Protection of personal information policy

The purpose of this policy is to ensure the protection of personal information and to define the procedures for the collection, use, disclosure, retention, destruction, and management of information by ImpecZone, including management, employees, suppliers, etc. In addition, it aims to inform any concerned person about the processing of their personal information by ImpecZone, whether clients, employees, or any other individuals.

RESPONSIBILITY

ImpecZone assumes full responsibility for the protection of personal information under its control. The information collected, used, disclosed, retained, or destroyed is governed by this policy with the objective of protecting everyone’s privacy.

To ensure optimal protection of personal information, the person responsible for privacy at ImpecZone must:

  • Oversee and review internal practices and procedures for processing personal information, as well as compliance with applicable laws;
  • Recommend measures to ensure the ongoing protection of personal information that align with privacy impact assessments;
  • Implement the necessary measures within the company to ensure the protection of information;
  • Ensure compliance and staff training on best practices for protecting personal information.
  • Coordinate, investigate, and respond to requests and complaints relating to the protection of personal information;
  • Communicate with the person(s) concerned and the Commission d’accès à l’information (CAI) in the event of a data breach or any incident;
  • Maintain a register of personal data incidents.

Protecting personal information is everyone’s responsibility. No retaliation may be taken against an individual who files a complaint relating to the protection of personal information or participates in a CAI investigation process.

COLLECTION OF PERSONAL INFORMATION

The personal information collected enables ImpecZone to carry out its functions and conduct its activities in accordance with applicable laws and standards. ImpecZone collects personal information only when necessary and to meet specific purposes defined in advance. Personal information is collected directly from the person concerned and with their consent, unless an exception is provided by law.

In Appendix A, you will find a non-exhaustive list of the information collected and the intended use of the data. Most of the personal information collected relates to employees in order to meet the company’s legal obligations. The disclosure of personal information about other individuals may be requested, for example to assist employees in an emergency. It is the employees’ responsibility to obtain their consent before providing us with their contact details.

With respect to customer information, data is provided to populate our CRM, contracts, and billing, but it is mostly professional or business information such as an email address and phone number to contact them, or the payment method for services rendered. Payment information is, whenever possible, entered by the customer in the CRM and is masked for the rest of the company’s members to ensure confidentiality. For customers who have completed a form that includes their credit card or their business/professional bank account number, the data is accessible only to a small number of employees such as administration and the owners to process the files.

CONSENT AND ACCURACY OF PERSONAL INFORMATION

ImpecZone ensures that personal information is collected for justified, clear, and specific reasons and with the individual’s free and informed consent. Consent is required for any collection, use, or disclosure of personal information. Before collecting personal information, we will ensure that we obtain your informed consent in writing and separately, by providing clear details on the purpose of the collection and how the information will be used. Your consent is essential to ensure the protection of your personal data.

LIMITATION ON THE USE OF PERSONAL INFORMATION

We collect and use your personal information only when necessary and for the purposes for which consent was obtained. ImpecZone must provide certain information to satisfy legal and regulatory verification processes and requirements. Use may vary, but may include various purposes as illustrated in Appendix A.

Information may be shared with third parties to the extent necessary for the purposes of the activities mentioned in Appendix A. ImpecZone cannot be held responsible for the conduct and use undertaken by third parties.

Personal information will not be used or disclosed for purposes other than specific objectives unless required by law.

PROTECTION OF YOUR PERSONAL INFORMATION

ImpecZone takes all reasonable precautions and has implemented significant physical and technical measures to prevent unauthorized or unlawful use of, and access to, personal information. The measures in place include, among others:

  • Using information only when necessary;
  • Ensuring the confidentiality and protection of personal information that a person becomes aware of in the course of their duties, unless authorized to disclose it by the person concerned.
  • Protecting files with selective and limited access for authorized persons;
  • Securing access to offices with locked doors and access codes;
  • Secure shredding of paper files;
  • Two-factor authentication for all platform logins;
  • Immediate removal of access following the end of a business relationship.

All individuals are required to contribute to the protection of personal information. If you suspect that sensitive information has been compromised, you must immediately notify the person responsible for the protection of personal information.

RETENTION PERIOD FOR YOUR PERSONAL INFORMATION

ImpecZone undertakes to comply with the minimum retention periods provided for according to the category of personal information and applicable laws. However, if the information collected is no longer useful to ImpecZone and its retention is neither necessary nor mandatory under the various legislative frameworks, it will be destroyed, erased, or converted in a way that preserves its anonymous nature.

COMMITMENT TO TRANSPARENCY

ImpecZone is committed to being transparent about the processing, procedures, and purposes of use governing personal information for clients, employees, interns, and business partners.

ACCESS TO YOUR PERSONAL INFORMATION

A person may request access to the personal information concerning them and the means used to collect it. Depending on the contents of the person’s file, exceptions may apply, such as personal information relating to another person; however, the person will be informed. In the event of inaccurate information in the file, the person concerned may request that it be corrected.

For any consultation, withdrawal, and/or modification of personal information, you may write to info@impeczone.ca. At any time, you may withdraw your consent to the disclosure of your personal information. A written request must be submitted to the person responsible for the protection of personal information at info@impeczone.ca. A response will be provided within 30 days of the date it is received. When it is not possible to share the requested information, a legal justification and support must be provided to substantiate the decision to the requester.

FILE A COMPLAINT

A person who believes that their personal information has been collected, retained, used, disclosed, or destroyed in a manner that does not comply with the provisions of this policy may submit a confidential complaint to the person responsible for the protection of personal information at info@impeczone.ca. The individual must provide their name, contact information, including a phone number, as well as the subject and reasons for the complaint. It is necessary to provide sufficient detail so that the complaint can be properly assessed. A response will be provided within 30 days of the date the complaint is received. If the complaint is not sufficiently specific, the person responsible for the protection of personal information may request any additional information deemed necessary to assess the complaint. The person responsible will conduct an investigation into the complaints received, minimize damages, and implement the necessary corrective actions.

It is also possible to file a complaint with the Commission d’accès à l’information du Québec. However, ImpecZone encourages concerned persons to first contact the person responsible for the protection of personal information and to wait for the conclusion of the processing process provided for.

APPROVAL

This policy is approved by the person responsible for the protection of personal information within ImpecZone.

Person responsible for the protection of personal information:
15 Rue Jos-Montferrand, Gatineau, QC J8X 0C2
info@impeczone.ca

For any request, question, or comment regarding this policy, please contact the person responsible by email.

APPENDIX A

Persons concerned
Categories of information
Types of information
Purposes for which the information is retained
Employees
Staffing
Information related to recruitment, such as a résumé, information on educational and professional background, and details regarding previous employers for employment verification for potential recruitment.
Internal management (candidate assessment)
Hiring (employees and internships)
Information to be included in the employee file, such as first and last name, contact details, SIN, compensation, banking information, employment or internship contract, emergency contacts, etc.
Internal management (payroll operations, legal obligations, CNESST, RRSP, pay equity, performance management, etc.)
Clients and suppliers
Accounting management system, CRM, and project management
Information related to services requested and/or provided.

Information related to billing and financial information, such as a billing address, information relating to a bank account, or payment data.
Internal management (IT services, cybersecurity, billing, project management, communications management, information gathering as part of a program, contract and service agreement)