As of: 5 October 2026
This policy explains what personal information we collect through the BrickFlow website (brickflow.ca) and the BrickFlow app (app.greenkey.site), why we collect it, who we share it with, and the choices you have.
BrickFlow is a trade name of GreenKey Information Management Corporation. When we say “we”, “us” or “BrickFlow”, we mean that company.
1. Who we are
GreenKey Information Management Corporation / GreenKey Gestion de l’information Corporation 64 Elmwood Place, London, ON N6J 1J2, Canada
We are a Canadian company. Our servers for the app are in Canada. Some of our service providers are in the United States (see sections 6 and 7).
Privacy Officer: John Kennedy, [email protected]
The Privacy Officer is responsible for our compliance with privacy law and is the person to contact with any privacy question, request or complaint.
2. What we collect
Website visitors
- Technical data: IP address, browser type, pages viewed, referring site, and similar data our hosting provider (Cloudflare) logs to run and protect the site.
- Analytics: only if you click “Accept” on our cookie banner, we use PostHog to understand how the site is used (pages visited, clicks, approximate location from IP). If you click “Reject”, we count your visit using a server-side hash that sets no cookies and is not linked to you across days.
- Contact form and bookings: your name, email, company, and whatever you write to us. The contact form is protected by Cloudflare Turnstile, which checks that you are not a bot. Bookings go through Google Calendar appointment scheduling.
- Deadline-reminder emails: if you sign up, your email address and the reminders you chose.
Account users
- Account details: name, work email, Google sign-in identifier, organization name, role, phone number if you give it.
- Billing: our payment processor, Stripe, collects your card details. We never see your full card number. We keep your billing contact, invoices and payment status.
- Usage data: sign-ins, features used, errors, and device and browser data in our server logs. The app does not use analytics cookies or session replay.
- Support: emails and messages you send us.
Customer data (bills, utility data and buildings)
Our customers are businesses. When a customer uses BrickFlow to manage its buildings, it uploads or connects data that can include personal information about other people, for example:
- utility bills, which can show the account holder’s name, service address, account number and usage;
- utility data from Ontario’s Green Button Connect My Data program (see below);
- building and tenant records, which in multi-residential buildings may include unit-level or tenant-level data;
- contacts for property managers, owners and utility accounts.
For this data, our customer decides what to collect and why. We process it only on the customer’s instructions and under our Terms of Service. If you are a tenant, contact or account holder and have a question about data a BrickFlow customer holds about you, please contact that customer. We will help them respond.
Green Button energy data
With the utility customer’s authorization, we receive electricity or natural gas data from the customer’s utility through Ontario’s Green Button Connect My Data program. Our Privacy Rules for Energy Data (section 10) explain exactly what we receive, what we do with it, whether we share it, how long we keep it and how we destroy it. Those rules cannot be changed, as they apply to your energy data, without your prior consent.
Communications
If you email us, book a meeting, or reply to a reminder, we keep the correspondence. Our email is hosted on Google Workspace.
3. Why we collect it, and on what basis
We collect and use personal information for these purposes:
| Purpose | Examples | Basis |
|---|---|---|
| Provide the service | Create your account, read your bills, sync with ENERGY STAR Portfolio Manager, produce reports | Your consent when you sign up; our contract with your organization |
| Billing | Charge your card, send invoices, collect overdue amounts | Contract; legal obligation to keep tax records |
| Security and fraud prevention | Log-in monitoring, bot detection, abuse prevention | Implied consent; our legitimate need to protect the service |
| Support | Answer your questions, fix problems | Consent / contract |
| Product analytics | Understand which features are used, find bugs | Express consent (cookie banner / in-app consent) |
| Marketing emails | Deadline reminders, product news | Express consent under Canada’s anti-spam law (CASL). You can unsubscribe at any time. |
| Legal compliance | Respond to lawful requests, keep required records | Legal obligation |
We do not sell personal information. We do not use personal information for automated decisions that have legal or similarly significant effects on individuals.
Consent. Where we rely on your consent, you can withdraw it at any time (section 11). Withdrawing consent may mean we cannot keep providing part of the service.
4. Cookies and analytics (summary)
Our website uses only one non-essential cookie, set by PostHog for analytics, and only after you click “Accept”. A small consent cookie remembers your choice for six months. The app uses a strictly necessary session cookie to keep you logged in. Cloudflare Turnstile, which protects our contact form, does not set cookies by default.
Full details, including cookie names and durations, are in our Cookie Policy.
