Policy relating to confidentiality and protection of personal information
___________________
Privacy Officer
Marcel Tremblay
Phone : 418.931.7363
Email : marcel.tremblay@proinscription.com
___________________
PRIVACY AND PRIVACY POLICY
Approved by the Board of Directors and the Privacy Officer
ProInscription recognizes the importance of privacy, security and the protection of personal information.
The purpose of this Privacy Policy (“Policy”) is to inform you of ProEnrollment’s privacy governance practices. It also aims to regulate the security of personal information collected, held, used, disclosed and retained.
The Policy applies to ProInscription, all employees, its clients and suppliers who may have access to personal information in the course of performing their duties.
In this Policy, the term “client” refers to ProInscription’s clients who use the services offered by ProInscription, including dance and music schools, sports clubs, summer camps, and clients wishing to organize various events.
The term “participant” refers to the individuals who benefit from the services offered by ProInscription clients.
1. General Principles of the Policy
ProInscription takes security measures to ensure the protection of personal information collected through its customers, held, used, communicated, retained or destroyed and which is reasonable in particular taking into account, in particular, its sensitivity, the purpose of its use, its quantity, its distribution and its medium, in particular by ensuring the following: :
- The integrity of the information, so that it is not destroyed or altered without authorization and in accordance with the law, and that the medium of the information provides the desired stability and durability;
- The confidentiality of personal information, by limiting its disclosure to only those authorized to know it, either externally in accordance with client agreements or internally when the information is necessary for the performance of employees’ duties;
- Identification and authentication, so as to confirm, when required, the identity of a person or the identification of a document;
- Compliance with legal, regulatory or business requirements to which ProInscription is subject.
2. Policy Objectives
The objectives of the Policy are to :
- Define the type of personal information that ProInscription uses and retains;
- Define the means used by ProInscription to protect this information;
- Specify the standards for the use, retention, disclosure and destruction of this information;
- Determine the rights of access, rectification and destruction of personal information by ProInscription regardless of the nature of its medium and regardless of the form in which it is accessible, whether written, graphic, audio, visual, computerized or other;
- Establish the roles of the individuals involved, including the Privacy Officer.
3. Definition of Personal Information
For the purposes of this Policy, “Personal information” means any information that relates to a natural person, that directly or indirectly identifies that person and that is not of a public nature within the meaning of the Act respecting the protection of personal information in the private sector.
4. What personal information is collected?
ProInscription offers 100% online services that manage registration for sports and cultural activities. The services provided include, but are not limited to, online registration for participants, an online store, a room reservation service as well as a registration service for member packages.
As part of these activities, necessary personal information collected by clients and retained by ProInscription may include, but is not limited to:
- Contact information such as first and last name, street address, email or IP address, telephone number, date of birth, gender of a person;
- Billing-related information such as a billing address, banking information, or payment system data;
- Identification information, such as a Medicare card number and expiry date, a Social Insurance Number;
- Information related to the use of ProInscription’s services, including technical information about visits or any other information collected through cookies or other similar tools;
- Registration information, such as a citizen number, a membership number, an association number, a federation number;
5. How is your personal information collected?
The client collects personal information from the participant and a potential third party. ProInscription uses and retains this personal information provided by the customer in accordance with a service agreement between them. The collection of personal information by the client as well as the use and retention by ProInscription is carried out through the services offered by ProInscription such as online registration, the online store, room reservations and the registration of member packages. ProInscription uses and retains personal information of participants provided by the client. The customer shall provide the following information at the outset and in simple and clear terms, including at the time of collection and subsequently upon request by the participant:
- The client’s name;
- The purposes for which the information is collected;
- The means by which the information is collected;
- The rights of access and rectification provided for by law;
- The right to withdraw consent to the disclosure or use of the information collected;
- The name of the third party for whom the collection is being carried out, if applicable;
- The names of the third parties to whom it will be necessary to disclose the personal information;
- The possibility that personal information may be communicated outside Quebec.
6. Consent to Collection
It is the responsibility of ProInscription’s clients to carry out the collection with the prior, free and informed consent of the participant, which is obtained through a detailed consent form in simple and clear terms on the platform.
In compliance with applicable laws, ProInscription will ensure that separate consent is obtained before using personal information held for purposes that are not compatible with those for which it was originally collected.
Any data subject may, at any time, withdraw his or her consent to the processing of his or her personal information by contacting the customer’s privacy officer. The client informs ProInscription and following receipt of the notice of withdrawal of consent, ProInscription undertakes to cease all processing of the personal information in question and to proceed with its destruction, subject to a legal or regulatory obligation relating to its retention.
ProInscription will also notify any person or entity to whom such personal information has been disclosed so that such persons or entities may also cease processing and destroy it, if applicable, subject to a legal or regulatory obligation relating to its retention.
Under no circumstances can ProInscription be held liable for the invalidity of a consent given by a participant to one of its clients. Indeed, ProInscription does not collect any personal information but provides the tool to its clients to do so.
7. Use of Information Collected
ProInscription uses and stores personal information in order to provide personalized and secure service to its clients and their participants, in compliance with applicable laws and security rules.
