The primary purpose of this policy is to ensure the protection of personal information while establishing clear guidelines for how data is collected, used, disclosed, retained, destroyed, and managed at CIDRERIE MILTON. This applies to all stakeholders,
including management, employees, suppliers, and others. This policy also aims to inform all individuals concerned—whether clients, employees, or other persons— about how CIDRERIE MILTON handles their personal information.
RESPONSIBILITY
CIDRERIE MILTON is responsible for ensuring the security and confidentiality of all personal information it manages. All data that is collected, used, disclosed, retained, or destroyed is subject to the terms of this policy, with the primary goal of protecting each individual's privacy.
To ensure effective protection of personal information, the person responsible for data protection within CIDRERIE MILTON must:
- Oversee and review internal practices and procedures related to the handling of personal information, and ensure compliance with applicable laws; •
- Recommend measures to ensure the ongoing protection of personal information, in line with privacy impact assessments;
- Implement the necessary safeguards within the organization;
- Ensure staff compliance and provide training on best practices for data privacy;
- Coordinate, investigate, and respond to privacy-related requests and complaints
- Communicate with affected individuals and the Commission d'accès à l'information (CAI) in the event of a data breach or incident;
- Maintain a register of incidents involving personal information.
Protecting personal information is everyone's responsibility. No individual will face retaliation for filing a privacy-related complaint or participating in an investigation conducted by the CAI.
COLLECTION OF PERSONAL INFORMATION
The personal information collected enables CIDRERIE MILTON to carry out its functions and conduct its activities in accordance with applicable laws and standards. We only collect personal information when necessary and for specific purposes identified in advance. Personal information is collected directly from the individual concerned and with their consent, unless an exception is provided by law.
Appendix A contains a non-exhaustive list of the types of information collected and how it is used. Most personal information relates to employees, collected to meet the company's legal obligations. In some cases — such as emergencies — employees may be asked to provide contact information for another person; it is the employee's responsibility to obtain that person's consent before sharing their details.
For clients, information is collected to maintain our records, management software, contracts, and billing. We place the highest importance on the confidentiality and security of our client's data. All information collected, including contact details and other personal information, is handled with the utmost care and in accordance with applicable privacy laws and regulations. We implement strong security measures to prevent unauthorized access and regularly train our team on data privacy best practices. Protecting our clients' personal information is a core responsibility and fundamental to maintaining trust in our services.
CONSENT AND ACCURACY
CIDRERIE MILTON ensures that personal information is collected for legitimate, clear, and specific reasons, and only with the individual's free and informed consent. Consent is required for any collection, use, or disclosure of personal information. Before collecting your information, we will obtain your informed consent in writing and we will provide clear details about the purpose of the collection and how your information will be used.
LIMITATION ON THE USE OF PERSONAL INFORMATION
We collect and use personal information only when necessary and for the purposes for which consent was obtained. In certain circumstances, CIDRERIE MILTON may be required to share information to comply with legal or regulatory audit requirements. Possible uses are outlined in Appendix A.
Information may be shared with third parties when necessary for the activities described in Appendix A. CIDRERIE MILTON is not responsible for how such third parties handle or use that information.
Personal information will not be used or disclosed for any purpose other than those specified, unless required by law.
PROTECTION OF YOUR PERSONAL INFORMATION
CIDRERIE MILTON takes all reasonable precautions and implements meaningful physical and technical safeguards to prevent unauthorized or unlawful access to personal information. These measures include:
- Using personal information only when necessary
- Ensuring that all individuals who access personal information in the course of their duties maintain its confidentiality, unless disclosure is authorized by the individual concerned;
- Restricting access to files to authorized personnel only;
- Securing office access through locked doors and access codes; • Secure shredding of paper documents;
- Two-factor authentication for all platform logins;
- Immediate revocation of access rights when a business relationship ends.
Everyone is expected to contribute to the protection of personal information. If you suspect that sensitive information has been compromised, notify the privacy officer immediately.
RETENTION OF YOUR PERSONAL INFORMATION
CIDRERIE MILTON undertakes to comply with the minimum retention periods required for each category of personal information under applicable laws. When information is no longer needed and retention is not required under any applicable legislation, it will be destroyed, deleted, or anonymized.
COMMITMENT TO TRANSPARENCY
CIDRERIE MILTON is committed to transparency regarding the handling of personal information, including the procedures and purposes governing its use, for clients, employees, interns, and business partners.
ACCESS TO YOUR PERSONAL INFORMATION
You have the right to request access to your personal information as well as information about how it was collected. Depending on the file, some exceptions may apply—for example, if it contains information about another individual. In such cases, you will be informed. If any information on file is inaccurate, you may request that it be corrected.
For any request to consult, withdraw, or update your personal information, please contact us at rh@cidereriemilton.com. At any time, you may withdraw your consent to the use of your personal information by submitting a written request to the person responsible for personal information protection at the same address. A response will be provided within 30 days of receiving the request. If it is not possible to provide the requested information, a legal justification and supporting explanation will be provided.
FILING A COMPLAINT
If you believe your personal information has been collected, retained, used, disclosed, or destroyed in a manner that does not comply with this policy, you may file a confidential complaint with the person responsible for personal information protection at rh@cidereriemilton.com. The complaint must include your name, contact information (including a phone number), and a clear description of the complaint with sufficient detail for it to be properly assessed. A response will be provided within 30 days of receiving the complaint. If the complaint lacks sufficient detail, the person responsible for personal information protection may request additional information necessary to evaluate it. All complaints will be investigated, and appropriate corrective action will be taken.
You may also file a complaint with the Commission d’accès à l’information du Québec. However, we encourage you to first contact the person responsible for personal information protection at CIDRERIE MILTON and allow our internal complaint handling process to be completed.
APPROVAL
This policy is approved by the person responsible for personal information protection at CIDRERIE MILTON.
Lynda Brousseau – HR Advisor
5 Rte 137
Sainte-Cécile-de-Milton, Qc, J0E 2C0
rh@cidreriemilton.com
For any questions, requests, or comments regarding this policy, please contact the privacy officer by email.