1. Context
UnionPPC Agency LLP is a Limited Liability Partnership that processes personal information as part of its activities. This policy is aimed at ensuring the protection of personal information and regulating how UnionPPC Agency LLP collects, uses, discloses, stores, and destroys or otherwise manages it. Furthermore, it aims to inform anyone interested about how UnionPPC Agency LLP handles their personal information. It also covers the processing of personal information collected by UnionPPC Agency LLP through technological means
2. Application et definitions
This policy applies to UnionPPC Agency LLP, including its executives, employees, consultants, volunteers, suppliers, as well as anyone else who otherwise provides services on behalf of UnionPPC Agency LLP. It also applies with regard to the UnionPPC Agency LLP website, as well as to all websites controlled and maintained by UnionPPC Agency LLP.
It encompasses all types of personal information managed by UnionPPC Agency LLP, whether it pertains to its clients, potential or current, its consultants, employees, members, or any other individuals (such as visitors to its websites or others).
For the purposes of this policy, personal information is information that relates to an identifiable individual, either directly or indirectly. For example, this could include a person’s name, address, email address, phone number, gender, or banking information, as well as information about their health, ethnic origin, language, etc.
Sensitive personal information refers to information for which there is a high degree of reasonable privacy expectation, such as health information, banking details, biometric information, sexual orientation, ethnic origin, political opinions, religious or philosophical beliefs, and so on.In general, a person’s professional or business contact information does not constitute personal information. For example, this includes a person’s name, title, work address, work email address, or work phone number. More specifically and for the sake of precision, as per the Quebec Private Sector Personal Information Protection Act, effective from September 22, 2023, Sections 3 (collection, use, disclosure), 4 (retention and disposal), and 6 (data security) do not apply to information about an individual related to their role within a business, such as their name, title, position, as well as their work address, work email address, and work phone number.
These same paragraphs also do not apply to personal information that is publicly available under the law, starting from the effective date of this policy.
3. Collection, Use, and Disclosure
As part of its activities, UnionPPC Agency LLP may collect various types of information for different purposes. The types of information that UnionPPC Agency LLP may collect, their use (or the intended purpose), and the means by which the information is collected are outlined in Appendix A of this policy.
UnionPPC Agency LLP will also inform individuals, at the time of personal information collection, of any other information being collected, the purposes for which it is being collected, and the means of collection, in addition to any other information that must be provided as required by law.
UnionPPC Agency LLP applies the following general principles regarding the collection, use, and disclosure of personal information:
Consent
- In general, UnionPPC Agency LLP collects personal information directly from the individual concerned and with their consent, unless an exception is provided by law. Consent may be obtained implicitly in certain situations, for example, when the individual decides to provide their personal information after being informed by this policy about its use and disclosure for the purposes outlined herein (see Appendix A for more details). Thus, this policy and the information it contains can be accessed by the individual concerned at the time of personal information collection.
- Normally, UnionPPC Agency LLP must also obtain the consent of the individual concerned before collecting their personal information from third parties, before disclosing it to third parties, or for any secondary use thereof. However, UnionPPC Agency LLP may act without consent in certain cases provided by law and under the conditions set forth therein. The main situations in which UnionPPC Agency LLP may act without consent are outlined in the relevant sections of this policy.
Collection
- In all cases, UnionPPC Agency LLP only collects information if it has a valid reason to do so. Furthermore, the collection will be limited to the necessary information required to fulfill the intended purpose.
- Please note that the services and programs of UnionPPC Agency LLP are not intended for minors, and, in general, UnionPPC Agency LLP does not intentionally obtain personal information about minors (in such cases, information cannot be collected from them without the consent of a parent or guardian).
Collection from Third Parties: UnionPPC Agency LLP may collect personal information from third parties. Unless an exception provided by law applies, UnionPPC Agency LLP will seek the consent of the individual concerned before collecting personal information about them from a third party. In cases where such information is not collected directly from the individual but from another organization, the individual concerned may inquire about the source of the information collected from UnionPPC Agency LLP.