5. AI processing of bills
When you upload a utility bill, we send the bill image or PDF to Anthropic’s Claude API, which reads the numbers off the bill (usage, cost, dates, account number). Anthropic is a US company and processing may happen in the United States.
We use Anthropic under its Commercial Terms of Service. Under those terms:
- Anthropic may not train its models on our content, which includes your bills.
- Anthropic automatically deletes API inputs and outputs from its systems within 30 days, unless the content is flagged by its automated trust and safety systems for a usage-policy violation, in which case it may be retained for up to two years.
You should review AI-extracted numbers before relying on them. The AI can make mistakes. Our Terms of Service explain that you are responsible for checking data before you file it with a regulator.
Development and test environments may use a different AI gateway (OpenRouter) for test bills. The production app does not use OpenRouter.
6. Who we share with
We share personal information only with service providers who help us run BrickFlow, and only for the purposes below. Each provider is bound by contract to protect the data and use it only to provide its service to us.
| Provider | Purpose | Location of processing |
|---|---|---|
| Google Cloud (Compute Engine, Cloud Storage) | Hosting the app and database (Toronto); nightly backups (Montreal) | Canada |
| Anthropic | AI reading of uploaded bills | United States |
| Cloudflare | Website hosting (Pages), content delivery, bot protection (Turnstile) | United States and global edge network |
| PostHog | Website analytics (after consent) | United States (US East) |
| Stripe | Payment processing, invoicing | United States (with Canadian operations) |
| Google Workspace | Our email (including alert emails the app sends you), calendar, appointment booking | United States and other countries where Google operates |
| Google (Sign-In) | Signing in to the app with your Google account | United States |
| Google Maps Platform | Showing maps of your buildings and looking up building addresses | United States |
| Resend | Delivering messages sent through our website contact form to our inbox | United States |
| ENERGY STAR Portfolio Manager | Benchmarking sync, only when you connect your account. Data for Canadian buildings is governed by Natural Resources Canada under Canada’s Privacy Act and Access to Information Act (NRCan) | Stored on a US EPA server in the United States |
| Your utility (Green Button) | Receiving the energy data you authorized (see section 10) | Canada |
We may also share personal information:
- with a buyer or successor if we sell or reorganize our business, under the same protections;
- when the law requires it, for example a court order, or to protect someone’s safety; and
- with your organization’s administrator, who can see the accounts and data in your organization’s workspace.
We will update this table when we add or change providers.
7. Cross-border transfers
Your account data, bills and utility data are stored in Canada. However, some of our providers process data in the United States: Anthropic (bill reading), Cloudflare (website), PostHog (analytics), Stripe (payments) and Google (sign-in, email, calendar).
While data is in the United States, it is subject to US law, and US courts, law enforcement and national security agencies may be able to access it under US law. We choose providers with strong security practices and contractual commitments, but we cannot promise that foreign law will not apply.
Quebec residents: before sending personal information outside Quebec, we assess whether it will receive adequate protection, considering the sensitivity of the information, the purpose, the safeguards in place, and the laws of the destination. Our assessment for each provider above is on file with our Privacy Officer.
8. Retention
- Account and customer data: we do not delete data automatically. We keep it while you have an account, so your history and reports stay complete, until you ask us to delete it. Closing your account counts as asking. We delete it from our live systems within 30 days of your request. If we ever need to free storage, we may delete data from accounts with no sign-in for more than two years, after giving 30 days’ email notice so you can export it first.
- Backups: nightly database backups expire after 30 days, so deleted data is gone from them within 30 days of deletion. When we delete your data we also delete the copies of your files in our offsite backup storage. Backups are not used to restore deleted data except to recover from a system failure, and if that happens we delete the data again.
- Billing records: kept for six years from the end of the tax year to which they relate, as the Income Tax Act requires.
- Green Button energy data: handled the same way: kept until you ask us to delete it or close your account (section 10).
- Analytics: PostHog keeps analytics data for up to one year.
- Website logs: Cloudflare retains request logs for a short period under its own policies.
- Emails and support: kept for as long as reasonably needed to deal with your request and for our records.
- Bills sent to Anthropic: deleted by Anthropic within 30 days (see section 5).
9. Security (summary)
We use industry-standard safeguards: encryption in transit (TLS) and at rest, access limited to staff who need it, logging of sign-ins, and nightly backups. Our staff, currently our founder, have administrator access and are bound by confidentiality. No system is perfectly secure, and we cannot guarantee that unauthorized access will never occur. Our Security and data page gives more detail. That page is also our posted cyber-security policy for Green Button energy data (section 10).
