Privacy policy
General Information
a) Introduction
Privacy is important to 2975131 Canada Inc. (Spinelli Group) (hereinafter "Entity", "We", "Us", "Our"). For this reason, We have implemented safeguards and management practices for your Personal Information in accordance with the laws applicable in Quebec and Canada.
This privacy policy (the "Policy"), which should be read in conjunction with our Terms and Conditions, describes our practices with respect to the collection, use, processing, disclosure, and retention of Personal Information of our customers, visitors and users.
By using Our https://www.spinelli.com/ website (the "Website") or one of our associated websites (as listed below), you agree that We may collect, use, process, disclose and retain your Personal Information in accordance with the terms described herein. If you do not agree to abide by and be bound by this Policy, you are not permitted to visit, access, or use Our Website or Services, or share your Personal Information with Us.
This Policy also applies to our associated websites:
- https://www.spinellivw.com/ (Concession Volskwagen);
- https://www.spinellihonda.com/ (Concession Honda);
- https://www.spinelliinfiniti.com/ (Concession Infiniti);
- https://www.spinellikia.com/ (Concession Kia);
- https://www.spinellilexuslachine.com/ (Concession Lexus Lachine);
- https://www.spinellilexuspointeclaire.com/ (Lexus Pointe-Claire dealership);
- https://www.spinellimazda.com/ (Concession Mazda);
- https://www.spinellinissan.com/ (Concession Nissan);
- https://www.spinellitoyotalachine.com/ (Concession Toyota Lachine);
- https://www.spinellitoyotapointeclaire.com/ (Concession Toyota Pointe-Claire).
This Policy does not apply to the Personal Information of the Entity's employees, representatives, and consultants, or to any other person affiliated with the Entity, as well as to any information that does not constitute Personal Information as defined by the laws applicable in Quebec and Canada.
b) Data Protection Officer
Questions, comments and complaints regarding the Entity's Privacy Policy and practices may be directed to Our Data Protection Officer at:
Telephone: 514-634-7171
Email: rprp@spinelli.com
Address: 200 Montreal-Toronto Blvd., Montreal (Québec) H8S 1B8
Definitions
The following words and phrases, when they appear with a first letter in capital letters in the Policy, shall have the meanings ascribed to them below, unless otherwise implied or explicitly stated in the text:
"Service Provider" means any natural or legal person who processes Personal Information on behalf of the Entity. These are third-party companies or individuals employed by the Entity to facilitate the Services, provide the Services on behalf of the Entity, perform services related to the Services, or assist the Entity in analyzing the use of the Services.
"Personal Information" means any information that relates to a natural person and allows him or her to be identified, i.e. that directly or indirectly reveals something about the identity, characteristics (e.g., skills, preferences, psychological tendencies, predispositions, mental capacities, character and behavior of the person concerned) or activities, regardless of the nature of the medium and regardless of the extent of the information and the form in which the information is accessible (written, graphic, audio, visual, computerized or otherwise).
"Data Protection Officer" means the person who is responsible for the application of this Policy and whose contact information is identified in Section 1 of this Policy.
"Services": Services refers to the Website, Our social media pages and services and products rendered to you, such as the purchase of a vehicle online.
Processing of Personal Information
Collection of Personal Information
In the course of Our business, We may process different types of Personal Information including the information listed below:
- Contact information, such as your first and last name, address, email address, telephone number, image, date of birth, age, legal status, and information to verify your identity;
- Information you choose to provide or transmit to Us, for example, when you fill out a form, book an appointment online, respond to surveys, apply for a job, or contact one of Our employees or representatives;
- Transaction and payment information, such as the payment method used, date and time, payment amount, billing zip code, your address, and other related information;
- Information collected automatically when you use the Website and Our Services, including:
- login information and other information about your activities on the Website, such as your IP address, the pages you viewed, the time and date of your visits, the number of connections, the type of browser you use, the operating system of your device, and other hardware and software information;
- Demographic and geolocation data, such as your IP address, a precise or approximate location determined from your IP address, or your mobile device's GPS (depending on your device settings).
In each case, such Personal Information is processed in accordance with the legitimate and necessary purposes listed in Section 3.2 below.
