Privacy & security

Written down, so you can hold us to it.

This page covers two things: how we handle the information clients share with us during an audit, and how this website itself is engineered so there is almost nothing to handle.

Last updated: July 9, 2026

1. This website collects nothing

This site is a static brochure. By design, it:

When you click “Book a call,” you leave this site and land on our scheduling and intake forms, which are operated by their own providers (see section 4).

2. What we collect during an engagement

If you book a discovery call or commission an audit, we collect only what the audit needs:

Least-data rule: we tell every client up front not to send us sensitive or regulated information, such as well coordinates, reserves data, land files, personnel records, or anything under regulatory hold. The audit works from task descriptions and hour counts, nothing deeper.

3. How your information is used and protected

We handle personal information in line with the principles of Canada’s PIPEDA and Alberta’s Personal Information Protection Act (PIPA), which cover consent, access, correction, and deletion. The sections below put those principles into practice.

4. Third-party services we use

A small set of established providers handle specific steps. Each processes only what that step requires, under its own privacy policy:

5. Retention and deletion

We keep engagement materials while we’re working together and for a reasonable period afterward so we can support what we delivered. At any time, you can ask us to delete your materials, including recordings, transcripts, intake responses, and working files, and we will confirm in writing when it’s done.

6. Your choices

7. Contact

Questions, requests, or security reports: modelriskgroup@gmail.com. Security researchers can also find our disclosure contact at /.well-known/security.txt.