- Identifying Purposes
- Limiting Collection
- Limiting Use, Disclosure and Retention
- Individual Access
- Challenging Compliance
PRINCIPLE #1 — ACCOUNTABILITY
Tatangelo’s is responsible for personal information under its control and will designate an individual or individuals who are accountable for the organization’s compliance with the following principles.
- Accountability for Tatangelo’s compliance with the principles rests with the senior management of Tatangelo’s and the person or persons designated by senior management as Privacy Officer, even though other individuals within the organization may be responsible for the day-to-day collection and processing of personal information. In addition, other individuals within the organization may be delegated to act on behalf of senior management or the Privacy Officer.
- Tatangelo’s Privacy Officer may be contacted at: Attention: Tatangelo’s Wholesale Produce c/o Privacy Officer 80 Hanlan Road, Unit 12 L4L 3P6 Canada E-mail: firstname.lastname@example.org Phone: 905-850-0545
- Tatangelo’s is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing. Tatangelo’s will use contractual or other means to provide a comparable level of protection while the information is being processed by a third party.
- Tatangelo’s will implement policies and practices to give effect to these principles, including:
- implementing procedures to protect personal information;
- establishing procedures to receive and respond to complaints and inquiries;
- training staff and communicating to staff information about Tatangelo’s policies and practices; and
- Developing information to explain Tatangelo’s policies and procedures.
PRINCIPLE #2 — IDENTIFYING PURPOSES
Tatangelo’s will identify the purposes for which personal information is collected at or before the time the information is collected.
- Tatangelo’s collects personal information only for the following purposes (“identified purposes”):
- to provide service(s) and/or products to its customers;
- to maintain commercial relations and to communicate with its customers (which will include, but not be limited to: billing, collection, advertising, promotion, account verification);
- to evaluate customers’ financial status and eligibility for credit;
- to identify customer needs and/or preferences;
- to meet legal and regulatory requirements;
- to administer and manage its business operations; and
- as otherwise required or permitted by law.
- Tatangelo’s will provide notice of the identified purposes either orally, electronically or in writing prior to or at the time of collection of the personal information.
- If individual persons collect personal information, they will be able to specify the purposes for which the information is being collected, or will refer the individual whose information is being collected to a designated person at Tatangelo’s who will specify the purposes.
- When personal information that previously has been collected is to be used for a purpose not previously identified, the new purpose will be identified prior to use. Unless the new purpose is required by law, and subject to the exceptions referred to in Principle #3, Tatangelo’s will obtain the consent of the individual before information is used for that new purpose.
- Occasionally, Tatangelo’s will communicate to you special bonus and new product offers that we think may be of value to you. Tatangelo’s may retain third parties to assist it in marketing such new or additional Tatangelo’s products and services to our customers (and for such purpose may share personal information with such third parties) but will not otherwise disclose or make available any personal information to any third parties seeking to market their products to Tatangelo’s customers. All Tatangelo’s customers have the right to chose not to participate in direct marketing of new products and services from Tatangelo’s. If you wish to opt-out of receiving targeted communications from Tatangelo’s in electronic, printed or verbal format (other than information included with your monthly bills), simply inform us in writing at Attention: Tatangelo’s Wholesale Produce c/o Privacy Officer 80 Hanlan Road, Unit 12 L4L 3P6 Canada E-mail: email@example.com Phone: 905-850-0545
- The Tatangelo’s website may provide hyperlinks, which are highlighted words or pictures within a hypertext document that may, when clicked, take you to another place within the document, to another document altogether, or to a third party website not controlled by Tatangelo’s. Such hyperlinked third party websites may collect and disclose information different than this website. Tatangelo’s is not responsible for the collection, use, or disclosure of information collected through these third party web sites, and Tatangelo’s expressly disclaims any and all liability related to such collection, use, or disclosure.
PRINCIPLE #3 — CONSENT
The knowledge and consent of the individual are required for the collection, use or disclosure of personal information, except where inappropriate.
- In certain circumstances, personal information can be collected, used, or disclosed without the knowledge and consent of the individual. For example, where collection or use is clearly in the interests of the individual and consent cannot be obtained in a timely way; where used or disclosed in the case of an emergency that threatens the life, health or security of an individual; where personal information is publicly available as defined by regulation; where collection with knowledge or consent might compromise the availability or accuracy of the information and the collection relates to investigation of a breach of agreement or contravention of law; and where disclosed for debt collection purposes or to comply with a subpoena, warrant or court order.
