PRIVACY
POLICY
The Monastery Privacy Policy
General Information
The Monastere is committed to respecting the privacy of individuals in the conduct of all its activities.
The very nature of the Monastere's activities—such as ticket purchases and communications with subscribers, donors, partners, sponsors, collaborators, employees, and volunteers—involves the collection, use, disclosure, and retention of various types of sensitive personal information.
Access to information and privacy legislation includes provisions requiring companies to take steps to inform individuals and obtain consent when collecting personal information.
Furthermore, they must subsequently protect the information collected. Such protection is important not only for the individuals whose personal information is at stake, but also for companies that could be held liable or see their reputations tarnished following the improper access, use, retention, or disclosure of personal information.
In addition to protection requirements, the law grants individuals the right to request access to their own information and the right to request the correction or amendment of any personal information they consider inaccurate.
Finally, legislative measures grant individuals the right to file a complaint if they believe that The Monastere is not fulfilling its obligations under the law. Misuse of personal information can lead to serious consequences for both The Monastere and the individuals involved.
Good privacy practices are essential for good governance, accountability, and risk management.
1.1 Objectives
This policy aims to define the framework and the responsibilities of each individual regarding the following:
Obtaining individuals' consent regarding the collection, retention, use, and disclosure of their personal information; the importance of not collecting more information than necessary; using information for the intended purposes; verifying the accuracy of information and retaining it for reasonable purposes; individuals' access to information collected about them; retention and destruction of information; and protection of information against inappropriate access, use, or disclosure.
1.2 Scope
This policy applies to any employee, volunteer, or partner to whom The onastere discloses personal information or who collects personal information on behalf of The Monastere.
1.3 DefinitionsIndividuals: the persons about whom The Monastere collects, uses, and retains personal information for the proper conduct of its activities. In this context, “individuals” include partners, volunteers, interns, donors, sponsors, ticket buyers, subscribers, employees, and other persons who have provided their data. Personal information: personal information is generally defined as information that allows an individual to be identified, either directly or indirectly.
For privacy protection legislation to apply, the personal information in question must relate to an individual, identify an individual, or make it possible to identify an individual.
Examples of personal information may include: name, date of birth, Social Insurance Number, home address, personal phone number, personal email address, medical information, salary, banking details, and family information.
EXPLICIT OR TACIT CONSENT: When The Monastere collects personal information from an individual, it must inform them of the purposes for which the information is being collected and the means of collection, as well as their rights of access and rectification and their right to withdraw consent.
Implied (or tacit) consent is consent that is self-evident, without being formally expressed verbally or in writing.
For example, if an employee, volunteer, member of the public, or donor fills out a registration, subscription, ticket, or donation form, they can reasonably expect that this information will be collected and used in connection with their involvement with The Monastere. In such cases, the individual voluntarily provides their personal information. Explicit (or express) consent is sometimes required; this means The Monastere must clearly inform individuals (verbally or in writing) that they have the option to consent or not, and must obtain formal agreement from them. Criminal background checks during recruitment require the individual's consent via a signed authorization document, as does the use of an individual's photograph in The Monastere’s publications. Internal forms must be available for these purposes.
Guiding principles
The Monastere collects personal information about its employees, donors, partners, sponsors, volunteers, and event participants. This information is used for fundraising, public education and awareness, the delivery of services and programs, and to establish, maintain, and manage relationships with these individuals.
2.1 Responsability
The information collected is entrusted to the Monastere, which is therefore responsible for the personal information it manages. General Management is designated as the party responsible for the protection of personal information, ensuring compliance with the principles set out below. It may delegate this function, in whole or in part, to any person in writing. The Monastere acts as the custodian of and is responsible for the information it has collected; this responsibility extends to all employees, partners, and volunteers who have access to such information. Consequently, all employees, partners, and volunteers are responsible for the personal information they collect, control, or access in the course of their duties. Furthermore, they are bound by obligations of discretion and confidentiality in accordance with this policy and the spirit of the Act; any breach thereof may result in disciplinary or administrative measures, ranging from the dismissal of employees or the dismissal of volunteers (in serious cases) to the termination of any partnership or agreement with a third party. Privacy-related matters are incorporated into agreements, governance policies, and orientation and training programs for employees, volunteers, donors, and partners.
