Quebec privacy

Personal information governance

Last updated: September 22, 2026

What this page is

This page publishes the rules 514IT Consulting Solutions Inc. follows for personal information it holds. It is separate from the privacy policy, which explains collection through this website, and from the terms of use.

Office: 502 Av. Delmar, Apt 5, Pointe-Claire, QC H9R 4A6. The person in charge can be reached at [email protected].

Roles and responsibilities

The person who exercises the highest authority in the company sees that the Act respecting the protection of personal information in the private sector is implemented and complied with. That person is the person in charge of the protection of personal information. They may delegate all or part of the function in writing to a member of the personnel.

The title and contact information of the person in charge are published in the privacy policy. Anyone who handles an inquiry or a client file uses only the information they need, only for the purpose that was stated, and keeps it confidential.

From collection to destruction

  • We define the purpose before we collect.
  • We collect only information that is necessary for that purpose.
  • At the time of collection, we state the purpose, the means of collection, the rights of access and rectification, the right to withdraw consent, and, when it applies, that the information may be communicated outside Quebec.
  • Consent is clear, free, informed, and specific. Sensitive information requires express consent. Optional purposes, including marketing and tracking, are requested separately and stay off until the person accepts.
  • Access inside the company is limited to people assigned to the file.
  • We keep information only for the periods below, then we destroy it or anonymize it.
  • We do not communicate it except to a provider under a written contract, when a law requires disclosure, or when the person concerned authorizes it.

Retention and destruction

  • Inquiries: up to 24 months after the last exchange, unless a contract or a law requires longer.
  • Client and accounting records: for the period tax law requires, generally six years after the relevant year.
  • Proof that a person unsubscribed from marketing: as long as needed to honour that refusal.
  • The register of confidentiality incidents: kept so it can be provided to the Commission d’accès à l’information du Québec on request. The register is not published.

Destruction means deletion from active systems, and from backups as those backups expire, or anonymization so the person can no longer be identified, directly or indirectly.

Confidentiality incidents

A confidentiality incident includes unauthorized access, use, or communication of personal information, the loss of personal information, or any other breach of its protection.

When we become aware of an incident, we:

  • take reasonable measures to reduce the risk of injury and to prevent new incidents of the same nature
  • assess whether the incident presents a risk of serious injury to the persons concerned
  • if it does, promptly notify the Commission d’accès à l’information du Québec and each person whose information is concerned
  • record the incident in the register, whether or not it presents a risk of serious injury

A notice to a person explains the personal information concerned, the circumstances, what we have done, what the person can do to reduce the risk, and how to reach the person in charge.

To report a suspected incident, email [email protected].

Complaints about personal information

  • Send the complaint to the person in charge, with enough detail for us to find the file.
  • We acknowledge it and say who is handling it.
  • We review what happened and we correct the practice when a correction is needed.
  • We reply in writing. If you are not satisfied, you may complain to the Commission d’accès à l’information du Québec: cai.gouv.qc.ca.

Privacy assessments

Before we communicate personal information outside Quebec, we assess the privacy factors. The assessment covers the sensitivity of the information, the purposes of the communication, the safeguards the recipient applies, and the legal regime that applies to the recipient. We communicate the information only if the assessment shows that it would receive adequate protection, including protection generally recognized under privacy principles.

We also enter a written agreement. It limits use to the agreed purposes, requires safeguards, and states what happens to the information at the end of the mandate.

A new system that collects, uses, communicates, or keeps personal information is reviewed the same way before launch, in proportion to the sensitivity of the information and the purposes.

Keeping these rules current

When these rules change, we update this page and the date at the top. The confidentiality policy for the website is updated on its own page when that policy changes.