Privacy Policy
Last updated: August 6, 2026
We run AI that answers your phones, works inside your CRM and acts on your business systems. That means we handle information about you, and about the people who contact you. This policy explains what we collect, why, who helps us, how long we keep it, and how to get it deleted — in plain language.
1. Who we are
Business Growth Partners (“BGP,” “we,” “us”) is operated by Friends Realty Investments Ltd., based in Ontario, Canada. For anything in this policy, including a request to access or delete your data, contact info@businessgrowthpartners.ai or call +1 (647) 709-1536.
2. What this policy covers
This one policy covers every service we offer:
- AI Employees — the AI Receptionist, AI Customer Service and AI Sales Assistant that answer and place calls, handle messages, book appointments and raise tickets for your business.
- Automation workflows — the automations we build and run inside your systems.
- CRM platform access — the customer relationship platform we provide with your plan, at portal.businessgrowthpartners.ai.
- BGP AI — the assistant platform at studio.businessgrowthpartners.ai, which connects to your own business tools. Sections 5 and 6 cover it in detail.
- Marketing services — campaign work delivered as part of your plan.
- Training, masterminds and events — including the Toronto AI Summit.
- This website and the consultation booking form.
3. Two different roles we play
This distinction decides who you should ask about what, so it is worth stating plainly.
- When the information is about you as our client — your account, your billing, your business details — we are the controller. We decide how it is handled, and this policy governs it.
- When the information is about your customers — the person who called your AI receptionist, the contact in your CRM, the recipient of an email your assistant sent — you are the controller and we are your processor. We handle it on your instructions to deliver the service, and we do not use it for our own purposes.
If you are a customer of one of our clients and want your data removed, you can still write to us at info@businessgrowthpartners.ai. Tell us which business you dealt with. We will pass the request to them as the controller and act on it ourselves as their processor.
4. What we collect
Website visitors and enquiries
Your name, email, phone number, business details and whatever you tell us when you book a consultation or contact us, plus ordinary server and device information such as IP address and browser type.
Clients and accounts
Account and contact details, your business profile, the configuration of your AI employees and workflows, usage records, support correspondence, and billing details. Card numbers are handled by our payment processor and never reach our servers.
Calls handled by AI Employees
This is the most sensitive category we handle, so it is set out in full:
- Caller and recipient phone numbers, call times, duration, direction and outcome.
- Call audio recordings and written transcripts, where recording is enabled for your account.
- Anything the caller says during the call — names, addresses, appointment details, order or account references, and any other detail they choose to give.
- The actions taken as a result: appointments booked, tickets raised, contacts created or updated, follow-ups scheduled.
Section 7 covers your obligations around recording and consent, which are yours rather than ours.
CRM and messaging
Contacts, conversation history across SMS, email and chat, calendars and appointments, opportunities and pipelines, invoices, forms and campaign statistics held in the CRM we provide.
BGP AI platform
Your conversations with the assistant, documents you upload and their contents, the notes the assistant keeps about your business, the actions it prepares along with their inputs and results, and the credentials for the tools you connect.
Training and events
Registration details, attendance, and any recordings or materials produced at sessions you join. If a session is recorded we tell you before it starts.
5. Connected services in BGP AI
BGP AI only reaches a third-party service after you connect it, and only with the permissions you granted at that moment. Nothing below happens for a service you have not connected. You can see every connected account, and disconnect any of them, on your Integrations page — we delete the stored credentials immediately, and for Google and Intuit we revoke the grant with the provider in the same step.
Google — Gmail
- Permissions we request — gmail.modify, userinfo.email and openid, requested when you connect a mailbox.
- What we read — Message headers, bodies, attachments, threads and labels, plus the mailbox address and message counts shown on your Integrations page.
- What we can write — Sends emails, replies inside existing threads, creates and sends drafts, applies and removes labels, archives messages, and marks them read or unread. We never request permanent deletion, and no tool in the assistant can permanently delete a message.
- What we store — The OAuth access and refresh tokens, encrypted. Message content is fetched live while the assistant is answering you; the part it acts on is stored on the resulting task record, encrypted, so you have an audit trail of what was sent and why.
Meta — Facebook Pages and Instagram
- Permissions we request — pages_show_list, pages_read_engagement, pages_manage_posts, pages_manage_engagement, pages_manage_metadata, read_insights, instagram_basic, instagram_content_publish, instagram_manage_insights, instagram_manage_comments and business_management.
