Welcome to the privacy policy (“Privacy Policy”) of Smith Assembly Inc. (“we”, “us”, “our”). Your privacy is important and we want you to understand what happens to your Personal Data when you connect with us. Here we’ll explain how we collect, use, disclose and store Personal Data from your use of our Website, your participation in our workshops, our client portal (the “Portal”), and any other engagements with us (collectively, and inclusive of the Website and Portal, our “Services”).
Please read this Privacy Policy carefully. If you do not agree with this Privacy Policy, please do not use our Services.
1. Commonly Used Terms
“Personal Data” means any information relating to a living person. It also includes information that may identify a person when combined with other information. Some examples of Personal Data include names, addresses, e-mail addresses, and phone numbers.
“Process” or “Processing” means any action that a person can take with respect to Personal Data, including collecting, using, sharing, and altering Personal Data.
2. Overview
- Why We Collect Personal Data
- What Personal Data We Collect
- How We Collect Personal Data
- Grounds for Processing Personal Data
- Disclosure of Personal Data
- Retention of Personal Data
- Security of Personal Data
- Rights Relating to Personal Data
- Third-Party Materials
- Communications with Us
- Personal Data About Other People
- Changes to Our Privacy Policy
- Contact Us
3. Why We Collect Personal Data
We may collect Personal Data in order to fulfill the following purposes (the “Purposes”):
(a) to provide our Services to you;
(b) to collect and process payments for Services;
(c) to respond to your communications with us;
(d) to contact you about updates to the Services, marketing and promotional offers, and service-related communications;
(e) for internal statistical and operational purposes to better understand how our Services are used;
(f) to improve our Services; and
(g) to carry out any other purpose which is disclosed to you and for which you consent, or as is otherwise permitted by applicable law.
4. What Personal Data We Collect
(a) General. Personal Data that we may collect through your use of the Services and/or any of your communications with us includes, but is not limited to:
(i) your first name, last name, and email address in order to send us messages from the Website;
(ii) your first name, last name, email address, and availability in order to book a chat with us;
(iii) your first name, last name, email address, and address in order to register for the Services;
(iv) photographs or videos of your participation in our Services;
(v) payment information (e.g., billing address, credit card information, and banking information) to be used to pay for Services;
(vi) information about how you use the Services (e.g., your length of visits to our Website and Portal, and the time and frequency of your visits to our Website and Portal), so that we can improve the effectiveness and function of our Services; and
(vii) information about your computer or mobile device, such as your Internet protocol (IP) address, device ID, browser and operating system type, resolution of your screen, language settings in your browser, referring URLs, and other technical information so that we can secure our Services and improve their effectiveness and function.
(b) Sensitive Personal Data. We don’t typically collect Sensitive Personal Data. In the event that we do, we will ask for your explicit, written consent before we collect any Sensitive Personal Data from you, unless another legitimate basis exists for collecting such data under applicable law. “Sensitive Personal Data” means data that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, health or sex life, sexual orientation; genetic data; or biometric data (e.g., fingerprints, voice recordings).
5. How We Collect Personal Data
(a) Collection through Services. We may collect Personal Data from you and any devices that you may use when you:
(i) provide information to us through your use of our Services (e.g., you access the Website and Portal and voluntarily provide your name and email address; you access the Website and Portal and we automatically collect data on your activity on the Website and Portal through the use of cookies);
(ii) communicate with us;
(iii) subscribe to any mailing lists; and
(iv) otherwise access and use our Services.
(b) Cookies. We may use cookies and similar technologies to track and analyze user activity in order to improve our Services and improve your experience. A cookie is a tiny element of data sent to your browser from a website. The cookie is stored on your hard drive so that your computer or other device may be recognized while you use the Website and Portal.
Most web browsers allow you to modify your settings to notify you when you receive a cookie or to reject cookies entirely. Your computer also provides you with the ability to clear all cookies that have been stored onto your hard drive, should you wish to do so. However, please be aware that you may be unable to access certain parts of the Services if you block or disable our cookies. For more information about cookies, please see: https://www.allaboutcookies.org.
(c) Web Analytics. We may use web analytics services (e.g., Google Analytics) in order to better understand the user experience on our Website and Portal, including, but not limited to:
(i) how you reached our Website and Portal;
(ii) the website you came from;
(iii) how long you stayed on our Website and Portal;
(iv) what pages you looked at;
(v) how many pages you looked at;
(vi) what buttons you clicked;
(vii) what browser you are using; and
(viii) what device you are using.
Any use of analytics services by us may result in analytics providers collecting your Personal Data when you access and use our Website and Portal. These third parties may set and access their own tracking technologies (including cookies and web beacons) and may otherwise collect or have access to your device identifier, site usage information, and related information about you.