If we have a breach that creates a real risk of significant harm to you, we will notify you and the Privacy Commissioner of Canada as the law requires. For Quebec residents, we will also notify the Commission d’accès à l’information when there is a risk of serious injury. If Green Button energy data is involved, we also tell the utility immediately (section 10).
10. Privacy Rules for Energy Data (Green Button)
These are our Privacy Rules for energy data we receive through Ontario’s Green Button Connect My Data program. They apply together with the rest of this policy, and if the two conflict, these rules win for energy data. We post these rules here and our cyber-security policy at brickflow.ca/security, and we give a copy of both to every customer who authorizes a utility to share data with us, at the time of authorization. They answer the five questions the Ontario Energy Board asks third parties to answer.
What energy data we receive
Only what you authorize at your utility, which can include:
- usage data: interval and daily readings, and monthly totals, for electricity or natural gas;
- billing data: billing periods, charges, rates and amounts;
- account data: account holder name, service address, account and meter numbers, rate class, and contact details on the utility account.
We ask the utility only for the data categories, accounts and period you select. If the utility sends us data you did not authorize, we delete it as soon as we discover it, tell the utility, and record what happened.
1. How we protect your privacy
- Energy data is stored on Google Cloud servers in Toronto, with encrypted backups in Montreal. It leaves Canada only if you connect ENERGY STAR Portfolio Manager (Canadian data is governed by Natural Resources Canada under Canadian privacy law, but stored on a US EPA server in the United States), and then only the building and meter data you choose to send there.
- Connections to utilities use OAuth 2.0, encrypted in transit with TLS, and the access tokens are stored encrypted. We request only the access needed for the purpose you authorized.
- Access is limited to named staff (currently our founder), and sign-ins to BrickFlow are logged.
- Our full safeguards are in our cyber-security policy at brickflow.ca/security.
- We comply with PIPEDA, Ontario Regulation 633/21 under the Electricity Act, 1998, and the third-party terms of each utility we connect to.
2. What we do with your energy data
We use it only for the purpose you authorized, which is described in the scope-of-use statement we have filed with your utility:
BrickFlow (a trade name of GreenKey Information Management Corporation) will retrieve the usage, billing and account data you authorize, for the accounts and period you select, and use it only to: (1) show the energy use and costs of your buildings in BrickFlow; (2) benchmark your buildings and, if you connect your ENERGY STAR Portfolio Manager account, send the property and meter data you choose to Portfolio Manager at your direction; (3) prepare the reports you ask for, such as Ontario Energy and Water Reporting and Benchmarking (EWRB), City of Toronto and GRESB submissions; and (4) check the data for billing anomalies and missing periods and tell you about them. We do not sell energy data, use it for marketing, build profiles of individuals from it, or use it to train artificial-intelligence models. We disclose it only to the people in your BrickFlow workspace, to the service providers that host BrickFlow in Canada, to ENERGY STAR Portfolio Manager when you direct it, to anyone else you authorize, or when the law requires. The data is stored in Toronto with encrypted backups in Montreal, is encrypted in transit and at rest, and is accessible only to named staff. When you revoke the authorization, we stop collecting at once: if you disconnect in BrickFlow we delete the access token immediately, and if you revoke at your utility the token stops working immediately and is deleted with your data. Data already received stays in your BrickFlow account, so your history and reports stay complete, until you ask us to delete it or close your account; we then delete it from our live systems within 30 days, and encrypted database backups expire 30 days later. Data sent to us in error is deleted as soon as we find it. You can revoke at any time at your utility or by emailing [email protected]. Our Privacy Rules for Energy Data are at brickflow.ca/privacy and our cyber-security policy at brickflow.ca/security.
In plain terms, that means showing your usage and costs in BrickFlow, producing reports and benchmarks for your buildings, and, if you connect it, sending building and meter data to ENERGY STAR Portfolio Manager on your instruction. We do not use energy data for marketing, we do not build profiles of individuals from it, and we do not use it to train artificial-intelligence models. Energy data received through Green Button arrives as structured data and is not sent to our AI bill-reading provider.
3. Whether we share it
We do not sell energy data. We disclose it only:
- to the people in your BrickFlow workspace that you have given access to;
- to the service providers we use to run BrickFlow, which for energy data is Google Cloud (hosting in Toronto and backups in Montreal), and ENERGY STAR Portfolio Manager (governed by Natural Resources Canada, stored in the United States) only if you connect your account and only the properties and meters you choose. Each provider is bound by contract to protect the data and use it only to provide its service to us;
- with your authorization, to anyone else you direct us to share it with; or
- when the law requires it, for example a court order.