- What we read — The Pages and Instagram professional accounts you administer, their posts and comments, and the engagement and reach metrics behind your reporting.
- What we can write — Publishes posts to the Pages and Instagram accounts you connect, and replies to or hides comments on them.
- What we store — Page and Instagram access tokens, encrypted, with the account names and IDs needed to show which accounts are connected.
Intuit — QuickBooks Online
- Permissions we request — com.intuit.quickbooks.accounting.
- What we read — Customers, vendors, invoices, estimates, payments, items, accounts and the company profile of the QuickBooks company you connect.
- What we can write — Creates and updates records such as invoices, estimates, customers and payments — each one only after it has been approved.
- What we store — OAuth tokens and the QuickBooks company (realm) ID, encrypted. Accounting records are read live.
GoHighLevel
- Permissions we request — Read scopes for contacts, conversations, calendars, opportunities, invoices, users, products, forms, locations, workflows, socialplanner, emails, voice-ai-agents and voice-ai-dashboard — plus write scopes for contacts, conversations/message, calendars/events, opportunities, invoices, socialplanner/post, emails/templates, emails/campaigns and voice-ai-agents.
- What we read — Contacts and their custom fields, conversation history, calendars and events, opportunities and pipelines, invoices, products, forms, workflows, the users and location settings on your account, scheduled social posts, email templates and campaigns with their statistics, and your voice AI agents and their dashboard.
- What we can write — Creates and updates contacts, sends messages logged on the contact timeline, books and updates calendar events, moves opportunities, creates invoices, schedules social posts, creates and updates email templates and campaigns, and configures voice AI agents.
- What we store — OAuth tokens and your location ID, encrypted. CRM records are read live.
6. Google user data and the Limited Use requirements
BGP AI’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In practice:
- We use Gmail data only to provide and improve the user-facing features described in this policy — reading the mail you ask about, drafting replies, and sending what you approve.
- We do not transfer Gmail data to others except as necessary to provide those features (see the subprocessors in Section 11), to comply with applicable law, or as part of a merger or acquisition after obtaining your explicit consent.
- We do not use Gmail data for advertising of any kind, including personalized, re-targeted or interest-based advertising.
- We do not use Google user data to develop, train or improve generalized artificial intelligence or machine learning models. Gmail content is sent to our AI providers only to generate the specific reply or action you asked for, and those providers are contractually prohibited from training on it.
- Our staff do not read your Gmail data, except with your explicit consent for a specific message, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.
7. Call recording, consent and outbound calling
Our AI employees answer and place calls on your behalf, which puts obligations on you as the business those calls come from. We build the tools; the legal duty to use them lawfully sits with you.
- Recording notice. Where calls are recorded, callers must be told at the start of the call. Some places require every party to consent, not just one — that includes several US states your customers may be calling from. We can configure a recording announcement for you; making sure it is present and adequate for the people you serve is your responsibility.
- Disclosing the AI. A growing number of jurisdictions require you to tell people they are speaking with an automated system. Our agents can say so, and we recommend leaving that on.
- Outbound calls and messages. You are responsible for having a lawful basis to contact the people on your lists, for honouring do-not-call and unsubscribe requests, and for complying with anti-spam and telemarketing rules — including Canada’s CASL and, where your contacts are in the United States, the TCPA. Do not upload lists you do not have permission to call or message.
8. How we use information
- To deliver, operate and support the services you bought;
- To run your AI employees and workflows — answering calls, replying to messages, booking appointments and preparing the actions you approve;
- To process payments and manage your subscription;
- To secure the services, prevent fraud and abuse, and keep an auditable record of actions taken;
- To respond to your enquiries and provide training and support;
- To improve our services using metadata and aggregated usage — never your conversations, documents, call recordings or connected-service data to train AI for anyone else;
- To send service, security and billing messages, and — where permitted — occasional updates you can opt out of;
- To meet our legal obligations and enforce our Terms of Service.
9. AI processing and your content
To answer a question, transcribe a call or draft an action, the relevant content is sent to our AI providers under commercial agreements that govern how they may use it. Under those agreements your content is used only to return the result for that request, and is not used to train their general models. We do not train models on your data, and what your business teaches your assistant never informs another client’s.
AI can be wrong. Outputs are drafts and suggestions, not professional advice, and you remain responsible for reviewing what you rely on or approve.
10. How your data is protected
- Encrypted at rest. In BGP AI, your conversations, uploaded document contents, assistant memories, and the inputs and results of every action are encrypted in our database. Someone reading the raw database rows cannot read them.
