Privacy and Confidentiality
Principle 1: Responsibility for Personal Information
Principle: A web provider bridging the gap between certain professionals, who are themselves subject to organizations ensuring public protection, and their clients must be responsible for the personal information under its control. To achieve this, it must designate one or more individuals responsible for enforcing the requirements of privacy laws and policies based on the standards established by these organizations for its members.
Dali-a proposes to undergo an audit of the IT security in order to meet the requirements and standards of privacy protection. The audit will take place once a year. Also, organizations whose members may act as collaborators and whose purpose is to ensure public protection will be invited to select the auditor who will proceed to the audit of its computer system. The resulting report will be available for consultation by the experts of each protection organization. Their recommendations may follow and Dali-a will abide by their requirements as long as such requirements are imposed on their own member or on providers offering data hosting services to members.
With respect to users, Dali-a has developed an information security policy and its terms of use to ensure the security of personal information.
Principle 2: Identifying Purposes for Collection of Personal Information
Principle: The purposes for which personal information is collected shall be identified by Dali-a before or at the time the information is collected and shall be made public.
The information security policy states the following regarding access to individual profiles:
Use
Individual Profile. The service displays an individual's personal data on their profile page only and only the data contained therein, except for the date of birth. The data provided must reflect the degree of an individual's intention to make known to collaborators working on one of his or her files and incidentally to individuals whose file is linked to his or her own. Otherwise, the profile data remains confidential at all times. The user may consult and modify the information in their profile at any time, except for the date of birth.
The terms of use stipulate the following regarding access to documents and forms:
Request for service. Once the registration is completed, the individual has the possibility to create files. Accordingly, service requests are made either by invitation to tender or by choosing a specific collaborator. The information contained in the specific forms is only visible to the associated collaborator. As for the documents filed in an application, access to them is only authorized by the custodian of the document, except when the collaborator leaves the file. In the latter situation, the individual shall be granted control of access to the documents filed by the collaborator in question. Thus, the individual is the holder of all documents filed in his or her file, since he or she can retrieve them at any time and retain control of access to them. In the case of a client administered by a collaborator, the individual must first agree that all employees may deposit their documents on the site. In this situation, they hold all the documents associated with their file until they are destroyed one year after the file in question is opened. Within this one-year period, the individual may request that his or her file be transferred to him or her.
As far as data conservation is concerned, it is necessary to mention the use that Dali-a can make of the registered or deposited data on its site.
Data retention. DALI-A retains information related to a user for as long as his or her account is active or as long as it is necessary to provide services to you. Even after an account is deleted, if necessary, information is retained to comply with legal obligations, resolve disputes and enforce certain agreements. In accordance with these requirements, the service strives to delete information promptly upon request. There may be a delay in deleting information from our servers and saved versions may remain after deletion. In addition, files that you have in common with other users are not deleted from our servers.
Dali-a retains personal information only as long as necessary for the fulfillment of those purposes or as required or permitted by law.
Dali-a may only collect the personal information necessary for the identified purposes. Personal information is collected directly from the individual and may with consent or as required by law be collected from other sources.
Principle 3: Consent
Principle: Consent is a key privacy principle that applies to disclosures made under the Privacy Act.
Any user of the site, whether as an individual, a collaborator or a temporary client, consents to the information security policy and the terms of use.
An individual shall be informed of the existence, use and disclosure of his or her personal information. A collaborator working on Dali-a will provide appropriate access to the information in their possession on behalf of the client. If the collaborator refuses access to personal information, they must provide an explanation.
Members may ask Dali-a to correct their personal information. If this information is erroneous, the necessary corrections will be made.
Consent to collect, use or disclose personal information is always express. Any individual may revoke consent at any time, subject to legal or contractual restrictions and considerations.
Personal information shall not, without consent, be used or disclosed to a third party for purposes other than those for which it was collected, except where such use or disclosure is required or permitted by law, such as where such use or disclosure is necessary to protect Dali-a's interests in civil proceedings or proceedings relating to criminal or fraudulent activity or misrepresentation.
Dali-a retains personal information only as long as necessary for the fulfillment of those purposes or as required or permitted by law.