In certain situations, UnionPPC Agency LLP may also collect personal information from third parties without the consent of the individual concerned if it has a legitimate and compelling interest to do so, and a) if the collection is in the best interest of the individual and it is not possible to collect it from them in a timely manner, or b) if this collection is necessary to ensure the accuracy of the information.
Additionally, UnionPPC Agency LLP may collect personal information indirectly. This collection through third parties may be necessary to access certain services or programs or to otherwise engage with UnionPPC Agency LLP. When required, UnionPPC Agency LLP will obtain the individual’s consent at the appropriate time.
Holding and Usage
- UnionPPC Agency LLP ensures that the information it holds is up-to-date and accurate at the time of its use in making a decision concerning the individual in question.
- UnionPPC Agency LLP can only use an individual’s personal information for the purposes stated herein or for any other reasons provided at the time of collection. If UnionPPC Agency LLP wishes to use this information for another reason or purpose, a new consent must be obtained from the individual concerned, which must be obtained explicitly if it involves sensitive personal information. However, in certain cases provided for by law, UnionPPC Agency LLP may use the information for secondary purposes without the individual’s consent, for example:
- when such use is clearly to the benefit of that individual;
- when it is necessary to prevent or detect fraud;
- when it is necessary to assess or improve protection and security measures.
- Limited Access: UnionPPC Agency LLP must implement measures to restrict access to personal information only to employees and individuals within its organization who have the authority to access it and for whom such information is necessary in the performance of their duties. UnionPPC Agency LLP will seek the consent of the individual before granting access to any other person.
Communication :
- In general, and unless an exception is specified in this policy or otherwise provided by law, UnionPPC Agency LLP will obtain the consent of the individual concerned before disclosing their personal information to a third party. Furthermore, when consent is required and it involves sensitive personal information, UnionPPC Agency LLP must obtain explicit consent from the individual before disclosing the information.
- However, the disclosure of personal information to third parties is sometimes necessary. Thus, personal information may be disclosed to third parties without the consent of the individual concerned in certain cases, including but not limited to the following:
- UnionPPC Agency LLP may disclose personal information, without the consent of the individual concerned, to a public body (such as the government) that, through one of its representatives, collects it in the exercise of its powers or in the implementation of a program under its management.
- Personal information may be shared with its service providers to whom it is necessary to communicate the information, without the consent of the individual. For example, these service providers may include event organizers, subcontractors designated by UnionPPC Agency LLP for the execution of mandates in programs administered by UnionPPC Agency LLP, and cloud service providers. In these cases, UnionPPC Agency LLP must have written contracts with these providers that specify the measures they must take to ensure the confidentiality of the communicated personal information, that the use of this information is only for the purpose of contract execution, and that they cannot retain this information after its expiration. Additionally, these contracts must stipulate that providers must notify the Data Protection Officer of UnionPPC Agency LLP (as indicated in this policy) of any breach or attempted breach of confidentiality obligations concerning the communicated personal information and allow this officer to conduct any related confidentiality verification.
- If necessary for the purpose of completing a business transaction, UnionPPC Agency LLP may also disclose personal information, without the consent of the individual concerned, to the other party to the transaction and subject to the conditions provided by law.
Disclosure Outside of Quebec: Personal information held by UnionPPC Agency LLP may be disclosed outside of Quebec, for example, when UnionPPC Agency LLP uses cloud service providers whose servers are located outside of Quebec or when UnionPPC Agency LLP deals with subcontractors located outside of the province.
Additional Information on Used Technologies:
- Use of Cookies
Cookies are data files sent to a website visitor’s computer by their web browser when they visit a site and can serve various purposes.
Websites controlled by UnionPPC Agency LLP use cookies, including:
- To remember visitors’ settings and preferences, such as language choice, and to enable tracking of the current session.
