Legal
Privacy policy
How we handle personal information at DDL Partners, on this website and inside an engagement.
Effective 11 September 2026 · Version 1.0
In short
We collect very little. This website sets no cookies of its own, runs no analytics, and carries no advertising trackers. The fonts are served from our own server, so visiting these pages sends nothing to a third-party font or ad network.
Inside an engagement we hold what the work requires and no more. Individual coaching conversations and individual assessment results stay with the individual. Sponsoring organizations receive themes, not transcripts. We do not sell personal information to anyone, ever.
1. Who this applies to
DDL Partners ("DDL", "we", "us", "our") is a leadership advisory firm based in Toronto, Ontario, working with healthcare and mission-driven organizations in Canada and internationally. This policy explains how we handle personal information, which means information about an identifiable individual.
It applies to everyone whose personal information we hold, including:
- visitors to dreamdarelead.com
- people who contact us, request a call, or subscribe to anything we send
- leaders we coach, and members of teams we work with
- people who take part in an interview, assessment, or diagnostic during an engagement
- people who attend a session, keynote, or programme we deliver
- contacts at client organizations, prospective clients, partners, and suppliers
Where we act as a service provider to a client organization, that organization may also have its own privacy policy covering the same work. Our engagement agreement sets out who is responsible for what.
2. Our privacy officer
Shiyen Shu, Founder and CEO, is accountable for our compliance with this policy and with applicable privacy law. She can be reached at shiyen@shiyenshu.com or 647-229-6379, or by mail at DDL Partners, Toronto, Ontario, Canada.
All access requests, corrections, deletion requests, questions, and complaints go to that address. We acknowledge every request in writing.
3. The laws we follow
We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), the federal private-sector privacy law of Canada, and its ten fair information principles.
Where other laws apply to a particular piece of work, we follow those as well:
- Quebec. Where we hold personal information about individuals in Quebec, we apply the protections of Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25, including the right to a portable copy of your information and the requirement to tell you when information will be held outside the province.
- Personal health information. We are not a health information custodian. We do not collect, use, or disclose personal health information about patients. If a particular engagement requires us to act as an agent of a custodian under Ontario's Personal Health Information Protection Act (PHIPA), or the equivalent law in another province, we do so only under a written agreement and only on that custodian's instructions.
- Commercial email. Messages we send are subject to Canada's Anti-Spam Legislation (CASL). See section 12.
- International work. For engagements outside Canada, we apply this policy as a floor and meet any additional local requirements agreed in the engagement contract.
Federal privacy law in Canada is under reform. If PIPEDA is replaced, we will update this policy and our practices before the new requirements take effect.
4. Information we collect
We collect only what is needed for the purpose at hand.
When you visit this website
Our pages themselves set no cookies and run no analytics. Our web host records standard server logs, including IP address, browser type, and the pages requested, for security and to keep the site running. We do not use those logs to build a profile of you and we do not connect them to any other information.
When you contact us or request a call
Your name, organization, role, email address, phone number if you give one, and whatever you choose to write to us. If you book a call, the date and time you select and anything you add to the booking.
When we work together
- Engagement administration. Contact details, role, reporting line where relevant to the work, scheduling information, invoicing and payment contacts.
- Diagnostic and interview material. What you tell us in a confidential interview, and notes we make from it.
- Assessment results. Where an assessment is part of the work, the results produced by the publisher's instrument, together with the stakeholder feedback gathered as part of a measured coaching method.
- Coaching records. Brief working notes of goals, themes, and progress. We do not record coaching sessions unless you ask us to and give written consent.
- Session participation. Attendance, and any feedback you choose to give afterwards.
Where a client organization gives us contact details for its own people so that we can work with them, we tell those people who we are and why we hold their information at the first point of contact.
5. What we do not collect
- We do not collect personal health information about patients.
- We do not collect information about your race, religion, sexual orientation, political views, or union membership, and we ask you not to send it.
- We do not buy personal information, contact lists, or enriched contact data from data brokers.
- We do not use advertising pixels, retargeting tags, or cross-site trackers on this website.
- We do not sell, rent, or trade personal information. There is no circumstance in which we would.
