Protecting Your Information
We meet or exceed all requirements under the HIPAA Privacy Rule in the USA, as well as Canada’s PIPEDA, PIPA, and FOIPPA legislation. All information in ePACT is stored in Canada, on secure servers in Toronto and Vancouver.
ePACT is SOC2 Type II-compliant, and works with 3rd-party auditors to review and assess privacy and security policies and practices. Organizations interested in ePACT can request copies of our Audit Reports here.
ePACT is fully compliant with Canadian Anti-Spam Legislation (CASL). We help organizations using our system make sure that they are too, by sending messages only to those people who have provided consent.
About the ePACT Services
The ePACT services, provided by ePACT Network Ltd. (“ePACT”/”we”/ “us”) and available via the www.epactnetwork.com website (the “ePACT Website”) or ePACT mobile application (the “ePACT Mobile Application”), enable registered users to build support networks of family, friends, caregivers and organizations, to store and exchange information, and to access communication tools for greater interaction and preparation in the course of their participation in programs and services offered by organizations registered with ePACT (including, for example a municipality, school or daycare), including in the event of an emergency (collectively, the “Services”).
The Services also enable authorized administrators within registered organizations to store and access information of registered users who have shared such information with the organization in the course of the organization’s provision of programs and services to such users.
Collection & Use of Personal Information
ePACT collects information in the following ways: 1) information you supply about yourself and others when registering or using the Services, including your dependants, your dependants’ legal guardians, and your emergency contacts; 2) information organizations or other individuals share about you (e.g. an individual who adds your name and contact information as an emergency contact to their ePACT account or information provided by a registered organization).
a) Registration information
When you sign up for the Services, you will be required to provide information including your full name, email address, a password that you select and, in some cases, additional profile information (as described below). We use this information to create and administer your ePACT account.
You may receive an invitation to join ePACT from organizations with whom you interact or have a relationship with (e.g. community programs, schools, municipalities, etc.). In order to send you this invitation, the organization provides ePACT with your (or your dependant’s) full name, email address, and in certain cases, the program(s) you are participating in, or the name of the neighbourhood or community where you reside. If you do not accept this invitation, we do not collect any other information from you. The organizations who collected such registration information from you have their own privacy policies and are responsible for treating your information in accordance with such policies. We require registered organizations to ensure that they have obtained all authority to provide personal information to us in accordance with applicable privacy laws.
You may also receive an invitation to join ePACT from family, friends, or other individuals who have added you to their support network. In order to send you this invitation, we collect your name and email address from such individuals.
b) Profile Information
Depending on the organization(s) you choose to connect with through the Services, the organization may request that you provide additional personal information about yourself, your dependants and members of your support network, which may include mailing address, telephone number, email address, medical and dietary information, photographs, age and date of birth, skills and capabilities in an emergency, and other details that may be relevant in an emergency or to the program or service being provided to you by such organization. You may also choose to add this information to your account profile at any time.
By providing information about other individuals, you represent to us that you have obtained the consent of those individuals to provide such information to ePACT.
c) Information You Provide About Others
If you would like to invite family members, friends, emergency contacts, or other individuals to connect with you through the Services, you will need to provide us with such individuals’ name and email address in order for us to send them an email on your behalf to (i) notify them of your request; (ii) invite them to join the Services; and (iii) enable them to opt-in to emergency or program/service-related notifications from you or other individuals or organizations they are connected with through the Services.
Please ensure that you only submit email addresses of individuals with whom you have a personal or family relationship and who would want to receive the message. If they elect not to register for the Services the information you have added about them will still be available in your ePACT account and to organizations you are connected with through the Services until such time as you remove it.
d) Information You Share About Others and Information Others Share About You
At your request, we share your profile information with other individuals, such as family members and emergency contacts, and authorize organizations such as schools, daycares or businesses you connect with through the Services to access and use such information in the course of providing their programs and services to you.
Sharing your profile information with your support network and registered organizations ensures that, in the event of an emergency or in the course of participating in a program or service offered by a registered organization, your support network, organizations and other third parties, including medical personnel, receive the information they need about each individual (to whom the personal information relates) in a timely and effective manner, including to enable organizations to (i) identify individuals affected by an emergency or participating in a program or service provided by the organization; (ii) contact you or individuals in your support network; (iii) inform medical personnel providing medical assistance to you or your dependants of personal health information relevant to such assistance; and (iv) otherwise take any other action necessary to disseminate the information needed to ensure the health and safety of you and individuals in your support network.
We may receive information about you from other registered users when they add you to their support network (for example, as a family member, emergency contact, out of area contact, or designated pick up person), including your name, contact information, and other identifying information. Where necessary for you to fulfill your role in such users’ support network, we, and organizations authorized to access this information by such users, use this information to contact and identify you in the course of delivering a program or service to such registered users.
We may also receive information about you from organizations you are connected with through the Services, including notes or documents added to your account for the purpose of the organization’s administration of the program or service you are participating in.
e) Customer Service
When you contact us with a comment, question, or complaint (including through our Live Chat or a contact us form available through the ePACT Website), you may be asked for information that identifies you (such as name and email address) along with additional information we need to help us promptly answer the question or respond to the comment or complaint. We may also provide you with the ability to post questions publically in the help center we make available through the ePACT Website. We may retain this information (including public questions) to assist our users in the future and to improve our customer service and product and service offerings.
f) Cookies and Information Obtained Automatically
We and/or our service providers (such as Google Analytics) collect IP (Internet protocol) and MAC addresses and other related information such as page requests, browser type, operating system, device type, unique device identifier, and average time spent on the ePACT Website and the ePACT Mobile Application. We also collect aggregated, anonymized information about the users of the Services (e.g. demographic information). This information is used to help us understand the activity on the ePACT Website and the ePACT Mobile Application and to monitor and improve the Services, the ePACT Website and the ePACT Mobile Application. For more information about Google Analytics, visit www.google.com/policies/privacy/partners/.
