Privacy policy
1. Background
StopGerms is a company that processes personal information in the course of its activities.
The purpose of this policy is to ensure the protection of personal information and to govern the manner in which StopGerms collects, uses, communicates, retains and destroys it or otherwise manages it. In addition, it is intended to inform all interested parties of the manner in which StopGerms handles their personal information. It also applies to the processing of personal information collected by StopGerms by technological means.
2. Application and definitions
This policy applies to StopGerms, including but not limited to its officers, employees, consultants, volunteers, and any person who otherwise provides services on behalf of StopGerms. It also applies to the StopGerms website, as well as to all websites controlled and maintained by StopGerms.
It applies to all types of personal information managed by StopGerms, whether it be information about its clients, potential or current clients, its consultants, its employees, its members or any other person (such as visitors to its websites or other).
For the purposes of this Privacy Policy, personal information is any information about an individual that directly or indirectly allows that individual to be identified. For example, it could be a person's name, address, e-mail address, telephone number, gender or banking information, information about his or her health, ethnic origin, language, etc.
Sensitive personal information is information about which there is a high reasonable expectation of privacy, e.g. health information, banking information, personal information about a person, personal information about a person, personal information about a person. Sensitive personal information is information about which there is a reasonable expectation of privacy, e.g. health information, banking information, biometric information, sexual orientation, ethnic origin, political opinions, religious or philosophical beliefs, etc.
Generally speaking, an individual's professional or business contact information does not constitute personal information, e.g. an individual's name, title, address, e-mail address or work telephone number. More specifically, and for greater clarity, within the meaning of Quebec's Act respecting the protection of personal information in the private sector, and as of September 22, 2023, sections 3 (collection, use, communication), 4 (retention and destruction) and 6 (data security) do not apply to an individual's information relating to the exercise of a function within an enterprise, such as name, title, function, as well as address, e-mail address and telephone number at work.
These same paragraphs do not apply to personal information that is public by law, as of the effective date of this policy.
3. Collection, use and communication
In the course of its business, StopGerms may collect different types of information for different purposes. The types of information StopGerms may collect, its use (or intended purpose) and the means by which the information is collected are set out in Appendix A of this Policy.
StopGerms will also inform individuals, at the time of collection of personal information, of any other information collected, the purposes for which it is collected and the means of collection, in addition to other information required by law.
StopGerms applies the following general principles with respect to the collection, use and disclosure of personal information:
Consent :
- Generally speaking, StopGerms collects personal information directly from the person concerned and with his or her consent, unless an exception is provided for by law. Consent may be obtained implicitly in certain situations, for example, when the individual decides to provide his or her personal information after having been informed by this policy of the use and disclosure for the purposes indicated herein (see Appendix A for more details). Thus, this policy and the information it contains will be available to the person concerned at the time personal information is collected.
- Normally, StopGerms must also obtain the consent of the person concerned before collecting his or her personal information from third parties, before communicating it to third parties or for any secondary use thereof. However, StopGerms may act without consent in certain cases provided for by law and under the conditions set forth therein. The main situations in which StopGerms may act without consent are indicated in the relevant sections of this policy.
Collection :
- In all cases, StopGerms will only collect information if it has a valid reason to do so. In addition, the collection of information will be limited to that which is necessary to fulfill the purpose for which it is collected.
- Please note that StopGerms' services and programs are not intended for minors, and more generally, StopGerms does not intentionally obtain personal information from minors (in such cases, information cannot be collected from them without the consent of a parent or guardian).
- Collection from third parties. StopGerms may collect personal information from third parties. Unless an exception is provided by law, StopGerms will seek the consent of the individual before collecting personal information about him or her from a third party. In the event that such information is not collected directly from the individual, but from another organization, the individual may request the source of the information collected from StopGerms.
In certain situations, StopGerms may also collect personal information from third parties, without the consent of the person concerned, if it has a serious and legitimate interest in doing so and a) if the collection is in the interest of the person and it is not possible to collect it from him or her in a timely manner, or b) if such collection is necessary to ensure that the information is accurate.
