PIPEDA sets out ground rules for how organizations can collect, use or disclose personal information in the course of commercial activities. It balances an individual’s right to privacy with the need of organizations to collect, use or discloses personal information for legitimate business purposes.
VEXSL, is accountable for the protection of all personal information within the association’s possession or control, including any personal information that has been transferred to a third party for regulatory, legal or processing purposes. VEXSL, will require a comparable level of protection of this information from its third party.
Any concern or issue about VEXSL, ’s personal information handling practices may be made, in writing, to our Privacy Officer. Upon verification of the individual’s identity, the Privacy Officer will act promptly to investigate the complaint and provide a written report to the individual. If the individual is dissatisfied with the report provided by the Privacy Officer or feels that the corrective action taken by VEXSL, is insufficient, the individual may direct a complaint to the Federal Privacy Commissioner in writing.
WHAT IS PERSONAL INFORMATION?
Under PIPEDA, personal information means any information that is identifiable to an individual, including name, home address, home telephone number, social insurance number, and date of birth. It also includes, but is not limited to, other information relating to identity, such as, nationality, gender, marital status, financial information and credit history.
USE AND PURPOSES FOR COLLECTING PERSONAL INFORMATION
The purposes will be limited to those which are related to our business and which a reasonable person would consider are appropriate in the circumstances. We collect, use, and disclose Personal Information concerning our customers for the following reasons:
· To provide timely, reliable and value-added services to customers including domestic and international shipping, shipment tracking, customs brokerage, account management and billing, global logistics, supply chain management, information management and technical support, e-commerce, and related services;
· To issue Bills of Lading, Proof of Delivery, invoices, collect billed amounts or purpose of court proceedings in accordance with the Act.
· To assist in law enforcement purposes, to collect unpaid debts, for credit reporting and rating purposes, and to protect the business interests of VEXSL and its customers;
· To process your account credentials, passwords, communicate offers, and updates to our services and other information, if you have signed up to access to our websites; for example, your email and password will be used to authenticate you in order for you to make changes to your profile;
· To meet requirements imposed by law.
· To resolve disputes, mitigate or attempt to prevent fraud, investigate privacy and security incidents; for example, during a privacy breach investigation, incident details may be shared with the Privacy Commissioner as part of our breach reporting due diligence program;
· To investigate safety and security incidents; for example, we may use video surveillance to investigate incidents occurring on or near our premises; this may be disclosed to law enforcement in accordance with PIPEDA requirements;
· Using identification information and contact information, such as your name, address, telephone number and e-mail address so that we can identify you and deliver the services that you request and to communicate with you regarding those services;
· To establish a customer relationship and to communicate with customers;
· To develop, implement, market, and manage services for customers;
· To manage and promote the business activities of VEXSL.
We collect, use, and disclose Personal Information concerning our employees for the following reasons:
To recruit, train, recognize, and retain a highly qualified and motivated workforce;
To establish and maintain harmonious employer-employee relations;
To administer VEXSL policies and procedures, including investigations related thereto;
To manage and promote the business activities of VEXSL;
To administer compensation and benefits;
To develop, manage, and promote employee services; and
To meet requirements imposed by law.
If we plan to use Personal Information we have collected for a purpose not previously identified, we will identify and document this purpose before such use.
We will make a reasonable effort to specify the identified purposes, orally or in writing, to the individual from whom the Personal Information is collected either at the time of collection or after collection but before use. We will state the identified purposes in such a manner that an individual can reasonably understand how the information will be used or disclosed.
We require the knowledge and consent of our members, customers, and employees for the collection, use or disclosure of their personal information, except where inappropriate. In certain circumstances we can collect, use or disclose personal information without the knowledge and consent of the individual. For example:
· Where legally authorized or required by law to do so without consent;
· When it is clearly in the best interest of the individual and consent cannot be obtained in a timely way, such as when the individual is seriously ill;
· An emergency where the life, health or security of an individual is threatened;
· Employee personal information if it is reasonable for the purposes of establishing, managing or terminating an employment relationship between VEXSL, and the individual; and,
· To a third party to collect a debt, comply with a subpoena, warrant or other court order.
VEXSL will get consent to use and disclose personal information at the same time it collects the information.
Members, customers or employees can consent orally, in writing or electronically and their consent may be implied or express depending on the nature and sensitivity of the personal information.
Members, customers or employees are considered to have given implied consent when the purpose for collecting, using or disclosing personal information is considered obvious and they have voluntarily provided the personal information for that obvious purpose.
Consent can be withdrawn at any time subject to legal or contractual restrictions and reasonable notice.
VEXSL will limit the type and amount of personal information it collects to that which is necessary for the business.
We will not collect, use or disclose personal information except for the identified purposes unless we have received further consent from you. VEXSL will collect personal information fairly, openly and lawfully in accordance with PIPEDA.
LIMITING USE, DISCLOSURE AND RETENTION
Personal Information which has been used to make a decision about an individual will be retained long enough to allow the individual access to the information after the decision has been made and, in the event of an access request or a challenge, long enough to exhaust any recourse an individual may have under the law. Where Personal Information is no longer required to fulfil the identified purposes, it will be destroyed, erased, or made anonymous.