- Where required, Tatangelo’s will generally seek consent for the use or disclosure of the information at the time of collection. In certain circumstances, consent with respect to use or disclosure may be sought after the information has been collected but before use (for example, when Tatangelo’s wants to use information for a purpose not previously identified).
- Tatangelo’s will make a reasonable effort to ensure that the individual is advised of the purposes for which the information will be used. To make the consent meaningful, the purposes will be stated in such a manner that the individual can reasonably understand how the information will be used or disclosed.
- Tatangelo’s will not, as a condition of the supply of a product or service, require an individual to consent to the collection, use, or disclosure of information beyond that required to fulfill the explicitly specified and legitimate purposes.
- The form of consent sought by Tatangelo’s may vary, depending upon the circumstances and the type of information disclosed. Tatangelo’s will seek express consent when the information is likely to be considered sensitive. Implied consent will generally be appropriate when the information is less sensitive.
- An individual may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. Tatangelo’s will inform the individual of the implications of such withdrawal. In order to withdraw consent, an individual must provide notice to Tatangelo’s in writing.
PRINCIPLE #4 — LIMITING COLLECTION
The collection of personal information will be limited to that which is necessary for the purposes identified by Tatangelo’s. Information will be collected by fair and lawful means.
- Tatangelo’s collects personal information from its customers for the purposes described under Principle #2.
- Tatangelo’s may also collect personal information from such third parties as credit bureaus, employers or personal references or other third parties that represent that they have the right to disclose the information.
PRINCIPLE #5 — LIMITING USE, DISCLOSURE, AND RETENTION
Personal information will not be used or disclosed for purposes other than those for which it was collected, except with the consent of the individual or as otherwise required or permitted by law. Personal information will be retained only as long as necessary for the fulfillment of those purposes or as otherwise required or permitted by law.
- Tatangelo’s may collect, use or disclose personal information without the individual’s knowledge or consent in certain circumstances as described in Principle #3.1.
- Tatangelo’s may disclose a customer’s personal information to:
- another company for the provision of its services to that customer;
- a company involved in providing communications directory services;
- a person involved in the development, promotion, marketing or enhancement of Tatangelo’s services;
- a credit collections agency;
- emergency services in an emergency situation;
- a person, who, in the reasonable estimation of Tatangelo’s, is an agent of the customer;
- third party affiliates for administrative purposes (for example, customer billing, marketing, etc.); and
- any other third party, upon receiving the consent of the customer or as required by law.
Such disclosures may in some cases be to recipients outside of Canada.
- Tatangelo’s will retain personal information that has been used to make a decision about an individual long enough to allow the individual access to the information after the decision has been made, and, in the event of an access request or a challenge, long enough to exhaust any recourse an individual may have under the law.
PRINCIPLE #6 — ACCURACY
Personal information will be updated as necessary for the purposes for which it is to be collected and used.
- The extent to which personal information will be updated will depend upon the use of the information, taking into account the interests of the individual. Information will be sufficiently accurate, complete, and up-to-date to minimize the possibility that inappropriate information may be used to make a decision about the individual.
- Tatangelo’s will not routinely update personal information unless such a process is necessary to fulfill the purposes for which the information was collected.
- Personal information that is used on an ongoing basis, including information that is disclosed to third parties, will generally be accurate and up-to-date to the best of Tatangelo’s knowledge, unless limits to the requirement for accuracy are clearly set out.
PRINCIPLE #7 — SAFEGUARDS
Tatangelo’s will use reasonable efforts to protect personal information by security safeguards appropriate to the sensitivity of the information.
- Tatangelo’s has invested and deployed a wide variety of technology and security features to ensure the privacy of personal and anonymous information on its network. In addition, Tatangelo’s has implemented strict operations guidelines to safeguard customer privacy at every level of its organization. Tatangelo’s will continue to revise policies and implement additional security features as new technologies become available. Unfortunately, no system is perfect; therefore, Tatangelo’s makes no representations or warranties with regard to the sufficiency of these security measures. Tatangelo’s shall not be responsible for any actual or consequential damages (or any other damages or liability of any kind whatsoever, whether as a result of negligence or otherwise) that result from a lapse in compliance with this Policy because of a security breach or technical malfunction.