We may use energy data in aggregated form, for example to publish industry benchmarks, only after it has been de-identified so that it would not directly or indirectly permit the discovery of the origin of the data. Energy data for a single building can be re-identifiable, so we aggregate across groups of buildings.
4. How long we keep it
- We keep energy data while your authorization is active and you have a BrickFlow account.
- When you revoke your authorization, we stop collecting new data immediately. If you disconnect in BrickFlow, we delete the access token at once; if you revoke at your utility, the token stops working at once and is deleted with your data. The energy data we already received stays in your account, so your history and reports stay complete, until you ask us to delete it.
- When you ask us to delete it, or close your account, we delete it from our live systems within 30 days.
- If we ever need to free storage, we may delete energy data from accounts with no sign-in for more than two years, after giving you 30 days’ email notice so you can export it first.
- Data we received in error is deleted as soon as we discover it.
- We keep archival copies only where a law requires us to. Otherwise, nightly database backups expire after 30 days and are never used to restore deleted data except to recover from a system failure, after which we delete the data again.
5. How we destroy it
We delete energy data from the live database and file storage, destroy the utility access token, and remove any copy held by a service provider listed above. Deletion is permanent. Database backups are encrypted and expire after 30 days. We can confirm deletion in writing on request.
How to revoke your authorization
You can revoke at any time, in either place:
- At your utility: through its Green Button or online account portal, where you can see and cancel the authorizations you have given.
- In BrickFlow: in the app under Data Sync > Green Button, or by emailing [email protected].
When you revoke, we stop collecting data immediately, and the access token can no longer be used. The energy data we already received stays in your account until you ask us to delete it. To have it deleted, including the copies inside reports we generated from it, email [email protected] or close your account; we delete it within 30 days. Export anything you want to keep first.
If something goes wrong
If we discover a breach of security involving energy data, we notify the affected utility immediately with a summary of what happened, the facts we know, the status of our investigation and the customers affected, and we update the utility as we learn more. We notify you and the Privacy Commissioner of Canada as section 9 describes.
Changes to these rules
We will not amend these Privacy Rules or our cyber-security policy, as they apply to your energy data, without your prior consent. If we propose a change, we will send it to you and ask you to agree before it applies to your data. If you do not agree, the version you accepted continues to apply, or you may revoke your authorization.
Your utility’s role
Your authorization is given through your utility’s own process, and the utility’s Green Button terms govern how it shares data with us. Your utility is not responsible for how BrickFlow handles your energy data once we receive it; we are. Green Button and utility names are trademarks of their owners, and BrickFlow is not provided, licensed, warrantied or sponsored by any utility.
11. Your rights
Subject to limited legal exceptions, you have the right to:
- Access the personal information we hold about you, and learn how we have used it and who we have shared it with.
- Correct information that is inaccurate or incomplete.
- Withdraw consent to our use of your information, including unsubscribing from emails or turning off analytics.
- Delete your personal information (for Quebec residents, the right to ask that it be de-indexed or cease to be disseminated in certain cases).
- Portability (Quebec): receive computerized personal information you provided to us in a structured, commonly used technological format, or have it sent to another organization.
- Complain. You can complain to us first. You can also complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Quebec, the Commission d’accès à l’information (cai.gouv.qc.ca).
If we refuse any part of a request, we will tell you why in writing and explain how to complain.
12. How to make a request
Email [email protected] or write to the address in section 1. Tell us what you want and how to reach you. We may ask you to confirm your identity, in proportion to the sensitivity of the information. We will respond within 30 days. If we need more time, we will tell you why and when to expect our answer, and remind you that you can complain to the Privacy Commissioner. There is no charge for ordinary requests. If a request is very large or repeated, we may charge a reasonable fee and will tell you first.
If your request relates to data a BrickFlow customer holds about you (for example a bill with your name on it), we will pass the request to that customer or ask you to contact them directly, because the customer controls that data.
13. Children
BrickFlow is a business tool. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact us and we will delete it.
14. Changes
We may update this policy. We will post the new version here with a new “as of” date. If a change materially affects how we use your personal information, we will tell account users by email or in the app before it takes effect, and where the law requires it, ask for your consent.
Exception for energy data. We will not change section 10 (Privacy Rules for Energy Data) or our cyber-security policy, as they apply to your Green Button energy data, without your prior consent.
15. Contact and Privacy Officer
Privacy Officer: John Kennedy Email: [email protected] Security issues: [email protected] General: [email protected] Mail: GreenKey Information Management Corporation, 64 Elmwood Place, London, ON N6J 1J2, Canada
This policy is available in French on request. / Cette politique est disponible en français sur demande.