SEM.TECHNOLOGY
PRIVACY GOVERNANCE POLICY
PREAMBLE
SEM.TECHNOLOGY (hereinafter “SEM.TECHNOLOGY” or the “Company”) is committed to protecting the privacy and confidentiality of personal information entrusted to it by its customers, employees, suppliers, business partners and other individuals.
This Privacy Governance Policy (the “Policy”) establishes the rules and procedures governing the collection, use, disclosure, retention, security, destruction and management of personal information held by SEM.TECHNOLOGY.
This Policy is adopted in accordance with the Act respecting the Protection of Personal Information in the Private Sector, CQLR, c. P-39.1 (the “Private Sector Act”), as amended from time to time, as well as applicable regulations and requirements of the Commission d’accès à l’information du Québec (the “CAI”).
The Policy applies throughout the entire life cycle of personal information and establishes the responsibilities of individuals who have access to or process such information on behalf of SEM.TECHNOLOGY.
- OBJECTIVES
The objectives of this Policy are to:
- establish a clear governance framework for the protection of personal information;
- ensure compliance with applicable privacy legislation;
- protect the rights of individuals with respect to their personal information;
- establish rules governing the collection, use, disclosure, retention and destruction of personal information;
- establish appropriate security measures;
- define procedures for managing confidentiality incidents;
- establish a process for receiving and handling privacy complaints;
- define the roles and responsibilities of personnel and service providers;
- promote privacy awareness and training within the organization; and
- ensure that personal information is handled in a manner that is appropriate to the purposes for which it is collected.
- LEGAL AND REGULATORY FRAMEWORK
SEM.TECHNOLOGY’s privacy practices are governed, where applicable, by:
- the Act respecting the Protection of Personal Information in the Private Sector, CQLR, c. P-39.1;
- the Civil Code of Québec;
- applicable regulations adopted under privacy legislation;
- applicable decisions, guidelines and publications issued by the Commission d’accès à l’information du Québec; and
- any other applicable legislation governing the protection of personal information.
This Policy must be interpreted consistently with applicable mandatory legal requirements. Where a provision of this Policy conflicts with a mandatory legal requirement, the applicable legal requirement prevails.
- DEFINITIONS
For the purposes of this Policy:
Commission d’accès à l’information (“CAI”)
The Commission d’accès à l’information du Québec, the independent administrative body responsible, among other things, for overseeing the application of Québec privacy legislation.
Life Cycle
The various stages through which personal information passes, including:
- collection;
- use;
- disclosure;
- retention;
- access and modification; and
- destruction or anonymization.
Privacy Impact Assessment (“PIA” / “EFVP”)
An assessment intended to identify and evaluate privacy risks associated with the collection, use, disclosure, retention or other processing of personal information.
Confidentiality Incident
Any unauthorized access, use, disclosure of personal information, or loss or other form of breach involving personal information.
Act
The Act respecting the Protection of Personal Information in the Private Sector, CQLR, c. P-39.1.
Individual / Data Subject
Any individual whose personal information is held or processed by SEM.TECHNOLOGY.
Personal Information
Any information about an individual that directly or indirectly allows the individual to be identified, as defined by applicable legislation.
Sensitive Personal Information
Personal information that, due to its nature, particularly medical, biometric or otherwise highly private or sensitive nature, carries a higher degree of sensitivity.
Privacy Officer
The individual designated by SEM.TECHNOLOGY to exercise the responsibilities relating to the protection of personal information.
- SCOPE OF APPLICATION
This Policy applies to:
- all personal information held by SEM.TECHNOLOGY;
- all activities involving the collection, use, disclosure, retention or destruction of personal information;
- all employees, officers, directors, contractors, consultants and other individuals acting on behalf of SEM.TECHNOLOGY who have access to personal information;
- information maintained in paper, electronic, digital, cloud-based or other formats; and
- service providers, suppliers and subcontractors to the extent that they process personal information on behalf of SEM.TECHNOLOGY.
Where a service provider processes personal information on behalf of SEM.TECHNOLOGY, contractual arrangements and appropriate safeguards must be implemented where required by law.
- PROCESSING OF PERSONAL INFORMATION
SEM.TECHNOLOGY applies the following principles throughout the life cycle of personal information:
5.1 Necessity
Only personal information that is necessary for a legitimate and identified purpose may be collected, subject to applicable legal exceptions.
5.2 Purpose Limitation
Personal information must only be used for the purposes for which it was collected, unless another use is authorized by law or by the individual where consent is required.
5.3 Lawful Disclosure
Personal information may only be disclosed where the disclosure is authorized by the individual or permitted or required by applicable legislation.
5.4 Access Limitation
Access to personal information must be limited to individuals who require access to perform their duties or who are otherwise legally authorized to access the information.
