• EN
  • FR
  • ES

Privacy Policy

In accordance with Act 25 (CQLR, c. P-39.1)

CERAASA / ASTECAA

Effective as of: July 27, 2026

1. Governance Framework

CERAASA / ASTECAA takes its responsibilities regarding the protection of personal information seriously by ensuring appropriate governance in matters of privacy. It applies the standards set out in the Act respecting the protection of personal information in the private sector (Act 25) and acts transparently toward the users of its services.

2. Legal Framework

This policy sets out how CERAASA / ASTECAA applies the provisions of the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), as of December 1, 2023.

3. Scope

This policy applies to personal information provided by users to CERAASA / ASTECAA, whether through the website, forms, or in the course of its activities.

4. Personal Information

Personal information refers to information that relates to a natural person and allows that person to be identified, directly or indirectly. For example, the following are considered personal information about a user: name, gender, age, date of birth, phone number, mailing address, email address, banking information, credit card number, IP address, and photo.

5. Consent

Unless a legal exception applies, no personal information will be collected without first obtaining the user's clear, free, informed, and specific consent. This consent may be withdrawn at any time.

When a user consents, their personal information is used by CERAASA / ASTECAA solely for the purposes set out in this policy. If a user declines to consent, their information will only be used to communicate with them, unless a legal provision permits otherwise.

In certain limited cases, consent may be implied, provided the information given to the user is clear, accessible, and understandable. Consent may be withdrawn at any time.

6. Collection of Personal Information

CERAASA / ASTECAA collects, verbally or in writing, from each user, the information necessary to:

  • Communicate with users and identify their needs;
  • Provide services, products, and information;
  • Allow partners and suppliers to offer relevant products or services;
  • Manage the relationship with the user;
  • Comply with its legal obligations.

The organization also uses the following tools, which may collect data automatically:

  • WordPress — website management platform (technical data and cookies);
  • Umani Cookie Control — cookie consent management (Google Consent Mode v2);
  • Fluent Forms — processing of contact and registration form submissions;
  • hCaptcha — anti-spam verification on the contact form.

These tools may host or process data outside Quebec. In such cases, a privacy impact assessment is carried out beforehand, as required by Act 25.

The contact forms on the site include a reference to this policy to inform users at the time of collection, in accordance with the transparency obligations under Act 25.

7. Disclosure of Personal Information

CERAASA / ASTECAA keeps personal information confidential and discloses it to third parties only in accordance with this policy and the Act.

It may, from time to time, share a list of users' names (name, address, email, phone number) with partners, provided that:

  • A contract exists with the partner specifying the exclusive use of the data;
  • An opt-out option has been offered to the user, simple and free of charge;
  • It does not infringe on privacy.

Users may refuse to have their information included on these lists by writing to:

[email protected]

No data is transferred outside Quebec without a risk assessment and a guarantee of equivalent protection.

8. Accuracy and Retention of Personal Information

CERAASA / ASTECAA ensures that the personal information it holds is accurate, up to date, and complete. If errors are found, the organization will contact the user to correct the information and will inform any third parties concerned, if applicable.

Personal information is retained only for as long as necessary for the purposes for which it was collected. Once that period has elapsed, the data is securely destroyed, deleted, or anonymized.

9. Protection of Personal Information

CERAASA / ASTECAA applies administrative, technological, and physical security measures to protect information against loss, theft, unauthorized access, or disclosure.

This includes, in particular:

  • IT security measures;
  • Restricted access systems;
  • Confidentiality agreements with employees and suppliers.

Contractual agreements with technology suppliers specify security and confidentiality obligations.

10. Access and Rectification

Any user may:

  • Request access to their personal information;
  • Have inaccurate or outdated information corrected;
  • Have unnecessary data deleted.

Requests must be sent in writing to the address of the person in charge (see section 11).

CERAASA / ASTECAA will respond within 30 days. In case of refusal, the reasons will be communicated in writing, along with the available recourses.

11. Person Responsible for the Protection of Personal Information

The person responsible for the protection of personal information is:

Name: Marc M.

Title: Webmaster

Email: [email protected]

12. Amendments to the Policy

CERAASA / ASTECAA reserves the right to amend this policy at any time. In the event of a significant change, users will be notified by email or by a notice on the website. When required, new consent will be requested.

13. Privacy Impact Assessment (PIA)

Before any project involving personal information, CERAASA / ASTECAA carries out a privacy impact assessment (PIA), particularly in the following cases:

  • Implementation or modification of a computer or cloud-based system;
  • Transfer of data outside Quebec;
  • Use of third-party platforms (e.g., Google Analytics, CMS, marketing tools);
  • Projects likely to have a significant impact on privacy.

The findings of this assessment allow appropriate security and compliance measures to be adopted before the project is implemented.