Legal
Privacy policy
How NSI North America collects, uses and retains personal information.
Draft — not for publication
The headings below are the structure a policy needs to satisfy PIPEDA in Canada, Quebec's Law 25 and applicable United States state privacy law. The text under each must be drafted or approved by counsel before launch.
Contents
01Who we are
02Information we collect
03How we use it
04Legal basis and consent
05Disclosure to third parties
06Transfers outside Canada
07Retention
08Your rights
09Security
10Cookies and analytics
11Contact and complaints
Privacy enquiries
privacy@nsi-adit.com
01
Who we are
The legal entity, its registered address, and the group relationship to NSI and the ADIT Group.
02
Information we collect
Enquiry-form submissions, correspondence, briefing-list subscriptions, and technical data collected automatically when the site is used.
03
How we use it
Responding to enquiries, delivering the briefing, meeting our own registration and disclosure obligations, and administering the site.
04
Legal basis and consent
The basis relied on for each purpose, and how consent is obtained, recorded and withdrawn.
05
Disclosure to third parties
Circumstances in which information is shared within the group, with service providers, or where required by law.
06
Transfers outside Canada
Processing by group offices and providers in the United States and Europe, and the safeguards applied.
07
Retention
How long each category of information is kept, and the criteria used to decide.
08
Your rights
Access, correction, deletion, portability and withdrawal of consent, and how to exercise each.
09
Security
The organisational and technical measures protecting personal information, and the incident-notification process.
10
Cookies and analytics
What is set, what it is used for, and how preferences are managed.
11
Contact and complaints
The privacy contact, and the route to the Office of the Privacy Commissioner or the relevant state authority.
Last updated — to be set on publication
