Personal Information Protection Policy

Version 1.0 – in force since 2026-05-01. Reviewed every two years or as needed. This English text is a courtesy translation; the French version prevails.

Privacy Officer

In accordance with the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), Modelage Simon Inc. has designated a person in charge of the protection of personal information. Address any access, correction, consent-withdrawal request or complaint to that person.

  • The President, Privacy Officer
  • Email: confidentialite@modelagesimon.com
  • Telephone: 819-346-8903
  • Address: 1014, rue Deschaillons, Sherbrooke (Québec) Canada, J1G 1X7

We answer requests within a maximum of 30 days of receipt.

1. Context and governance

Modelage Simon Inc. ("Modelage Simon") is subject to the Act respecting the protection of personal information in the private sector , to the Act to modernize legislative provisions as regards the protection of personal information (Law 25) and to the Act to establish a legal framework for information technology .

Policy objectives

  • Ensure compliance with applicable personal information protection legislation;
  • Protect the rights of employees, clients and partners;
  • Embed personal information protection good practices into operations;
  • Prevent the risk of data breaches.

Scope

  • The company is accountable for the personal information it holds.
  • A privacy officer is appointed and their contact information is published.
  • Applicable laws are complied with.
  • Suitable technological tools protect the confidentiality of data.
  • Data protection risks are documented and managed.
  • Staff receive training so they clearly understand their responsibilities.

Roles and responsibilities

The main stakeholders in the company's information security and their respective responsibilities for the protection of personal information are described below.

President

  • Is ultimately accountable for compliance with this policy;
  • Must formally designate a privacy officer;
  • Must provide the necessary resources, ensure suitably skilled people are in place, and promote awareness of personal information protection and of this policy.

Privacy Officer

  • Ensures the company protects the privacy rights of its employees and clients;
  • Manages the confidentiality incident management process;
  • Ensures every confidentiality incident is entered in a register;
  • Reports any data breach or accidental exposure of personal information to the Commission d'accès à l'information (CAI) and to the individuals concerned;
  • Ensures a risk management process is in place;
  • Approves policies and processes and their internal and external communication;
  • Ensures a privacy impact assessment (PIA / EFVP) process is in place;
  • Ensures reasonable processes and technological measures are in place, proportionate to the sensitivity of the information;
  • Ensures employees are trained and made aware of the laws and of personal information protection;
  • Oversees compliance with obligations for handling access requests and complaints.

All employees

  • Comply with personal information protection policies and procedures;
  • Take active part in Law 25 training and information security awareness programs;
  • Report any confidentiality incident without delay.

2. Guiding principles

  • The purposes of data collection must be clear from the outset.
  • Individuals are informed and give their consent, unless the law provides otherwise.
  • Only necessary data is collected, honestly and transparently.
  • Data is used only for the stated purposes and kept only as long as necessary.
  • Data must be accurate, complete and up to date.
  • Data security must match the sensitivity of the data.
  • Data management policies are publicly available.
  • Anyone may access their data, request its correction or challenge its accuracy, within the limits of the law.
  • Complaints may be addressed to the privacy officer.
  • Every initiative involving personal data is subject to a privacy risk assessment.

3. Consent and data processing

  • Consent must be free, informed and specific, and expressed in plain language;
  • Personal information is processed fairly, transparently and only for the declared purposes;
  • Only authorized staff have access to the data;
  • Data is kept only as long as necessary, in accordance with the law;
  • Privacy protection is built into projects and systems by design;
  • A personal data retention schedule is kept up to date.

4. Personal information handled by third parties

  • A list of third parties and data-related services is kept up to date;
  • Agreements set out the roles and responsibilities of each party;
  • A privacy and security risk assessment is performed before any new collaboration;
  • Data processing and backup locations are known and documented;
  • Risks tied to the countries or jurisdictions involved are assessed before any outsourcing.

5. Transfers of data outside Québec

  • The company takes measures to limit transfers of personal data outside Québec;
  • Where a transfer is necessary, all applicable legal requirements are met, including performing a privacy impact assessment (PIA / EFVP).

Transfers made by our websites are listed in the annex.

6. Handling access requests and complaints

Rights of individuals

  • Be informed of how their data is used;
  • Access their data and obtain a copy of it;
  • Request the correction, deletion or erasure of their data;
  • Decline certain services (e.g. automated decisions, mass mailings);
  • Give consent before any sharing with third parties (except where the law provides otherwise).

Company commitments

  • Clearly inform individuals about the use of their data;
  • Process requests, unless a refusal is justified by law;
  • Keep a register of requests and complaints.

