PRIVACY POLICY
Last update : December 01, 2023
1. General Information
1.1 Introduction
Protecting your privacy is important to Marcil Lavallée (hereinafter the “Company“, “we“, “us“, “our“). For this reason, we have implemented safeguards and sound management practices regarding your Personal Information in accordance with applicable laws.
This Privacy Policy (the “Policy“), which should be read in conjunction with the website’s Terms of Use and Services agreements entered with the Company, describes our practices with respect to the collection, use, processing, disclosure and retention of Personal Information of our clients, visitors and users.
By using our website Home – Marcil Lavallée (marcil-lavallee.ca) (the “website“) or any of our Services, you agree that we may collect, use, process, disclose and retain your Personal Information in accordance with the terms and conditions described herein. If you do not agree to comply with and to be bound by this Policy, you may not visit, access, or use our website or Services or share your Personal Information with us.
This Policy does not apply to Personal Information of the Company’s employees, representatives and consultants, or any other person affiliated with the Company, or to any information that does not constitute Personal Information as defined by the applicable law.
1.2 Privacy Officer
Questions, comments and complaints regarding the Company’s Privacy Policy and Practices may be addressed to our Privacy Officer at the following contact information:
E-mail address: protection@mlcpa.ca
Address:
400 – 1420 Blair Place
Ottawa, Ontario
K1J 9L8
Canada
2. Definitions
The following words and expressions, when they appear with an initial capital letter in the Policy, have the meanings attributed to them hereinafter, unless otherwise implied or explicit in the text:
“Service Provider“: any natural or legal person who processes data on behalf of the Company. These are third-party organizations or individuals employed by the Company to facilitate the Services, provide the Services on behalf of the Company, perform services related to the Services or assist the Company in analyzing the use of the Services.
“Personal information“: any information that relates to a natural person and allows that person to be identified, i.e., that directly or indirectly reveals something about the identity, characteristics (e.g., abilities, preferences, psychological tendencies, predispositions, mental abilities, character and behaviour of the person concerned) or activities of that person, regardless of the nature of the medium or the form in which the information is accessible (written, graphic, sound, visual, computerized or other).
“Sensitive Personal Information“: means Personal Information which, by its nature or the context in which it is used or communicated, gives rise to a high reasonable expectation of privacy. It may include, for example, medical, biometric, genetic, or financial information, or information about a person’s life orsexual orientation, religious or philosophical beliefs, trade-union membership, or ethnic origin.
“Privacy Officer“: the person who is responsible for the application of this Policy and whose contact information is identified in Section 1.2 of this Policy.
“Services“: refers to the website and all related services offered by the Company, which include professional services and, where applicable, associated media, printed materials and “online” or electronic documentation.
3. Personal Data Processing
3.1 Collection of Personal Information
Your Consent to Share Your Personal Information With Us
Your privacy and the confidentiality of your data are important to us. That is why we have developed this Privacy Policy to tell you what information we collect, how we handle it, and when we need to share it with subcontractors or third parties.
With your consent, you authorize the Company to collect and process your Personal Information that is necessary to provide you with our services. Please note that you always retain control of your Personal Information, and that the consent you give us to collect or process your Personal Information may be withdrawn at any time. We will respect your choice in accordance with our legal obligations.
Please read this Policy in conjunction with our Terms of Use document.
During our activities, we may collect, process and use the various types of Personal Information you give us only as permitted by law, including the information listed below:
In carrying out the mandates you entrust to us:
- professional or employment-related information, such as your resume, place of employment, government titles or positions, employers, companies owned, salary or self-employment income, criminal history information and other information you provide to us when you apply for a job with the Company;
- contact information, such as your first and last name, e-mail address, telephone number, address and company numbers for the creation of a client account;
- financial and tax information, including your income and other details of your personal finances;
- information about products or services, such as information about the services we have provided to you;
- information provided as part of our assurance, tax, consulting and bookkeeping services;
- transaction and payment information, such as the payment method used, the date and time, the payment amount, the billing postal code, your address and other related information;
- information you choose to provide or transmit to us, for example, when you fill out a form, • respond to a survey or communicate with one of our employees or representatives.
Through our website:
- contact information, such as your first and last name and e-mail address, to enable you to communicate with us;
- contact information, such as your first and last name, e-mail address and résumé, to enable you to apply for a position with us;
- information automatically collected during use of the website and our Services, including :
- connection and other information about your activities on the website, such as your IP address, the pages you have visited, the time and date of your visits, the type of browser you use, the operating system of your device and other hardware and software information;
- geolocation data, such as your IP address, a precise or approximate location determined from your IP address or the GPS of your mobile device (depending on your device’s settings).
In each case, such personal information is processed in accordance with the legitimate and necessary purposes listed in Section 3.2 below. In addition, we ensure that we only collect and process data and Personal Information that is necessary for the purposes for which you provide it to us. In the event of any subsequent use of your Personal Information, we will notify you as required by law.