As such, ProInscription will use personal information in accordance with customer instructions, including for the following purposes:
- Generate invoices, statements of account and statements at the request of clients or participants;
- Manage the various customer packages;
- Manage the various accounts receivable;
- Share personal information with third parties for retention;
- Prepare statistical data for clients, including at the request of their funders;
- Generate reports containing statistical data at the request of clients;
- Keep a participant’s journey history so that their record is up-to-date and accurate;
- Ticket sales, if applicable;
- As permitted or required, for any applicable legal or regulatory obligation or provision;
- Enforce your rights, if applicable;
- Any other purpose to which a person has consented.
ProInscription uses information only for the purposes identified by the client and for which consent has been obtained. Thus, without specific consent, ProInscription does not communicate, sell, rent, give, exchange, share or disclose any information to third parties.
This information is accessible only to those clients or suppliers who necessarily need it for the performance of their duties and they are required to respect the confidentiality of this information.
8. Disclosure of Personal Information to Third Parties
ProInscription clients must obtain the consent of the individual concerned before disclosing his or her personal information to a third party, unless applicable laws permit the disclosure of such information without such consent.
As part of the services offered, ProInscription may communicate, in compliance with applicable legal requirements, personal information to its external suppliers located in Quebec and outside Quebec. These providers include Akamai, which stores ProEnrollment’s computer servers, and Amazon, which facilitates the sending of e-mail as part of the services offered by ProEnrollment. In this case, ProInscription’s external service providers are subject to confidentiality agreements.
ProInscription and its suppliers may be required to provide personal information held as a result of court order, administrative investigation or other legal situation.
In the context of a possible restructuring of ProInscription’s activities, ProInscription may be required to disclose personal data, which may be assimilated to personal information, to potential or existing acquirers and their advisors for the purposes of the said transaction.
9. Retention and Security of Personal Information
ProInscription may use and store personal information collected through its clients outside the province of Quebec. All personal information collected, regardless of its medium, is stored in a secure environment against unauthorized access, disclosure, copying, use or modification, as well as loss or theft. These security measures include, where appropriate, the use of firewalls and secure servers, encryption, the deployment of appropriate access rights management systems and procedures, and other measures necessary to ensure that personal information is appropriately protected from unauthorized use or disclosure.
However, despite best efforts, no method of electronic transmission or storage is completely secure. As a result, ProInscription cannot guarantee the security of the personal information transmitted to it or that such personal information will not be obtained, accessed, disclosed, modified or destroyed as a result of a breach of security and protection measures.
10. Destruction of Personal Information
Personal information is retained for as long as necessary to fulfill the purposes for which it was collected, and is subsequently destroyed. Personal information may be retained beyond the fulfillment of the purposes for which it was collected when another period provided for by law applies. They will be destroyed in accordance with applicable laws.
Participants’ personal information will be destroyed when a customer terminates their contract with ProInscription. Information will be destroyed in accordance with applicable laws.
11. Responsibility of the Person Providing the Information
Any participant who forwards information to a ProInscription client is responsible for the accuracy of the information.
The participant using the client’s services must also ensure that the system or equipment with which the participant transmits or receives information is sufficiently secure.
ProInscription is not responsible for unauthorized access to information resulting from negligence or vulnerabilities on the equipment or system of a customer or participant who transmits or receives information.
In the event that the confidentiality of his/her information is compromised or his/her identity is stolen, the individual is required to notify ProInscription as soon as possible by contacting the person responsible for the protection of personal information designated below. ProInscription will promptly notify the client, if applicable.
12. Complaint Management
Any person who wishes to file a complaint regarding the use, retention, disclosure, destruction or rights of access or correction of his or her personal information by ProInscription must forward his or her complaint to ProInscription’s Privacy Officer designated below. ProInscription undertakes to deal with the complaint within fifteen (15) business days of receipt of the complaint.
13. Data, Cookies and Privacy Settings
ProInscription collects cookies, “Cookies”, when using the ProInscription platform in order to ensure proper management of the creation by participants of their account and the transactions charged to the online store’s shopping cart.
A cookie is a small data file that is stored on the user’s computer or mobile device. A consent banner is automatically displayed upon arrival on the ProInscription platform to allow the user to activate cookies. The effectiveness of certain services offered by the website may be affected if the user refuses the activation of cookies. The cookies used fall into four (4) distinct categories:
- Necessary witnesses;
- Functionality cookies;
- Performance cookies;
- Tracking cookies.
An individual who provides personal information under this section consents to the use and disclosure of personal information for the purposes for which the information was collected.
14. Dissemination of this Policy
ProInscription publishes this policy on its website and disseminates it by any means appropriate to reach the persons concerned. ProInscription does the same for any changes to this policy..
15. Incident Reporting
In the event of an incident affecting the protection of personal information, ProInscription will take the necessary measures to reduce the risk of harm being caused and to prevent future incidents of the same nature from occurring.
16. Maintaining an Incident Log
ProInscription keeps a record of all confidentiality incidents, if any, even those that do not pose a risk of serious harm to the participant.
ProInscription will allow the Commission d’accès à l’information to consult this register and may provide it with a copy at its request.
17. Roles and Responsibilities
The President of ProInscription is the Privacy Officer and can be reached at info@proInscription.com or at 418931-7363.
The Privacy Officer and his/her partner are the only staff members of ProInscription and will be the only ones with roles and responsibilities throughout the life cycle of personal information.
Effective date
This policy will be effective on the day it is adopted by the ProInscription Board of Directors.
September 22, 2023