Security and privacy

INFORMATION SECURITY POLICY

1. POLICY OBJECTIVE

This policy aims to guarantee the integrity, confidentiality and availability of Spectralite / Signoplus information, protecting it against internal and external threats, intentional or accidental.

2. SCOPE OF THE POLICY

This policy applies to all information we process, including personal information, whether stored electronically, on paper or transmitted by other means. All employees, contractors, partners and third parties with access to our information are required to comply with this policy.

“Personal information” means any information relating to a natural person and which allows, directly or indirectly, to identify him or her.

3. ROLES AND RESPONSIBILITIES

Every member of our organization has a responsibility to protect information. Specific roles, such as Information Security Manager, have been established to oversee and implement this policy and associated procedures.

4. CLASSIFICATION AND CONTROL OF INFORMATION

Our information is classified based on its sensitivity and importance to our organization. Appropriate control measures are put in place for each classification level.

5. PHYSICAL AND LOGICAL ACCESS

Access to our information is strictly controlled. Only people who need access to certain information to do their job can do so. Physical and logical access controls are in place to prevent unauthorized access.

6. SAFETY MEASURES

Physical, technical and administrative security measures are in place to protect our information. This includes, among other things, firewalls, data encryption, regular security audits and locking systems for data storage rooms.

7. AWARENESS

Ongoing information security awareness is essential to ensure that all employees understand their responsibilities and the value of the information they handle. Awareness reminders will be distributed regularly to inform employees about good security practices, potential threats, and how to prevent security incidents.

8. INCIDENT MANAGEMENT

All information security incidents will be reported and managed in accordance with our security incident management procedure. Incidents will be analyzed to prevent their recurrence.

9. EVALUATION AND REVIEW

This policy and all associated procedures will be regularly evaluated and revised to ensure that they are always adapted to evolving threats, technologies and the organization.

10. SANCTIONS

Any violation of this policy is considered a serious incident and will be handled accordingly. It should be noted that some information security breach incidents may also result in legal consequences.

This information security policy is supported by our management and is an integral part of our corporate culture. We are committed to protecting our information and managing it responsibly.

PERSONAL INFORMATION COLLECTION AND RETENTION POLICY

“Personal information” means any information relating to a natural person and which allows, directly or indirectly, to identify him or her.

This policy describes how Spectralite / Signoplus uses, maintains and deletes our customers' personal information.

1. COLLECTION OF PERSONAL INFORMATION

When you first request a price at one of our service points or digitally (via our website or by email), a customer account is created. This account is then updated during each visit.

When creating or updating this customer account, we collect the following personal information: First name, last name, street address and telephone number.

2. CUSTOMER CONSENT

Your consent to the collection, use or communication of your personal information must be manifest, free and informed. It must be given for the specific purposes and objectives identified in this policy.

Depending on the nature and sensitivity of your personal information, your consent may be explicit (such consent may be given verbally, in writing or electronically) or implicit (for example, when you voluntarily provide personal information).

By creating a customer account, you consent to your personal information being collected, used, communicated and stored in accordance with this policy. Please read it carefully.

Consent is a voluntary action; each customer has the right to refuse to provide their information. However, it is important to note that without this information we are unable to proceed with production of your order.

Except where the law provides otherwise, you may withdraw your consent at any time, upon giving reasonable notice. Please note that if you choose to withdraw your consent to the collection, use or disclosure of your personal information, we will no longer be able to offer you some of our services.

3. USE OF PERSONAL INFORMATION

The personal information we collect is used primarily to identify individuals who request quotes and order our products. This information allows us to better manage our inventory and ensure quality of service.

This personal information is used exclusively to provide and improve our services. By keeping a history of each customer's purchasing habits and the issues encountered, we are able to better understand the specific needs of our customers and adapt our services accordingly.

However, we may share this information with third parties in certain specific circumstances permitted by law. For example, we may share this information with companies with whom we subcontract, such as transportation services, employees of related companies, the designer and host of our website, or at meetings general with our shareholders. We may also share this information with lawful authorities, lawyers or other people or organizations.

