Skip to main content
Vermont Solutions

Canadian Privacy Notice (PIPEDA)

Supplemental privacy notice for users in Canada

⚠️ Draft pending legal review

This Canadian addendum is a working draft pending review by a Canadian privacy lawyer (PIPEDA / CASL specialist) before being published as legally binding.

1. Introduction

This Canadian Addendum applies to users accessing from Canada. It supplements our main Privacy Policy and explains compliance with PIPEDA, CASL, and applicable provincial laws (Alberta PIPA, British Columbia PIPA).

2. Identity and accountability (PIPEDA Principle 1)

Vermont Solutions S.L., a Spanish company with NIF B66520446 and registered office at Agustín de Betancourt Street, 21 — 28003 Madrid, Spain.

Data Protection Officer: dpo@vermont-solutions.com (response within 30 days)

3. Identifying purposes (Principle 2)

Personal information is collected to: respond to inquiries; send commercial communications under CASL-compliant consent; improve website experience (analytics, anonymized); comply with legal obligations.

4. Consent (Principle 3 + CASL)

Vermont Solutions obtains your express, meaningful consent: opt-in checkboxes on forms; double opt-in for newsletter (CASL); granular cookie consent banner. You can withdraw consent at any time via dpo@vermont-solutions.com or unsubscribe links.

5. Limiting collection (Principle 4)

We only collect what is necessary: name, email, company, job title, message. No sensitive personal information (health, biometric, financial) is collected.

6. Limiting use, disclosure and retention (Principle 5)

Personal information is used only for stated purposes, disclosed only to authorized service providers under written data processing agreements, and retained for a maximum of 24 months from collection (or until you request deletion).

7. Accuracy (Principle 6)

Personal information will be as accurate, complete and up-to-date as necessary. Request corrections via dpo@vermont-solutions.com.

8. Safeguards (Principle 7)

Physical, organizational and technological security measures appropriate to sensitivity, compliant with ISO/IEC 27001:2022: SSL/TLS encryption in transit, encryption at rest, role-based access control, MFA, regular audits, vendor due diligence.

9. Individual access (Principle 9)

On written request to dpo@vermont-solutions.com, you can: confirm existence of information about you; receive a copy; request correction; learn third parties to whom your data was disclosed. Response within 30 days.

10. Challenging compliance (Principle 10)

Contact us first at dpo@vermont-solutions.com. If unresolved, file a complaint with:

Office of the Privacy Commissioner of Canada (OPC) — 30 Victoria Street, Gatineau, Quebec K1A 1H3 — Toll-free: 1-800-282-1376 — https://www.priv.gc.ca/en/report-a-concern/

Alberta residents: OIPC Alberta (https://www.oipc.ab.ca/). BC residents: OIPC BC (https://www.oipc.bc.ca/).

11. Cross-border transfers (Spain ↔ Canada)

Your personal information is transferred to and processed in Spain (EU). This transfer relies on the European Commission's adequacy decision regarding PIPEDA (Decision 2001/2/EC) and contractual safeguards with sub-processors.

12. CASL compliance

Commercial Electronic Messages (CEMs) sent by Vermont Solutions identify the sender (legal name + Spanish business address), provide working one-click unsubscribe processed within 10 business days, and are sent only with valid express consent. Penalties under CASL reach CAD $10M per violation.

13. Children's privacy

We do not knowingly collect personal information from children under 13. Contact dpo@vermont-solutions.com for immediate deletion.

14. Breach notification

In the event of a breach creating real risk of significant harm (PIPEDA s. 10.1): we report to the OPC as soon as feasible; notify affected individuals; maintain breach records for 24 months.

15. Updates

Last reviewed: 2026-05-14.