PRIVACY NOTICE
1 - Your personal information is precious
We, MRa and its affiliates, are doing everything we can to protect the personal information you entrust to us. That is why we are committed to continually reassessing our practices, keeping them up to date and in line with high standards regarding your privacy and management of your personal information.
2 - What we are doing to protect your personal information
First and foremost, what constitutes personal information? It is information that concerns you and can be used to identify you or your dependents, directly or indirectly.
2.1 - We operate on the basis of 4 important principles
The following principles govern how we ensure your privacy.
- Ensure secure management. We implement good management and safeguard practices to secure your personal information and oversee its use.
- Respect your rights. You have rights related to the personal information we hold about you. You may exercise them at any time.
- Be transparent. We provide you with all relevant information about our privacy practices.
- Act responsibly. Our employees, suppliers and representatives (including our financial services advisors) must comply with our privacy practices. Our Privacy Officer ensures that they do and that our practices are always up to date.
2.2 - We only collect personal information that is necessary
From whom do we collect your personal information?
We collect your personal information primarily from you. We may also collect it from others, depending on the circumstances and the products or services you have with us. For example:
- Your employer
- Your professional association or board
- Public entities
- Our representatives
- Personal references
- Credit bureaus and reporting agencies
- Other insurers, reinsurers or financial institutions
- Public and private insurance, fraud and claims databases
- Partners who distribute our products and services, such as independent brokers, specialized insurance coverage providers, travel agencies or car dealerships
A person who has or wishes to obtain a product or service from us may also disclose your personal information to us so that you can benefit from that product or service. For example, this person could add you as an insured person.
How do we collect your personal information?
We may collect your personal information in a number of ways, including:
- By phone
- In person
- Via our paper and online forms
- Via cookies, when you visit our websites
What personal information do we collect?
We only collect the personal information necessary to fulfill the purposes outlined in this notice.
Here are some examples of personal information we may collect.
Categories | Examples |
Identification information | Name, date of birth, postal address, email, phone number, marital status, government identifiers (passport number, driver’s licence number, etc.), social insurance number, citizenship, country of birth |
Financial information | Income, salary, financial report, investments, information on financial products you have with us or elsewhere, investor profile, rent, mortgage, bank account, credit history and score |
Health information | Medical records, medical information related to your claims, paramedical test results, medical history |
Insurance information | Information on insurance policies you have with us or elsewhere, claims history, sex at birth, lifestyle habits, criminal record |
Employment information | Employment status, current employer, former employers |
Information about your family | Name, age, financial situation and health status of your spouse, children or parents |
We may also create or infer information from the personal information we collect. For example, we may create a client profile or identifier for you. This information is considered personal information. We manage and protect it in accordance with the same practices as the rest of your personal information.
2.3 - We collect your personal information for specific purposes
We collect, use, disclose and retain your personal information solely for the purposes outlined in this notice. We will inform you of the intended purposes at or prior to the time we collect your personal information.
The following purposes may be essential to our relationship with you, depending on the products and services you request:
Categories | Specific purposes |
Know who you are |
|
Build a relationship with you |
|
Maintain our relationship with you |
|
Comply with laws and manage risk |
|
Some purposes are optional for doing business with us. You can consent to them to benefit from a distinctive client experience and to obtain offers tailored to your needs.
We must obtain your separate consent to collect, use, disclose and retain your personal information for the following purposes:
Categories | Specific purposes |
Improve our products and services and provide a distinctive client experience |
|
Keep you informed of our promotions, products, services, contests and events that may be of interest to you |
|
2.4 - We may share your personal information with other individuals or organizations
To whom may we disclose your personal information?
In order to fulfill the purposes outlined in this notice, we may sometimes need to share your personal information with other individuals or organizations.
For example, we may share it with the following third parties:
- Your financial services advisor
- Your insurer
- Your employer, union or association
- A person who has a product or service with us from which you are benefitting
- Other MRa entities and their representatives
- Credit bureaus and reporting agencies, such as Equifax or TransUnion
- Public and private insurance, fraud and claims databases
- Public entities, such as the Société de l’assurance automobile du Québec or health care institutions
- Other insurers, reinsurers and financial institutions
- Your employer, union or association
- Partners who distribute our products and services, such as independent brokers, general agents, specialized insurance coverage providers, travel agencies or car dealerships
- Suppliers, for example of document printing, delivery or data storage services
- Courts, regulatory authorities or self-regulatory organizations
- Fraud prevention and management organizations, for example, law enforcement agencies
We may disclose your personal information outside of Canada
We store your personal information primarily in Canada, but we may sometimes disclose it to parties outside of Canada. For example, if we are doing business with a supplier based in another country. In this case, we contractually ensure that our supplier meets our expectations in terms of managing and protecting your personal information. Before we transfer your personal information outside of Canada, we ensure that it is adequately protected.
We may also disclose your personal information to another Canadian province or territory.
2.5 - We obtain your consent, except in certain cases prescribed by law
When do we obtain your consent?
We obtain your consent before we collect, use or disclose your personal information. We may obtain consent directly from you. It may also be obtained from another person, such as your financial services advisor, employer, car dealer, etc.
We will request your consent again if we wish to use or disclose your personal information for a purpose to which you have not consented.
When do we not request your consent?
In some cases, the law permits us to collect, use or disclose your personal information without your consent.