5.5 Retention
Personal information must only be retained for as long as necessary to fulfill the purposes for which it was collected or to comply with legal, contractual or other applicable requirements.
5.6 Security
Reasonable security safeguards appropriate to the sensitivity of the information must be implemented.
5.7 Destruction or Anonymization
When personal information is no longer required, it must be securely destroyed or, where appropriate and permitted by applicable legislation, anonymized.
- COLLECTION AND USE OF PERSONAL INFORMATION
6.1 Collection
SEM.TECHNOLOGY collects personal information only when permitted or required by law and, where applicable, after providing the individual with the required information regarding:
- the purposes for which the information is being collected;
- the means by which the information is collected;
- the individual’s rights;
- the categories of individuals or organizations to whom the information may be disclosed;
- the retention period, where required; and
- the contact information of the person responsible for privacy matters.
6.2 Consent
Where consent is required, it must be obtained in accordance with applicable legislation.
Consent must be meaningful and, where required, specific, informed and expressed clearly.
The mere use of SEM.TECHNOLOGY’s website does not automatically constitute consent to every possible use or disclosure of personal information.
6.3 Collection from Third Parties
Where personal information is obtained from a third party, SEM.TECHNOLOGY must ensure that the collection is authorized by applicable law and that any required consent or other legal basis is obtained.
6.4 Secondary Use
Personal information must not be used for purposes unrelated to the original purpose of collection unless the use is authorized by law or appropriate consent has been obtained.
6.5 Internal Access
Employees and other authorized individuals may only access personal information that is necessary for the performance of their responsibilities.
- DISCLOSURE OF PERSONAL INFORMATION
SEM.TECHNOLOGY may disclose personal information:
- with the individual’s consent, where consent is required;
- where the disclosure is authorized or required by law;
- to service providers and subcontractors where necessary to provide services and where appropriate safeguards are in place;
- where disclosure is necessary for legitimate business operations and permitted by applicable legislation; or
- in any other circumstance authorized by applicable law.
7.1 Service Providers and Subcontractors
Where a third party processes personal information on behalf of SEM.TECHNOLOGY, appropriate contractual and organizational measures must be implemented to protect the information.
7.2 Disclosure Outside Québec
Where personal information is communicated outside Québec, SEM.TECHNOLOGY must comply with applicable legal requirements, including conducting a privacy impact assessment where required and implementing appropriate contractual or other safeguards.
Where required by law, SEM.TECHNOLOGY must ensure that the information receives adequate protection in the jurisdiction to which it is communicated.
- RETENTION, DESTRUCTION AND ANONYMIZATION
8.1 Retention
SEM.TECHNOLOGY maintains personal information only for the period necessary to fulfill the purposes for which it was collected or to satisfy applicable legal, contractual or operational requirements.
Retention periods may vary depending on:
- the nature of the information;
- the purpose for which it was collected;
- contractual requirements;
- legal obligations; and
- operational requirements.
8.2 Destruction
Personal information that is no longer required must be securely destroyed in a manner appropriate to the medium and sensitivity of the information.
Destruction methods may include:
- secure deletion of electronic files;
- physical destruction of paper records;
- shredding;
- secure disposal of storage media; and
- other methods providing reasonable assurance that the information cannot be reconstructed.
8.3 Anonymization
Where appropriate and permitted by law, information may be anonymized so that it is no longer reasonably possible to identify the individual.
Anonymization must not be treated as automatically achieved simply by removing names or direct identifiers. Appropriate techniques must be used to reduce the risk of re-identification.
- ACCESS TO AND RECTIFICATION OF PERSONAL INFORMATION
Individuals may request access to personal information concerning them, subject to applicable legal restrictions and exceptions.
Individuals may also request the correction of inaccurate, incomplete or outdated personal information.
Requests must be submitted to the Privacy Officer using the contact information provided in this Policy.
SEM.TECHNOLOGY will process requests within the time periods prescribed by applicable legislation.
Where access or correction is refused, SEM.TECHNOLOGY will provide the individual with the reasons for the refusal where required by law.
- RIGHTS OF INDIVIDUALS
Subject to applicable legislation, individuals may have the right to:
- know whether SEM.TECHNOLOGY holds personal information concerning them;
- access their personal information;
- request correction of inaccurate or incomplete information;
- withdraw consent where consent is the legal basis for processing and withdrawal is legally available;
- request information concerning the handling of their personal information;
- exercise other rights provided under applicable privacy legislation; and
- file a complaint with the Commission d’accès à l’information where appropriate.