If you do not wish to participate in web analytics, you may be able to download an opt-out browser add-on. Your web browser may also allow you to set a “Do Not Track” signal when you use online services. To learn more about “Do Not Track” signals, visit http://www.allaboutdnt.com. You may also contact us at the “Contact Us” section below regarding any questions about web analytics services that we may use.
(d) Third Party Data. We may also obtain Personal Data from third parties. We protect such personal Data according to the practices described in this Privacy Policy, plus any additional restrictions imposed by the source of the data and applicable laws.
6. Grounds for Processing Personal Data
(a) General. We will not process your Personal Data without your consent, unless we are permitted or required to do so by applicable law. Your consent may be express or implied. The type of consent we may rely on in processing your Personal Data will vary based on your reasonable expectations, the sensitivity of your Personal Data, and the circumstances surrounding the collection of your Personal Data. Express consent is when you willingly agree (e.g., orally, in writing, or electronic agreement) to the processing of your Personal Data for particular purposes. Implied consent is when: (a) you do not expressly give consent, but you rather volunteer Personal Data for obvious purposes that a reasonable person would consider appropriate in the circumstances; or (b) you are given notice and a reasonable opportunity to opt-out of your Personal Data being processed for specified purposes, and you do not opt-out.
(b) European Union. For persons to whom the General Data Protection Regulation (“GDPR”) applies, we may process your Personal Data on the following grounds, in addition to any other grounds that may be available pursuant to applicable law:
(i) Consent. Where you have given us consent through a statement or clear affirmative action agreeing to the processing of your Personal Data. For instance, by submitting your Personal Data on a form on our Website and Portal for a specified purpose.
(ii) Contract. Where processing of Personal Data is necessary to perform a contract between yourself and us.
(iii) Legal Obligation. To comply with a legal obligation to which we are subject.
(iv) Legitimate Interests. Where the processing of Personal Data is based on our legitimate interests, provided that these do not override your own interests and fundamental rights. We have legitimate interests in the following:
(A) to properly operate and deliver our Services to you;
(B) to understand how users engage with our Services;
(C) to improve our Services;
(D) to market our Services; and
(E) to provide customer service, including but not limited to, responding to inquiries and feedback.
7. Disclosure of Personal Data
(a) General. When we disclose your Personal Data to third parties, we take reasonable measures to ensure that the rules set forth in this Privacy Policy are complied with and these third parties provide contractual guarantees to implement appropriate technical and organizational measures in accordance with applicable privacy and data protection laws. We minimize the amount of Personal Data we disclose to what is directly relevant and necessary to accomplish the specified purpose.
(b) Service Providers. We may provide your Personal Data to third party service providers in order to help us achieve the Purposes and operate our Services. For example, we may use third party service providers to help us process payments, analyze usage of our Services, track the effectiveness of our marketing strategies and communications, assist with the prevention, detection and investigation of potentially illegal acts and security breaches, collect and process error and crash reports, and store data. These third parties are authorized to use your Personal Data only as necessary to provide these services to us. We take commercially reasonable steps to help ensure our service providers provide at least the same level of protection for Personal Data as we do.
(c) Corporate Transactions. We may also disclose or transfer your Personal Data to affiliates or third parties in the event of a proposed reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or equity, subject in each case to customary confidentiality agreements.
(d) Legal Disclosure. We may disclose Personal Data if we reasonably believe disclosure is permitted or required by any applicable law, regulation or legal process. This includes the disclosure of Personal Data where necessary for the establishment, exercise, or defense of legal claims. We will have no liability associated with any such disclosures made in good faith.
(e) International Transfer and Storage. Your Personal Data may be stored and processed in any country where we have facilities or in which we engage third party service providers. By using our Services and otherwise providing us your Personal Data, you consent to the transfer of your Personal Data to countries outside of your country of residence, which may have different data protection rules than in your country. While such information is outside of Canada, it is subject to the laws of the country in which it is held, and may be subject to disclosure to the governments, courts or law enforcement or regulatory agencies of such other country, pursuant to the laws of such country. However, our practices regarding your Personal Data will at all times continue to be governed by this Privacy Policy and, if applicable, we will comply with the GDPR requirements providing adequate protection for the transfer of Personal Data from the European Economic Area to a third country.
8. Retention of Personal Data
Our data retention periods may vary depending on the country in which you receive Services and applicable law. In Canada, if we use Personal Data to make a decision that directly affects you, we will retain that Personal Data for at least one year, so that you have a reasonable opportunity to request access to it. In any event, we will retain your Personal Data only as long as necessary to: (a) fulfill the Purposes; (b) protect our legal rights; and (c) comply with applicable law. We will securely delete or anonymize the Personal Data once it is no longer necessary for us to hold it. We are not responsible for any liability or loss you experience as a result of such disposal of Personal Data.
