The situation
Nadia called on a Tuesday morning between clients, phone propped against a mirror, explaining that her previous lawyer had gone quiet on her file two months earlier. She had paid a retainer, been sent a draft privacy policy that was maybe sixty percent finished, and then heard nothing — no calls returned, no emails answered, no explanation. She did not know if the file was abandoned, on hold, or simply lost in someone else's backlog, and she had a growing sense that whatever the problem was, it was now hers to solve on a deadline she did not control.
Nadia owned a hairdressing business with three chairs and a small staff, built up over eight years from a single rented chair to her own storefront. The business was modest by revenue, sitting in the low hundreds of thousands annually, but it had a silent investor on the books — a family friend named Attila who had put in early capital in exchange for a minority stake and stayed out of day-to-day decisions entirely. Attila's involvement mattered less for the daily running of the salon and more for the fact that, as a matter of prudent governance, any formal compliance step was better handled with a second stakeholder in mind, even one who never set foot in the shop.
The trigger for all of this was mundane on its surface: Nadia had switched booking software two years earlier to a system that handled appointment scheduling, client contact information, and payment processing in one package. It was convenient and her clients liked the text reminders. What she had not realized, until a client asked a pointed question about where her data was stored, was that the platform routed customer information, including names, phone numbers, and appointment history, through servers operated by an American company.
Tyler, one of Nadia's regular clients and, as it turned out, an auto body technician with an unusually sharp interest in data privacy after a scare with his own shop's customer records, was the one who asked. He wanted to know whether Nadia's privacy policy — the one posted on her booking page — actually reflected what was happening to his information. Nadia looked at the policy for the first time in months and realized she could not honestly answer him. She read through the draft her previous lawyer had left her and found sections that referenced software features she no longer used and none that mentioned anything about servers outside Canada.
The problem
The unfinished file we inherited had two separate problems tangled together, and untangling them was most of the early work. The first was procedural: the previous lawyer's draft policy described data practices that no longer matched what the booking platform actually did, because the platform had changed its data handling terms in an update Nadia was never told about. The draft was not just incomplete, it was inaccurate, and publishing it as-is would have created a bigger problem than not having a policy at all, since a business that tells its customers one thing and does another faces more scrutiny than one that says nothing.
The second problem was substantive. Personal information about Ontario residents was being transferred to and stored by a processor in the United States, which meant it became subject to American law as well once it crossed the border — though that did not relieve Nadia's business of its own accountability for that information under Canadian privacy law. This is not automatically prohibited — many small Ontario businesses use American software vendors — but it does trigger an obligation to be transparent with customers about where their information goes and to take reasonable steps to ensure it is protected once it gets there. Nadia's existing policy said nothing about cross-border transfer at all, and neither, it turned out, did the platform's own public terms until you dug several layers into a separate data processing page most small business owners never think to look for.
Attila's silent stake complicated the practical side of fixing this. Any material change to how the business operated, including a decision to switch platforms entirely if that became necessary, was not something Nadia was strictly obligated to clear with him absent a shareholders' agreement that said so, but it was safer to at least inform him as a minority shareholder than to leave him finding out later, even though he had never asked a single question about operations in three years. Nadia was not used to thinking of her business decisions as needing anyone else's input, and the idea of looping in an investor over something as specific as booking software felt disproportionate to her, though it was a step we could not skip.
Underneath both problems was the platform itself. The booking software was central to how Nadia ran her business — her clients expected the text reminders and the online booking link, and switching systems entirely would have meant re-training staff, notifying every client, and risking a rocky few months of missed appointments. The realistic options were narrower than a clean rebuild: fix the disclosure, push the platform for better terms, or accept that some risk would remain. Nadia also had to weigh the cost of any of this against a business that, at her revenue level, could not easily absorb a large legal bill or a month of disrupted bookings while a new system was learned by staff and explained to clients.
What we did
- Audited the inherited file before touching it. Rather than assuming the previous lawyer's draft was a usable starting point, we compared it line by line against the booking platform's current terms of service and data processing disclosures. This mattered because publishing an inaccurate policy would have been worse for Nadia than her current gap, and we needed to know exactly what had gone stale before deciding what to keep.