Privacy Officer
Alexandre Boucher
Privacy Officer
SEM.TECHNOLOGY
Email: [email protected]
Website: https://SEM.technology
- PRIVACY COMPLAINTS
Any individual who believes that their personal information has been handled inappropriately may submit a complaint to SEM.TECHNOLOGY.
Complaints must be submitted to the Privacy Officer.
The complaint should, where possible, include:
- the complainant’s name and contact information;
- a description of the issue;
- the relevant dates;
- the personal information involved, where known; and
- any supporting documentation.
SEM.TECHNOLOGY will review complaints in a confidential and impartial manner.
The organization will document the complaint, investigate the circumstances and communicate the outcome to the complainant within the timeframe required by applicable legislation.
Individuals may also contact the Commission d’accès à l’information where permitted by law.
- SECURITY OF PERSONAL INFORMATION
SEM.TECHNOLOGY implements reasonable security measures appropriate to the sensitivity of personal information.
Security measures may include:
Administrative Measures
- privacy policies and procedures;
- confidentiality obligations;
- employee awareness and training;
- access management;
- incident response procedures; and
- periodic review of privacy practices.
Technological Measures
- password protection;
- authentication mechanisms;
- access controls;
- encryption where appropriate;
- backups;
- security monitoring;
- software and system updates; and
- protection of electronic storage environments.
Physical Measures
- controlled access to premises;
- secure storage of physical records;
- appropriate disposal procedures; and
- measures designed to prevent unauthorized access to paper records or equipment.
Security measures must be reviewed periodically and adapted to changes in technology, risks and business operations.
- CONFIDENTIALITY INCIDENTS
A confidentiality incident includes any unauthorized:
- access to personal information;
- use of personal information;
- disclosure of personal information;
- loss of personal information; or
- other breach affecting the confidentiality of personal information.
13.1 Reporting an Incident
Any individual who becomes aware of a suspected confidentiality incident must report it promptly to the Privacy Officer or another designated individual.
13.2 Assessment
SEM.TECHNOLOGY will assess the incident and determine, among other things:
- the nature of the information involved;
- the number of individuals affected;
- the circumstances of the incident;
- the likelihood that the information may be used for harmful purposes; and
- the seriousness of any potential harm.
13.3 Measures
Depending on the circumstances, SEM.TECHNOLOGY may:
- contain the incident;
- secure affected systems;
- recover or protect information;
- notify affected individuals where required;
- notify the Commission d’accès à l’information where required;
- take corrective measures; and
- document the incident and measures taken.
13.4 Incident Register
SEM.TECHNOLOGY maintains a register of confidentiality incidents in accordance with applicable legal requirements.
The register must contain the information required by applicable legislation and be retained for the prescribed period.
The incident register is maintained in accordance with Appendix 6 of this Policy.
- ROLES AND RESPONSIBILITIES
14.1 Privacy Officer
The Privacy Officer is responsible for overseeing the application of this Policy and coordinating the organization’s privacy governance activities.
The Privacy Officer may:
- implement and maintain the Policy;
- respond to access and correction requests;
- receive and investigate privacy complaints;
- coordinate privacy impact assessments;
- oversee confidentiality incident management;
- provide privacy guidance to personnel;
- coordinate privacy training;
- review contracts involving personal information;
- monitor regulatory developments; and
- maintain required records and documentation.
14.2 Management
Management is responsible for supporting the implementation of appropriate privacy practices and ensuring that personnel comply with this Policy.
14.3 Employees and Contractors
Employees, contractors and other authorized individuals must:
- comply with this Policy;
- protect confidential information;
- only access information necessary for their responsibilities;
- report suspected privacy incidents;
- follow applicable security procedures; and
- participate in required privacy training.
14.4 Service Providers
Service providers and subcontractors that process personal information must comply with applicable contractual obligations and privacy requirements.
- TRAINING AND AWARENESS
SEM.TECHNOLOGY promotes privacy awareness among personnel who have access to personal information.
Training and awareness activities may address:
- privacy principles;
- confidentiality obligations;
- secure handling of personal information;
- access controls;
- incident reporting;
- phishing and cybersecurity risks;
- retention and destruction requirements; and
- applicable organizational policies and procedures.
Training must be provided when appropriate and may be updated following legislative, technological or operational changes.
- SANCTIONS
Failure to comply with this Policy may result in appropriate administrative or disciplinary measures, subject to applicable employment, contractual and legal requirements.
Depending on the circumstances, measures may include:
- additional training;
- restriction or removal of access privileges;
- corrective measures;
- disciplinary action; or
- termination of employment or contract where legally permitted.
Where conduct may constitute a violation of law, SEM.TECHNOLOGY may take any action permitted or required by applicable legislation.