How to exercise your rights

Write to confidentialite@modelagesimon.com and describe your request. If the officer's answer does not satisfy you, or if you receive no answer within 30 days, you may file an application for review with the Commission d'accès à l'information du Québec .

7. Incident management

  • The company has a clear, documented process for handling incidents;
  • A confidentiality incident register is kept up to date and made available to the CAI on request;
  • Any breach is reported in accordance with legal requirements as soon as it is discovered;
  • Corrective measures are applied promptly;
  • Every incident is analyzed to assess the risk of injury and determine whether notification is required.

8. Employee training

A training program on cybersecurity risks, including personal information protection, is in place and reviewed annually.

9. Breaches of this policy and sanctions

Compliance with this policy is mandatory for all Modelage Simon employees, suppliers and subcontractors.

Anyone in breach of this policy may face disciplinary measures up to and including dismissal or termination of contract.

10. Exceptions

The company may disclose personal information without consent in certain cases provided for by law, in particular:

  • To the competent authorities;
  • In an emergency threatening the life, health or safety of a person;
  • In exceptional circumstances provided for by law;
  • Where required to provide an essential service to the person concerned.

11. Review

This policy is reviewed every two years or as needed, in particular following legal, contractual or organizational changes.


Annex – Information collected by our websites

This annex explains how the policy applies to modelagesimon.com (public website) and to upload.modelagesimon.com (file transfer portal).

A. What we collect and why

Information Site Purpose Retention
Name, email and message sent through the contact form Public website Answer your request As long as needed to follow up
Username, email, company, password (hashed) Transfer portal Create and secure your account Until the account is closed
Transferred files, along with sender, recipient and timestamp Transfer portal Deliver the file to the intended recipient 90 days after upload, then deleted automatically
IP address and technical server logs Both sites Security, incident detection, troubleshooting Rolling logs, 12 months at most
Traffic statistics (Google Analytics) Public website, with your consent only Measure page traffic Per Google Analytics settings (26 months at most)
IP address and browser type (Google Maps) Public website, with your consent only Display the map on the Contact page For as long as the map is shown, per Google

We do not sell or rent your personal information. We do not profile you and we make no fully automated decisions about you.

B. Cookies and tracking technologies

By default, only the cookies required to operate the sites are set. Google Analytics and Google Maps are optional, off by default, and enabled only if you accept them separately in the banner, or, for the map, by clicking "Show the map" on the Contact page.

Cookie Role Category
ASP.NET_SessionId Keep your session while you browse Required
.AspNet.ApplicationCookie Keep you signed in on the transfer portal Required
__RequestVerificationToken Protect forms against request forgery Required
_culture Remember the display language you chose Required
ms_consent Remember your choices about Google Analytics and Google Maps (12 months) Required
_ga, _gid Google Analytics – tell visitors apart, IP address anonymized Audience measurement, on consent

You can change or withdraw each of these choices at any time by clicking "Cookies" at the bottom of any page. Withdrawing Analytics consent also erases the measurement cookies already set. Withdrawing Maps consent stops the map from loading automatically.

C. Suppliers and transfers outside Québec

Some services needed to run the sites are provided by third parties. Transfers outside Québec are covered by a privacy impact assessment and by contractual protection commitments, in accordance with section 17 of the Act.

Supplier Role Information disclosed Processing location
Website and database host Host the applications, the transferred files and the logs Accounts, files, technical logs Canada / United States
Mailgun (Sinch) Deliver transactional email (account, file upload notices) Email address, email content United States
Google Analytics Measure traffic, on consent only Anonymized IP address, pages viewed United States
Google Maps Display the map on the Contact page, after consent (banner or click) IP address, browser type United States

On the Contact page, the Google map loads only if you already accepted it in the banner, or if you click "Show the map" (that click is then consent for the map only). Until you consent, no data is sent to Google.

D. Security

  • The sites are served over HTTPS only and authentication cookies are encrypted.
  • Passwords are stored as hashes, never in clear text.
  • Repeated sign-in attempts temporarily lock the account.
  • Access to transferred files is limited to the designated sender and recipient.
  • Files are deleted automatically 90 days after upload.

E. Document history

Date Version Change description Approval
2026-05-01 1.0 Policy introduced. The President

CONTACT US


Send Us A Message:

modsimon@ModelageSimon.com


Call Us:

819-346-8903


Visit Us:

1014, rue Deschaillons

Sherbrooke (Québec) Canada

J1G 1X7