Use of Personal Information
We may use your Personal Information for the legitimate purposes described below:
- Operate, maintain, monitor, develop, improve and offer all features of Our Websites;
- Present and provide Services to you;
- Allow you to create an online account;
- Allow you to apply for job openings;
- Allow you to acquire Our Services and complete transactions in connection with Our Services;
- Allow you to start applying for financing;
- For marketing and business development purposes, if you have previously consented to the processing of your Personal Information for those purposes;
- Answer your questions and provide you with assistance as needed;
- Interact with Our instant messaging module;
- Collect reviews, testimonials, and feedback in connection with Our Services;
- Carry out Our contractual obligations to you;
- Developing, improving, and offering new Services;
- Send you messages, updates, security alerts;
- Detect and prevent fraud, errors, spam, abuse, security incidents, and other harmful activities;
- For any other purpose permitted or required by law.
Disclosure of Personal Information
We may share your Personal Information with Our employees (including marketing and sales departments), contractors, consultants, agents, service providers and other trusted third parties (collectively, "Service Providers"), who need the information to help Us operate Our Website, conduct Our business or serve You, provided that such Service Providers have previously agreed in writing to ensure the confidentiality of your Personal Information in accordance with applicable laws and Our Information Governance Program.
We do not sell, trade, or otherwise disclose your Personal Information to third parties.
Service Providers and Other Third Parties
Although We try to avoid sharing your Personal Information with third parties, We may use Service Providers to perform various services on Our behalf, such as IT management and security, marketing, and data analytics, hosting, and storage. We have defined below the cases in which such sharing may take place:
- We use Google Analytics to analyze the website's audience, compile statistics and communicate with customers and prospects. Check out their privacy policy;
- We use Google Ads to analyze the audience of Our Services, compile statistics and converse with customers and prospects. Check out their privacy policy. Check out their privacy policy;
- We use the services of Astral Internet to host our websites. Check out their privacy policy;
- We use the services of SM360 and Site Ground to host Our Websites. Check out their privacy policy;
- We use Didomi's services to manage your cookie preferences. Check out their privacy policy;
- We use the services of MailChimp. Check out their privacy policy;
- We use the services of Amazon Web Services. Check out their privacy policy;
- We use Dealertrack's services for credit file submissions. Check out their privacy policy;
- We use the services of Xtime to make appointments. Check out their privacy policy;
- We use Decisionning.IT services for express credit pre-approval. Check out their privacy policy;
- We use the services of Facebook Pixel to help understand and serve ads, compile statistics and communicate with customers and prospects. Check out their privacy policy;
- We use Bing Ads technology to collect and store data in order to create usage profiles using pseudonyms. Check out their privacy policy;
- We use Stripe's services to make payments and pre-payments for our Services and products. Check out their privacy policy;
- We use the services of Indeed and Autojobs to recruit Our employees. View their respective privacy policy;
- We use the Meta Group's Facebook and Instagram social media services to communicate about Our Services and products. Check out their privacy policy;
- We use the services of the social network LinkedIn to communicate about Our Services and products. Check out their privacy policy;
- We use YouTube to present Our products and Services. Check out their Google Privacy Policy;
- We use the services of VIN Solutions CRM. Check out their privacy policy;
- We use Google Drive to store our documents. Check out their privacy policy;
- We use Metatracer to ensure Our compliance with the privacy laws that apply to Us. Check out their privacy policy.
Before disclosing your Personal Information to Service Providers outside the province of Quebec or depending on the nature of the Personal Information disclosed, We conduct privacy impact assessments. When We disclose your Personal Information to Service Providers, We insure that the Personal Information disclosed and provided is strictly necessary to carry out their mandate. As part of the contracts with our Service Providers, We are committed to adhering to the principles set out in this Policy. Our Service Providers are required to use Personal Information securely and confidentially, as directed by us, and only for the purposes for which it was provided. We provide sufficient assurances that adequate safeguards are in place to commensurate with the sensitivity of the Personal Information processed or disclosed. When Our Service Providers no longer need your Personal Information, We require them to destroy that data appropriately.
Complying with Legislation, Responding to Legal Requests, Preventing Harm, and Protecting Our Rights
We may disclose your Personal Information where We believe such disclosure is authorized, necessary or appropriate, including:
- To respond to requests from public and government authorities, including public and government authorities outside your country of residence;
- To protect Our business;
- To comply with legal process;
- To protect Our rights, privacy, safety, property, yours or those of others;
- To allow Us to pursue available remedies or limit the damages We may sustain; and
- In accordance with applicable laws that are applicable, including laws outside your country of residence;
- In accordance with applicable standards in the automotive industry or the requirements imposed by our partners and/or manufacturers.