- POLICY REVIEW AND UPDATES
This Policy must be reviewed periodically and updated when necessary to reflect:
- legislative or regulatory changes;
- changes to SEM.TECHNOLOGY’s business activities;
- changes in technology;
- changes in privacy risks;
- changes to internal processes; or
- lessons learned from privacy incidents or complaints.
The most recent version of the Policy must be made available to individuals where required by law.
APPENDIX 1
PRIVACY POLICY FOR THE COLLECTION OF PERSONAL INFORMATION BY TECHNOLOGICAL MEANS
SEM.TECHNOLOGY is committed to protecting personal information collected through its website, digital platforms, forms, applications and other technological means.
When collecting personal information through technological means, SEM.TECHNOLOGY will provide the information required by applicable privacy legislation, including, where applicable:
- the purposes of the collection;
- the categories of personal information collected;
- the means of collection;
- the individual’s rights;
- the contact information of the Privacy Officer;
- the categories of third parties who may receive the information;
- information concerning retention where required; and
- information concerning technological mechanisms used to collect information.
Where applicable, the privacy policy may also address:
- cookies;
- analytics technologies;
- tracking technologies;
- online forms;
- advertising platforms;
- CRM systems;
- communication platforms; and
- other technological services involving personal information.
Individuals may contact SEM.TECHNOLOGY’s Privacy Officer for additional information.
APPENDIX 2
DIGITIZATION PROCEDURE
Where paper documents containing personal information are digitized, SEM.TECHNOLOGY must take reasonable measures to ensure the integrity, confidentiality and accessibility of the resulting electronic records.
The digitization process should include:
- identification of the documents to be digitized;
- preparation and organization of the documents;
- scanning;
- verification of image quality and completeness;
- verification that the electronic version corresponds to the original;
- secure storage of the electronic version;
- documentation of the digitization process; and
- destruction of the original paper document where legally and operationally appropriate.
Where originals are destroyed, SEM.TECHNOLOGY must use an appropriate secure destruction method.
APPENDIX 3
PERMANENT DOCUMENT DESTRUCTION TECHNIQUES
| Medium | Recommended destruction method |
| Paper documents | Cross-cut shredding or secure destruction |
| Electronic files | Secure deletion |
| Hard drives | Secure wiping or physical destruction |
| USB drives | Secure wiping or physical destruction |
| Optical media | Physical destruction |
| Backup media | Secure deletion or destruction |
| Other storage media | Method appropriate to the medium and sensitivity of the information |
The selected destruction method must provide reasonable assurance that the personal information cannot be reconstructed or recovered.
APPENDIX 4
DIGITIZATION REGISTER
The digitization register should include, where applicable:
| Information | Description |
| Date | Date of digitization |
| Document type | Description of the document |
| Department | Responsible department |
| Person responsible | Individual performing or supervising digitization |
| Storage location | Electronic storage location |
| Verification | Confirmation that digitization was verified |
| Original disposition | Information concerning the original document |
| Comments | Additional relevant information |
The register must be maintained securely and retained for the period determined by applicable requirements.
APPENDIX 5
PROCEDURE FOR HANDLING PRIVACY COMPLAINTS
Step 1 — Receipt
A complaint is received by the Privacy Officer.
Step 2 — Registration
The complaint is documented and assigned a reference number where appropriate.
Step 3 — Preliminary Review
The Privacy Officer determines:
- the nature of the complaint;
- the information involved;
- the relevant individuals and systems;
- whether additional information is required; and
- whether immediate protective measures are necessary.
Step 4 — Investigation
The Privacy Officer reviews the relevant facts, documents, systems and procedures.
Where necessary, additional personnel or external experts may be consulted.
Step 5 — Decision
The Privacy Officer determines whether corrective or preventive measures are required.
Step 6 — Communication
The complainant is informed of the outcome within the timeframe required by applicable legislation.
Step 7 — Corrective Measures
Where appropriate, SEM.TECHNOLOGY may implement:
- procedural changes;
- additional security measures;
- employee training;
- access modifications;
- corrections to personal information; or
- other appropriate measures.
Step 8 — Record Retention
Documentation concerning the complaint and its resolution is retained in accordance with applicable retention requirements.
APPENDIX 6
CONFIDENTIALITY INCIDENT REGISTER
The confidentiality incident register should contain, where applicable:
- date and time of the incident;
- date and time the incident was discovered;
- description of the incident;
- nature of the personal information involved;
- number or categories of individuals affected;
- circumstances surrounding the incident;
- assessment of the risk of serious harm;
- measures taken to reduce the risk;
- measures taken to prevent recurrence;
- notifications made to affected individuals;
- notifications made to regulatory authorities;
- date of closure; and
- any other information required by applicable legislation.
The register must be maintained securely and retained for the period prescribed by applicable law.