We will use our best efforts to ensure that Personal Information that is used on an ongoing basis, including information that is disclosed to third parties, and information that is used to make a decision about an individual, is accurate, complete, and up-to-date. Personal information contained in closed files is not updated.
Our safeguards will protect Personal Information against loss or theft, as well as unauthorized access, disclosure, copying, use or modification, regardless of the format in which the information is held. We will make our employees aware of the importance of maintaining the confidentiality of Personal Information, and we will exercise care in the disposal or destruction of Personal Information to prevent unauthorized parties from gaining access to the information.
Our methods of protection will include:
· Physical – active files are stored in locked filing cabinets located in restricted work areas to VEXSL, employees and authorized volunteers. Closed files are stored in locked cabinets for a period of three years, after which, the information is shredded prior to disposal.
· Organizational – VEXSL, employees, volunteers, and third-party service providers sign confidentiality agreements binding them to safeguarding the confidentiality of personal information to which they have access.
· Technological – personal information contained on VEXSL, computers and the electronic database is encrypted and access of information is on a “need-to-know” basis. The Internet server or router has firewall protection to protect against virus attacks and hacking into the database.
· Electronic Transmission of Information – notwithstanding the technological safeguards implemented by VEXSL, all Internet transmissions are susceptible to possible loss, misrouting, interception and misuse. For this reason, as part of the application that member’s sign consenting to their personal information being collected, used, retained and disclosed, VEXSL, will assume that it has the individual’s consent to communicate via the Internet unless notified to the contrary.
VEXSL will make available to members, customers and employees’ specific information about its policies and practice s relating to the management of personal information. In addition, our Privacy Officer will answer any questions about our policies and procedures in the management of personal information that is under our control.
We will respond to an individual’s written request within a reasonable time (generally within 30 days). We will assist any individual who informs us that they need assistance in preparing a request. We may require an individual to provide sufficient information to permit us to provide an account of the existence, use, and disclosure of Personal Information. While our response will typically be provided at no cost to the individual, depending on the nature of the request and the amount of information involved, we reserve the right to impose a cost. In these circumstances, we will inform the individual of the approximate cost to provide the response and proceed upon payment by the individual of the cost. Requested information will be provided or made available in a form that is generally understandable. Where possible, we will indicate the source of the information.
In providing an account of third parties to which we may have disclosed Personal Information about an individual, we will attempt to be as specific as possible. When it is not possible to provide a list of the organizations to which we have actually disclosed Personal Information, we will provide a list of organizations to which we may have disclosed the information.
If an individual successfully demonstrates the inaccuracy or incompleteness of Personal Information, we will amend the information as required. If a challenge is not resolved to the satisfaction of the individual, we will record the substance of the unresolved challenge. Where appropriate the amended information or the existence of the unresolved challenge, as the case may be, will be transmitted to third parties having access to the information in question.
In certain situations, we may refuse a request or not be able to provide access to all the Personal Information we hold about an individual. Exceptions to the access requirement will be limited and specific, as permitted or required by law. Where permitted, the reasons for denying access will be provided to the individual upon request. Exceptions may include: information that contains references to other individuals or contains confidential commercial information, where such information cannot be severed from the record; information collected in the course of investigating a breach of an agreement or in the course of a formal dispute resolution process; and information that is subject to solicitor-client privilege.
We will investigate all written complaints. If we find a complaint to be justified, we will take all appropriate measures, including, if necessary, amending our policies and practices. If you feel at any time that we are not complying with the principles set out in the Act, please contact our Privacy Officer.
Members are notified that the information they share on community websites, including e-mail addresses, will be available to all persons accessing the community site, and that such information may be read, collected or used by others for any purpose, including sending members’ unsolicited messages. Members are informed that VEXSL is not responsible for any information they elect to submit to community sites, or the use of such information.
USE OF THE WEBSITE
A technology called cookies could be used, now or in the future, on certain pages of our website or at the websites that any links will visit. A cookie is a tiny element of data that a website can send to your browser, which may be stored on your hard drive so the website can recognize your return. Cookies allow companies to provide tailored or targeted information and services to you via the Internet. You can disable cookies by turning them off in your browser; however, some areas of the site may not function properly if you do so. (See the documentation provided with your Internet browser for more information on cookies and how to disable them.)
Our websites could contain links to third party websites. These linked sites are not under our Company’s control and we are not responsible for the privacy practices or the contents of any such linked site, or any link contained in any linked site. We provide such links only as a convenience, and the inclusion of a link on our website does not imply endorsement of the linked site by our Company. You should familiarize yourself with the privacy policies and practices of any such third parties.
AMENDMENTS OF OUR POLICY
CONTACTING OR COMMUNICATING WITH US
• Have any questions with respect to our privacy policies or practices;
• Have any questions with respect to our handling of your personal information;
• Wish to request access to or correction of your personal information under our care or control; or
• Are dissatisfied with our handling of your personal information or any response we may have given,
You can contact our Privacy Officer at:
Attention: Privacy Officer