We undertake to only share this information when strictly necessary.

4. ACCESS TO PERSONAL INFORMATION

Personal information may be accessed by our sales software provider who has service points around the world, as well as by Spectralite / Signoplus employees.

For Spectralite / Signoplus employees, access is granted on the basis of need to know personal information to perform their functions.

Our goal is to guarantee quality service and optimal operation of our system, while ensuring the protection and confidentiality of our customers' personal information.

5. PLACE OF STORAGE OF PERSONAL INFORMATION

We take the security of our customers' personal information seriously. All information collected is stored in secure and restricted locations located exclusively in Quebec.

We have implemented robust security measures to protect this information from unauthorized access, use or disclosure.

6. RETENTION OF PERSONAL INFORMATION

We retain customers' personal information for the duration of their relationship with our company and for up to 3 years after the last account activity, except where it must be retained in our backup archives for a period of up to seven years in order to meet legal requirements or when other legal requirements or legally recognized contractual interests require us to retain them for a longer period. Information is held securely and in accordance with our information security policy.

7. DELETION OF PERSONAL INFORMATION

Customer accounts that have not had activity for more than 3 years will be deleted from our database, except when legal requirements or legally recognized contractual interests require us to retain them for a longer period.

8. CUSTOMER RIGHTS

Customers have several rights regarding their personal information. They have the right to request access to their personal information that we hold and to correct it if it is inaccurate. In addition, they can request the deletion of their information when its retention is no longer necessary.

In certain cases, customers can object to the use of their personal information, restrict its use or withdraw their consent to these operations. To exercise this right, reasonable notice must be sent to the email address provided at the end of this policy.

Finally, customers have the right to be informed of a confidentiality incident involving their personal information that may cause them serious harm. To this end, we keep a register of cyber security incidents and we assess the potential harm they may cause.

All requests regarding these rights should be sent by email to protectiondonnees@spectralite.ca

9. COMPLIANCE AND POLICY REVISIONS

This policy will be reviewed and updated as necessary to ensure compliance.

10. . RESPONSE TO CUSTOMER REQUESTS

We undertake to respond to your requests regarding your personal information within 30 days of receipt, except where the law allows an extension of this period. You can send your requests to the Personal Information Manager:

Marie-Chantal Robert
Telephone: 819 378-2765 ext. 203
Email: protectiondonnees@spectralite.ca

Subject to the restrictions provided by law, in the event of refusal to provide or correct your information, we will communicate to you the reasons for this refusal, information on your recourses as well as the applicable legal provisions.

If we refuse to rectify your personal information, we will allow you to provide written comments in your file regarding the personal information that was the subject of the refusal to rectify.

We will also retain personal information that has been the subject of an access request for as long as necessary to allow you to exhaust the remedies provided by law.

11. POLICY DISTRIBUTION

Following its adoption by management, this Personal Information Collection and Conservation Policy is accessible to the general public via our website. We suggest that you print a copy for your personal records and review the content of the “Personal Information Collection and Retention Policy” section of our website on a regular basis.

In addition, during any purchase or rental from Spectralite / Signoplus, a link to this policy is clearly mentioned and made available to you in the terms of our orders, it being an integral part of it. By accepting these terms, you acknowledge that you have read this policy, as well as our way of collecting, storing and processing your personal information, and that you undertake to respect it.

Signoplus - A Spectralite division

Signoplus is a large sign manufacturer of signage (street names, traffic signs, signage for bicycle paths, industries, road transport, transport of dangerous goods, tourism (pictograms), signs in inuktitut and cree, emergency stops for school buses, custom panels, posts and mounting hardware (fasteners). Signoplus uses the following materials: aluminum, CoroplastMC, PlexiglasMD, retroreflective sheeting, vinyl sheetings (stickers), fiberglass, CrézonMD, AlumaliteMD, LusterboardMD, Omega-BondMD and magnetic vinyl.