Here are a few examples:
- Disclosing your personal information to suppliers for a purpose outlined in this notice, to provide you with the requested product or service
- Conduct statistical studies using de-identified personal information, where permitted by law
- Take appropriate action if we detect potential fraud
- In Quebec only: Using your personal information if it is clearly for your benefit or for purposes related to those to which you have already agreed
- Outside of Quebec: Using or disclosing your personal information if it is clearly for your benefit and we are unable to obtain your consent
We may also be required by law to disclose personal information. For example, if ordered by a court or requested by a regulatory authority or a self-regulatory organization.
2.6 - We are doing everything we can to protect your personal information
Our employees, representatives and other stakeholders are committed to protecting your personal information. Our internal procedures clearly define the roles and responsibilities of each individual in the management of personal information of personal information.
We limit access to and use of your personal information
We keep access to your personal information to a minimum. Access to your personal information is restricted to those who need it to perform their duties.
Here are some of the measures in place to control access to and use of your personal information:
- We train our employees, representatives and consultants to handle your personal information with care and in accordance with best management practices. Our suppliers are obligated to do likewise.
- Our employees, representatives and suppliers may access and use personal information we collect only if we obtained consent for this purpose or if permitted by law.
- We regularly review the access rights of employees, representatives and suppliers, according to their roles and responsibilities.
We protect our facilities and IT systems
We have security measures in place to protect our IT platforms, facilities and systems. Your personal information is protected at all times by a multidisciplinary team, monitoring tools and state-of-the-art technological environments.
Here are some of the security measures in place:
Technological measures |
|
Physical or administrative measures |
|
We communicate with you in a secure manner
We have measures in place to ensure the security of our communications with you, including when we collect your personal information.
Here are some examples of these security measures:
- We always verify your identity, whether online, by phone or in person. Other than to authenticate you, we avoid collecting certain personal information over the phone, such as your date of birth or social insurance number.
- We will never ask you for your password or PIN code.
- We will not contact you for the sole purpose of obtaining your personal information.
2.7 - We retain your personal information for a limited time
We retain your personal information only as long as necessary to:
- Fulfill the purposes for which we collected it, and
- Meet our legal obligations
We have implemented a retention schedule. It guides us as to how long we should keep each type of personal information, depending on the context. We destroy personal information once the retention period has elapsed. The duration of this period depends, among other things, on our legal and regulatory obligations and on the time needed to protect our rights in the event of legal recourse.
We may anonymize certain personal information before destroying it and retain a copy. Once the information is anonymized, it can no longer be used to identify you and is therefore no longer deemed personal. We use it, among other things, to improve our product pricing, identify trends and establish performance indicators.
2.8 - We respect your privacy rights
Manage your consent preferences
You may review and change your consent preferences for the collection, use and disclosure of your personal information at any time. Please be aware, however, that we will no longer be able to offer you our products and services if you withdraw your consent for a purpose that is essential to our relationship with you (See the section We collect your personal information for specific purposes for further details).
For optional purposes, you may withdraw your consent at any time without adversely affecting our relationship with you.
You can contact us at consentement.mra@cabinetmra.com to withdraw your consent for one or both of the following purposes:
- Improve our products and services and provide a distinctive client experience
- Keep you informed of our promotions, products, services, contests and events that may be of interest to you
Withdrawing your consent may take up to 30 days to be processed and applied.
Accessing, rectifying or deleting your personal information
You have several rights regarding the personal information we hold about you. You may exercise them at any time.
Know whether we hold personal information about you |
You can ask us:
|
Access your personal information |
You may ask to access the personal information we hold about you. You can also obtain a copy, but you may have to pay a reasonable fee for it. In some cases, we are unable to provide you with the requested information. For example:
|
Rectify your personal information |
You can request that we rectify your personal information if it is incomplete or inaccurate. You can also update it if it has changed. |
Delete your personal information |
You can request that we delete your personal information. Our response will depend on the situation. If we have fulfilled the purposes for which the personal information was collected, we will delete it. However, we may retain it in order to meet our legal and regulatory obligations and protect our rights in the event of legal recourse. If we have not yet fulfilled the purposes for which the personal information was collected, we will delete the information that is out of date, inaccurate, incomplete or no longer required. If you request that we delete the rest of your personal information, we will no longer be able to offer you our products and services. |
You may submit a written request to exercise any of your rights in relation to your personal information. You will receive our written response within 30 days. If we deny your request in whole or in part, we will provide you with several pieces of information:
- Reasons for the denial
- The references of the laws and regulations that justify this denial
- Your right to challenge this denial before the privacy regulatory authority of your province or territory
- Timeframe for appealing the denial
Filing a complaint
You may file a complaint if you feel that we have mishandled your personal information.
We invite you to contact us first if you wish to file a complaint. We will take the time to analyze your complaint and work with you to resolve the situation.
You can also file a complaint with the privacy regulatory authority of your province or territory.
3 - How to contact us regarding your privacy
You can contact us in writing at the addresses below to:
- Submit a request to access, rectify or delete your personal information
- File a complaint about the handling of your personal information
- Request assistance, send us a comment or ask any question related to your privacy
Make sure you provide us with all the information we need to follow up on your request.
By mail:
Privacy Officer
Michel Rhéaume et Associés
7171 Jean Talon Street East, Suite 301
Montreal (Quebec) H1M 3N2
4 - If we update this notice
We regularly update our practices to bolster them and ensure that they reflect changing privacy laws, regulations and standards. We will notify you on our website of any material changes to this notice.