Privacy policy
Héroux-Devtek Personal Information Privacy Policy
Our commitment to personal information protection
Héroux-Devtek Inc. and other companies of the Héroux-Devtek group (collectively, “Héroux-Devtek” or “we”) are responsible for protecting the personal information they hold, whether it is retained by them or entrusted to a third party, and regardless of the format of the documents (written, graphical, audio, visual, computerized or other). As such, Héroux-Devtek will take appropriate security measures to protect this information in a manner commensurate with its level of sensitivity and will adopt this Privacy and Personal Information Protection Policy (the “Policy”).
Scope of application
The Policy applies to all personal information concerning individuals (“you”), including users and visitors of the Website, as well as Héroux-Devtek’s clients, partners, agents and employees.
Consent
BY VISITING, USING OR OTHERWISE CONTACTING US THROUGH HÉROUX-DEVTEK’S WEBSITE, YOU AGREE TO BE BOUND BY THIS POLICY AND CONSENT TO THE COLLECTION, USE, RETENTION, DISCLOSURE AND DESTRUCTION OF YOUR PERSONAL INFORMATION IN ACCORDANCE WITH THE TERMS AND CONDITIONS DESCRIBED HEREIN OR BEFORE OR AT THE TIME OF ITS COLLECTION, USE OR DISCLOSURE, AS APPLICABLE.
YOU UNDERSTAND THAT CERTAIN FEATURES OF OUR WEBSITE WILL NO LONGER BE ACCESSIBLE OR WILL BE LIMITED IF YOU REFUSE OR WITHDRAW YOUR CONSENT TO BE BOUND BY THE POLICY.
If you do not want your personal information collected, used or disclosed in this way, you can:
- Choose not to provide them to us;
- Exercise the refusal option set out below or proposed at the time of collection;
- Refuse the proposed consent procedure at the time of collection.
Only personal information that is necessary to achieve a specific and defined objective related to our mission can be collected, even if the individual consents to other objectives. Consent is expressly given for specific purposes with regard to sensitive information.
Purpose of the policy
Personal information is information about you that can directly or indirectly identify you. Examples of such information include your name, address, email address and telephone number. The purpose of this Policy is to protect any personal information obtained by Héroux-Devtek and its representatives in the course of their work or by third parties.
Personal information collection
We do not automatically collect personal information from Website visitors other than through cookies. The information collected may be of a different nature, be it information about employees, agents, partners or Website users and visitors. This information may be used for tax or financial purposes, to identify an individual, and so on.
We only collect personal information online if you voluntarily provide it to us, usually by contacting us by email. This information includes, but is not limited to:
- First and last names
- Date of birth
- Mailing address
- Telephone number: home, mobile and office
- Email address, IP addresses
- Employee banking information
- Social Insurance Number, as required
- IP address used to connect your computer to the Internet
- User name
- Email address
- Information about your system and connections
- Full URL path to, via and from our Website, including date and time of connection and your number of cookies.
You are not required to provide personal information to view the content of our Website. In addition, information you share in public areas of the Website may be viewed and used by other users. We encourage you to exercise good judgment when doing so.
Communication to third parties
Any disclosure of personal information to a third party generally requires the consent of the individuals involved.
At its discretion, Héroux-Devtek may disclose personal information it collects to third parties when necessary for the performance of warrants or contracts, or under the terms and conditions set out by law. Any disclosure of personal information without the consent of the individuals involved must be specifically approved by Héroux-Devtek’s Privacy Officer. Héroux-Devtek can share your personal information with the following parties:
- Business partners and third parties to provide services to you (including software developers and providers of data processing, document management and administrative services);
- A financial institution, confidentially and only in the context of assigning a right to receive or make a payment;
- One or more third parties, when the person concerned consents to this disclosure, or if authorized by law or necessary for its application (e.g., insurance provider, legal counsel).
When personal information is disclosed under a mandate or a service or business contract, Héroux-Devtek ensures that the following conditions are met:
- The mandate or contract is written;
- The mandate or contract includes a confidentiality clause that indicates the measures to be taken to protect the confidentiality of personal information, to ensure that they are used only in the performance of the mandate or contract, and not retained after their expiration;
- Supplier employees who will have access to any personal information from Héroux-Devtek must have signed a confidentiality agreement with that supplier;
- The supplier undertakes to notify Héroux-Devtek of any breach or attempted breach of its confidentiality obligations and to allow Héroux-Devtek to perform any audit related to this confidentiality.
Collection purposes
We only collect personal information that is necessary for a specific purpose prior to collection.
With respect to information collected on job applicants and employees, information is collected to:
- Offer the job and manage the person in the course of their employment;
- Conduct a criminal record check in accordance with applicable laws;
- Process payroll and related statutory reporting (T4-R1, pension plan, group benefits, RRSP).
With respect to information collected about Website visitors, information is collected to:
- Better meet their needs;
- Ensure compliance with applicable industrial security regulations;
- Facilitate navigation on the Website.
Vendor information is collected to:
- Pay invoices;
- Fulfill other contractual obligations;
- Conduct audits (in some cases).