- For statistical purposes, to understand visitor behavior, the content viewed, and to facilitate website improvement.”
Websites controlled by UnionPPC Agency LLP use the following types of cookies
- Session cookies: These are temporary cookies that are stored only for the duration of the website visit.
- Persistent cookies: They are stored on the computer until they expire and will be retrieved during the next website visit
Some cookies may be disabled by default, and visitors can choose whether to enable these features or not when browsing UnionPPC Agency LLP websites. It is also possible to enable or disable the use of cookies by changing preferences in the settings of the browser being used.
- Use of Google Analytics
Some UnionPPC Agency LLP websites use Google Analytics to enable continuous improvement. Google Analytics, in particular, allows the analysis of how a visitor interacts with a UnionPPC Agency LLP website. Google Analytics uses cookies to generate statistical reports on the behavior of visitors to these websites and the content viewed.
- Other Technological Means Used
UnionPPC Agency LLP also collects personal information through technological means such as web forms integrated into a website controlled by UnionPPC Agency LLP, online questionnaires accessible on its platforms and applications, as well as other forms or tools.
If UnionPPC Agency LLP collects personal information by offering a technological product or service that has privacy settings, UnionPPC Agency LLP must ensure that these settings provide the highest level of privacy by default (cookies are not included).
4. Retention and Disposal of Personal Information
Unless a minimum retention period is required by applicable law or regulations, UnionPPC Agency LLP will retain personal information only for the duration necessary to achieve the purposes for which it was collected.
Personal information used by UnionPPC Agency LLP to make a decision concerning an individual must be retained for a period of at least one year following the relevant decision or even seven years after the end of the fiscal year in which the decision was made if it has tax implications, for example, in the case of employment termination circumstances.
At the end of the retention period or when personal information is no longer needed, UnionPPC Agency LLP will ensure that:
- it is destroyed; or
- it is anonymized (meaning it can no longer be used to identify the individual in an irreversible manner, and it is no longer possible to establish a link between the individual and the personal information) for use in legitimate and compelling purposes.
The destruction of information by UnionPPC Agency LLP must be carried out in a secure manner to ensure the protection of this information.
This section may be supplemented by any policy or procedure adopted by UnionPPC Agency LLP regarding the retention and disposal of personal information, as applicable. Please contact UnionPPC Agency LLP’s Data Protection Officer (as indicated in this policy) for more information.
5. Responsibilities of UnionPPC Agency LLP
In general, UnionPPC Agency LLP is responsible for the protection of the personal information it holds.
The Data Protection Officer of UnionPPC Agency LLP is the Director of the organization’s administration. They are generally responsible for ensuring compliance with applicable legislation regarding the protection of personal information. The Data Protection Officer must approve policies and practices governing the governance of personal information. Specifically, this individual is responsible for implementing this policy and ensuring that it is known, understood, and applied. In the event of the absence or inability of the Data Protection Officer to act, the President of UnionPPC Agency LLP will assume the responsibilities of the Data Protection Officer.
Staff members, suppliers, and consultants of UnionPPC Agency LLP who have access to personal information or are otherwise involved in its management must ensure its protection and comply with this policy.
The roles and responsibilities of UnionPPC Agency LLP employees and consultants throughout the life cycle of personal information may be specified by any other policies of UnionPPC Agency LLP in this regard, if applicable.
6. Data Security
UnionPPC Agency LLP is committed to implementing reasonable security measures to ensure the protection of the personal information it manages. The security measures in place correspond to, among other things, the purpose, quantity, distribution, format, and sensitivity of the information. This means that information that can be classified as sensitive (see the definition in section 2) should be subject to more extensive security measures and should be better protected. Specifically, and in accordance with the previously mentioned limited access to personal information, UnionPPC Agency LLP must implement necessary measures to restrict the rights of use of its information systems so that only employees who need access are authorized to do so.