6. Why we collect it
We collect, use, and disclose personal information for these purposes and no others:
- to answer your enquiry and arrange a conversation
- to scope, deliver, administer, and measure an engagement
- to give a leader feedback on their own assessment and coaching
- to report progress to a sponsoring organization at the level agreed in the engagement contract, which is themes and aggregate movement rather than individual content
- to invoice and keep the business records the law requires us to keep
- to send information you have asked to receive
- to meet our legal, professional, insurance, and contractual obligations
If we ever want to use information for a purpose that is not on this list, we will ask you first.
7. Consent, and taking it back
We collect, use, and disclose personal information with your knowledge and consent, except where the law allows or requires otherwise, for example to investigate a breach of an agreement or to comply with a court order.
For anything sensitive, and for anything beyond the obvious purpose you gave the information for, we ask for express consent. Participation in coaching, interviews, and assessments is voluntary, and we say so at the start of every engagement. A participant who does not want to take part can say so to us directly, and we will not report that refusal to their employer as a performance matter.
You can withdraw consent at any time by writing to our privacy officer, subject to legal and contractual limits and reasonable notice. We will tell you plainly what withdrawing means. In some cases it means we can no longer deliver part of the service.
8. Coaching and assessment confidentiality
This is the part that matters most to the people we work with, so it is worth stating precisely.
- The content of a coaching conversation belongs to the person being coached. We do not report it to their manager, their chief executive, or their board.
- Individual assessment results are released to the individual. They are shared with anyone else only with that individual's express, informed consent, and that consent is recorded.
- Where an organization sponsors the work, our reporting to that organization covers themes, patterns, and movement against agreed outcomes, drawn from the group and de-identified. Where a group is small enough that a theme could identify a person, we aggregate further or leave it out.
- Stakeholder feedback gathered as part of a measured coaching method is summarized for the leader without attributing comments to named individuals, unless the stakeholder agrees to be named.
- The exceptions are narrow and we will tell you if one arises: a serious risk of harm to you or someone else, or a legal obligation to disclose.
These commitments are repeated in our engagement agreements. If an engagement agreement and this policy ever conflict, the stricter protection applies.
9. Who we share information with
We share personal information only where it is needed to do the work, and only with:
- Our associates. Senior advisors and associates who work on an engagement, under written confidentiality obligations that match our own.
- Assessment publishers. Where an assessment is used, the publisher of that instrument processes the responses on its own platform. Depending on the engagement this may include the publishers of Leadership Circle Profile, Hogan, Everything DiSC, The Five Behaviors, LEADS in a Caring Environment, and Marshall Goldsmith Stakeholder Centered Coaching. Each publisher has its own privacy policy, which we will point you to before you complete anything.
- Operating service providers. Our website host, our booking and enquiry platform, our email and file storage provider, our video hosting, and our accounting and invoicing software. They act on our instructions, are bound by confidentiality terms, and may not use the information for their own purposes.
- Professional advisors. Our accountant, insurer, or lawyer, where they need it and under professional duties of confidence.
- Where the law requires it. In response to a valid legal demand. We satisfy ourselves that the demand is valid, and we tell you unless we are prohibited from doing so.
If our business is ever sold or reorganized, personal information may transfer as part of it. Any buyer would be bound to use it under the terms of this policy, and we would give notice on this page.
10. Storage and access outside Canada
Some of our service providers store or process information outside Canada, including in the United States. While information is in another country it is subject to the laws of that country, and may be accessible to that country's courts, law enforcement, and national security authorities.
We use providers that offer contractual confidentiality and security commitments, and we keep the amount of information held outside Canada to what the service actually needs. If you would like to know where a specific category of your information is held, write to our privacy officer and we will tell you.
11. Cookies, analytics, and embedded content
This website sets no cookies of its own. There is no analytics package, no tag manager, no advertising pixel, and no cross-site tracking. Typefaces are served from our own server rather than from a third-party font service, so simply reading these pages sends nothing to an outside company.
Three things on this site do involve a third party, and each one is visible to you before it happens:
- Video. The clips on the home and About pages are hosted on Google Drive and load in a player provided by Google. When a player loads or you press play, Google receives your IP address and may set its own cookies under its privacy policy.
- Booking and enquiry. Booking a call or sending an enquiry passes what you enter to the platform we use to manage enquiries, which processes it on our instructions.
- Outbound links. Links to LinkedIn and to other sites take you to services that set their own cookies. We have no control over them.
If we ever add website analytics, we will update this policy and put a consent choice in place before we turn anything on.
