Privacy Policy
Limestone Sailing Company
PRIVACY POLICY
In Canada, the privacy of personal information is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA). This Policy is based on the standards required by PIPEDA as interpreted by the organization.
Definitions
-
The following terms have these meanings in this Policy:
-
“Commercial Activity” – any particular transaction, act or conduct that is of a commercial character.
-
“Personal Information” – any information about an individual that relates to the person’s personal characteristics including, but not limited to: gender, age, income, home address, home phone number, ethnic background, family status, health history, and health conditions
-
Purpose
-
The organization recognizes individual’s right to privacy with respect to their Personal Information. This policy describes the way that the organization collects, uses, safeguards, discloses, and disposes of Personal Information.
Application of this Policy
-
This Policy applies to all individuals in connection with personal information that is collected, used, or disclosed during any organization activities.
-
Except as provided in PIPEDA, the organization’s leadership will have the authority to interpret any provision of this Policy that is contradictory, ambiguous, or unclear.
Obligations
-
The organization is obligated to follow and abide by PIPEDA in all matters involving the collection, use, and disclosure of Personal Information.
-
In addition to fulfilling the legal obligations required by PIPEDA, the organization and its representatives will not:
-
Publish, communicate, divulge, or disclose to any unauthorized person, firm, corporation, or third party any Personal Information without the express written consent of the individual
-
Knowingly place themselves in a position where they are under obligation to any organization to disclose Personal Information
-
In the performance of official duties, disclose Personal Information to family members, friends, colleagues, or organizations in which their family members, friends, or colleagues have an interest
-
Derive personal benefit from Personal Information that they have acquired during the course of fulfilling their duties with the organization
-
Accept any gift or favour that could be construed as being given in anticipation of, or in recognition for, the disclosure of Personal Information
Accountability
-
The Privacy Officer is responsible for the implementation of this policy and monitoring information collection and data security, and ensuring that all staff receives appropriate training on privacy issues and their responsibilities. The Privacy Officer also handles personal information access requests and complaints. The Privacy Officer may be contacted at the following address:
Limestone Sailing Company
1270 Coverdale Drive
K7M 8X7
Kingston, Ontario
limestonesailingco@gmail.com
-
Duties - The Privacy Officer will:
-
Implement procedures to protect personal information
-
Establish procedures to receive and respond to complaints and inquiries
-
Record all persons having access to personal information
-
Ensure any third party providers abide by this policy
-
Ensure organization representatives are trained and educated on the privacy policies and practices.
Identifying Purposes
-
The organization may collect Personal Information from individuals for purposes that include, but are not limited to:
Communications
-
-
Sending communications in the form of e-news or a newsletter with content related to programs, events, fundraising, activities, discipline, appeals, and other pertinent information.
-
Publishing articles, media relations and postings on the organization website, displays or posters.
-
Award nominations, biographies, and media relations
-
Communication between individuals and organization representatives
-
Discipline results and long-term suspension list.
-
Checking residency status
-
Registration, Database Entry and Monitoring
-
-
Registration of programs, events and activities
-
Database entry with Sail Canada and their approved software for sailing programs, Checklick
-
Database entry with Coaches Association of Canada to determine level of coaching certification coaching qualifications and coach selection.
-
Database entry to determine level of officiating certification and qualifications
-
Determination of eligibility, age group and appropriate level of participation/competition
-
Athlete Registration, outfitting uniforms, and various components of athlete and team selection
-
Technical monitoring, officials training, educational purposes, sport promotion, and media publications
-
Sales, Promotions and Merchandising
-
-
Purchasing equipment, coaching manuals, resources and other products
-
Promotion and sale of merchandise
-
General
-
-
Travel arrangement and administration
-
Implementation of the organization screening program
-
Medical emergency, emergency contacts or reports relating to medical or emergency issues
-
Determination of participant demographics and program planning
-
Managing insurance claims and insurance investigations
-
Managing complaints related to safe sport policies
-
Video recording and photography for personal use, and not commercial gain, by spectators, parents and friends
-
Video recording and photography for promotional use, marketing, and advertising by the organization
-
Payroll, honorariums, company insurance and health plans
-
-
The organization may collect Personal Information from participants for other purposes, provided that documented consent specifying the use of the Personal Information is obtained from the individual or in the case of minors, their parent/guardian.
Consent
-
By providing Personal Information to the organization, individuals are implying their consent to the use of that Personal Information for the purposes identified in the Identifying Purposes section of this Policy.
-
At the time of the collection of Personal Information and prior to the use or disclose of the Personal Information, the organization will obtain consent from individuals by lawful means. The organization may collect Personal Information without consent when it is reasonable to do so and permitted by law.
-
In determining whether to obtain written or implied consent, the organization will take into account the sensitivity of the Personal Information, as well the participants’ reasonable expectations. Individuals may consent to the collection and specified use of Personal Information in the following ways:
-
Completing and/or signing an application or registration form
-
Checking a check box, or selecting an option (such as ‘Yes’ or ‘I agree’)
-
Providing written consent either physically or electronically
-
Consenting orally in person
-
Consenting orally over the phone
-
The organization will not, as a condition of providing a product or service, require individuals to consent to the use, collection, or disclosure of Personal Information beyond what is required to fulfill the specified purpose of the product or service.