Principle 4: Limiting Collection of Personal Information
Principle: The institution may only collect personal data that is necessary for the purposes identified by it and must do so by fair and lawful means.
Information that the service collects and stores:
1- Information provided by users. When a user opens an account, DALI-A collects certain personal data, such as name, telephone number, e-mail address and postal address of home and work. The user may also ask DALI-A to import his contacts by giving access to its third party services (e.g. your email account) or to use information available on social networks if the user grants access to their account on such networks.
2- Documents. DALI-A collects and stores the documents that each user uploads, downloads or consults using the DALI-A Service (the "Documents") in the selected folders.
3- Logging data. When using the site, the service automatically records information from the device or software used. This information may include the Internet Protocol (IP) address of the device, browser type, the web page visited before accessing the site, information searched for on the site, regional settings, identification numbers associated with devices, mobile operator, timestamp associated with transactions, system configuration information, file metadata and other interactions with the service.
4. Cookies. The service also uses "cookies" to collect information and improve its services. A cookie is a small data file transferred to a device. DALI-A may use "persistent cookies" to store a user name and password for subsequent connections to the service. The site does not use "session identification cookies".
Geolocation information. Some devices allow applications to access real-time location-based information (for example, GPS applications). As of the effective date of this policy, DALI-A's mobile applications do not track or access information on mobile devices at any time while a user is downloading or using such mobile applications, but may do so in the future with the user's consent. Some of the information collected from a device, for example, the IP address, may sometimes be used to find the location of a device at the user's discretion.
Principle 4: Limiting Collection of Personal Information
Principle: Personal information shall not be used or disclosed for purposes other than those for which it was collected or used for that purpose, except with the consent of the individual or as required by law.
Use
The main use is the processing of a client's file. Every effort is made to facilitate its execution and make the solution more efficient and accessible to all. The platform offers a solution for communication and document storage.
Communication
The communication in a file is done through private conversation or through the follow-up of the file. Any person involved in a file, having been the subject of a liaison, could have access to the follow-ups since their creation. The collaborator must ensure that no sharing of information by this means is contrary to the respect of privacy. On the other hand, the individual remains aware that this is a public platform and that by making certain information available, it can be shared.
Dali-a does not communicate any information to third parties outside the platform.
Retention and Disposal
Provisional records that are not required to be kept by an individual are deleted within one year of their creation. Otherwise, when an individual no longer sees the need to retain the data on the site, they may delete their account or only the record in question. This has the effect of eliminating any content that may be contained in it.
Principle 6: Accuracy of Personal Information
Principle: Personal information shall be as accurate, complete, and up-to-date as is necessary for the purposes for which it is to be used.
Dali-a makes every reasonable effort to ensure that personal information is accurate and complete for the purposes for which it is used.
Principle 7: Safeguards for the Protection of Personal Information
Principle: Personal information shall be protected by security safeguards appropriate to the sensitivity of the information.
Dali-a is committed to deploy the best efforts to ensure the protection of personal files and to keep them in a secure environment. In this regard, Dali-a deploys in particular the following methods and measures to achieve this objective:
• Secure Sockets Layer (SSL) Transmission Protocol
• Secure Electronic Transaction (SET) Protocol
• Manage access to personal files
• Manage personal file distribution authorizations
• Network monitoring software
• Computer backup protocols
• Develop digital certificates
• Procedures for identifying users and access seekers
• Firewalls
Dali-a protects the security and confidentiality of personal information by security safeguards appropriate to the sensitivity of the information.
Principle 8: Openness in the Management of Personal Information
Principle: The provider must make readily available to individuals specific information about its policies and practices relating to the management of personal information and shall be open about those policies and practices.
Dali-a's privacy standards are available to clients and the public. Upon written request from an organization ensuring public protection, we will provide a copy of the privacy standards and answer questions about our personal information practices.
Principle 9: Access to Personal Information and Changes to Personal Information
Principle: Upon request, an individual must be informed of the existence, use, and disclosure of their personal information and shall be given access to that information.
Principle 10: Complaints about the Handling of Personal Information
Principle: An individual must be able to make a complaint to the head of the institution about its privacy management practices.
Under "Contact", any user may contact the site administrators to challenge a privacy management practice.