2.2
Determination of purposes for information collection: Personal information is collected from and about individuals to ensure the effectiveness of programs, activities, fundraising, volunteer recruitment, and the management and termination of relationships with volunteers and employees. Information may also be used to compile statistics or evaluate recruitment and management strategies; however, in such cases, it will be anonymized and will no longer constitute personal information. Proper information management ensures the availability of personal information for decision-making and protects the rights of both the Monastere and the individuals involved. The Monastere collects only the personal information necessary for the determined purposes and proceeds in a fair and lawful manner.
2.3
Consent: Every individual is informed of any collection, use, or disclosure of personal information concerning them and has provided tacit or explicit consent, subject to exceptions provided by law. To this end, The Monastere: Clearly defines which information is mandatory and essential to its processes; Describes how the collected information will be used in the course of its activities; Is transparent regarding when personal information might be disclosed and specifies whether it will be shared with other programs or external third parties; Specifies whether The Monastere intends to verify the personal information submitted; Ensures, to the extent possible, that the information provided by individuals is complete, accurate, and truthful; Mentions the right of access to and rectification of personal information as provided by law; Informs individuals of the right to withdraw consent for the disclosure or use of personal information; Indicates any administrative or other penalties that may apply if an individual provides false information.
2.4. Use and disclosure
Personal information is not used or disclosed for purposes other than those for which it was collected, unless the individual concerned consents or the law requires it. The Monastere does not retain personal information longer than necessary to fulfill the specified purposes.
Furthermore, subject to prior authorization, the personal information of employees, volunteers, donors, partners, and community members (including photographs and biographies) may be collected, used, and disclosed in connection with The Monastere’s activities, such as in newsletters or on websites and social media.
The disclosure of personal information is subject to the legislation applicable to The Monastere; however, in general, personal information may be disclosed: for the purposes for which the information was collected or for a use aligned with a specific need (e.g., determining or verifying a person’s suitability to work for the organization); if an individual has consented in writing to the disclosure of their personal information (e.g., to enable communication with a spouse, family member, or friend in an emergency); or if such disclosure is necessary to comply with federal or provincial law. Regardless of the circumstances, The Monastere does not rent, sell, or exchange individuals' personal information.
2.5 Conservation
Personal information, references, criminal record checks, and other similar personal information are stored in databases. The Monastere retains personal and financial information only for as long as necessary to fulfill the purposes for which it was collected, and in accordance with relevant federal and provincial regulatory requirements.
2.6. Measures and safety
Personal information is protected by security measures commensurate with its level of sensitivity. The Monastere implements and maintains appropriate safeguards to ensure that access to personal information contained in the files of employees, donors, volunteers, and other individuals associated with Le Monastère is restricted to the following: individuals authorized by The Monastere who require access to perform their duties; individuals to whom the data subjects have given their consent; and individuals authorized by law. The Monastere makes every reasonable effort to implement necessary safeguards against the loss, misuse, or alteration of personal information under its control. Security policies are reviewed periodically. An emergency plan is in place to ensure a rapid response in the event of a system failure or cyberattack.
A privacy impact assessment is conducted prior to any project involving the acquisition, development, or redesign of an information system or the electronic delivery of services involving personal information.
In certain limited circumstances, it may be necessary to share certain information with a service partner hired by or associated with The Monastere. All our service providers or partners must maintain the confidentiality and security of personal information and use it only in compliance with applicable privacy laws.