-
An individual may withdraw consent in writing, at any time, subject to legal or contractual restrictions. The organization will inform the individual of the implications of withdrawing consent.
-
The organization will not obtain consent from individuals who are minors, seriously ill, or mentally incapacitated. Consent from these individuals will be obtained from a parent, legal guardian, or a person having power of attorney.
-
The organization is not required to obtain consent for the collection of Personal Information, and may use Personal Information without the individual’s knowledge or consent, only if:
-
It is clearly in the individual’s interests and the opportunity for obtaining consent is not available in a timely way
-
Knowledge and consent would compromise the availability or accuracy of the Personal Information and collection is required to investigate a breach of an agreement or a contravention of a federal or provincial law
-
An emergency threatens the individual’s life, health, or security
-
The information is publicly available as specified in PIPEDA
-
The organization is also not required to obtain consent for the collection of Personal Information if the information is for journalistic, artistic, or literary purposes.
-
The organization may disclose Personal Information without the individual’s knowledge or consent only:
-
To a lawyer representing the organization
-
To collect a debt that the individual owes to the organization
-
To comply with a subpoena, a warrant, or an order made by a court or other body with appropriate jurisdiction
-
To a government institution that has requested the information and identified its lawful authority, if that government institution indicates that disclosure is for one of the following purposes: enforcing or carrying out an investigation, gathering intelligence relating to any federal, provincial, or foreign law, national security or the conduct of international affairs, or administering any federal or provincial law
-
To an investigative body named in PIPEDA or a government institution, if the organization believes the Personal Information concerns a breach of an agreement, contravenes a federal, provincial, or foreign law, or if organization suspects the Personal Information relates to national security or the conduct of international affairs
-
To an investigative body for purposes related to the investigation of a breach of an agreement or a contravention of a federal or provincial law
-
In an emergency threatening an individual’s life, health, or security (the organization will inform the individual of the disclosure)
-
To an archival institution
-
20 years after the individual's death or 100 years after the record was created
-
If it is publicly available as specified in PIPEDA
-
If otherwise required by law
Accuracy, Retention, and Openness
-
In order to minimize the possibility that inappropriate Personal Information may be used to make a decision about an individual, Personal Information will be accurate, complete, and as up to date as is necessary for the purposes for which it will be used.
-
Personal Information will be retained as long as reasonably necessary to enable participation in organization programs, events, and activities, and in order to maintain historical records as may be required by law or by governing organizations.
-
Organization representatives will be made aware of the importance of maintaining the confidentiality of Personal Information.
-
Personal Information will be protected against loss or theft, unauthorized access, disclosure, copying, use, or modification by security safeguards appropriate to the sensitivity of the Personal Information.
-
Personal Information that has been used to make a decision about an individual will be maintained for a minimum of one year in order to allow the individual the opportunity to access the Personal Information after the decision has been made.
-
The organization will make the following information available to individuals:
-
This Privacy Policy
-
Any additional documentation that further explains the organization’s Privacy Policy
-
The name or title, and the address, of the person who is accountable for the organization’s Privacy Policy
-
The means of gaining access to Personal Information held by the organization
-
A description of the type of Personal Information held by the organization, including a general account of its use
-
Identification of any third parties to which Personal Information is made available
Access
-
Upon written request, and with assistance from the organization after confirming the individual’s identity, individuals may be informed of the existence, use, and disclosure of their Personal Information and will be given access to that Personal Information. individuals are also entitled to be informed of the source of the Personal Information, and provided with an account of third parties to which the Personal Information has been disclosed.
-
Unless there are reasonable grounds to extend the time limit, requested Personal Information will be disclosed to the individual, at no cost to the individual, within thirty (30) days of receipt of the written request.
-
individuals may be denied access to their Personal Information if the information:
-
Is prohibitively costly to provide
-
Contains references to other individuals
-
Cannot be disclosed for legal, security, or commercial proprietary purposes
-
Is subject to solicitor-client privilege or litigation privilege
-
If the organization refuses a request for Personal Information, it shall inform the individual the reasons for the refusal and identify the associated provisions of PIPEDA that support the refusal.
Compliance Challenges
-
individuals are able to challenge the organization for its compliance with this Policy.
-
Upon receipt of a complaint, the organization will:
-
Record the date the complaint is received
-
Notify the Privacy Officer who will serve in a neutral, unbiased capacity to resolve the complaint;
-
Acknowledge receipt of the complaint by way of telephone conversation and clarify the nature of the complaint within seven (7) days of receipt of the complaint
-
Appoint an investigator using the organization’s personnel or an independent investigator, who will have the skills necessary to conduct a fair and impartial investigation and will have unfettered access to all file and personnel
-
Upon completion of the investigation and within thirty (30) days of receipt of the complaint, the investigator will submit a written report to the organization
-
Notify the complainant the outcome of the investigation and any relevant steps taken to rectify the complaint, including any amendments to policies and procedures
-
The organization will not dismiss, suspend, demote, discipline, harass, or otherwise disadvantage any individual who:
-
Challenges the organization for its compliance with this Policy
-
Refuses to violate this Policy or PIPEDA
-
Takes precautions to be compliant with this Policy and/or PIPEDA; even though said precautions may be in opposition to the regular duties performed by the individual