- Requested the platform's current data processing terms directly. Nadia's account gave her limited visibility into where her data actually went, so we contacted the platform's support and legal channels to get a written description of its data storage and processing locations. This gave us something concrete to describe to customers instead of relying on marketing language from the platform's public website, which turned out to be vaguer than its actual practices.
- Briefed Attila as a courtesy and a governance step. Even though Attila had never engaged with operational decisions, we recommended a short written notice to him describing the privacy review and any potential platform change under consideration. This protected Nadia from a later argument that she had made a material decision without informing her minority shareholder, and it took less than an afternoon to prepare.
- Drafted a new privacy policy that matched reality. We rebuilt the policy from the ground up around what the platform actually did, including a plain-language section on cross-border data transfer, rather than patching the previous lawyer's draft clause by clause. Starting fresh took less time than trying to identify every inaccurate line in someone else's unfinished work, and it produced a document Nadia could publish with confidence instead of one still carrying hidden gaps.
- Opened a negotiation with the platform over data handling terms. Because Nadia was one client among many thousands on a large platform, we did not expect a custom contract, but we pushed for specific commitments: a written confirmation of where data was stored, an option to limit certain fields from cross-border transfer, and a data processing addendum Nadia could point to if a client asked. Platforms will sometimes offer this to small business customers who ask directly and specifically, even without leverage.
- Negotiated a compromise on what data left the country. The platform agreed to let Nadia disable storage of certain optional client notes fields on its American servers, keeping only the core booking and contact data flowing through the standard system. This was not a full fix, but it reduced the volume and sensitivity of what was transferred, which was the most the platform was willing to offer a single small-business account.
- Trained Nadia and her staff on what the new policy actually meant. A finished policy is only useful if the people at the front desk can explain it, so we did not treat the drafting as the last step. We walked Nadia through a short, plain-language summary she could give a client who asked, similar to Tyler's original question, and had her practice it out loud, so the business could answer honestly and consistently going forward instead of pointing a curious client to a document nobody at the salon had actually read.
The outcome
Nadia ended up with an accurate, published privacy policy that described what actually happened to her clients' data, including the cross-border transfer, in plain language rather than the vague boilerplate she had before. The platform's concession on the optional notes field reduced the amount of sensitive information leaving the country, though the core booking and contact data continued to be processed by the American servers as before, because that was baked into how the platform's core service worked and was not something a single small account could change.
This was not the clean resolution Nadia initially wanted. She had hoped, going in, that we could simply force the platform to store everything in Canada or find an equivalent Canadian alternative overnight. Neither was realistic on her timeline or budget, and switching platforms entirely remained a future option rather than an immediate one. What she got instead was honesty in her disclosures, a real if partial reduction in what left the country, and a documented record that she had acted responsibly once the gap was identified.
Tyler, when he eventually asked again, got a clear answer, and Nadia later said that mattered to her more than she expected. Attila acknowledged the notice about the platform review without comment, which was itself useful, since it meant Nadia now had a record of engaging her minority shareholder appropriately. The file that had sat stalled for two months was closed within six weeks of Nadia's first call, with a policy she could stand behind and a platform relationship she understood far better than before.
Nadia also came away with a habit she did not have before: reading the fine print when a vendor updates its terms, rather than assuming a platform she trusted two years ago still worked the same way today. We suggested a brief annual check-in on her privacy policy against her vendors' current terms, low-cost compared to the alternative of finding out from a client's question a second time.
What you can learn from this
- If a file transfers between lawyers, do not assume the previous work is a safe starting point — verify it against current facts before publishing or relying on any of it.
- Using a foreign software platform is not automatically a legal problem, but failing to disclose where customer data actually goes is. Transparency is often the fastest fix available.
- A silent investor is still a shareholder. Material operational decisions, even ones that feel purely administrative, may call for at least a written notice to protect against later disputes.
- Small businesses rarely get custom contracts from large platforms, but specific, written requests for data handling commitments sometimes get partial concessions that blanket policies do not offer.
- A privacy policy is only as good as the staff who have to explain it. Build a short plain-language summary your team can actually use when a customer asks a direct question.
This is a corporate problem we handle
Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.