Business Transaction
We may share, transfer or communicate, in strict accordance with this Policy and the provisions of the Act respecting the protection of personal information in the private sector, CQLR c P-39.1 (the "Private Sector Act ") and the Act to modernize legislative provisions as regards the protection of personal information, SQ 2021, c 25 (the "Bill 25") (assented to September 22, 2021), your Personal Information in the event of a sale, transfer or assignment, in whole or in part, of the Entity or Our assets (e.g., as a result of a merger, consolidation, change of control, reorganization, bankruptcy, liquidation or other business transaction, including in connection with the negotiation of such transactions). In this case, We will notify you before your Personal Information is transferred and is governed by a different privacy policy.
Consent to Personal Information
To the extent possible, the Entity obtains consent directly from the data subject to the collection, use and disclosure of their Personal Information. However, if you provide Personal Information about other individuals to Us, you must ensure that you have given them due notice that you are providing their information to Us in addition to obtaining their consent to such disclosure.
We will collect your explicit, clear, free and informed consent and identify specific purposes for which consent is required before using or disclosing your Personal Information for purposes other than those set out herein. We will also collect your explicit consent whenever sensitive Personal Information is involved in any of the Entity's processing activities. We will ask for your consent for each specific purposes in plain and clear terms, and distinctively from any other information.
BY USING OUR WEBSITES, BY SUBMITTING YOUR PERSONAL INFORMATION BY EMAIL OR TROUGH AN ONLINE FORM, YOU CONSENT TO THIS PRIVACY POLICY AND TO THE COLLECTION AND PROCESSING OF YOUR PERSONAL INFORMATION IN ACCORDANCE WITH THE PRIVACY POLICY.
If You do not consent, please stop using the Website. Except where otherwise required by law, You may withdraw your consent at any time upon reasonable notice. Please note that if You choose to withdraw your consent to the collection, use or disclosure of Your Personal Information, certain features of Our Website may no longer be available to You or we may no longer be able to offer You some of Our services.
Retention of Personal Information
Subject to applicable law, We retain your Personal Information only for as long as necessary to fulfill the purposes for which it was collected, unless you consent to your Personal Information being used or processed for another purpose. As an indication, the duration of certain information may extend up to 7 years following the end of the Services rendered by the Entity to you. In addition, Our retention periods may be changed from time to time due to legitimate interests (e.g., to ensure the security of Personal Information, to prevent abuse and breaches, or to prosecute criminals).
For more information on the periods for which your Personal Information is retained, please contact Our Data Protection Officer using the contact information provided in section 1b) of this Policy.
Your Rights
As a data subject, you may exercise the rights set out below by contacting Our Data Protection Officer in writing at the contact information provided in section 1b) of the Policy. Please note that We may ask you to verify your identity before responding to any of these requests.
- You have the right to be informed of the Personal Information We hold about you, its use, disclosure, retention and destruction, subject to the exceptions provided by applicable law;
- You have the right to access your Personal Information, to request a copy, including hard copy, of the documents containing your Personal Information, subject to the exceptions provided by applicable law, and to obtain, where applicable, additional details about how we use, disclose, retain and destroy it;
- You have the right to have the Personal Information We hold about you corrected, amended and updated if it is incomplete, ambiguous, out of date or inaccurate;
- You have the right to withdraw or modify your consent to the Entity's collection, use, disclosure or retention of your Personal Information at any time, subject to applicable legal and contractual restrictions;
- You have the right to ask Us to stop disseminating your Personal Information and to de-index any link to your name that provides access to that information if such disclosure would contravene the law or a court order;
- You have the right to request that your Personal Information be disclosed to you or transferred to another organization in a accessible and commonly used technological format;
- The right to be notified of a privacy incident involving your Personal Information that may cause you serious harm. To this end, we maintain a register of all confidentiality incidents and assess the harm they may cause to data subjects;
- You have the right to file a complaint with the Commission d'accès à l'information, subject to the conditions set out in applicable law.
In order to comply with your request, you may be asked to provide appropriate identification or otherwise identify yourself.