StopGerms may also collect personal information indirectly through the use of :
- Shopify : Shopify has its own terms and conditions and privacy policy for more information.
- Hubspot : Hubspot has its own terms and conditions and privacy policy for further information.
- Klaviyo : Klaviyo has its own conditions and privacy policy for more information.
- Google : Google has its own conditions and privacy policy for more information.
- Facebook : Facebook has its own conditions and privacy policy for more information.
Holding and use :
- StopGerms ensures that the information it holds is up-to-date and accurate at the time it is used to make a decision about the individual concerned.
- StopGerms may only use an individual's personal information for the purposes identified herein or for any other purposes provided at the time of collection. If StopGerms wishes to use the information for another reason or purpose, a new consent must be obtained from the person concerned, which must be obtained expressly if the information is sensitive personal information. However, in certain cases provided for by law, StopGerms may use information for secondary purposes without the consent of the individual, e.g.:
a) when such use is clearly for the benefit of the individual;
b) when it is necessary to prevent or detect fraud;
c) when it is necessary to evaluate or improve protection and security measures. - Limited access. StopGerms shall implement measures to limit access to personal information to those employees and individuals within its organization who have a right to know the information and for whom the information is necessary in the performance of their duties. StopGerms will seek the consent of the individual before granting access to any other person.
Communication :
- Generally, and unless an exception is indicated in this policy or otherwise provided by law, StopGerms will obtain the consent of the individual concerned before disclosing his or her personal information to a third party. In addition, where consent is required and where sensitive personal information is involved, StopGerms will obtain the individual's express consent prior to disclosing the information.
- However, disclosure of personal information to third parties is sometimes necessary. Thus, personal information may be disclosed to third parties without the consent of the individual concerned in certain cases, including, but not limited to, the following:
a) StopGerms may disclose personal information, without the consent of the individual concerned, to a public body (such as the government) which, through one of its representatives, collects it in the exercise of its powers or the implementation of a program under its management.
b) Personal information may be transmitted to service providers to whom it is necessary to communicate the information, without the individual's consent. For example, these service providers may be event organizers, StopGerms subcontractors designated to carry out mandates in programs administered by StopGerms, and information service providers. In these cases, StopGerms must have written contracts with these suppliers that indicate the measures they must take to ensure the confidentiality of the personal information communicated, that the use of this information is made only within the framework of the execution of the contract and that they may not retain this information after its expiration. In addition, such contracts shall provide that suppliers shall notify StopGerms' Privacy Officer (identified in this Policy) of any breach or attempted breach of the confidentiality obligations with respect to the personal information communicated and shall permit such Privacy Officer to conduct any audit relating to such confidentiality.
c) If necessary for the purposes of concluding a business transaction, StopGerms may also disclose personal information, without the consent of the individual concerned, to the other party to the transaction and subject to the conditions provided by law. - Disclosure outside Quebec: Personal information held by StopGerms may be disclosed outside Quebec, for example, when StopGerms uses cloud service providers whose server(s) are located outside Quebec or when StopGerms deals with subcontractors located outside the province.
Further information on the technologies used :
Use of cookies
Cookies are data files that are sent to the visitor's computer by their Web browser when they visit a website and can serve several purposes.
The websites controlled by StopGerms use cookies in particular:
- To memorize visitors' settings and preferences, e.g. for language selection, and to enable tracking of the current session.
- For statistical purposes, to track visitor behavior and content, and to help improve the website.
The websites controlled by StopGerms use the following types of cookies:
- Session cookies: These are temporary cookies that are stored only for the duration of your visit to the website.
- Persistent cookies: These are kept on the computer until they expire, and are retrieved the next time the site is visited.
Some cookies may be disabled by default and visitors may choose whether or not to enable these functions when visiting StopGerms websites.
It is also possible to enable and disable the use of cookies by changing the preferences in the settings of the browser used.
- Using Google Analytics
Some StopGerms websites use Google Analytics to enable continuous improvement. In particular, Google Analytics makes it possible to analyze how a visitor interacts with a StopGerms website. Google Analytics uses cookies to generate statistical reports on the behavior of visitors to these websites and the content consulted.
