Benchcube Analytics Inc. Privacy Policy — Local Government
Effective Date: 28 November 2025
Benchcube Analytics Inc. (“Benchcube,” “we,” “our,” or “us”) provides subscription-based financial reporting and comparison services. This policy describes data management and privacy protection for Benchcube's local government products. It is designed to help you (the Customer, Local Government User, or Authorized User) understand how we handle the financial data provided to us subject to the terms of your Software-as-a-Service Agreement (“Agreement”).
Objective
Benchcube's overall objective is to provide decision-makers and other stakeholders with a means of quickly and intuitively understanding complex financial information. Local governments face a challenge in this regard because they serve a diverse range of stakeholders, including decision-makers, the media, and the public. Thus, the specific objective is to provide the appropriate information to each category of stakeholder.
Definitions
| Authorized User | An individual, such as an employee, contractor, or elected official explicitly authorized by the Local Government Customer to access Benchcube's Secure Services. |
| Valid Security Credential | A protected key, token, login, or access method approved jointly by Benchcube and the Local Government Customer to identify Authorized Users. |
| Secure Services | Elements of the Benchcube visual interactive dashboards, reports, and extracts that are available only to Authorized Users from the associated Local Government Customer. |
| Public-Facing Services | Elements of the Benchcube visual interactive dashboards, reports, and extracts that are available to anyone with the website link. |
| Personally Identifiable Information (PII) | Information that could potentially be used, alone or combined with other data, to identify confidential information associated with a single person. |
1. Our Data Categories
The financial data we process is supplied by our Local Government Customers. We maintain strict distinctions between the different categories of data used to provide our services:
A. Confidential Source Data
This category includes the core accounting data provided by the Customer, which forms the basis for our services. To minimize privacy risks, Benchcube only accepts data at the General Ledger (GL) account level and strictly does not accept finer-grained data at the sub-ledger or work order level. Even with this precaution, it is possible (though unlikely) that GL account-level data could indirectly or inadvertently reveal PII. Because of this risk, we treat all GL account-level data as Confidential Source Data. Examples include:
| Source Data | Description | Purpose |
|---|---|---|
| Trial balances | Exports from a financial system showing balances strictly at the GL account level. | Foundational information for the dashboards. Provides annual actuals. |
| Unpublished/unadopted budgets | Projected balances strictly at the GL account level. These budgets are provisional and are intended for internal use until adopted. | Permits budget analysis and comparisons. |
| Assessment information (optional) | Property roll summaries showing property class and assessed value. | Used to calculate comparative metrics such as mill rate, typical households, and so on. |
B. Aggregated and Benchmarking Data
This category is the financial information that Benchcube generates by processing and aggregating the Source Data. It is used to produce visual interactive dashboards and benchmarking information. The critical feature of this category of data is that it is summarized to a level of detail comparable to information routinely shared publicly by local governments, such as public budget documents and financial statements.
C. Contributed Information
Contributed Information is defined as:
- Annotations and explanations added to the source data by Customers.
- Any elaborations and interpretations generated automatically (e.g., by artificial intelligence (AI) systems) based on Contributed Information and the source data.
Contributed information is typically provided by one or more authorized users within the Customer's organization (e.g., CFO) to provide additional context to the source data. As noted below, all such contributions are designated by the Customer as "internal" or "shared".
2. How We Use and Share Financial Data
Given our objective—enabling local governments to provide useful and appropriate information to their full range of diverse stakeholders—our use of data follows from the categories above:
| Data Category | Policy | Example of Use |
|---|---|---|
| Confidential Source Data | Available via Benchcube services to users with a Valid Security Credential. The scope of access is limited to information from the Authorized User's organization. | Local government employees or elected officials log in and are granted the ability to drill down within a high-level expense category. They can view GL account-level details, which are not available to unauthorized users. Their dashboard may also include non-public information, such as estimates from provisional budgets. |
| Aggregated and Benchmarking Data | Similar to financial statements and public budget documents, aggregated data is considered non-confidential and free of PII. Benchcube's visual interactive dashboards are generally made available through the Local Government's website and are freely viewable by the public. In addition, aggregated data is used to perform benchmarking with peer communities. | Users can start with a financial overview of the organization and drill down to examine expenditures for "Wages and benefits" in the "Fire and protective services" category. Finer-grained, account-level data within these categories is not available to unauthorized users. |
| Contributed Information | Contributed Information is designated "internal" by default and is not available except to Authorized Users. However, Contributed Information that is explicitly "shared" by the Local Government Customer is considered non-confidential and is made available to the public. | During provisional budget discussions, the CFO may tag a large expenditure with an explanation intended for internal deliberation and marked "internal". Once the budget is adopted, the CFO may "share" the comment so that the explanation is viewable on the public dashboard. The explanation may also be used by Benchcube's AI functionality to ground an automatically-generated interpretation of a dashboard, graph, or graphic element. |
3. Access Control and Protection
Benchcube employs controls to ensure data is protected appropriately based on its category, as described above.
