
Email: privacy@aionglobalinc.com
Website: aionglobalinc.com/contact

If you are not satisfied with our response to your privacy concern, you may contact the Office of the Privacy Commissioner of Canada:

Office of the Privacy Commissioner of Canada
30 Victoria Street
Gatineau, Quebec K1A 1H3
Toll-free: 1-800-282-1376
Website: www.priv.gc.ca

If you are located in the EEA, you also have the right to lodge a complaint with your local data protection supervisory authority.