Skip to content
Agreely
FR EN English

Assurance Boréale

Personal information governance policy

Effective January 15, 2026 v1.0

Here, in plain and clear terms, is how Assurance Boréale governs the protection of personal information throughout its life cycle, in accordance with P-39.1 s. 3.2. The text below sets out, among other things, the retention and destruction framework, the roles and responsibilities of personnel, and the complaint-handling process.

  • The retention and destruction framework: how long personal information is kept, then its destruction or anonymization once the purposes are achieved.
  • The roles and responsibilities of the people involved across the life cycle of personal information.
  • The process for handling complaints about the protection of personal information.

This policy governs personal information in accordance with s. 3.2 of the Act respecting the protection of personal information in the private sector (as amended by Law 25).

1. Roles and responsibilities

The person in charge of personal information protection is: Marie-Claude Gagnon, Responsable de la protection des renseignements personnels - protection@assurance-boreale.example. They ensure this policy is followed across the entire life cycle of personal information and are the contact for individuals concerned and for the Commission d'accès à l'information.

2. Retention

Personal information is kept only for the time necessary to fulfil the purposes for which it was collected (s. 23). Retention periods are recorded by category and purpose.

3. Destruction and anonymization

Once the purposes are achieved, the information is destroyed or anonymized in accordance with s. 23. Information used to render a decision is kept for at least one year after the decision (s. 11, para. 2).

4. Security measures

We take the security measures necessary to ensure the protection of personal information; these measures are reasonable given, in particular, the sensitivity of the information, the purposes for which it is used, its quantity, its distribution and its medium (s. 10). They cover the entire life cycle of the information, from collection to its destruction, which is carried out securely. The main measures in place are: cloud hosting with Nordlys Cloud Services Ltd (Ireland, European Union), governed by a privacy impact assessment and contractual clauses ensuring equivalent protection.

5. Confidentiality-incident handling

Every confidentiality incident is entered in the register. Where it presents a risk of serious injury, the Commission d'accès à l'information and the individuals concerned are notified with diligence (ss. 3.5 to 3.8).

6. Complaint handling

Any complaint regarding personal information protection is addressed to the privacy officer, who acknowledges receipt and responds within a reasonable time.

7. Communication outside Quebec and assessments

Any communication of personal information outside Quebec is subject to a prior privacy impact assessment (s. 17). Projects to acquire, develop or redesign an information system or an electronic service delivery involving personal information are also subject to such an assessment (s. 3.3).

8. Training and internal access

Only persons whose duties require it have access to personal information. Staff are made aware of this policy.

Person in charge of the protection of personal information

Marie-Claude Gagnon, Responsable de la protection des renseignements personnels

protection@assurance-boreale.example

Exercise your rights

You may request access to your personal information, its rectification, or exercise any other right provided by law (P-39.1 s. 29).

Exercise a right

Current version: v1.0. Last updated on January 15, 2026.