Secure Services
Access to detailed, confidential data (Confidential Source Data) is limited to the Customer's Authorized Users. This access is granted solely for the Customer’s internal business purposes.
- Control: Access is controlled through a Valid Security Credential. Customers must use all reasonable endeavors to prevent any unauthorized access to the Services.
- Scope: Authorized Users only have access to the detailed data from their specific organization.
Public-Facing Services
Access to the Aggregated and Benchmarking Data is available to the public for comparison purposes.
- Control: Access is provided via a specific identifier used to link to the public dashboard. This aggregated data is treated as publicly available and non-confidential information.
Benchcube takes all reasonable steps to ensure Confidential Information is not disclosed through unauthorized data access or by its employees or agents.
4. Third-Party Sub-Processors and Artificial Intelligence
To deliver our services reliably and securely, Benchcube engages trusted third-party service providers (sub-processors) for cloud infrastructure and specialized data processing. We ensure all sub-processors are contractually bound to rigorous data security and confidentiality standards and are prohibited from using Customer Data for their own commercial purposes.
Cloud Infrastructure and Storage
We utilize enterprise-grade cloud computing providers (such as Amazon Web Services) to host and securely store Customer Data. To support our local government customers' data residency requirements under applicable privacy legislation, all Confidential Source Data at rest is hosted on servers located exclusively within Canada.
Artificial Intelligence and Large Language Models (LLMs)
As part of our Contributed Information features, Benchcube utilizes generative AI technologies provided by industry-leading Large Language Model (LLM) providers (such as OpenAI and Anthropic) to automatically generate elaborations and interpretations of financial data. When Authorized Users utilize these specific features, the following strict privacy controls apply:
- Zero Model Training: We utilize enterprise-tier API agreements that strictly prohibit LLM providers from using your Confidential Source Data, Contributed Information, or prompts to train, improve, or fine-tune their foundational AI models.
- Limited Security Retention: Data securely transmitted to our LLM partners via API is used strictly to generate the requested output. To support automated safety and abuse monitoring, providers temporarily hold request data in secure storage for a maximum of 30 days, after which it is automatically and permanently purged.
- Cross-Border Processing: While our primary data storage remains in Canada, Authorized Users acknowledge that data submitted for AI interpretation may be temporarily and securely routed through LLM provider servers located outside of Canada for the duration of the processing request.
- Sub-Processor Updates: Benchcube will maintain an updated list of sub-processors and notify Customers in advance of any material changes or additions to sub-processors handling Customer Data.
5. Your Responsibilities and Legal Compliance
The Customer Organization holds the primary responsibility for the lawful transfer and use of its data.
- Data Lawfulness: The Customer must ensure it is entitled to transfer the relevant data to Benchcube.
- Benchcube's Limitations: Benchcube is not responsible for any loss, destruction, alteration, or disclosure of Confidential Information caused by any third party.
- Data Subject Rights & Breach Notification: Benchcube shall promptly assist Customers in responding to data subject access requests and notify Customers without undue delay upon becoming aware of a confirmed security incident or data breach affecting Customer Data.
- Governing Law: The Agreement is governed by the laws of British Columbia and the laws of Canada applicable therein.
6. Data Retention and Changes
We retain Customer Data for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required under applicable law.
- Post-Termination Use: Upon expiration or termination of the Agreement, the Customer is not entitled to demand that Benchcube cease to use its Customer Data.
- Policy Changes: Benchcube may amend this Privacy Policy from time to time. Any updates will be posted on our website, and material changes will be communicated to Customers with at least 30 days' advance notice.
7. Contact Us
If you have questions about this Policy or our data practices, please contact us:
Benchcube Analytics Inc.
Attn: Legal / Privacy
1867 Sandstone Drive
Penticton, British Columbia, Canada, V2A 8Y6
info@benchcube.com