Information from Google Analytics will never be shared by StopGerms with third parties.
You can install a browser add-on to disable Google Analytics.
- Other technologies used
StopGerms also collects personal information through technological means such as web forms integrated into a website controlled by StopGerms (for example, its contact form, its membership form, its newsletter and seminar registration form), questionnaires accessible online on its platforms and applications, as well as other platforms or form tools (e.g., Microsoft Forms).
If StopGerms collects personal information by offering a technological product or service that has privacy settings, StopGerms must ensure that these settings offer the highest level of privacy by default (cookies are not covered).
In certain circumstances, we may disclose your personal information to third parties for legitimate purposes in accordance with this Privacy Policy. These circumstances may include:
With suppliers or other third parties who provide services on our behalf (for example, IT management, payment processing, data analysis, customer support, cloud storage, processing and shipping).
With business and marketing partners, including Shopify, Hubspot, Klaviyo, Google and Facebook, to provide services and advertise to you. Our business and marketing partners will use your information in accordance with their own privacy notices.
When you tell us, request or otherwise consent to our disclosure of certain information to third parties, for example, to ship products to you or through the use of social media widgets or login integrations, with your consent.
With our subsidiaries or within our group of companies, in our legitimate interest in conducting a successful business.
In connection with a business transaction such as a merger or bankruptcy, to comply with any applicable legal obligation (including responding to subpoenas, search warrants and similar requests), to enforce applicable terms of service, and to protect or defend the Services, our rights and the rights of our users or others.
4. Retention and Destruction of Personal Information
Unless a minimum retention period is required by applicable law or regulation, StopGerms shall retain personal information only as long as necessary for the fulfillment of the purposes for which it was collected.
Personal information used by StopGerms to make a decision about an individual shall be retained for a period of at least one year following the decision in question or even seven years after the end of the fiscal year in which the decision was made if the decision has tax implications, for example, the circumstances of a termination of employment.
At the end of the retention period or when the personal information is no longer required, StopGerms will:
a) destroy it; or
b) anonymize it (i.e. it no longer irreversibly identifies the individual and it is no longer possible to establish a link between the individual and the personal information) in order to use it for serious and legitimate purposes.
The destruction of information by StopGerms shall be done in a secure manner to ensure the protection of such information.
This section may be supplemented by any policies or procedures adopted by StopGerms regarding the retention and destruction of personal information, if any. Please contact the StopGerms Privacy Officer (identified in this policy) for further information.
5. Responsibilities of StopGerms
In general, StopGerms is responsible for protecting the personal information it holds.
StopGerms' Privacy Officer is the organization's Director of Operations. In general, he or she is responsible for ensuring compliance with applicable legislation concerning the protection of personal information. The person in charge must approve the policies and practices governing the governance of personal information. More specifically, this person is responsible for implementing this policy and ensuring that it is known, understood and applied. In the event that the Privacy Officer is absent or unable to act, the President of StopGerms will assume the duties of the Privacy Officer.
StopGerms employees who have access to personal information or who are otherwise involved in the management of personal information must ensure its protection and comply with this policy.
The roles and responsibilities of StopGerms employees throughout the life cycle of personal information may be specified by any other StopGerms policy in this regard, if applicable.
6. Data security
StopGerms is committed to implementing reasonable security measures to ensure the protection of personal information under its control. The security measures in place correspond, among other things, to the purpose, quantity, distribution, medium and sensitivity of the information. This means that information that may be considered sensitive (see definition in section 2) will require more stringent security measures and greater protection. In particular, and in accordance with what was mentioned above concerning limited access to personal information, StopGerms must put in place the necessary measures to impose constraints on the rights of use of its information systems so that only employees who need to have access to them are authorized to do so.
7. Rights of access, rectification and withdrawal of consent
To exercise his or her right of access, rectification or withdrawal of consent, the person concerned must submit a written request to this effect to the StopGerms Privacy Officer, at the e-mail address indicated in the following section.