3.2 Use of Personal Information
As stated in Section 3.1, we only use your Personal Information to the extent permitted by law. We may use your Personal Information for the legitimate purposes described below:
- provide our Services;
- allow you to subscribe to our newsletter and bulletins;
- verify your identity and review your personal history, as permitted by law;
- operate, maintain, supervise, develop, improve and offer all functionalities of our website; • manage risk and operations;
- comply with our obligations under applicable laws and regulations;
- develop new Services and improve our website and Services;
- for marketing and business development purposes, if you have previously consented to the processing of your Personal Information for these purposes;
- send you messages, updates and security alerts;
- answer your questions and provide assistance as needed;
- administer a contest, promotion, survey or other feature of the website or our Services; • collect opinions and comments regarding our Services;
- carry out research and analysis related to our company and Services;
- detect and prevent fraud, errors, spam, abuse, security incidents and other harmful activities; • establish, exercise or defend a right or legal claim;
- share communications with you in accordance with the law;
- enable you to apply for a position within the Company;
- any other purpose permitted or required by law.
The Personal Information we collect is stored securely on our internal and external servers located in Canada. Rest assured that Personal Information is disclosed only when we are legally required to do so.
3.3 Disclosure of Personal Information
We may share your Personal Information with our employees, contractors, consultants, agents, Service Providers and other trusted third parties who need to know that information to help us operate our website, to conduct and protect our business, or to serve you.
In addition, our internal Privacy Policy limits access to those members of our Company personnel who may have a need to access and process your Personal Information.
We do not sell, trade, or otherwise disclose your Personal Information to third parties, subject to exceptions provided by law.
3.3.1 Service Providers and Other Third Parties
Although we try to avoid disclosing your Personal Information to third parties, we may use Service Providers to perform various services on our behalf, such as IT management and security, marketing, and data analysis, hosting, and storage.
Here are the types of Service Providers for which such sharing can take place:
- Business management system;
- Marketing services;
- Work tools to allow us to provide our professional services;
- Secure document exchange portal
When we share your Personal Information with Service Providers, we take reasonable steps to ensure that the rules set out in this Policy are respected. We provide them with only the Personal Information they need to carry out their mandate. These Service Providers are required to use Personal Information in accordance with our instructions and only for the purposes for which it was provided. In addition, we ensure that such Service Providers take sufficient measures to implement adequate safeguards that are proportionate to the sensitivity of the Personal Information being processed or disclosed.
3.3.2 Complying with Legislation, Responding to Legal Requests, Preventing Harm and Protecting our Rights
We may disclose your Personal Information when we believe such disclosure is authorized, necessary or appropriate, including:
- to respond to requests from public and government authorities, including those outside of your country of residence;
- to protect our business;
- to comply with legal proceedings;
- to protect our rights, our privacy, our safety, our property, yours or that of third parties; • to enable us to pursue available remedies or limit the damages we may suffer; and • in accordance with applicable laws, including laws outside your country of residence.
3.3.3 Commercial Transaction
We may share, transfer, or disclose, strictly in accordance with this Policy, your Personal Information in the event of a sale, transfer, or assignment, in whole or in part, of the Company or our assets (for example, as a result of a merger, consolidation, change of control, reorganization, bankruptcy, liquidation or other business transaction, including in connection with the negotiation of such transactions). In such a case, we will inform you before your Personal Information is transferred and is governed by another privacy policy.
3.3.4 Personal Information Consent
Wherever possible, the Company obtains consent directly from the individual concerned by the collection, use and disclosure, by us, of his, her or their Personal Information. However, if you provide us with Personal Information about other persons, you must ensure that you have duly notified them that you are providing us with their information, in addition to obtaining their consent to such disclosure.
We will seek your consent before using or disclosing your Personal Information for purposes other than those set out herein.
3.3.5 Retention of Personal Information
Subject to applicable laws, we retain your Personal Information only for as long as is necessary to fulfill the purposes for which it was collected, unless you consent to your Personal Information being used or processed for another purpose. In addition, our retention periods may be modified from time to time in response to legitimate interests (for example, to ensure the security of Personal Information, to prevent abuse and breaches or to prosecute criminals).
3.4 Sensitive Personal Information
During our activities, we collect Personal Information considered to be of a sensitive nature, when it is necessary for our operations. In such cases, we ensure that we have your express consent to do so, in accordance with the law.
4. Your Rights
As a data subject, you may exercise the rights set out below by completing the form available on request and sending it by e-mail or by mail to the attention of our Privacy Officer at the contact details given in Section 1.2 of the Policy:
- You have the right to access the Personal Information we hold about you and to request a copy of the documents containing your Personal Information, subject to the exceptions provided by applicable law;
- You have the right to have the Personal Information we hold about you rectified, amended and updated if it is incomplete, ambiguous, out of date or inaccurate;
You have the right to request the destruction of some or all of your Personal Information, to the extent permitted by applicable law;
- You have the right to withdraw or change your consent to the Company’s collection, use, disclosure or retention of your Personal Information at any time, subject to applicable legal and contractual restrictions;
- You have the right to ask us to stop disseminating your Personal Information and to de-index any link attached to your name that gives accessto thisinformation if such dissemination contravenes the law or a court order;
- You have the right to file a complaint with the Commission d’accès à l’information, or any competent authority dependent upon the province, subject to the conditions set forth in the applicable law.