- Credentials held separately. Access tokens for your connected accounts are encrypted under their own record and are never placed in the AI model’s context. The assistant asks our server to act; the server holds the token. The model never sees a password or a token.
- Isolated to your workspace. Every record carries the workspace it belongs to and queries are scoped to it. One client’s assistant cannot see another client’s data.
- Nothing goes out unapproved. In BGP AI, anything the assistant writes or sends waits for approval — by a person on your team by default, or by your Board AI reviewing it against your standing rules if you choose that. Anything it cannot decide comes back to a person.
- Encrypted in transit. Traffic to and from our services, and between our services and the tools you connect, travels over TLS.
- Least-privilege staff access. Our staff see only metadata in the ordinary course of business and cannot impersonate you. Access for support or a security investigation is limited, logged and only with a legitimate need.
- Everything is on the record. Actions are logged with who or what approved them and when.
No system is perfectly secure, but we work to protect your information and will notify you and the relevant authorities of a breach where the law requires it.
11. Who helps us run the services (subprocessors)
Each of these is bound by contract to protect your data and use it only to provide services to us:
- Anthropic and OpenAI — the AI processing behind our agents and assistant, under agreements that prohibit training on your content.
- Amazon Web Services — hosting and storage.
- GoHighLevel — the CRM, messaging and voice infrastructure behind the platform we provide with your plan.
- Stripe — payment processing; stores card details so we never do.
- Resend — delivery of our transactional email.
Services you connect to BGP AI yourself — Google, Meta, Intuit QuickBooks, your own GoHighLevel account — are not subprocessors. They are your accounts, we reach them on your instruction, and each is governed by its own terms and privacy policy.
We do not sell your personal information and we do not share it with third parties for their own marketing. We may disclose information where the law requires it, to protect our rights or someone’s safety, or in connection with a merger or sale of assets — in which case we will tell you.
12. International transfers
We are based in Canada and our providers may process information in other countries, including the United States. Where personal data moves out of the EEA or UK we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and the UK Addendum.
13. How long we keep it
We keep client data for as long as your account is active, so your business’s history and what your assistant has learned stay available to you. Call recordings and transcripts are kept for the period configured on your account and deleted after it. Where a retention window is set for conversations, tasks or assistant memories, anything past it is deleted on a nightly schedule; tasks still awaiting approval are never deleted by that process.
When you close your account, or on request, we delete or anonymize your personal data within a reasonable period, except where we must keep it to meet legal, tax or accounting obligations, resolve disputes or enforce our agreements. Backups are purged on a rolling schedule.
14. Deleting your data
You do not need a subscription, an account, or a reason to ask. Either route works:
- Inside the product — delete individual conversations or tasks in BGP AI, and disconnect any tool from your Integrations page, which deletes its stored credentials immediately.
- Ask us — email info@businessgrowthpartners.ai saying what you want removed: a connected service’s data, your call recordings, your workspace, or your account entirely. We confirm in writing when it is done.
15. Your rights
Under Canada’s PIPEDA you may ask what personal information we hold about you, why we have it, and who we have shared it with; ask us to correct it; and challenge our handling of it. If you are in the EEA or UK you also have rights of access, correction, deletion, portability, and objection to or restriction of processing, and you may complain to your data protection authority. If you are a California resident you may request access, deletion and correction; we do not sell or share personal information as the CCPA/CPRA define those terms.
Exercise any of these by emailing info@businessgrowthpartners.ai. We reply within the time the law allows and will not treat you worse for asking. If you are unhappy with our response you can complain to the Office of the Privacy Commissioner of Canada.
16. Cookies and third-party content
This website uses strictly necessary cookies to keep it working and to remember your light or dark theme preference. We do not currently run advertising or analytics cookies and we do not sell data to advertisers. Some pages load fonts and icons from Google Fonts and Cloudflare, and our consultation form is hosted by GoHighLevel; those providers receive your IP address as part of serving that content. You can control cookies in your browser, though blocking necessary ones may break parts of the site.
17. Children
Our services are business tools for adults. They are not directed at children and we do not knowingly collect personal information from anyone under 16. Tell us if you believe a child has given us information and we will delete it.
18. Changes
We may update this policy as our services evolve. When a change is material we will update the date above and tell you by email or in the product before it takes effect.
19. Contact us
Email info@businessgrowthpartners.ai or call +1 (647) 709-1536. A real person will reply.