Privacy policy
1. What is the purpose of this notice?
We, Sanimax ABP Inc. and its entities (“Sanimax” or “we”), recognize the importance of protecting privacy and are committed to protecting the privacy and security of your personal information (“PI”).
This Privacy Notice (“Notice”) describes our privacy policies and practices pertaining to the protection of PI that we collect, use, store, or communicate (collectively the “processing“) as part of our operations.
2. What is personal information?
Personal information (PI) is any information that relates to a natural person and that allows that person to be identified, either directly (when used alone) or indirectly (when combined with other information). For example, the name, mailing address, telephone number, email address, social insurance number, bank account number, identification number, location data, and online identifier of a natural person, or the factors specific to a person’s physical, physiological, genetic, mental, economic, cultural or social identity are PI.
Sensitive personal information is any PI that, due to its nature, in particular its medical, biometric or otherwise intimate nature, or the context of its use or release, entails a high level of reasonable expectation of privacy. For example, genetic and biometric data as well as data concerning a natural person’s health and finances, racial or ethnic origin, political opinions, sex life or sexual orientation, and religious or philosophical beliefs are sensitive PI.
3. What PI do we collect?
We only collect PI that is required for business purposes. The types of PI we collect are generally described in the following list:
- Government-issued identifiers such as social insurance number (SIN), or driver’s licence number;
- Internal identifiers such as employee number;
- Contact information such as last name, first name, email address, telephone number, or home address;
- Financial information such as bank account number, payment card information, or tax information;
- Technical data or login information such as identifiers (username, password, secret questions and answers), browsing history, IP address, or log history;
- Socio-demographic data such as date of birth, place of birth, or information on marital status;
- Employment information such as employee number, position title, type of contract, working hours, salary, performance assessment, health and safety information, disciplinary actions, or background check (criminal record, reference inquiry, or screening);
- Sensitive PI such as social insurance number (SIN), health insurance number, financial information, employment information, or health information.
4. Why do we collect and process your PI?
We collect and process your PI for the purposes for which you have consented, or to the extent permitted by law. The purposes for which we collect and process your PI are identified at the time of collection. You may also be informed of these purposes upon request. The purposes for which we collect and process your PI are generally described in the following list:
- Confirm the identity of the persons concerned, verify the accuracy of, and update their PI;
- Receive and evaluate applications for our job postings, and manage the relationship with job applicants;
- Customize and tailor the browsing experience to the needs of individuals who visit our websites;
- Operate our websites in accordance with their terms and conditions;
- Compile statistics;
- Reply to any communication received from you.
5. How do we collect your PI?
5.1 Directly from you
Most of the PI we collect is the PI you provide directly to us, for instance when:
- You fill out the various forms available on the site;
- You ask about our products and services;
- You provide comments or file complaints;
- You submit a request for a donation or a sponsorship;
- You make a media inquiry;
- You subscribe to our newsletter;
- You apply to one of our job postings.
5.2 From third parties
We may also collect your PI from third parties, with your consent or if authorized by law.
5.3 Through our websites and online services
We can also collect PI when you visit our websites or connect to our online services (e.g. your job application account).
Subject to applicable requirements pertaining to the consent to data collection through a technology service or solution, the IP address used by your device for connecting to our sites is automatically collected when you access our websites.
We and some of our partners may also collect other information about your use of our websites using cookies. These files allow us to identify users of our website when they access it and when they move from one page to another. We and our partners, where appropriate, use these cookies to identify people who have a particular interest in certain pages of our website, to provide a personalized welcome to website users, to improve service, and to compile statistics.
For more information about cookies used by Sanimax, you may consult our Cookie Policy.
6. Under what conditions do we collect and process your PI?
We only collect and process your PI with your consent, in accordance with applicable requirements, or without your consent, in certain cases prescribed for by law, such as in criminal proceedings.
For primary purposes such as confirming your identity, verifying and updating your personal information, and managing the relationship with job applicants, it will generally not be possible to withdraw your consent for contractual or legal reasons or without affecting Sanimax’s ability to respond to your requests and provide you with products and services.
