Skip to main content
Chasseur de Talents

Personal Information Governance Policy

Last updated: July 29, 2026

Section 3.2 of the Act respecting the protection of personal information in the private sector requires every enterprise to establish and publish rules governing the personal information it holds. This policy sets out the rules Sam7 applies internally.

1. Roles and responsibilities

The Privacy Officer (Person in charge of the protection of personal information) ensures compliance with the law, approves privacy impact assessments, handles access and rectification requests, maintains the incident register, and reports to management.

Persons with access to personal information in the course of their duties are individually designated, receive training, and are bound by a confidentiality undertaking.

Management allocates the necessary resources and integrates the protection of personal information into product design decisions.

2. Information lifecycle

Collection — purposes are determined before collection and recorded; only information necessary for those purposes is collected.

Use — limited to the determined purposes; any new use requires a new basis (consent or statutory exception).

Communication — governed by a written agreement; outside Québec, preceded by a privacy impact assessment.

Retention — according to the schedule published in the Privacy Policy.

Destruction or anonymization — once purposes are achieved, irreversibly and with documentation.

3. Privacy by design

Every new product, service, or information system involving personal information is subject to a privacy impact assessment from the design stage, in accordance with section 3.3 of the Act.

The settings providing the highest level of confidentiality are enabled by default, without any action on your part: non-persistent session, no non-essential tracker, strict partitioning by organization, exclusion of photographs from automated processing.

4. Security and access control

Access granted on the least-privilege principle and reviewed periodically · identity verified securely on every request · robust encryption in transit and at rest, with additional layers of protection on sensitive fields · logging of sensitive actions · encrypted and tested backups.

5. Incident management

Every confidentiality incident — unauthorized access, use, or communication, or loss of personal information — is recorded in the incident register, retained for five (5) years.

We take reasonable measures without delay to reduce the risk of injury and prevent recurrence. Where the incident presents a risk of serious injury, we promptly notify the Commission d’accès à l’information and the persons concerned.

The seriousness assessment takes into account the sensitivity of the information, the anticipated consequences, and the likelihood of it being used for a harmful purpose.

6. Complaint handling

Any complaint about the processing of personal information is sent to contact@chasseurdetalents.com, recorded, and handled within thirty (30) days.

The response sets out the grounds and, in the event of refusal, indicates the avenues of recourse — internal review by a different person, then application to the competent authority.

7. Training and review

The persons concerned receive training upon taking up their duties and an update whenever there is a significant legislative change.

This policy is reviewed at least once a year, and whenever there is a material change to the Service or to the legal framework.