7. Rights of Access, Correction, and Withdrawal of Consent
To exercise their rights of access, correction, or withdrawal of consent, the individual concerned must submit a written request for this purpose to the Data Protection Officer of UnionPPC Agency LLP, at the email address provided in the following section.
Subject to certain legal restrictions, individuals concerned can request access to their personal information held by UnionPPC Agency LLP and request its correction if it is inaccurate, incomplete, or ambiguous. They can also demand the cessation of the dissemination of personal information concerning them or the removal of any hyperlink attached to their name that provides access to this information through a technological means, when the dissemination of this information violates the law or a court order. They can do the same or demand that the hyperlink providing access to this information be reindexed, when certain conditions specified by law are met.
The Data Protection Officer of UnionPPC Agency LLP must respond in writing to these requests within 30 days from the date of receiving the request. Any refusal must be substantiated and accompanied by the legal provision justifying the refusal. In such cases, the response must specify the remedies available under the law and the timeframe within which they can be exercised. The responsible person must assist the requester in understanding the refusal if necessary.
Subject to applicable legal and contractual restrictions, individuals can withdraw their consent for the communication or use of the collected information.
They can also request from UnionPPC Agency LLP the personal information collected from them, the categories of individuals within UnionPPC Agency LLP who have access to it, and its retention period.
8. Processus de traitement des plaintes
Réception
Any individual who wishes to file a complaint regarding the application of this policy or, more generally, the protection of their personal information by Agence UnionPPC S.E.N.C., must do so in writing by addressing it to the Data Protection Officer of Agence UnionPPC S.E.N.C., at the email address provided in the following section. The individual must provide their name, contact information, including a phone number, as well as the subject and reasons for their complaint, providing sufficient details for it to be assessed by Agence UnionPPC S.E.N.C. If the complaint filed is not sufficiently specific, the Data Protection Officer may request any additional information deemed necessary to evaluate the complaint.
Traitement
Agence UnionPPC S.E.N.C. is committed to treating any received complaint confidentially. Within 30 days of receiving the complaint or receiving any additional information deemed necessary and required by the Data Protection Officer of Agence UnionPPC S.E.N.C. to process it, the Data Protection Officer must evaluate it and provide a reasoned written response by email to the complainant. This evaluation aims to determine whether the processing of personal information by Agence UnionPPC S.E.N.C. complies with this policy, any other policies and practices within the organization, and applicable legislation or regulations.
If the complaint cannot be processed within this timeframe, the complainant must be informed of the reasons for the extension, the status of the complaint’s processing, and the reasonable timeframe needed to provide a definitive response. Agence UnionPPC S.E.N.C. must maintain a separate record for each complaint received. Each record includes the complaint, the analysis, supporting documentation for its evaluation, and the response sent to the complainant. It is also possible to file a complaint with the Commission d’accès à l’information du Québec or any other supervisory authority responsible for the enforcement of the law relevant to the subject of the complaint.
However, Agence UnionPPC S.E.N.C. encourages anyone interested to first contact its Data Protection Officer and wait for the completion of Agence UnionPPC S.E.N.C.’s complaint handling process.”
9. approval
This policy is approved by the Privacy Officer of Agence UnionPPC S.E.N.C., whose business contact information is as follows:
Privacy Officer:
François Lebel
246, route du Président-Kennedy
Scott (Québec) G0S 3G0
[email protected]
For any requests, questions, or comments regarding this policy, please contact the responsible party via email.
10. Publication et modifications
This policy is published on the Agence UnionPPC S.E.N.C. website, as well as on all websites controlled and maintained by Agence UnionPPC S.E.N.C. to which this policy applies, with regard to the personal information collected on those sites. This policy is also disseminated through any means appropriate for reaching the individuals concerned.
Agence UnionPPC S.E.N.C. must also do the same for any modifications to this policy, which must also be subject to notice to inform the individuals concerned.
*Note: Please note that the use of the masculine gender is intended to streamline this policy and make it easier to read.