Cookies and Other Tracking Technologies
We use cookies and other similar technologies (collectively, "Cookies") to help us operate, protect and optimize the Website and Services We offer. Cookies are small text files that are stored on your device or browser. They collect certain information when you visit the Website, including your language preference, browser type and version, the type of device you are using, and your device's unique identifier. While some of the Cookies we use are deleted after your browser session has ended, other cookies are stored on your device or browser to allow us to recognize your connection the next time you visit the Website. The Personal Information collected through these Cookies is not intended to identify you. More precisely, they make it possible to ensure the proper functioning of the Website, to improve the browsing experience of users and to provide certain data that allows us to better understand the traffic and interactions that take place on Our Website, as well as to detect certain types of online fraud. Cookies do not cause any damage to your device and cannot be used to extract your Personal Information. We collect your IP address, information about your device and operating system or browser, your online activity relating to the Website and your browsing history on Our Website as well as your queries, browsing preferences (the languages used), etc.
You can configure your browser so that you are informed about Cookies’ settings when you visit the Website, so that you can decide, in each case, whether to accept or refuse the use of some or all of the Cookies. Please note that disabling Cookies on your browser may adversely affect your browsing experience on the Website and prevent you from using some of its features.
To learn more about how we use Cookies, you can visit the "Choice of Consent" tab on Our Website.
Security Measures
The Entity has implemented physical, technological and organizational security measures to adequately protect the confidentiality and security of your personal information against loss, theft or any unauthorized access, disclosure, copying, communication, use or modification. These measures include, but are not limited to:
On the administrative side, the adoption of a series of policies and procedures as part of the implementation of Our information governance program, including:
- Regulate the access, communication, retention, de-identification, including anonymization and/or, where applicable, destruction of Personal Information;
- Determine the roles and responsibilities of Our employees throughout the life cycle of Personal Information and documents;
- Establish procedures for responding to and responding to confidentiality incidents;
- Govern the process of requests and complaints relating to the protection and handling of Personal Information.
On the technical level, the use of several means such as:
- The use of a secure server. All sensitive or credit information provided is transmitted via Secure Socket Layer (SSL) technology and then encrypted in Our Payment Gateway Provider Database only for access by authorized persons with special access rights to such systems, and are required to keep the information confidential;
- The use of backup systems, network monitoring software, etc.;
- The use of encryption and segregation of duties, access controls and internal audits.
Despite the measures described above, We cannot guarantee the absolute security of your Personal Information. If you have reason to believe that your Personal Information is no longer protected, please contact Our Data Protection Officer immediately using the contact information provided in Section 1(b) above.
Changes to this Privacy Policy
We reserve the right to change this Policy at any time in accordance with applicable law. If We make any changes, We will post the revised Privacy Policy and update the date in the footer of the Privacy Policy. We will also notify you within a reasonable delay prior to the effective date of the new version of Our Policy. If you do not agree to the new terms of the Privacy Policy, please cease using Our Website and Services. If you continue to use Our Website or Services after the new version of Our Policy comes into effect, then your use of Our Website and Services will be governed by the new version of the Policy.
Links to Third-Party Websites
From time to time, We may include references or links to Our Facebook page, websites, products or services provided by third parties (the "Third-Party Services") on Our Website. These Third-Party Services, which are not operated or controlled by the Entity, are governed by privacy policies that are entirely separate and independent from ours. We therefore assume no responsibility for the content and activities of these sites. This Policy applies only to the Website and the Services offered by Us. The Policy does not extend to third-party services such as Our Facebook Page.
ReCAPTCHA invisible
The invisible reCAPTCHA analyzes activity on a web page function (e.g., mouse movements and typing patterns) to determine if a user is a robot.
The invisible reCAPTCHA service may collect information from your device. The information collected by the reCAPTCHA is retained in accordance with its privacy policy.
Payment Details
With respect to credit card details or other payment information that you have provided to Us, We are committed to ensuring that such confidential information is stored as securely as possible.
Individuals under the age of 14
We do not knowingly collect or use Personal Information from anyone under the age of 14. If you are under the age of 14, you should not provide Us with your Personal Information without the consent of your parent or guardian. If you are a parent or guardian and you become aware that your child has provided Personal Information to Us without consent, please contact Us using the contact information provided in Section 1(b) above to request that We delete that child's Personal Information from our systems.
Applicable Laws
The laws of Canada and Quebec, excluding its conflict of law rules, will govern this Agreement and your use of the Website. Your use of the Website may also be subject to other local, provincial, national, or international laws.