Under the terms of a confidentiality agreement signed by said service providers or partners, they are further prohibited from using or disclosing personal information for any purpose other than providing the services for which they were engaged. Secure, protected data networks meeting industry standards, as well as password protection systems, are employed. Credit card information is processed using encryption systems and industry security standards, in compliance with Canadian laws governing commerce and banking transactions. The use of computers and email is governed by the Monastere’s regulations regarding access to and use of computers, the Internet, and email.
Staff, employees of partners and suppliers, and members of the Monastere’s Board of Directors demonstrate respect and dignity by ensuring the confidentiality of information regarding employees, volunteers, interns, partners, and donors, and by not sharing details of discussions with anyone who does not need to be informed of the facts.
2.7. Transparency and access to personal information
The Monastere ensures that clear information regarding its policies and practices concerning the management of personal information is readily accessible to any individual. Any individual may inquire—by submitting a written request to the General Management—about the existence of personal information concerning them, how it is used, and whether it has been disclosed to third parties. They may also challenge the accuracy and completeness of the information and have appropriate corrections made. Subject to legal and contractual requirements, an individual may, at any time, refuse or withdraw consent regarding certain of the stated purposes by contacting The Monastere.
2.8 File a complaint regarding non-compliance with the principles.
Any individual may lodge a complaint regarding non-compliance with this policy or generally recognized privacy principles by contacting the person responsible for the protection of personal information to ensure these standards are upheld within The Monastere. If, at any time, an individual wishes to have their name removed from distribution or solicitation lists, they need only contact The Monastere to make such a request. Should The Monastere believe that a confidentiality incident involving an individual’s personal information has occurred, it will: investigate and implement measures deemed necessary to limit harm and prevent a recurrence; conduct a risk assessment; notify the Access to Information Commission if the incident presents a serious risk of harm and, unless prohibited by law, also notify the affected individual; and record the confidentiality incident in a register. Any individual may lodge a complaint regarding non-compliance with this policy or generally recognized privacy principles by contacting the person responsible for the protection of personal information to ensure these standards are upheld within The Monastere. If, at any time, an individual wishes to have their name removed from distribution or solicitation lists, they need only contact The Monastere to make such a request. If The Monastere believes that a confidentiality incident involving an individual’s personal information has occurred, it will: investigate and implement measures deemed necessary to limit harm and prevent a recurrence; conduct a risk assessment; notify the Access to Information Commission if the incident presents a serious risk of harm and, unless prohibited by law, also notify the affected individual; and record the confidentiality incident in a register.
2.9. Collection via technological means
A specific privacy policy is available when The Monastere collects personal information via its website or an application. It also ensures that privacy settings are set to the highest level by default, with the exception of cookies. A cookie is a piece of information sent to a web browser and stored on a computer. Users will be informed of the use of cookies and may enable or disable certain functions. Cookies do not contain personal data and can be deleted by users at any time.
Responsabilities
3.1 Board of Directors
The members of the Board of Directors are responsible for: approving this policy and any subsequent amendments; ensuring that the person responsible for the protection of personal information carries out appropriate monitoring; and monitoring the implementation of this policy with the person responsible for the protection of personal information.
3.2 Privacy Officer
The person responsible for the protection of personal information must ensure: that all personnel, partners and their staff, and volunteers possess the training and knowledge required to properly apply this policy and the principles of the Act; and that measures and controls are in place to ensure the proper collection and management of personal information.
That it possesses the means and resources required to ensure the proper implementation of this policy and to raise any issues related thereto; That a summary of the confidentiality incident register be presented to the Board of Directors’ Governance and Strategy Committee or, failing that, directly to the Board of Directors; That a review of the implementation of this policy be presented to the Board of Directors upon request, along with recommendations for any necessary amendments. To ask questions or provide comments regarding this Personal Information Protection Policy or personal information, to exercise your rights, to file a complaint, or to obtain information about our policies and practices concerning service providers located outside Quebec, please contact our Personal Information Protection Officer by email at: info@le-monastere.ca
The person responsible for the protection of personal information will contact you within thirty (30) days of receiving your email.
Inspired by Tohu’s personal information protection policy.