- Tatangelo’s protects all personal information regardless of the format in which it is held. The methods of protection include:
- physical measures, such as locked filing cabinets and restricted access to offices;
- organizational measures, such as security clearances and limiting access on a “need to know” basis;
- technological measures, such as the use of passwords and encryption.
PRINCIPLE #8 — OPENNESS
Tatangelo’s will, upon written request, make readily available to individuals specific information about its policies and practices relating to the management of personal information, other than confidential commercial information.
- Tatangelo’s will make its policies and practices with respect to the management of personal information comprehensible and accessible, by providing upon request:
- the name, title, and address of the Privacy Officer accountable for Tatangelo’s policies and practices and to whom complaints or inquiries can be forwarded;
- the means by which an individual can gain access to his or her personal information held by Tatangelo’s; and
- a description of the type of information held by Tatangelo’s and/or its subsidiaries, including a general account of its use.
PRINCIPLE #9 — INDIVIDUAL ACCESS
Upon written request, an individual will be informed of the existence, use, and disclosure of his or her personal information and will be given access to that information. An individual will be able to challenge the accuracy and completeness of the information and have it amended as appropriate.
- Upon written request, Tatangelo’s will inform an individual whether or not the organization holds personal information about that individual, and will provide that individual with a reasonable opportunity to review the personal information in his or her file.
- Tatangelo’s will allow the individual access to his or her personal information once the individual has provided Tatangelo’s with a written request application. The application will include sufficient information to permit Tatangelo’s to provide an account of the existence, use, and disclosure to any third parties of this personal information. Tatangelo’s will use the application only for this purpose.
- Tatangelo’s will respond to an individual’s written request within 30 days, unless this period is extended in accordance with applicable legislation, in which case notice will be sent to the individual within 30 days regarding the extension, the reasons for it and the individual’s rights in connection with it. Tatangelo’s will assist any individual who informs it that they need assistance in preparing a request. While the response will typically be provided at no cost to the individual, depending on the nature of the request and the amount of information involved, Tatangelo’s reserves the right to impose a cost. In these circumstances, Tatangelo’s will inform the individual of the approximate cost to provide the response and proceed upon payment. The requested information will be provided or made available in a form that is generally understandable.
- Tatangelo’s will be as specific as possible in providing an account of third parties to which it has disclosed personal information about an individual. When it is not possible to provide a list of the organizations to which it has actually disclosed information about an individual, Tatangelo’s will provide a list of organizations to which it may have disclosed information about the individual.
- In certain instances, Tatangelo’s will not be able to provide the individual access to his or her personal information. Where permitted, the reasons for denying access will be provided to the individual. This will be done upon the individual’s request, unless Tatangelo’s is required by law to provide such written reasons. Exceptions to the grant of an access request may include: information that contains references to other individuals or contains confidential commercial information, where such information cannot be severed from the record; information protected by solicitor-client privilege; information properly collected without the knowledge or consent of the individual for purposes related to investigating a breach of an agreement or a contravention of law; information generated in the course of a formal dispute resolution process; and as required or permitted by law.
- When an individual successfully demonstrates the inaccuracy or incompleteness of personal information, Tatangelo’s will amend the information as required. Depending upon the nature of the information challenged, amendment may involve the correction, deletion or addition of information. Where appropriate, the amended information will be transmitted to third parties having access to the information in question.
- When a challenge is not resolved to the satisfaction of the individual, Tatangelo’s will record the substance of the unresolved challenge. When appropriate in Tatangelo’s judgment, the unresolved challenge will be transmitted to third parties having access to the information in question.
PRINCIPLE #10 — CHALLENGING COMPLIANCE
An individual will be able to address a challenge concerning compliance with the above principles to Tatangelo’s Privacy Officer.
- Tatangelo’s will maintain procedures to receive and respond to complaints or inquiries about its policies and practices relating to the handling of personal information.
- Tatangelo’s will inform individuals who make inquiries or lodge complaints of the existence of relevant complaint procedures.
- Tatangelo’s will investigate all complaints. If a complaint is found to be justified, Tatangelo’s will take appropriate measures, including, if necessary, amending its policies and practices.