Personal Information Protection Policy
Privacy Officer
In accordance with the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), Modelage Simon Inc. has designated a person in charge of the protection of personal information. Address any access, correction, consent-withdrawal request or complaint to that person.
- The President, Privacy Officer
- Email: confidentialite@modelagesimon.com
- Telephone: 819-346-8903
- Address: 1014, rue Deschaillons, Sherbrooke (Québec) Canada, J1G 1X7
We answer requests within a maximum of 30 days of receipt.
1. Context and governance
Modelage Simon Inc. ("Modelage Simon") is subject to the Act respecting the protection of personal information in the private sector , to the Act to modernize legislative provisions as regards the protection of personal information (Law 25) and to the Act to establish a legal framework for information technology .
Policy objectives
- Ensure compliance with applicable personal information protection legislation;
- Protect the rights of employees, clients and partners;
- Embed personal information protection good practices into operations;
- Prevent the risk of data breaches.
Scope
- The company is accountable for the personal information it holds.
- A privacy officer is appointed and their contact information is published.
- Applicable laws are complied with.
- Suitable technological tools protect the confidentiality of data.
- Data protection risks are documented and managed.
- Staff receive training so they clearly understand their responsibilities.
Roles and responsibilities
The main stakeholders in the company's information security and their respective responsibilities for the protection of personal information are described below.
President
- Is ultimately accountable for compliance with this policy;
- Must formally designate a privacy officer;
- Must provide the necessary resources, ensure suitably skilled people are in place, and promote awareness of personal information protection and of this policy.
Privacy Officer
- Ensures the company protects the privacy rights of its employees and clients;
- Manages the confidentiality incident management process;
- Ensures every confidentiality incident is entered in a register;
- Reports any data breach or accidental exposure of personal information to the Commission d'accès à l'information (CAI) and to the individuals concerned;
- Ensures a risk management process is in place;
- Approves policies and processes and their internal and external communication;
- Ensures a privacy impact assessment (PIA / EFVP) process is in place;
- Ensures reasonable processes and technological measures are in place, proportionate to the sensitivity of the information;
- Ensures employees are trained and made aware of the laws and of personal information protection;
- Oversees compliance with obligations for handling access requests and complaints.
All employees
- Comply with personal information protection policies and procedures;
- Take active part in Law 25 training and information security awareness programs;
- Report any confidentiality incident without delay.
2. Guiding principles
- The purposes of data collection must be clear from the outset.
- Individuals are informed and give their consent, unless the law provides otherwise.
- Only necessary data is collected, honestly and transparently.
- Data is used only for the stated purposes and kept only as long as necessary.
- Data must be accurate, complete and up to date.
- Data security must match the sensitivity of the data.
- Data management policies are publicly available.
- Anyone may access their data, request its correction or challenge its accuracy, within the limits of the law.
- Complaints may be addressed to the privacy officer.
- Every initiative involving personal data is subject to a privacy risk assessment.
3. Consent and data processing
- Consent must be free, informed and specific, and expressed in plain language;
- Personal information is processed fairly, transparently and only for the declared purposes;
- Only authorized staff have access to the data;
- Data is kept only as long as necessary, in accordance with the law;
- Privacy protection is built into projects and systems by design;
- A personal data retention schedule is kept up to date.
4. Personal information handled by third parties
- A list of third parties and data-related services is kept up to date;
- Agreements set out the roles and responsibilities of each party;
- A privacy and security risk assessment is performed before any new collaboration;
- Data processing and backup locations are known and documented;
- Risks tied to the countries or jurisdictions involved are assessed before any outsourcing.
5. Transfers of data outside Québec
- The company takes measures to limit transfers of personal data outside Québec;
- Where a transfer is necessary, all applicable legal requirements are met, including performing a privacy impact assessment (PIA / EFVP).
Transfers made by this portal are listed in the annex.