Subject to certain legal restrictions, the persons concerned may request access to their personal information held by StopGerms and request its correction in the event that it is inaccurate, incomplete or equivocal. They may also demand that StopGerms cease disseminating personal information about them, or that StopGerms de-index any hyperlink attached to their name allowing access to this information by technological means, when the dissemination of this information contravenes the law or a court order. They may do the same, or require that the hyperlink allowing access to this information be re-indexed, when certain conditions provided for by law are met.
StopGerms' Privacy Officer shall respond in writing to such requests within 30 days of the date of receipt of the request. Reasons must be given for any refusal, together with the legal provision justifying the refusal. In such cases, the reply must indicate the remedies available under the law and the time limit for exercising them. The person in charge must help the applicant understand the refusal if necessary.
Subject to applicable legal and contractual restrictions, the persons concerned may withdraw their consent to the communication or use of the information collected.
They may also ask StopGerms what personal information has been collected from them, which categories of persons at StopGerms have access to it and how long it is kept.
8. Complaints handling process
Reception
Any person who wishes to make a complaint regarding the application of this policy or, more generally, regarding the protection of his or her personal information by StopGerms, must do so in writing to the StopGerms Privacy Officer, at the e-mail address indicated in the following section.
The individual must indicate his or her name, contact information, including a telephone number, as well as the subject and reasons for his or her complaint, providing sufficient detail to allow StopGerms to evaluate the complaint. If the complaint is not specific enough, the Privacy Officer may request any additional information he or she deems necessary to assess the complaint.
Treatment
StopGerms undertakes to treat all complaints received confidentially.
Within 30 days of receiving the complaint or of receiving all additional information deemed necessary and required by StopGerms' Privacy Officer in order to process it, the latter shall evaluate it and formulate a reasoned response in writing by e-mail to the complainant. The purpose of this assessment will be to determine whether StopGerms' processing of personal information complies with this policy, any other policies and practices in place within the organization, and applicable legislation or regulations.
If the complaint cannot be processed within this timeframe, the complainant must be informed of the reasons for the extension, the status of the processing of the complaint, and the reasonable time required to provide a definitive response.
StopGerms must establish a separate file for each complaint addressed to it. Each file contains the complaint, the analysis and documentation supporting its evaluation, as well as the response sent to the person who filed the complaint.
It is also possible to file a complaint with the Commission d'accès à l'information du Québec or any other personal information protection oversight body responsible for the application of the law concerned by the subject of the complaint.
However, StopGerms invites all interested parties to first contact their privacy officer and wait for StopGerms to complete its processing.
9. Approval
This policy is approved by StopGerms Privacy Officer, whose business contact information is as follows:
Privacy officer:
Matthieu Laroche
766Rue Bériault
Longueuil (Québec) J4G 1R8
info@stopgerms.ca
514-666-3627
For any request, question or comment regarding this policy, please contact the person in charge by email
10. Publication and modifications
This policy is published on the StopGerms website, as well as on all websites controlled and maintained by StopGerms, to which this policy applies, with respect to the personal information collected therein. This policy shall also be disseminated by any means appropriate to reach the persons concerned.
StopGerms shall also do the same for all modifications to this policy, which shall also be the subject of a notice informing the persons concerned.
*Notes : Please note that the use of the masculine gender is intended to lighten this policy and make it easier to read.
Appendix A
The following is a non-exhaustive list of the types of information StopGerms may collect, how it is used, or for what purpose, and the means by which it is collected. As such, it includes, but is not limited to, the following.
Please note that most of the personal information managed by StopGerms is the personal information of employees, job applicants and consultants. For the other categories of individuals listed in the table below, the information provided is, in the majority of cases, of a professional or business nature (see section 2 on business contact information). Please note that in most cases, StopGerms also collects the individual's professional title/function, the name of the organization and/or the organization's address (see section 2 on professional contact information).
Relationship with StopGerms, services, program, etc. |
Type of personal information |
End of collection / uses |
Means of gathering information |
Any of the above, when required: |
Used for : |
The following can be collected: |
|
Customers |
|
|
|
Job applicants and employees |
|
|
|
Service providers, partners and consultants |
|
|
|
Last update : 2023-09-15