Customer Data Privacy Policy (PIPEDA)
This policy establishes the mandatory framework for collecting, using, disclosing, retaining, and destroying customer personal information in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA). It applies to all customer-facing and back-office operations that handle personally identifiable information (PII).
Ryxen and its affiliates are committed to protecting the privacy of customer personal information in accordance with PIPEDA (S.C. 2000, c. 5). This policy outlines the ten fair information principles — accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance. Every employee, contractor, and agent who handles customer data must adhere to these principles. Non-compliance may result in disciplinary action up to and including termination of employment or contract.
The policy applies to all customer personal information collected, used, or disclosed in the course of commercial activities, including but not limited to: contact data, billing records, service history, technical support logs, and any unique identifiers linked to an individual. This document serves as the authoritative standard for privacy practices across all departments and operational units.
This policy applies to all Ryxen entities, subsidiaries, and divisions operating within Canada. It covers any individual or organization that provides personal information to Ryxen in the context of a commercial transaction, service agreement, or customer relationship. The policy also extends to third-party service providers, subcontractors, and data processors who handle customer information on behalf of Ryxen.
Explicitly included are: customer name, email address, phone number, billing and shipping addresses, payment card data (when stored or transmitted), account credentials, service usage logs, and any metadata that can be reasonably linked to an identifiable individual. This policy does not apply to anonymized or aggregate data that cannot be re-identified, nor to information collected solely for journalistic, artistic, or literary purposes.
- Valid Consent Required: Personal information shall only be collected, used, or disclosed with the knowledge and consent of the individual, unless an exception under PIPEDA applies (e.g., legal demand, emergency). Consent must be obtained in writing or via an equally verifiable electronic method and must be freely given.
- Limit Collection & Retention: Only information that is reasonably necessary for the identified purpose shall be collected. Retain personal information only as long as needed to fulfill that purpose, plus any legally mandated retention period. Destroy or anonymize data once the purpose is satisfied.
- Safeguards & Breach Response: Implement administrative, technical, and physical safeguards proportionate to the sensitivity of the data. Mandatory breach reporting to the Office of the Privacy Commissioner of Canada (OPC) and affected individuals as required by PIPEDA. Maintain a breach response log.
- Accuracy & Individual Access: Keep personal information accurate, complete, and up-to-date. Upon written request, provide an individual with access to their personal information held by Ryxen, and allow them to challenge its accuracy and completeness, all within 30 days.
- Openness & Transparency: Make the organization's privacy policies and practices readily available to customers via the corporate website, customer portals, and upon request. Designate a Chief Privacy Officer (CPO) responsible for compliance and inquiries.
- Chief Privacy Officer (CPO): Oversees PIPEDA compliance, approves privacy impact assessments, handles formal complaints, and acts as the primary contact for the OPC. Reviews policy annually.
- Department Heads / Managers: Ensure their teams receive annual privacy training, enforce data handling procedures, and report any privacy incidents to the CPO within 24 hours.
- All Employees & Contractors: Must complete mandatory privacy awareness training, handle customer data only for authorized purposes, and immediately report suspected breaches or policy violations.
- IT & Security Team: Implements technical safeguards (encryption at rest and in transit, access controls, logging), conducts periodic vulnerability assessments, and supports breach response forensics.
- Third-Party Data Processors: Must sign a data processing agreement (DPA) that contractually binds them to PIPEDA-equivalent standards and requires notification of any data breach within 48 hours.