12. Email we send you
We send commercial electronic messages only where you have given consent or where we have an existing business relationship that permits it under CASL. Every message identifies us, gives our contact details, and carries a working unsubscribe link that we action within ten business days and usually the same day. Unsubscribing from updates does not affect emails about an engagement that is under way.
13. How we protect information
We apply safeguards proportionate to how sensitive the information is. Coaching notes and assessment results are treated as our most sensitive category.
- Information in transit is encrypted. This website is served over HTTPS.
- Files are held in access-controlled cloud storage with multi-factor authentication on every account.
- Access is limited to the people working on that engagement, on a need-to-know basis.
- Associates and contractors sign confidentiality agreements before they touch client material.
- Devices are encrypted, locked, and kept current with security updates.
- Paper notes taken in a session are stored securely and shredded once transcribed or no longer needed.
- We review these practices at least once a year.
No safeguard is perfect, and we do not claim otherwise. What we do commit to is limiting what we hold, so that there is less to lose.
14. If something goes wrong
We keep a record of every breach of security safeguards involving personal information under our control, and we keep those records for at least twenty-four months.
If a breach creates a real risk of significant harm to an individual, we report it to the Office of the Privacy Commissioner of Canada and notify the affected individuals as soon as feasible, with a description of what happened, what information was involved, what we are doing about it, and what they can do. Where the information relates to individuals in Quebec, we also notify the Commission d'accès à l'information. Where a client organization is affected, we notify that organization in parallel.
15. How long we keep it
We keep personal information only as long as it is needed for the purpose it was collected for, or as long as the law requires, then destroy or de-identify it securely.
- Enquiries that do not lead to work. Twenty-four months, then deleted.
- Engagement and contract records, including invoices. Seven years after the engagement ends, consistent with Canadian tax and professional record-keeping requirements.
- Coaching notes and interview notes. Destroyed within twenty-four months of the engagement ending, or sooner at the individual's request.
- Assessment results. Held for the engagement and for as long as the publisher's platform retains them under its own terms. We can request deletion from the publisher on your behalf.
- Mailing list. Until you unsubscribe, then removed and suppressed so we do not contact you again in error.
- Breach records. Twenty-four months, as required by law.
16. Your rights, and how to use them
You have the right to:
- Know what personal information we hold about you, how we use it, and who we have shared it with.
- Access a copy of it.
- Correct it if it is inaccurate or incomplete.
- Delete it, where we are not required by law or contract to keep it.
- Receive a portable copy of the information you gave us, in a structured, commonly used electronic format, and ask us to send it to another organization where that is technically possible.
- Withdraw consent for future use, as described in section 7.
- Complain to us, and to a regulator if our answer does not satisfy you.
To exercise any of these, write to shiyen@shiyenshu.com. We may ask for enough information to confirm who you are, and we will use that only to verify the request. We respond within thirty days at no cost. If we need more time, we will tell you why before the thirty days are up. If we refuse all or part of a request, we will explain the reason in writing and tell you how to challenge it.
17. Automated decisions and artificial intelligence
We do not make decisions about you by automated means alone. Assessment instruments generate scores and reports, and those are always interpreted by a certified practitioner and discussed with you. Nothing on this website profiles you.
We do not upload identifiable client material, coaching notes, interview transcripts, or assessment results into public generative artificial intelligence tools.
18. Children
Our services are for working adults and this website is not directed to children. We do not knowingly collect personal information from anyone under the age of eighteen. If you believe a child has given us information, write to us and we will delete it.
19. Changes to this policy
We may update this policy as our practices, our tools, or the law change. The version in force is always the one posted here, with its effective date and version number at the top. Where a change is significant, we will say so on this page and, if we hold your contact details for an active engagement, tell you directly.
20. Contact and complaints
Talk to us first. Most questions are resolved quickly.
DDL Partners
Attention: Privacy Officer, Shiyen Shu
Toronto, Ontario, Canada
shiyen@shiyenshu.com
647-229-6379
If you are not satisfied with our response, you can take the matter to the regulator:
- Office of the Privacy Commissioner of Canada, 30 Victoria Street, Gatineau, Quebec K1A 1H3. priv.gc.ca
- Individuals in Quebec: Commission d'accès à l'information du Québec. cai.gouv.qc.ca
- Matters involving personal health information in Ontario: Information and Privacy Commissioner of Ontario. ipc.on.ca