ANDREWS & CO. CHARTERED ACCOUNTANTS ("Andrews") recognizes the importance of privacy and the sensitivity of personal information.
Principle #1: Accountability
Principle #2: Identifying Purposes
The purposes for which we collect personal information will be identified at or before the time the information is collected. These purposes presently include: day to day operations of Andrews including, but not limited to, providing professional accounting services; Retention of information as required by various statutes of law and the Institute of Chartered Accountants of Ontario and any other relevant professional organization. Any new purposes will be identified prior to use for those purposes. Your consent will be obtained for the new uses, except where such uses are required by law.
Principle #3: Consent
Your knowledge and consent are required for the collection, use or disclosure of personal information, except where inappropriate. We will specify the reasons for collection, use or disclosure. Your consent may be obtained, depending on the particular information and circumstances, orally or in writing, implied or expressed. Where information is sensitive we will obtain express consent. Our engagement letters set out our responsibility to obtain any consents required under applicable privacy legislation, for collection, use and disclosure to us of personal information. By signing such engagement letters, you are formally acknowledging this consent.
Principle #4: Limiting Collection
The collection of personal information will be limited to the amount and type necessary for our purposes. The information will be collected by fair and lawful means. Wherever possible we will collect your personal information directly from you in the ordinary course of conducting our business.
Principle #5: Limiting Use, Disclosure and Retention
Your personal information shall not be used or disclosed for purposes other than those for which it was collected, except with your consent or as required by law. We use your personal information to provide and market our services to you and to administer your account with us. If you advise us that you no longer wish to receive information about our services we will not send any further material. Andrews does not disclose your personal information to any third party to enable them to market their products or services. Whenever we disclose your personal information to third parties for the purpose of providing services to us, we require such parties to maintain levels of confidentiality and security that are equivalent to our own practices. Your personal information shall be retained only for as long as is necessary to complete the purposes for which it was collected, or as long as required by law or professional obligation. Personal information that is no longer required is discarded or destroyed using methods that protect your privacy (e.g. by paper shredding and/or deletion of electronic files).
Principle #6: Accuracy
The personal information managed by Andrews shall be as accurate, complete and up-to-date as is necessary for the purposes for which it is being used. If any of your personal information changes, we require details of those changes for our own uses and for the uses of third parties to whom such information is disclosed.
Principle #7: Safeguards
Andrews takes all reasonable precautions to ensure that your personal information is kept safe from loss, unauthorized access, modification or disclosure. Among the steps taken to protect your information are:
• Premises security;
• Restricted file access to personal information;
• Deploying technological safeguards such as security software and firewalls to prevent hacking or unauthorized computer access;
• Internal password and security policies.
Principle #8: Openness
Privacy Officer David Brighten 540 Lacolle Way , Ottawa, ON K4A 0N9 Phone: 613-837-8282 Fax: 613-837-7482
Principle #9: Individual Access
Upon request, Andrews will provide you with details of the existence, use and disclosure of your personal information and will provide you with reasonable access to that information. You will be able to amend any of the information for accuracy and completeness. For access to your personal information contact the Privacy Officer by the means indicated in section 8 above.
Principle #10: Challenging Compliance