To process your request, you may be asked to provide appropriate identification or to identify yourself in some other way.
We encourage our clients to keep their Personal Information with us up to date. Decisions regarding the various services we can offer our clients may vary depending on the accuracy of this data. It is therefore essential to ensure that we have an accurate picture of your situation.
5. Cookies and Other Tracking Technologies
We use cookies and similar technologies (collectively, “Cookies”) to help us operate, protect, and optimize the website and Services we offer. Cookies are small text files that are stored on your device or browser. They enable us to collect certain information when you visit the website, including your preferred language, browser type and version, the type of device you are using and your device’s unique identifier. While some of the Cookies we use are deleted after your browser session ends, other Cookies are retained on your device or browser to enable us to recognize your browser the next time you visit the website. The data collected via these cookies is not intended to identify you. More specifically, they are used to ensure that the website functions properly and to improve users’ browsing experience. They provide certain data that enables us to better understand the traffic and interactions that take place on our website, as well as to detect certain types of fraud. Cookies do not damage your device and cannot be used to extract Personal Information.
You can set your browser to notify you when Cookies are set on your visit to the website, so that you can decide whether to accept some or all Cookies. Please note that deactivating Cookies on your browser may impair your browsing experience on the website and prevent you from using some of its features.
6. Safety Measures
The Company has implemented physical, technological, and organizational security measures to adequately protect the confidentiality and security of your personal information against loss, theft or any unauthorized access, disclosure, reproduction, communication, use or modification. These measures include encryption, access control, segregation of duties, internal auditing, etc.
Among the various measures put in place:
- Our website uses Secure Sockets Layer (SSL) technology to ensure a secure connection between your device and our server;
- The Company’s employees have read this Policy and are committed to complying with it and to respecting the confidentiality of Personal Information concerning our potential and existing clients. In addition, each employee undertakes to follow and respect a data governance policy applicable to all Company personnel;
- As mentioned in Section 3.3, we have put in place measures to restrict access to Personal Information to persons who may have a valid reason to consult, process, communicate or otherwise use your information;
- As mentioned in Section 3.3, subcontractors and third parties who do business with the Company and with whom we may need to communicate your Personal Information have provided us with satisfactory assurance of their commitment to protecting the confidentiality and privacy of such information.
Despite the measures described above, we cannot guarantee the absolute security of your Personal Information.
7. Changes to this Privacy Policy
We reserve the right to modify this Policy at any time in accordance with applicable law. In the event of a change, we will publish the revised version of the Privacy Policy and update the date in the footer of the Policy. An alert on the website will indicate that a change to the Policy has been published. We therefore encourage you to consult our Privacy Policy when you visit the website to obtain timely notice of the updated Policy.
If you do not agree to the new terms of the Privacy Policy, please do not continue to use our website and Services. If you choose to continue using our website or Services after the new version of our Policy becomes effective, your use of our website and Services will be governed by the new version of the Policy.
8. Links to Third-Party Websites
From time to time, we may include on our website references or links to websites, products or services provided by third parties (“Third-Party Services”). These Third-Party Services, which are not operated or controlled by the Company, are governed by privacy policies entirely separate from and independent of our own. We therefore assume no responsibility for the content and activities of these sites. This Policy applies only to the website and Services we offer. This Policy does not extend to third-party Services.
9. Limitation of Liability
The Company undertakes to take all reasonable steps to ensure the confidentiality and security of Personal Information in accordance with technological standards appropriate to its business sector.
Notwithstanding the foregoing, you declare that you understand and acknowledge that no computer system offers absolute security and that there is always some degree of risk involved in transmitting Personal Information over the public network that is the Internet.
You hereby agree that the Company shall not be held liable for any breach of confidentiality, hacking, virus, loss, theft, misuse, or alteration of Personal Information transmitted or hosted on its systems or on those of a third party. You also waive any claim in this regard, except in the case of gross negligence or willful misconduct on the part of the Company. Accordingly, you agree to indemnify and hold harmless the Company and its officers, directors, affiliates, and business partners from and against any and all damages of any kind, whether direct or indirect, incidental, special or consequential, arising out of or in connection with the use of your Personal Information.
In the event of a breach of confidentiality or security of your Personal Information that presents a high risk to your rights and freedom, you will be notified of such breach as soon as possible, and the Company will take the necessary steps to preserve the confidentiality and security of your Personal Information.
10. Individuals Under 14 Years of Age
During our activities, we collect and use Personal Information from persons under the age of 14. To collect and process such data lawfully, we obtain the consent of the minor’s parent or legal guardian before proceeding with such data collection and use. If you are under 14, you must not provide us with your Personal Information without the consent of your parent or guardian. If you are a parent or guardian and become aware that your child has provided us with Personal Information without your consent, please contact us to request the deletion of that child’s Personal Information from our systems.
11. Contact Us
Any questions, comments, requests, or concerns regarding this Privacy Policy should be directed to our Privacy Officer at the contact information provided in Section 1.2 of this Policy.