You may at any time withdraw your consent to the use of your PI for secondary purposes (i.e. not essential to the provision of products and services). If you wish, we will stop using your PI for these purposes.
Any request to withdraw your consent must be communicated to the person in charge of the protection of personal information (Privacy Officer – see below for contact information).
7. Who do we disclose your PI to?
Your PI is only accessible to our staff members who need it as part of their duties.
We may disclose your PI to partners or service providers for the purposes described above, or to public authorities when required by law. Here are the third parties to whom we may disclose your PI:
- To our business partners and service providers, such as technological solutions providers, and advertising and public relations agencies, to help us operate the site and offer, manage and promote our products;
- To the authorities, in order to comply with our obligations under any law or regulation, search, subpoena or court order, another court, or an administrative or government authority;
- To a regulator (Privacy Control Authority) and to all individuals authorized by law to obtain such personal information.
8. How do we store your PI and for how long?
Your PI is typically stored on our servers in Canada. However, it is possible that sharing PI with certain technology solution providers may result in this information being transferred to the United States. In such case, we make sure that adequate security measures are implemented, and we manage such transfers of PI by way of contracts.
We store your PI for as long as necessary for the purposes for which it was collected, and for the applicable statutory retention periods, which may at times justify longer retention periods. The destruction or, in cases where a serious purpose gives rise to it, the anonymization of personal data is carried out in a secure manner.
9. How do we protect your PI?
We implement security measures that are proportionate to the sensitivity of your PI, and that allow us to protect them from loss or theft, and from unauthorized access, disclosure, copying, modification or destruction, in accordance with applicable law. Here are the security measures implemented by Sanimax:
- Administrative measures such as the implementation of a framework for protecting our information assets, including your PI, based on the international standard ISO 27002, the ongoing audit of the evolution of security threats to your PI, and the continuous deployment of training and awareness activities on PI protection for our employees;
- Physical measures such as the restricted access to our premises, and the implementation of passwords or two-factor authentication mechanisms for accessing our computer equipment, systems and internet networks;
- Technical measures such as the restricted access to your PI on a need-to-know basis, that is to say limiting the access to your PI to only those who need it to perform their duties, the implementation of alerts in case of suspicious events, and the secure encryption of communications.
Even if we deploy a number of security measures to adequately protect your PI and reduce the risk of a privacy breach to a minimum level, there is always a risk, and we are unable to fully guarantee that your PI will not be subject to a privacy breach. If you have reason to believe that your PI has been compromised, please contact the person in charge of the protection of personal information (Privacy Officer – see below for contact information).
10. What are your rights with respect to your PI?
We respect the rights granted to the persons concerned with regards to their PI, and we follow the procedures to process requests from the persons concerned to exercise their rights, including requests for the access, rectification, and portability of their PI, and for the withdrawal of their consent. Requests from persons concerned to exercise their rights must be sent to the person in charge of the protection of personal information (Privacy Officer – see below for contact information), so they can be processed in accordance with the law.
We will respond to all PI access and rectification requests within 30 days of receipt of such a request. When we are unable to respond within this 30-day period, or if additional time is required to meet a request, the person concerned will be notified in writing.
11. What happens if you have a question or complaint about your PI?
Any questions regarding your PI or any complaints arising from non-compliance with the principles set out in this Notice should be directed to the person in charge of the protection of PI (Privacy Officer – see below for contact information).
12. Person in charge of the protection of personal information (Privacy Officer)
The Privacy Officer function has been assigned to:
Name: Isabelle Savard
Address: 9900 Maurice-Duplessis Blvd., Montréal, Québec, H1C 1G1
Email: loi25@sanimax.com
Phone number: 514-648-6001
13. Can this Notice be changed, and if so, will you be informed?
The content of this Notice can be amended from time to time. If that happens, a notice will be posted on our websites and in our communication tools.
14. Effective date and review of this Notice
This Notice comes into effect on February 12, 2024. Sanimax will review this Notice at least every three years or earlier to reflect changes in applicable laws and regulations, technological developments, and Sanimax practices.