Privacy Policy for Conforme.ca

Last Updated: December 3, 2025

This Privacy Policy explains how Conforme.ca collects, uses, stores, and protects personal information through its privacy compliance software for businesses subject to the applicable Quebec private-sector privacy law (the law).

1. Purpose of This Privacy Policy

This document describes how Conforme.ca processes personal information to deliver privacy-compliance automation, governance tools, data-management modules, and incident-response features required under the law.

2. Information We Collect

We collect only the information necessary to provide and secure the platform:

  • Account information: name, professional email address, authentication credentials.
  • Organization compliance data: information submitted to generate compliance registers, assessments, incident logs, and governance documentation.
  • Technical data: IP address, device and browser details, and logs required for security, performance, and diagnostics.
  • Voluntary information: content entered into privacy assessments, forms, templates, or documentation tools.

3. How We Use Your Information

Your personal information is used strictly to:

  • create and manage your Conforme.ca account
  • deliver privacy-compliance and governance modules
  • generate legal and regulatory registers and documentation required by the law
  • provide security monitoring and ensure reliable operation of the platform
  • offer customer support and resolve technical issues
  • improve the platform and meet audit or legal requirements

4. Legal Basis and Consent

Essential processing is based on your implied consent when you use Conforme.ca to fulfill your organization's obligations under the law. Any non-essential processing, such as optional analytics or marketing, is based on explicit consent obtained through a separate, clear mechanism that you may withdraw at any time.

5. Disclosure of Information

We may share personal information with carefully selected service providers who support the operation, hosting, security, and monitoring of the platform. Some providers may be located outside Quebec. Whenever information is transferred outside Quebec, we perform a privacy impact assessment to ensure that the information benefits from adequate protection, as required by the law, and we use appropriate contractual safeguards.

6. Retention and Destruction

We retain personal information only for as long as needed to operate the service, support your compliance activities, and meet our legal and regulatory obligations. When information is no longer required, it is securely deleted or irreversibly anonymized in accordance with recognized best practices and the law.

7. Security Measures

Conforme.ca implements technical and organizational safeguards appropriate to the sensitivity and volume of the information processed, including:

  • role-based and least-privilege access controls
  • encryption of data in transit (TLS) and at rest
  • logging, monitoring, and incident-response procedures
  • internal governance practices for privacy and security

8. Your Rights

Under the law, you may exercise the following rights regarding your personal information processed through Conforme.ca:

  • Right of access: obtain confirmation and a copy of personal information held about you.
  • Right to rectification: request correction of inaccurate, incomplete, or ambiguous information.
  • Right to withdraw consent: withdraw consent for non-essential processing, where applicable.
  • Right to complain: file a complaint with the Commission d'accès à l'information (CAI) of Quebec.

9. Privacy Officer

Conforme.ca has designated a Privacy Officer responsible for overseeing compliance with this policy and the law. For questions, access or rectification requests, or to exercise your rights, please contact the Privacy Officer at legal@conforme.ca.

10. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our services, practices, or legal requirements. Any material updates will be posted on this page with a revised "Last Updated" date. Your continued use of the Conforme.ca platform following an update constitutes acceptance of the revised policy.