Protection of personal information policy
Date : 2023-09-13
This policy aims to ensure the protection of personal information and to define the procedures for collecting, using, disclosing, retaining, destroying and managing information by FENOMAX, which includes management, employees, suppliers, etc. Moreover, it aims to inform anyone concerned about how their personal information is processed by FENOMAX, whether it be customers, employees, or any other individuals.
RESPONSIBILITY
FENOMAX assumes full responsibility for the protection of personal information under its control. Information collected, used, disclosed, retained, or destroyed is governed by this policy in order to protect the privacy of every individual.
To ensure the optimal protection of personal information, FENOMAX’s Privacy Officer shall:
- Oversee and review internal practices and procedures for processing personal information as well as compliance with current laws;
- Suggest measures to ensure ongoing protection of personal information in line with Privacy Impact Assessments;
- Implement necessary measures within the business to ensure the protection of information;
- Ensure staff compliance and training in best practices for protecting personal information.
- Coordinate, investigate, and respond to inquiries and complaints about personal information protection;
- Communicate with the concerned individual(s) and the Access to Information Commission (CAI) in case of a data leak or any incident;
- Keep a record of personal data-related incidents.
- Use of information only when necessary ;
- Ensure the confidentiality and protection of personal information that someone may have learned in the course of their duties, unless authorized to disclose it by the person concerned ;
- Protection files with selective and limited access to authorized persons ;
- Secure access to offices with locked doors and access codes ;
- Secure shredding of paper files ;
- Two-factor authentication for all platform connections;
- Immediate withdrawal of access following the end of a business relationship.
Concerned individuals | Information categories | Information types | Purposes for which information is retained |
---|---|---|---|
Employees | Recruitment | Recruitment information, such as curriculum vitae, educational and professional background, details of previous employers to verify employment for potential recruitment. | Internal management
(resume evaluation)
|
Staffing | Information to be included in the employee file, such as first and last name, contact details, SIN, salary, bank details, employment or internship contract, emergency contacts, etc. | Internal management
(example : payroll, operations, legal obligations, CNESST, RRSP, pay equity, performance review, etc.)
| |
Customers and suppliers | Accounting, CRM and project management systems | Details of services requested and/or provided. Billing and financial information, such as a billing address, bank account information or payment details. | Internal management (IT services, cybersecurity, billing, project management, communication, information collection as part of a program, contracts, service agreements, etc.) |