Personal information governance

Our governance policies and practices, published under section 3.2 of the Act respecting the protection of personal information in the private sector

Last updated: July 30, 2026

The Act respecting the protection of personal information in the private sector ("Law 25") requires every enterprise to establish policies and practices governing the personal information it holds, and to publish detailed information about them in clear and simple language. This page is that publication. It sets out what we have adopted, who answers for it, and what you can hold us to. What we collect and why is in our Privacy Policy; hosting and encryption are on our Security page.

1. What we have adopted

Four procedures drafted by our external legal counsel, plus a retention schedule, have been in force since July 30, 2026. They apply across the organization and are reviewed at least once a year.

  • Privacy incident response procedure How a report reaches us, how we determine whether it is an incident, how we assess the risk of serious injury, and who we notify.
  • Register of confidentiality incidents An internal register where every incident is recorded, including those we conclude carry no risk of serious injury — together with the reasoning behind that conclusion. Kept for at least 5 years from the date we became aware of it.
  • Notice template for affected individuals The template for the notice you would receive if an incident presented a risk of serious injury to you: what was affected, when, what we are doing, what you can do.
  • Complaints handling procedure How to file a complaint about the handling of your personal information, and what happens next.
  • Retention and destruction schedule The period applicable to each category of information and the reason that justifies it. It mirrors section 5 of the Privacy Policy.

2. Who answers for it

The law requires that a person be designated as responsible for the protection of personal information, and that their identity be published. At CondoAide, that is the president.

  • Name: Nicolae Racovita, president of Solutions Nicvi inc. (CondoAide)
  • Title: Person Responsible for the Protection of Personal Information
  • Email: privacy@condoaide.ca
  • Mailing address: 4143 chemin Ste-Angélique, Saint-Lazare (Quebec) J7T 2N5, Canada
  • Roles across the whole life cycle of the information: CondoAide is a small organization and the person responsible currently holds every role — collection, access, retention, destruction, incident response and complaints handling. Anyone acting for the organization must relay any report to them without delay and cooperate in handling the file. Internal access to a syndicate's data is limited to a specific operational need, logged, and subject to confidentiality agreements.
  • This person receives access and rectification requests, incident reports and complaints. They report annually to management and maintain the incident register.

3. If there is a privacy incident

A confidentiality incident is unauthorized access to, use of, or disclosure of personal information, or its loss. Here is what happens.

  • We record it. Every incident is entered in the register, whether or not it carries a risk.
  • We assess the risk of serious injury based on the sensitivity of the information, possible malicious uses, anticipated consequences, and the likelihood the information is used for harmful purposes.
  • If there is a risk of serious injury, we notify the Commission d'accès à l'information du Québec and the individuals concerned, as promptly as possible. Our internal target is 72 hours after confirming the incident — a target we set ourselves, not a deadline fixed by Quebec law, which speaks of diligence instead.
  • We take the measures needed to manage the incident, limit the injury and prevent recurrence, and we record those measures.
  • We cooperate with privacy authorities in the event of an investigation.
  • If one of our providers suffers an incident affecting your information, they must notify us without delay; we then run the steps above.

4. Your requests and complaints

Write to privacy@condoaide.ca. You do not have to give a reason for an access request or use any particular form.

  • Access or rectification request Written response within 30 days of receiving the request.
  • Complaint — acknowledgement Within 15 days of receipt. If the complaint appears inadmissible we tell you why; if it instead reveals a confidentiality incident, we explain how it will be handled.
  • Complaint — decision No later than 90 days after the complaint is received.
  • If our answer does not satisfy you You may complain to the Commission d'accès à l'information du Québec (cai.gouv.qc.ca), or to the Office of the Privacy Commissioner of Canada (priv.gc.ca) if you live outside Quebec. We ask for the chance to put things right first, but that is not a condition.

5. Privacy impact assessments

The law requires a privacy impact assessment (PIA) before certain projects — notably acquiring, developing or redesigning a system that processes personal information, and any communication of information outside Quebec.

  • We maintain an internal PIA, structured by provider and by feature, and update it on every material change and at least once a year.
  • Flows that leave Quebec are listed in section 3 of the Privacy Policy, with the categories of information and the location of each provider.
  • Every provider that processes personal information on our behalf is bound by a written agreement covering confidentiality, use limited to the mandate, and what becomes of the information when the mandate ends.
  • A PIA is not a declaration of compliance: it is an analysis of residual risk, with the measures that bring it to a level we judge acceptable.

6. Retention and destruction

We destroy personal information once the purpose it was collected for has been fulfilled, except where a law requires us to keep it longer. Every period we apply is written down and justified.

  • The breakdown by category is in section 5 of the Privacy Policy.
  • The 7-year periods there are fiscal and accounting in origin; they deliberately exceed the regulatory floor for pre-authorized debit mandates, and we own that choice for that reason.
  • The incident register is kept for at least 5 years from the date we became aware of the incident.
  • After deletion in production, copies may persist in our backups for up to 30 days before rotation and destruction.

7. Review

The procedures, the retention schedule and this page are reviewed at least once a year, and on every material change — a new provider, a new feature processing personal information, a new flow outside Quebec, or a change in the law. The next annual review is scheduled for July 30, 2027.

8. Contact us

For any question about this page, to exercise a right, to report an incident or to file a complaint:

Person Responsible for the Protection of Personal Information: privacy@condoaide.ca

General support: support@condoaide.ca

Mailing address: CondoAide, 4143 chemin Ste-Angélique, Saint-Lazare (Quebec) J7T 2N5, Canada