PROPELIA SECURITY AND PRIVACY POLICY
1. Introduction
Propelia Solutions (“Propelia”, “we”, “us”,
or “our”) is committed to protecting the personal information of
visitors to our website at www.firebrick-buffalo-322294.hostingersite.com (the “Site”) and of
the clients, prospects, and partners we work with in the course of our
strategy, growth & acquisition, and business transfer advisory services.
This Security and Privacy Policy explains what personal
information we collect, why we collect it, how we protect it, and the rights
available to you under Québec’s Act respecting the protection of personal
information in the private sector, as amended by Law 25, and the federal Personal
Information Protection and Electronic Documents Act (PIPEDA) where
applicable.
By using the Site or providing us with your information,
you acknowledge that it will be handled as described in this Policy.
2. Who We Are — Privacy Officer
Propelia Solutions is established in Québec, Canada, and
is the organization responsible for the personal information described in this
Policy.
In accordance with Law 25, we have designated a person
responsible for the protection of personal information:
|
Privacy Officer |
Michel Vincent, President |
|
Email |
privacy@firebrick-buffalo-322294.hostingersite.com |
|
Mailing address |
301, Seigneurial Blvd. East, St-Bruno,
Quebec, J3V 2J3 |
|
Phone |
514-296-2894 |
If you have
questions, concerns, or requests regarding your personal information, please
contact our Privacy Officer using the details above.
3. Personal Information We Collect
Depending on how you interact with us, we may collect:
•
Contact and identification
information — name, email address, phone number,
company name, job title, mailing address (e.g., when you submit a contact form
or request a consultation).
•
Business information — details you voluntarily share about your company, financials, or
transaction objectives when engaging us for advisory services (strategy, growth
& acquisition, or business sale/transfer mandates).
•
Communications — records of correspondence, meeting notes, and inquiries you send
us.
•
Technical and usage
information — IP address, browser type, device
information, pages visited, referring URLs, and approximate location, collected
automatically through cookies and similar technologies (see Section 6).
•
Newsletter/marketing
information — if you subscribe to updates, your
email address and engagement data (opens, clicks).
We do not knowingly
collect sensitive categories of information (e.g., biometric or health data)
through the Site.
4. Why We Collect and Use Your Information
We collect and use personal information only for
purposes that are reasonable and identified at or before the time of
collection, including to:
•
Respond to inquiries and
provide requested information about our services;
•
Deliver our consulting,
growth/acquisition, and business transfer advisory services under an engagement
with you;
•
Manage our business
relationship, including invoicing and record-keeping;
•
Operate, secure, and improve
the Site;
•
Send communications you have
consented to receive (e.g., a newsletter), which you may opt out of at any
time;
•
Comply with legal, accounting,
and regulatory obligations.
We do not sell personal
information to third parties.
5. Consent
Except where otherwise permitted or required by law, we
collect, use, or disclose your personal information only with your consent.
Consent may be express (e.g., checking a box to subscribe) or implied by
context (e.g., providing your email to receive a reply to your inquiry).
Where we ask for consent to a new purpose not previously
identified, we will seek your consent separately before proceeding. You may withdraw
your consent at any time, subject to legal or contractual restrictions, by
contacting our Privacy Officer. Withdrawing consent may limit our ability to
provide certain services.
6. Cookies and Similar Technologies
The Site uses cookies and similar technologies (such as
those provided through our hosting and security provider, Cloudflare) to:
•
Ensure the Site functions
correctly and securely;
•
Distinguish returning visitors
and remember preferences;
•
Measure and analyze traffic and
usage (e.g., via analytics tools);
On your first visit, you
will be presented with a cookie banner allowing you to accept, refuse, or
customize non-essential cookies. You can also manage or delete cookies at any
time through your browser settings. Essential/strictly necessary cookies (required
for security and basic Site functionality) cannot be disabled without affecting
Site performance.