Version and Change Log Table:
Version | Effective on | Changes since the last version |
1.0 | September 22 2023 | S.O. – First version |
2.0 |
Annexe A
Here is a non-exhaustive list of the types of information that Agence UnionPPC S.E.N.C. may collect, their use or intended purpose, and the means by which the information is collected. This includes, but is not limited to, the following elements.Please note that most of the personal information managed by Agence UnionPPC S.E.N.C. pertains to employees, job applicants, and consultants. As for the other categories of individuals mentioned in the table below, the information provided is, in most cases, professional or business-related information (see Section 2 on professional contact information). It should be noted that in the majority of cases, Agence UnionPPC S.E.N.C. also collects the professional title/position of individuals, the name of the organization, and/or the organization’s address (see Section 2 on professional contact information).
Relationship with Agence UnionPPC S.E.N.C., services, programs, etc. | Type of personal information | End of collection / uses | Way of collecting information (means) |
Either of this information, when required | Used for: | Can be collected | |
Clients | name phone number email addresses banking or payment information language Postal code Business address | establish and manage customer relationships (and obtain a means of communication) provide a service (e.g., digital marketing service, SEO, training, strategy, etc.) collect information as part of a program. Note that it is sometimes necessary to share the information provided with the program in question. respond to inquiries about the cybersecurity ecosystem or any other information request register clients for events organized by Agence UnionPPC S.E.N.C. determine the preferred language of communication ensure payment of costs related to services or programs Schedule payment of advertising expenses paid directly by the client in various advertising channelssubscription to Agence UnionPPC S.E.N.C.’s newsletter and seminars provide training Payment of commissions | through web forms integrated into a website controlled by Agence UnionPPC S.E.N.C., online questionnaires accessible on its platforms and applications, as well as other technological form platforms. by email (directly or through an attached document or other type of form) By phone Through various communication software (e.g., Slack) |
Job applicants and employees | name phone number email banking informationSocial Insurance Number (SIN) date of birth Languages Address Other information relevant for group insurance if applicable Work permit Status and citizenship | Managing communications with the candidate, the employee. Ensuring the operation of the payment system and billing Ensuring the operation of the group insurance Completing the required tax documents Validating work status in Canada and the validity of the permit Knowing the languages in which they can provide services and the preferred language of communication Commission payments | by email by phone Through various communication software (e.g., Slack) via web forms and other technological form platforms |
Consultants | Name phone number email languages banking information social insurance number date of birth address Other information relevant to group insurance, if applicable Work permit Status and citizenship | managing communication with the candidate or employee. ensuring the operation of the payment system and billing. Ensuring the operation of group insurance. Completing required tax documents. Validating work status in Canada and the validity of the work permit. knowing the languages in which they can provide services and the preferred language of communication. Payment of commissions. | by email by phone Through various communication software (e.g., Slack) through web forms and other technological form platforms |
Fournisseurs de services | Namephone numberaddress email banking information language | mandate management invoice payment knowing the languages in which they can provide services Payment of commissions | via web forms and other technological form platforms by email Using various communication software (e.g., Slack) By phone |
Members (individuals and organizations) | Name phone number email Languages banking information social insurance number date of birth address Other information relevant to group insurance if applicable Work permit Status and citizenship | membership registration future communications billing group insurance registration for activities organized by Agence UnionPPC S.E.N.C. and access to cybersecurity expertise portals surveys the creation of Agence UnionPPC S.E.N.C. databases on member expertise knowing the languages in which they can provide services and their preferred language of communication Commission payment | through web forms and other technological form platforms from third parties |
Partners of Agence UnionPPC S.E.N.C. | Name Phone number Email Address Banking information (when necessary) | establishing the partnership (signing partnership agreements) CollaborationBilling Sales commissions | by email (directly or through an attached document or other type of form) By phone via web forms and other technological platforms or toolsThrough various communication software (e.g., Slack) |