Sharing of Personal Information
You may choose to connect with organizations (e.g. sports associations, schools, camps, municipalities) through the Services. In doing so, you authorize ePACT to disclose to organizations the personal information organizations have identified to you as required in order to provide the program or service they offer to you. This may include enabling an organization to disclose your personal information to medical personnel providing medical assistance to you or individuals in your support network. This information will be used and treated in accordance with the organization’s privacy and information retention policies.
You may disclose additional information to such organizations at your discretion. In the event of an emergency or in the course of delivering a program or service to you, organizations you are connected with through the Services may contact you by phone, email or SMS (text message) using the contact information you disclosed to them.
Organizations are responsible for restricting access to personal information to authorized administrators within such organizations who require access to fulfil their designated functions. We may share aggregated information with registered organizations for the purposes of such organizations’ research and analytics to improve the programs and services they offer.
We may share personal information with our service providers who require access in order to provide services on our behalf. For example, we use third parties to host the ePACT Website or transmit email, telephone and SMS (text message) notifications that you have subscribed to through the ePACT Website or ePACT Mobile Application. Such third parties may receive your mobile telephone number and/or email address (as applicable), solely for the purpose of transmitting those notifications. From time to time we may also employ service providers to help us improve the Services. Some features of the Services, including our help desk ticketing system as well as the email, text, and voice messaging systems, require limited user data to pass through, or be stored or accessed on servers in the United States by ePACT or its service providers. This data may include: email address, telephone numbers, and any information that you provide to us via our ‘Help’ feature. All other data is stored and backed up in Canada.
We have put in place contractual and other organizational safeguards with our service providers to ensure a proper level of protection of your personal information (see further Security information below), and to prohibit them from using information about our users for their own purposes. Service Providers are only given the information they need to perform their designated functions.
Legal and Compliance
We and our Canadian, US, and other service providers may provide personal information in response to a search warrant or other legally valid inquiry or order (which may include lawful access by Canadian, US, or other foreign governmental authorities, courts, or law enforcement agencies), or to an organization in the case of a breach of an agreement or contravention of law, or as otherwise required or permitted by applicable Canadian, US, or other law.
We may disclose personal information to third parties without consent if we have reason to believe that disclosing this information is necessary to the investigation, establishment, exercise, or defence of legal claims against someone who may be causing loss or harm (whether intentionally or unintentionally) to persons or property; or where necessary to detect, suppress, or prevent fraud.
We may also disclose personal information in connection with a corporate re-organization, stock sale, or a prospective or completed acquisition or share sale (including transfers made as part of insolvency or bankruptcy proceedings) involving all or part of ePACT (including any due diligence exercise carried out in relation to the same), or other change in corporate control.
Access to Information
You may access, correct inaccuracies in, and update your personal information in our custody or control at any time by accessing your account profile through the ePACT Website and making the necessary changes. We rely on our users to ensure the information provided to us is accurate and up to date. Having accurate information enables us to provide the best possible service.
You may also request access, corrections, or updates to other personal information in our records, including information not available through your account profile, by contacting our Privacy Officer at the email set out below. Upon receipt of a written request, we will provide you with access to or a copy of your personal information, subject to limited exceptions set out by applicable law. We may request certain personal information for the purposes of verifying the identity of the individual seeking access to his/her personal information records. We will endeavour to deal with all requests for access, corrections, or updates in a timely manner.
We will make every reasonable effort to keep your personal information accurate and up-to-date, and provide mechanisms to update, correct, delete or add to your personal information as appropriate. Should you or we, at your request, make any changes to your personal information, the amended personal information may be transmitted to the organizations you have chosen to connect with through the Services, and as otherwise permitted or required by law.
You may view the information you have authorized ePACT to disclose to organizations, and organizations to access and use, and revoke such authorization at any time by logging in to your account and making the necessary changes.
Closing Your Account/Deletion of Personal Information
When you delete an account, it is deleted from the Services. Deleted accounts are removed from the Services immediately and your account (including all information held within your account) is no longer accessible by you or any other user with whom it was shared.
However, because ePACT maintains information back-ups to ensure the safety of our users’ information, such information may remain in backup copies and logs for a limited period of time.
Organizations with whom you are connected through the Services may retain copies of the information you disclosed to them, based on their own privacy and information retention policies.
You can delete your account at any time from the Account Settings page in your ePACT account. For more information, visit our Help Center.
ePACT protects personal information by making reasonable physical, technical and administrative security arrangements against such risks as theft, loss, unauthorized access, collection, use, modification, disclosure or disposal. Security measures have been integrated into the design, implementation and day-to-day operating practices as part of ePACT’s commitment to the protection of personal information it holds. For more information please see our Security page.
Third Party Links
Compliance with Privacy Laws
ePACT complies with applicable laws and regulations of the jurisdictions in which ePACT operates at any given time. Personal information is collected, used and disclosed in accordance with this policy and all applicable privacy laws as required by each jurisdiction.
The organizations whom you authorize to access and use your personal information through the Services have separate and independent privacy and information retention policies. We do not have any control over such organizations’ personal information practices, and therefore we have no responsibility or liability for the manner in which such organizations may collect, use or disclose, secure and otherwise treat personal information. If you have any questions or concerns about an organization’s personal information practices, you should contact the applicable organization directly.
Privacy Compliance Officer
ePACT has appointed a knowledgeable individual within its organization to be responsible for privacy compliance.
Last Updated: August 1, 2018