01 — Risk-based approach
Protection reflects sensitivity and use.
We consider the amount, sensitivity, purpose, format, and number of people who may access information. Location, compensation, signature, and private job files require more restrictive handling than public marketing content.
No safeguard eliminates every risk. Our objective is to reduce the likelihood of unauthorized access, use, disclosure, loss, or alteration and to detect and address anomalies promptly.
02 — Service measures
Layered controls appropriate to the service.
- Access management
- Authentication and session controls protect accounts and functions.
- Company separation
- Logical controls restrict access to information belonging to the authorized company.
- Permissions
- Access follows role, task, and need to know and can be reviewed or removed.
- Private files
- Non-public content is limited to authorized people and functions.
- Sensitive operations
- Elevated access and administrative actions receive additional restrictions.
- Monitoring
- Relevant events may be retained to support service integrity, support, and incident analysis.
- Minimization
- Collection and display are limited to what is useful for the function and access level.
- Evidence and integrity
- Important approvals may retain reasonable context needed to establish what occurred.
03 — Customer responsibility
The best protection starts with individual accounts.
- Give each person an individual account and use stronger authentication for sensitive roles.
- Remove former employees, devices, and connections promptly.
- Assign the minimum role and regularly review supervisors and administrators.
- Avoid unnecessary sensitive information in notes, photos, or messages.
- Protect devices with a passcode, supported updates, and automatic locking.
- Verify recipients before sending a message, estimate, or export.
- Report suspicious login, incorrect disclosure, or device loss immediately.
04 — Privacy incidents
Contain, assess, document, and notify.
An incident may involve unauthorized access, use, disclosure, loss, or another failure to protect information. Our process aims to confirm scope, contain access, preserve useful evidence, correct the cause, and reduce recurrence.
The assessment considers sensitivity, possible consequences, and likelihood of harmful use. Where a risk of serious injury exists, Fondation Flow and the Customer coordinate required notices to the Commission d’accès à l’information and affected individuals according to their roles.
Personal-information incidents are recorded for the period required by applicable law, including at least five years where Quebec law requires it.
05 — Report a concern
Precise reporting helps protect everyone.
Report a vulnerability or incident with the affected page or function, date, observed steps, and a safe way to reach you. Do not download another company’s data, expand access, or perform disruptive testing. Do not include passwords, secret keys, full identity documents, or unnecessary sensitive information in the first message.
Privacy officer
A question, complaint, or access request?
Write to Fondation Flow’s privacy officer. We may need to confirm your identity before disclosing or correcting information.