OKIOK is concerned about respecting your privacy and protecting your personal and confidential information.
In the course of using our services, OKIOK may collect personal and/or confidential information.
The collection, use, disclosure and retention of your personal information are subject to the Act respecting the protection of personal information in the private sector (R.S.Q., c. P-39.1) and, where applicable, the European Union’s General Data Protection Regulation (GDPR).
OKIOK reserves the right to modify this policy at any time. Any modification will be published on the various OKIOK web platforms. Your use of the services following the posting of modifications to the policy constitutes acceptance of these modifications.
The purpose of this policy is to inform users of the services offered by OKIOK of the following:
- How their personal and/or confidential data is collected and processed;
- What are the rights of the users regarding this data?
- Who is responsible for processing the personal data collected and processed?
- To whom this data is transmitted;
2. Personal Information
Any factual or subjective information about an identifiable individual is considered personal. Your personal information may include, but is not limited to, your first and last name, address, telephone numbers, gender, e-mail address, marital status, lifestyle or health information.
However, an individual’s name, business title, business address, business telephone number and business e-mail address are not personal information.
Personal information must be protected regardless of the medium in which it is held or the form it takes: written, graphic, audio, visual, computerized or other.
3. Our Commitment
We have established and implemented internal policies and procedures to adequately protect personal information in our possession and we review them on a regular basis.
4. Information Collection Objectives
When using our services, we collect your personal and confidential information only to enable us to provide you with the requested services in an appropriate and personalized manner. In all cases, the disclosure of your personal and confidential information will be subject to obligations to maintain confidentiality and to comply with applicable laws.
5. Personal or Confidential Information
5.1. General Activities
In the course of its day-to-day operations, OKIOK may collect the following information:
- Contact information, such as name, address, telephone number(s), e-mail address and company.
Most of the information collected in this category is business contact information and is protected by recognized encryption mechanisms. This information is used internally to contact and send information about our products and services, to provide said services or for system maintenance and administration.
OKIOK websites collect the following information:
- IP address
- Browser and device information
- Information related to the user’s session via cookies.
Cookies are small data files that are stored on your computer or mobile device when you visit a website or application in order to enhance your user experience by storing certain data on your computer or device. By using OKIOK’s web services, you consent to this use.
5.2.1. Google Analytics
The OKIOK public website uses Google Analytics, a web analytics tool. We automatically collect certain non-personal information to help us understand how our visitors use our web services such as:
- IP address and approximate geolocation
- Visited pages
- Browser and device information
This data may be used to analyze trends, administer the site, monitor visitor traffic patterns and gather demographic information about our visitors. The data collected by these cookies is aggregated and remains anonymous.
Google Analytics collects information about your use of this website by means of cookies, which are stored on servers located in the United States. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the data on Google’s behalf.
5.2.2. Cookie Management
- External Sources of Cookie Information: You can block the receipt of third-party cookies used to show you ads tailored to your interests by visiting the following sites:
- On your browser: Most browsers allow you to refuse to receive cookies and to delete cookies. How you do this is specific to each browser and version. However, you can get up-to-date information on how to block and delete cookies through these links:
- Chrome, https://support.google.com/chrome/answer/95647?co=GENIE.Platform%3DDesktop&hl=en
- Firefox, https://support.mozilla.org/fr/kb/activer-desactiver-cookies-preferences
- Edge, https://privacy.microsoft.com/en-us/windows-10-microsoft-edge-and-privacy
- Safari, https://support.apple.com/en-ca/guide/safari/manage-cookies-and-website-data-sfri11471/mac
- Opera, https://www.opera.com/help/tutorials/security/cookies/
5.3. S-Filer/Portal and S-Filer/Sanctum
Customer information processed by S-Filer/Portal™ and S-Filer/Sanctum™ is stored on their own systems, but some data may be stored on OKIOK systems.
OKIOK does not collect other personal or sensitive information.
Personal, confidential or sensitive information uploaded to S-Filer is encrypted and protected. Only senders and people in their sharing community will have access to information uploaded or shared on S-Filer.
5.4. RAC/M Identity
The customer information processed by RAC/M Identity is as follows:
Information provided by customers about users of their computer systems, such as, but not limited to:
- Employee number
- Types of employment and status
- Email addresses
- Identity and access information collected from integrated systems.
5.5. OKIOK SIEM
Customer information processed by OKIOK SIEM includes information included in logs ingested into the solution, such as, but not limited to:
- Dates and times of logged events
- User names
- IP addresses and derived geolocation data
- System names
- Processes carried out
Some information may be transferred to third parties for specific data enrichment capabilities and functionality. Third parties are bound by the same terms and conditions documented in this policy.
Subject to the exceptions and requirements of applicable laws, we will not disclose or share your personal information with any other third parties without your consent.
By using our services, you consent to the collection, use and disclosure of your personal and confidential information in accordance with this policy.
We may collect or obtain this personal information with your consent, for example, by filling out a form on our website, because your employer or primary service provider has provided it to us, or because of the public nature of the information.
You may withdraw your consent at any time, subject to certain legal or contractual restrictions.
In certain limited circumstances, we may collect, use or disclose personal information without your knowledge or consent. Such circumstances arise when, for legal, medical or security reasons, it is impossible or unlikely to obtain your consent, or when the information is needed to investigate a possible breach of contract, to prevent or detect fraud, or to enforce the law.
Before disclosing personal information about another individual to us, you must obtain that individual’s consent to the disclosure and processing of that personal information under the terms of this policy.