9. Security of Personal Data
We protect your Personal Data using appropriate technical and organizational measures to reduce the risks of loss, misuse, unauthorized access, disclosure, and alteration. However, no method of transmission over the Internet, or other method of storage, is 100% secure. Therefore, we cannot guarantee its absolute security. We encourage you to also take steps to protect Personal Data by, for example, closing all web browsers after using our Website and Portal.
10. Rights Relating to Personal Data
(a) General. You have certain rights relating to your Personal Data, subject to applicable law in each instance:
(i) Right to be Informed. To know how your Personal Data is collected, how it is used, and how it is disclosed and stored. This further includes:
(A) Right to Withdraw Consent. To withdraw your consent to the processing of your Personal Data at any time. Please be advised that withdrawing your consent to the processing of Personal Data may impact our ability to provide certain Services. For further information on this, please contact us as provided in the “Contact Us” section below.
(B) Right to Make a Complaint. To make a complaint about the processing of your Personal Data.
(ii) Right to Access. To receive a copy of your Personal Data.
(iii) Right to Rectification. To request correction of your Personal Data.
(b) European Union. If the GDPR applies to you, then you have the following additional rights relating to your Personal Data, subject to applicable law in each instance:
(i) Right to Erasure. To request the deletion of Personal Data when: (A) you believe it is no longer necessary for the purposes collected; (B) you withdraw your consent or object to the processing of your Personal Data; or (C) your Personal Data was unlawfully processed.
(ii) Right to Restriction of Processing. To restrict the processing of Personal Data if you dispute its accuracy or object to its processing.
(iii) Right to Portability. To request that your Personal Data be transferred to another organization.
(iv) Right to Information about Automated Decision Making. To receive information about the basis of any automatic decision making (e.g., algorithms).
(v) Right not to be Subject to Automated Decision Making. To not be subject to decisions based solely on automated processing, unless this is necessary pursuant to a contract between you and We.
(vi) Right to Object to Processing Activities. To object to the processing of your Personal Data based on our legitimate interests.
If you want to learn more about any rights under the GDPR, you can visit the European Commission’s page on Data Protection at https://ec.europa.eu/info/law/law-topic/data-protection_en.
(c) Exercising Your Rights.
If you would like to exercise any of your Personal Data rights, please refer to our “Contact Us” section below. When doing so, please tell us which right you are exercising and provide us with contact information to direct our response. Response procedures may vary depending on the laws applicable to you.
Subject to applicable law: (i) we may verify your identity before fulfilling requests to exercise any rights; and (ii) we may request additional information if we cannot initially verify your identity, or if we require such additional information in order to properly assess your request. Any Personal Data you disclose to us for purposes of verifying your identity and/or exercising your rights will solely be used for the purpose of verification and processing of your request.
11. Third-Party Materials
Occasionally, we may include third party links, applications and products through our Services (collectively, the “Third-Party Materials”). These Third-Party Materials are not owned, maintained, operated or controlled by Us. If you engage any Third-Party Materials, such third-party’s privacy notices and practices will apply. We cannot guarantee the privacy or security of your Personal Data once you provide it to a third-party. We encourage you to evaluate the privacy and security policies of each third-party before any such engagement or disclosure. We are not responsible for the content of any Third-Party Materials and do not make any guarantees regarding the privacy or security practices of such third parties. For certainty, we disclaim any liability associated with your access to, use of, or reliance on, such Third-Party Materials and their content. If you decide to access, use, or rely on any such Third-Party Materials, you do so at your sole risk.
12. Communications with Us
To opt-out of receiving certain communications from us (the “Communications”), you may either contact us as provided in the “Contact Us” section below, or, if applicable, click “Unsubscribe”. Please note that certain Communications may be necessary for the proper function of the Services, and opting out of those Communications may hinder your use of the Services.
13. Personal Data About Other People
Before providing any Personal Data on behalf of another person, you confirm that you have received all necessary authorizations from that person to do so.
14. Changes to Our Privacy Policy
We may update this Privacy Policy from time to time. Please review it periodically. We may provide you with notice of important changes to the Privacy Policy as appropriate under the circumstances.
15. Contact Us
If you have any questions about this Privacy Policy or wish to exercise any applicable rights, you may contact our Privacy Officer at team@smithassembly.com or at the following mailing address:
1703 - 110 Switchmen Street
Vancouver, BC V6A 0C6
Canada