Privacy policy

1. Person responsible for the protection of personal information

Geneviève Bauer — Person responsible for the protection of personal information — Planisource Inc.

2000 McGill College Avenue, 6th floor

Montréal, Québec H3A 3H3

Email: genevieve.bauer@planisource.com.

2. The firm's commitment

Our firm is committed to protecting its clients' personal information in accordance with the Act respecting the protection of personal information in the private sector. To this end, it has adopted and implemented a personal information governance policy that governs the collection, use, retention and destruction of information.

This policy is reviewed regularly to ensure its compliance with legislative developments and best practices in data protection.

3. Collection and use of personal information

We limit the collection, use and retention of personal information to what is strictly necessary to provide our financial services and financial products, in accordance with the principle of data minimization.

Before any information is collected, clients are informed in writing of the purposes of collection, the means used, their rights of access and correction, and their right to withdraw their consent.

When required by law, consent will be obtained in a clear and specific form before any new use of personal information for a different purpose.

Information is used only for the purposes specified when it was collected, particularly to carry out the mandate entrusted by the client, such as financial planning, or to purchase an insurance or investment product, unless otherwise authorized by law.

Access to personal information is strictly restricted to employees and representatives whose duties require it. Access is granted on a need-to-know basis and is subject to regular checks to prevent unauthorized access.

Any change in the use of information will be communicated to the client. New consent will be required only if the modified use departs from the originally intended purposes or is not necessary to provide the requested service.

4. Access to and correction of personal information

Clients have the right to access their personal information. They may also request a copy in a structured and commonly used format, under their right to data portability. Where applicable, reasonable copying and transmission fees may be charged.

Clients may also request the correction of their personal information.

All requests must be submitted in writing to the person responsible for the protection of personal information. A response will be provided within a maximum of 30 days.

In the event of a refusal, the client will be informed of the reasons and available remedies.

5. Disclosure of personal information

Information may be disclosed to third parties when necessary to carry out the mandate, provide a financial product or deliver the service requested by the client. When required by law, information may also be sent to the competent authorities.

All suppliers and subcontractors with access to personal information must comply with specific contractual data protection requirements, including confidentiality clauses and security commitments that meet the standards of Law 25.

Before any information is collected, clients are informed of the categories of third parties to whom information may or must be disclosed.

Personal information transferred or stored outside Québec and Canada may only be transferred or stored there if adequate protection safeguards are in place, equivalent to those required by Law 25. In this regard, the firm will conduct a personal information protection risk assessment (ERPRP) and implement adequate protection measures. These safeguards include strict contractual clauses and appropriate security measures.

A register of personal information transfers is kept up to date.

4. Security

We adopt physical, technological and organizational security measures to preserve the confidentiality of this data. These measures include:

  • Physical security: Restricted access to premises and secure archiving of paper documents.
  • Technological security: Data encryption, password protection, two-factor authentication and firewalls.
  • Organizational security: Regular employee training, control of access to information and ongoing risk assessment.

5. Retention and destruction of information

Personal information is retained only for the time necessary to provide the service or meet applicable legal and regulatory requirements, particularly those of the Act respecting the distribution of financial products and services and tax regulations. Once this period has elapsed, the data is securely destroyed.

Paper documents are destroyed by shredding, and electronic data is irreversibly deleted after the required retention period.

6. Handling of complaints and privacy breaches

Any complaint concerning the protection of personal information must be sent to the person responsible for the protection of personal information and will be handled diligently, and a response will be provided to the client within a maximum of 30 days.

In the event of a confidentiality incident, the person responsible for the protection of personal information will ensure that a risk assessment is carried out; if a risk of serious injury arises, she will notify the Commission d’accès à l’information du Québec and the individuals concerned as soon as possible.

A register of security incidents is maintained and accessible to regulatory authorities.

7. Training and awareness

Employees and representatives attached to the firm receive regular training on the protection of personal information and their legal obligations.

The firm periodically reviews its personal information protection policy to ensure its compliance with legal obligations and industry best practices

An internal policy governs the use of digital tools, including cloud services and tracking technologies (cookies, pixels, etc.).

8. Digital technologies and cloud storage

If personal information is used in an automated decision-making process, the client will be informed of the underlying logic, the significance and the anticipated consequences of this processing. An option for human intervention will be made available where possible.

Personal information collected through our website complies with privacy settings by default (essential cookies only, tracking disabled by default).

Any transfer of information outside Québec and Canada is subject to risk assessments and contractual obligations to ensure an adequate level of protection in accordance with Québec and Canadian laws.

9. Contact and information

We encourage our clients to contact our person responsible for personal information with any questions about the protection of their personal information at the following address:

Geneviève Bauer

2000 McGill College Avenue, 6th floor

Montréal, Québec H3A 3H3

Email: genevieve.bauer@planisource.com.

This policy will be reviewed annually or whenever a regulatory or organizational change requires it. Clients and employees will be informed of significant changes before they take effect.

Updated: February 2025

English translation of the original French policy (February 2025). HTML conversion and translation: October 2, 2026.

Shopping Basket