Cookies
The Website may use cookies to learn about users’ viewing habits. A cookie is a small data file that some websites put on your computer’s hard drive when you view them. It can only contain the information you provide. It cannot read your hard drive data or cookie files created by other sites. Héroux-Devtek does not link this information to individual user data, nor does it disclose or sell it to third parties. We only use cookies to personalize the experience of those who visit the Website.
If you prefer not to receive cookies from the Website, you can set your browser settings so that you are notified before accepting cookies and you may refuse them. You can also configure your browser to refuse all cookies. However, this may restrict your access to some sections of the Website.
We may use software that receives and records the Internet protocol (IP) address of the computer that contacted Héroux-Devtek’s Website. We do not intend to link these addresses to the identity of individuals accessing the Website.
If you have submitted your personal information to us and wish to withdraw your consent to its retention, use or disclosure, please send an email to our Privacy Officer using the contact information listed in section 16 below. You may withdraw your consent at any time upon reasonable notice and subject to any legal or contractual restrictions that may apply. If you withdraw your consent, we may no longer be able to provide you with certain products or services.
Personal information protection governance safeguards, policies and practices
Information security is a priority for Héroux-Devtek. Consequently, we have adopted policies and practices that govern how we manage personal information. These include the following:
- The framework for their use, disclosure, retention and destruction;
- The roles and responsibilities of our employees throughout the life cycle of this information;
- Policies to manage privacy incidents;
- A retention schedule for this information;
- A process for handling complaints about their protection.
We also use physical, organizational and technological safeguards to protect your personal information from theft and loss, as well as unauthorized access, use, disclosure and destruction.
These physical and material security measures include:
- Controlled-access desks and locked cabinets;
- Classification of this information to facilitate its retrieval;
- Access to your personal information limited to a select group of individuals;
- Written contractual obligations with third parties who need access to your personal information, requiring them to protect, through security measures, its confidentiality and security and to use it only for the purposes of the contract, mandate or service they carry out.
Computer security measures include:
- The use of passwords;
- Restricted access to our data processing and storage rooms;
- A regular review of our safety practices;
- Regular updates to our technology.
These security measures are also subject to internal training and awareness initiatives.
Personal information retention
Personal or sensitive information is securely destroyed when the purpose for which it was collected is fulfilled or anonymized for serious and legitimate purposes.
Accuracy of the information we hold
Héroux-Devtek ensures that the personal or sensitive information it collects and holds is kept up to date, accurate and complete. This includes recording the dates on which the information was last corrected, modified, completed or deleted.
Access and rectification rights
Any person concerned by personal information may have access to it free of charge, within the limits provided by law. They may request a copy for a reasonable fee, of which they are previously informed.
They may also request the correction of personal information that is inaccurate, incomplete, ambiguous or not authorized by law.
In order to exercise these access and rectification rights, the person concerned must submit their request in writing and justify their identity as a person concerned. The request should be addressed to the Privacy Officer and sent by email or mail using the contact information in section 16 of this Policy.
Withdrawal of consent
You may change or withdraw your consent to the collection, use and disclosure of your personal information at any time by submitting a written notice to the Privacy Officer.
Policy amendment
Your use of the Website and any litigation arising from it are subject to this Policy and governed by our Terms of Use, including the clause pertaining to the choice of the applicable law. We reserve the right to amend the Policy and update it in a diligent and timely manner. We encourage you to refer to our Policy regularly to see what changes we may have made. If any change affects prior consent, we will send out a notice to all the persons concerned.
Privacy impact assessment (PIA)
Héroux-Devtek conducts a PIA of the persons concerned, in particular before undertaking any acquisition, development and redesign project related to its computer system that impacts personal information, and before disclosing personal information to an individual or organization outside the province.
Privacy and complaint management officer contact information
If you have any concerns about this Policy, the security of your personal information or our compliance with applicable privacy legislation, please provide us with a brief written explanation of these concerns.
Any individual from whom personal information is collected, used, disclosed or retained by Héroux-Devtek may file a complaint with the Privacy Officer in the event of a breach of any obligation under the Policy. The complaint must indicate the nature of the alleged facts, the name of the person(s) involved, the date on which the incident occurred, and expectations of the outcome of the complaint.
The Privacy Officer acknowledges receipt of any complaint and processes it within 30 days. While they diligently provide a written response to the person who submitted the complaint, they are not required to disclose the outcome of the investigation. They respond diligently to all other requests.
Privacy Officer,
Jean-Philippe Sanche, Vice-President, Legal Affairs,
Héroux-Devtek
1111 Saint-Charles West
West Tower, Suite 658
Longueuil, Quebec J4K 5G4
Tel.: 450-679-5450
jpsanche@herouxdevtek.com
Héroux-Devtek reviews all privacy complaints and takes appropriate action to resolve them.
Policy amendment and notification to that effect
Héroux-Devtek reserves the right to amend its Policy at any time. In this case, it will notify all those concerned.
Effective date
The Policy took effect on September 22, 2023.