Collection of Personal Information
From Website Visitors
When you use our website, we collect de-identified statistical data using Google Analytics (such as your location and which pages you visited).
We use this information for statistical purposes and to better understand the needs and interests of our website visitors.
All data collected by Google Analytics is generally de-identified.
It may be possible for you to prevent this information from being collected from you by Google Analytics (and, in turn, by COCo) by using an add-on such as Google Analytics Opt-out or other software. Although COCo does not discourage you from doing so, COCo takes no responsibility for your use of any such software.
We collect your IP address and the URLs of pages you visit, in order to be able to serve you the web pages you request. This information is collected by our web hosting service in the United States.
From Newsletter Subscribers
When you sign up to our newsletter, we collect the following information:
- First and last names
- Email address
- IP address
- Job title and name of organization (for the Atelier/C newsletter only)
- Which newsletter(s) you are signing up for
With the exception of your IP address, all of the data is provided by you through the sign-up form. We use this information to send you our newsletters. This information is stored in our website database, hosted on SiteGround.
Our newsletter is distributed through Elastic Email, which means that some personal information (name, email address) will be shared with this service to facilitate sending and receiving the newsletter.
Please note that these external services collect and store your personal information in the United States.
Workshop participants (such as Atelier/C)
If you sign up to participate in an Atelier/C workshop or other public workshop hosted by COCo, we might ask for the following information:
- First and last name
- Phone number
- Job title and organization
- Accessibility needs
Groups that COCo serves
COCo uses Salesforce as our Customer relationship management (CRM) software. The following information is generally stored in our CRM when an organization makes it available to us:
- First and last name of our main contact in the organization
- Email address and/or phone number of this person
- Job title and organization of this person
- Information that was shared with us during an intake or assessment meeting
Some information, such as training materials, the signed project contract and any other written material relevant to a contract, might also be stored in our Google Drive. These files are shared only with relevant staff members and the COCo external affiliates who are working on the project.
Although COCo no longer provides website hosting or development services to new clients, existing client websites are hosted on a service called Flywheel which is run by the United States-based company WPEngine, Inc.
Please note that these external services store your data outside of Quebec and Canada.
Job Applicants, Employees and Board Members
COCo uses Paperform for job applications, which means that the following information might be stored on our Paperform account if you apply for a job with us:
- First and Last Name
- Email address, phone number
- The answers that you provide to the job related questions
- Any information that you choose to provide us relating to employment equity
- Your CV
Sensitive employee and board member data, such as financial information, SIN number, ID cards and any other HR-related sensitive documents are stored in a remote repository that includes two layers of password protection. This information is only accessible by the Executive Coordinators and the Technology Coordinator. This service is run by a United States-based company and the information is stored outside of Quebec and Canada.
Other staff information, such as employment contracts and salary information, is stored in COCo’s Google Drive and is accessible to all staff members. This is in accordance with COCo’s values and practices regarding transparency and collective management.
Who Has Access and Security Practices
Access to personal information within COCo is limited to those who need access for the purpose the information was collected. In particular:
- The Atelier/C coordination committee and any other staff member who is involved in organizing an Atelier/C event that you are attending have access to personal information collected for this purpose.
- The Organizational Development and Technology coordinators have access to personal information provided to us by the groups that we serve (generally this is limited to the contact information of the person who contacts us on behalf of the organization).
- The Technology and Communications Coordinators have access to personal information collected through the website, such as newsletter subscribers’ information and information collected through Google Analytics.
- The Executive Coordinators and the Technology Coordinator have access to HR-related documents and information, such as SIN numbers, financial and health information of employees, IDs and addresses of board members.
- COCo’s Salesforce is only accessible to its staff and only staff members who work with a certain organization or who need to access information about that organization for a specific purpose will access the relevant information.
COCo hires external contractors from time to time in the following fields:
- Bookkeeper and Accountant, who have access to employee financial information
- External facilitators for Atelier/C have access to the list of participants and their accessibility needs
- Counselors who provide psychological support during training or staff days.
Additionally, COCo has a group of external affiliates who provide services to the organizations that we serve. These affiliates have access to personal information in relation to contracts that they work on (which is provided to them by the organizations during the work).
COCo is committed to keeping our security practices up-to-date to safeguard the confidentiality of your personal information. Some of the practices that we have in place to ensure this are: limiting access to sensitive data to a needs-to-know basis, password protection on documents with sensitive data, and limiting downloads of personal information to local computers as much as possible. We are putting in place staff training on cybersecurity and on personal information best practices.
How Long We Keep Your Information
When you visit our website, your IP address is stored for a period of 30 days.
COCo will store the personal information of workshop participants for a period of 3 years, after which point the personal information will be anonymized but the names of the organizations that participated in the workshop will be kept. The email address that you used to register for the event will also remain in the Atelier/C newsletter unless you request that it is removed.
COCo will store job applications for a period of two years, after which point they will be deleted.
If you signed up to our newsletter, your name and email address will be stored until you request to be removed from our newsletter.
COCo will continue to store all relevant information about the organizations that we have served in our CRM, unless they request that we delete the information.
COCo retains employee records unless the employee has left COCo and requests that their information is removed (legal obligations allowing). The same is true for current and past board members.
When COCo has a legal obligation to retain information for longer periods than those set out in this policy, those obligations will prevail over this policy.
How to Access Your Information, Complain or Exercise Another Right
You may at any time:
- Ask to access the personal information that we have regarding yourself;
- Ask COCo to make a correction to personal information it holds about you;
- Withdraw your consent to the retention of your personal information; or
- Make a complaint regarding your privacy.
To exercise any of these rights, please email our Privacy Officer at firstname.lastname@example.org.
If you would like to attend one of our workshops or in another way work with COCo but would like to opt out of providing any of the information that was mentioned in this policy, don’t hesitate to write to our Privacy Officer at email@example.com to explore alternative options.