6.1. Minor Personal Information
Personal information about a minor under the age of 14 will not be collected from the minor without the consent of the parent or guardian.
7. Limiting Collection, Use and Disclosure
We limit the collection, use and disclosure of your personal information to the purposes we have identified to you. Your personal information may only be accessed by certain authorized individuals for the purposes for which they have been designated.
If you submit personal information to one of our websites for the purpose of publication, we will publish it and may use that information in accordance with the permissions you grant us.
We may use the personal information we collect for the following purposes:
- To provide the requested service;
- To answer your requests for information;
- To improve our service offering;
- To provide any other complementary services associated with the requested service;
- To meet the requirements of the laws;
- To control the quality of customer service and prevent errors and fraud.
We may disclose your personal information to any of our employees, professional advisors, suppliers, or subcontractors or affiliates to the extent reasonably necessary to provide the services requested and for the purposes set forth in this policy.
Generally, we do not disclose your personal information. Occasionally, we may share your personal information with certain suppliers or agents in order to provide the services you have requested. In all cases, we comply with the restrictions and requirements set out by law when we disclose your personal information, and all such disclosures are subject to a written agreement and a security assessment that demonstrates that your personal information is adequately protected in a manner similar to that implemented at OKIOK.
We may share the information we collect with our service providers in order to provide applicable services, including for the purposes noted below.
We do not sell your personal information to third parties.
7.4. International Data Transfers
The information we collect may be stored, processed and transferred to any country in which OKIOK or its subcontractors provide services, to enable us to use the information in accordance with this policy.
The information we collect may be transferred to the following countries: the United States of America and the United Kingdom .
Personal information that you post on our website or submit for publication may be available via the Internet worldwide. We cannot prevent the use or misuse of this information by third parties.
You expressly agree to the transfer of personal information described in this section.
We make every effort to ensure that your personal information is accurate and complete for the purposes for which it was collected, used or disclosed.
9. Information Retention
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected. We must destroy or anonymize this information in accordance with the law and our record retention policy.
Your personal and confidential information is retained, directly or through subcontractors, only for as long as necessary for the purposes of the requested services and applicable legal and regulatory requirements. We require our subcontractors to adhere to privacy commitments and to apply policies equivalent to this one. In all cases, access to your personal and confidential information is restricted to those persons for whom access is required in the performance of their duties.
We are responsible for personal information in our possession or custody, including information that we entrust to third parties for the purpose of providing you with the requested service. We require these third parties to maintain this information under strict confidentiality and security standards.
Our staff is knowledgeable and properly trained in privacy policies and practices.
11. Security Measures
We have implemented a number of security measures with respect to personal information and confidential data held by us in order to protect such information against loss or theft and to prevent unauthorized access, transmission, use or modification of such personal information, including :
11.1. Privacy Impact Assessment
OKIOK conducts a privacy impact assessment for any project involving the acquisition, development or redesign of an information system or electronic service delivery that involves the collection, use, disclosure, retention or destruction of personal information. This assessment documents the bona fide and legitimate interests in the use of personal information.
11.2. Access Management
Only employees whose duties require them to have access to personal or confidential information. Data access is logged and monitored.
11.3. Commitment to Confidentiality
The signing of a confidentiality agreement by our employees: failure to comply with this agreement may result in sanctions up to and including dismissal .
Security audits are carried out by firms specialized in information security.
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected. We must destroy or de-identify this information in accordance with the law and our record retention policy. When we destroy or de-identify your personal information, we take appropriate steps to ensure that it remains confidential and that no unauthorized person has access to it during the destruction or de-identification process.
11.5. Personal Information Incident Management
If OKIOK has reason to believe that a confidentiality incident involving personal information has occurred that presents a risk of serious prejudice, OKIOK shall inform, with diligence, the Commission d’accès à l’information as well as any person whose personal information is concerned by the incident. , by communicating only the personal information necessary for this purpose without the consent of the person concerned. In all cases, a log will document the incident for reference purposes.
12. User Rights
12.1. Request for Access, Removal or Correction
You may, subject to any regulatory or contractual restrictions, access, correct or destroy the personal information we hold about you.
We will provide you with such information within a maximum of 30 days from the date we receive your written request. A fee may be charged for processing your request.
12.2. Data Portability
The user has the right to request the portability of his/her personal data in a recognized standard format held by OKIOK.
12.3. Limitation and Opposition to Data Processing
The user has the right to request the limitation of or to oppose the processing of his/her data by OKIOK and OKIOK cannot refuse this request unless it can be shown that there are legitimate and compelling reasons for doing so, which may override the interests and rights and freedoms of the user.
12.4. Decision based Exclusively on an Automated Process
The user has the right not to be subject to a decision based exclusively on an automated process if the decision produces legal effects concerning him or her, or significantly affects him or her in a similar manner.
13. Inquiries, Complaints and Questions
We are committed to responding to your questions and concerns about the protection of your personal information. If you are not satisfied with the response, you may contact the Privacy Officer at the above address.
13.1. Contact Details
Any requests or complaints regarding the protection of personal information should be directed to the Privacy Officer at the address below:
655 Promenade Du Centropolis #230
Laval, Quebec H7T 0A3
In the event that OKIOK’s Privacy Officer decides not to respond to a user’s request, and the user wishes to contest this decision, or if he or she believes that one of his or her rights has been infringed, he or she is entitled to contact the Commission d’accès à l’information du Québec (Commission d’accès à l’information du Québec | (gouv.qc.ca)).