6. Handling access requests and complaints
Rights of individuals
- Be informed of how their data is used;
- Access their data and obtain a copy of it;
- Request the correction, deletion or erasure of their data;
- Decline certain services (e.g. automated decisions, mass mailings);
- Give consent before any sharing with third parties (except where the law provides otherwise).
Company commitments
- Clearly inform individuals about the use of their data;
- Process requests, unless a refusal is justified by law;
- Keep a register of requests and complaints.
How to exercise your rights
Write to confidentialite@modelagesimon.com and describe your request. If the officer's answer does not satisfy you, or if you receive no answer within 30 days, you may file an application for review with the Commission d'accès à l'information du Québec .
7. Incident management
- The company has a clear, documented process for handling incidents;
- A confidentiality incident register is kept up to date and made available to the CAI on request;
- Any breach is reported in accordance with legal requirements as soon as it is discovered;
- Corrective measures are applied promptly;
- Every incident is analyzed to assess the risk of injury and determine whether notification is required.
8. Employee training
A training program on cybersecurity risks, including personal information protection, is in place and reviewed annually.
9. Breaches of this policy and sanctions
Compliance with this policy is mandatory for all Modelage Simon employees, suppliers and subcontractors.
Anyone in breach of this policy may face disciplinary measures up to and including dismissal or termination of contract.
10. Exceptions
The company may disclose personal information without consent in certain cases provided for by law, in particular:
- To the competent authorities;
- In an emergency threatening the life, health or safety of a person;
- In exceptional circumstances provided for by law;
- Where required to provide an essential service to the person concerned.
11. Review
This policy is reviewed every two years or as needed, in particular following legal, contractual or organizational changes.
Annex – Information collected by this portal
This annex explains how the policy applies to upload.modelagesimon.com (file transfer portal). The public website modelagesimon.com publishes its own policy, including optional services that are not used here.
A. What we collect and why
| Information | Purpose | Retention |
|---|---|---|
| Username, email, company, password (hashed) | Create and secure your account | Until the account is closed |
| Transferred files, along with sender, recipient and timestamp | Deliver the file to the intended recipient | 90 days after upload, then deleted automatically |
| IP address and technical server logs | Security, incident detection, troubleshooting | Rolling logs, 12 months at most |
We do not sell or rent your personal information. We do not profile you and we make no fully automated decisions about you. This portal uses neither audience measurement nor a third-party map.
B. Cookies and tracking technologies
This portal sets only the cookies required to operate. No audience-measurement, advertising or map cookies are used.
| Cookie | Role | Category |
|---|---|---|
ASP.NET_SessionId |
Keep your session while you browse | Required |
.AspNet.ApplicationCookie |
Keep you signed in on the transfer portal | Required |
__RequestVerificationToken |
Protect forms against request forgery | Required |
_culture |
Remember the display language you chose | Required |
ms_consent |
Remember that you have read the cookie notice (12 months) | Required |
You can read this notice again at any time by clicking "Cookies" at the bottom of any page.
C. Suppliers and transfers outside Québec
Some services needed to run the portal are provided by third parties. Transfers outside Québec are covered by a privacy impact assessment and by contractual protection commitments, in accordance with section 17 of the Act.
| Supplier | Role | Information disclosed | Processing location |
|---|---|---|---|
| Portal and database host | Host the application, the transferred files and the logs | Accounts, files, technical logs | Canada / United States |
| Mailgun (Sinch) | Deliver transactional email (account, file upload notices) | Email address, email content | United States |
D. Security
- The sites are served over HTTPS only and authentication cookies are encrypted.
- Passwords are stored as hashes, never in clear text.
- Repeated sign-in attempts temporarily lock the account.
- Access to transferred files is limited to the designated sender and recipient.
- Files are deleted automatically 90 days after upload.
E. Document history
| Date | Version | Change description | Approval |
|---|---|---|---|
| 2026-05-01 | 1.0 | Policy introduced. | The President |