- Home
- »
- Privacy Policy
Privacy Policy
Our Commitment to Your Privacy
ABM Canada provides regulatory compliance, risk management, and training services to banks, financial institutions, and other regulated businesses. Handling information carefully is central to that work, and we apply the same standard to the personal information we hold about the people who visit our website, contact us, and work with us.
This policy explains what personal information we collect, why we collect it, how we use and protect it, and the rights you have over it. It applies to our website and to the professional services we deliver.
We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, including Quebec’s Act respecting the protection of personal information in the private sector and the Personal Information Protection Acts of Alberta and British Columbia.
Information We Collect
We collect only the personal information we need for the purposes described in this policy.
Information you provide directly
- Name, job title, employer, and professional contact details
- Email address, telephone number, and correspondence with us
- Information submitted through contact forms, service enquiries, or training registrations
- Details you share when scoping or receiving an engagement
- Billing and payment information where you engage our services
Information we collect automatically
- IP address, browser type, device type, and operating system
- Pages visited, time spent, and referring website
- Cookie and analytics data, as described below
Information we receive during engagements
Where we deliver compliance, audit, review, or advisory services, we may receive personal information contained in our client’s records. This can include information about our client’s own customers, employees, or counterparties. In these cases we act on our client’s instructions and handle that information under the terms of our engagement agreement and this policy.
Why We Collect Personal Information
We use personal information for the following purposes:
- To respond to enquiries and provide the information you request
- To deliver, manage, and improve our consulting and training services
- To administer engagements, including scoping, reporting, and invoicing
- To maintain client records and meet our professional obligations
- To send service updates, regulatory alerts, and marketing communications where you have consented
- To operate, secure, and improve our website
- To comply with legal, regulatory, and record-keeping obligations that apply to us
We do not sell personal information, and we do not use it for automated decision making that produces legal or similarly significant effects.
Consent
We collect, use, and disclose personal information with your knowledge and consent, except where the law permits or requires otherwise. Consent may be express, for example when you submit an enquiry form or subscribe to updates, or implied, for example when you provide contact details in the course of an engagement.
You may withdraw your consent at any time, subject to legal and contractual restrictions and reasonable notice. Withdrawing consent may mean we can no longer provide certain services. Where we hold information under a legal retention obligation, withdrawal of consent does not remove that obligation.
Disclosure of Personal Information
We do not sell, rent, or trade personal information. We may disclose it in the following circumstances:
- Service providers. We use third parties for functions such as website hosting, email delivery, secure file transfer, and accounting. They may access personal information only as needed to perform their function and are bound by confidentiality and privacy obligations.
- Professional advisers. Legal, insurance, and audit advisers where necessary.
- Legal and regulatory requirements. Where disclosure is required by law, court order, or a lawful request from a regulator or law enforcement authority.
- Business transactions. In connection with a merger, acquisition, or reorganisation, subject to appropriate safeguards.
Where we act for a client on a compliance engagement, any reporting obligation to a regulator, including reporting to FINTRAC, rests with the client as the reporting entity. We support clients in meeting those obligations, and we do not assume them on a client’s behalf.
Storage, Transfers, and Cross Border Processing
Personal information may be stored or processed by service providers located outside Canada. Where that happens, the information may be subject to the laws of the jurisdiction where it is held, including lawful access requests by authorities in that jurisdiction. We take reasonable steps, including contractual protections, to ensure a comparable level of protection.
If you would like more information about our practices regarding service providers outside Canada, contact our Privacy Officer using the details below.
How Long We Keep Information
We keep personal information only as long as necessary for the purposes it was collected, or as required by law.
Retention periods vary by record type. Engagement files and related records are generally retained for the period required by our professional, contractual, and legal obligations. Certain records connected to work under Canadian anti money laundering legislation are subject to statutory retention requirements, and we retain these for the full period the legislation requires even if you ask us to delete them sooner. When information is no longer needed, we securely destroy, erase, or anonymise it.
Safeguards
We protect personal information with safeguards appropriate to its sensitivity, including:
- Access controls limiting information to staff who need it
- Encryption in transit and at rest for sensitive material
- Secure file transfer for client documentation
- Confidentiality obligations binding all personnel
- Physical security controls for premises and stored records
- Periodic review of our security practices
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do, however, maintain procedures to identify, contain, and respond to security incidents.
Privacy Breaches
If we become aware of a breach of security safeguards involving personal information under our control, we assess whether the breach creates a real risk of significant harm. Where it does, we report the breach to the Office of the Privacy Commissioner of Canada, notify affected individuals as required, and keep a record of the incident in accordance with our legal obligations.
Cookies and Website Analytics
Our website uses cookies and similar technologies to operate the site, remember your preferences, and understand how visitors use our pages.
- Necessary cookies allow core functions such as page navigation and form submission
- Analytics cookies help us understand which pages are useful and where the site can be improved
- Preference cookies remember choices you make
You can control cookies through your browser settings, and disabling some may affect how parts of the site work. Where required, we ask for consent before setting non-essential cookies.
Marketing Communications
Where you have consented, we may send you regulatory updates, service information, and training announcements. Every marketing message includes a way to unsubscribe, and you may opt out at any time by using that link or contacting us directly. We send commercial electronic messages in accordance with Canada’s Anti-Spam Legislation.
Opting out of marketing does not stop administrative messages relating to a service you have engaged us to provide.
Your Privacy Rights
Subject to legal limits, you have the right to:
- Access the personal information we hold about you and be told how it has been used and to whom it has been disclosed
- Correct information that is inaccurate or incomplete
- Withdraw consent to further collection, use, or disclosure
- Ask questions about our privacy practices and raise a concern
- Request deletion of information we no longer have a legal or business reason to keep
We respond to written requests within thirty days, or tell you if we need more time and why. There are circumstances where we cannot provide access, for example where doing so would reveal personal information about another person, breach solicitor client privilege, or conflict with a legal obligation. If we refuse a request, we explain why.
Depending on where you live, you may have additional rights under provincial privacy legislation. Residents of Quebec, for example, have specific rights relating to the portability of personal information and to being informed about automated processing.
Information About Third Parties
Where a client provides us with personal information about their own customers, employees, or counterparties, the client remains responsible for having a lawful basis for that disclosure. We process the information under the client’s instructions and for the purposes of the engagement only.
If you believe an organisation has provided us with your personal information and you want to know more, contact that organisation directly. You may also contact our Privacy Officer, who will direct you appropriately.
Links to Other Websites
Our website may link to third party sites, including regulator and industry pages. We are not responsible for the privacy practices or content of those sites, and we encourage you to read their privacy policies.
Children
Our website and services are directed to businesses and professionals. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
Changes to This Policy
We review this policy periodically and may update it to reflect changes in our practices or in the law. The current version is always posted on this page with the date it was last updated. Material changes will be brought to your attention where appropriate.
Contact Us
Our Privacy Officer is responsible for our compliance with this policy and with applicable privacy legislation. To ask a question, request access to your information, or raise a concern:
Privacy Officer ABM Canada 7-2070 Harvey Ave. Unit #164 Kelowna, BC V1Y 8P8, Canada
Email: info@abmglobalcompliance.ca
Telephone: +1 (604) 245 5830
We take privacy concerns seriously and aim to resolve them directly. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca, or the privacy regulator in your province where one applies.