7. How We Protect Your Information
We maintain administrative, organizational, and
technical security measures appropriate to the sensitivity of the information
we hold, including:
•
Encryption in transit — the Site is served over HTTPS/TLS, and our hosting and security
provider, Cloudflare, Inc., provides web application firewall (WAF) protection,
DDoS mitigation, and encrypted traffic routing across its global network.
•
Access controls — personal information is accessible only to personnel and service
providers who need it to perform their duties, on a need-to-know basis.
•
Vendor due diligence — third-party service providers who process personal information on
our behalf are bound by contractual confidentiality and security obligations
consistent with Law 25.
•
Monitoring — we monitor the Site for security vulnerabilities and unauthorized
access attempts.
•
Retention limits — see Section 9.
No method of transmission
or storage is 100% secure. While we take reasonable steps to protect your
information, we cannot guarantee absolute security.
8. Third-Party Service Providers and Cross-Border Transfers
We rely on third-party service providers to operate the
Site and our business, including:
•
Cloudflare, Inc. — content delivery network, DNS, security, and performance services
for the Site.
Some of these providers, including Cloudflare, operate
infrastructure located outside Québec and Canada (including in the United
States). As required by Law 25, before transferring personal information
outside Québec we assess — through a privacy impact assessment — whether the
information will receive protection equivalent to that provided under Québec
law, and we require our service providers to commit contractually to
safeguarding the information accordingly.
We do not otherwise disclose your personal information
to third parties except: with your consent, to comply with a legal obligation,
or in connection with a potential business transaction (e.g., a sale or
transfer involving Propelia), in which case we take reasonable steps to protect
the information involved.
9. Data Retention
We retain personal information only for as long as
necessary to fulfill the purposes described in this Policy, or as required by
law, contract, or professional/accounting obligations (which may require
retention for several years after the end of an engagement). When information
is no longer needed, we securely destroy, delete, or anonymize it.
10. Your Privacy Rights
Under Law 25, subject to certain exceptions, you have
the right to:
•
Access the personal information we hold about you;
•
Rectify inaccurate, incomplete, or outdated information;
•
Withdraw consent to the collection, use, or disclosure of your information (where
consent was the basis for processing);
•
Request deletion or
de-indexing of your personal information in certain
circumstances;
•
Data portability — request that computerized personal information you provided be
transferred to you or to a third party, in a structured, commonly used
technical format, where technically feasible;
•
Be informed of, and object to,
any decision based exclusively on automated processing of your personal
information that has legal or similarly significant effects on you, and to
request that such a decision be reviewed by a member of our personnel. (We
do not currently use automated decision-making of this kind on the Site.)
To exercise any of these
rights, contact our Privacy Officer (Section 2). We will respond within the
timelines required by law. We may need to verify your identity before actioning
a request.
If you are not satisfied with our response, you may file
a complaint with Québec’s Commission d’accès à l’information (CAI) at
www.cai.gouv.qc.ca.
11. Confidentiality Incidents (Data Breaches)
In the event of a “confidentiality incident” (a breach
involving personal information) that presents a risk of serious injury to
affected individuals, we will:
•
Take reasonable steps to reduce
the risk of harm and prevent further incidents;
•
Notify the CAI and affected
individuals, without unreasonable delay, as required by law;
•
Maintain a register of
confidentiality incidents in accordance with Law 25.
12. Children’s Privacy
The Site is intended for business audiences and is not
directed at children. We do not knowingly collect personal information from
individuals under the age of 14 without verifiable parental or guardian
consent, as required under Québec law.
13. Changes to This Policy
We may update this Policy from time to time to reflect
changes in our practices or legal requirements. The “Last updated” date at the
top of this page indicates when it was last revised. Material changes will be
posted on the Site.
14. Contact Us
Questions about this Policy or how we handle your
personal information can be directed to:
Propelia
Solutions Inc.
Attn: Privacy
Officer
301, Seigneurial Blvd. East
St-Bruno, Qc
J3V 2J3
514-296-2894
You may also contact Québec’s Commission d’accès à
l’information at www.cai.gouv.qc.ca or 1-888-528-7741.