Protection of Privacy Statement


Introduction

At PolicyWise for Children & Families, we are committed to protecting privacy and safeguarding information. This policy statement explains what information we collect, how we use and protect it, and your rights regarding that information.

Although PolicyWise, as a non-profit registered under Part 9 of the Companies Act, is not subject to the Personal Information Protection Act (PIPA) under section 56, it is committed to protecting personal information and managing data in accordance with recognized privacy and governance best practices.

PolicyWise aligns its practices with applicable legislation, regulations, contracts, grant agreements, partner requirements, and recognized frameworks, including Alberta’s Personal Information Protection Act (PIPA), the Protection of Privacy Act (POPA), the Tri-Council Policy Statement: Ethical Conduct for Research Involving Humans (TCPS2, 2022), and the National Standard of Canada: Data Governance—Part 11: Delivery of Community and Human Services.

Principles

In addition to these guiding frameworks, we have committed to the following principles to help guide our actions:

  1. People-centred and community-centred: PolicyWise prioritizes the needs, rights, well-being, and interests of individuals and communities in all data-related decisions and practices. PolicyWise uses data ethically and transparently, and in ways that promote collective benefit and avoid exploitation.
  2. Equitable: Data policies and processes will consider diversity, equity, justice, and inclusivity. PolicyWise aims to mitigate bias, avoid perpetuating disparities, and advance equity through its work with data.
  3. Proportional: Processes for managing and governing data will be proportionate to its value and risk, and balance societal and personal costs, benefits, and trade-offs. PolicyWise aims to apply data practices in balanced and context-sensitive ways.

What information we collect

We primarily collect de-identified, anonymized, or anonymous information (“non-personal data”) to support our projects and services. When we receive data from our partners, it is typically provided in a non-identifiable way.

We only collect personal information such as name, contact information, or other identifiers when it is necessary for a specific purpose.

We may also collect organizational information to complete projects or provide services.

We collect limited, anonymous web and social media data such as page visits, clicks, and views. 

We provide additional details about what information is being collected and why at the point of collection.

We sometimes receive information from our partners to support our work with them. Information received from partners is protected using the same safeguards as information we collect directly.

Why we collect information

We collect information to deliver our services, carry out our projects, and support our mission. Depending on the activity, this may include research, evaluation, reporting, learning, engagement, advocacy, website administration, and communications.

We only collect and use personal information when it is necessary for purposes such as, but not limited to:

  • Providing our services.
  • Managing and delivering workshops, webinars, or other events.
  • Scheduling and conducting interviews or focus groups.
  • Sending newsletters or updates when you have subscribed.
  • Responding to inquiries or requests.
  • Accepting a donation and issuing tax receipts.
  • Meeting legal and regulatory obligations.

How we collect information

We collect information in two primary ways:

Directly from you, such as when you contact us, sign up for our newsletter, complete a form or survey, or participate in a focus group or interview.

Automatically, through limited technical information collected when you use our website, including cookies and website analytics tools.

When we collect information directly from you, we will ask for your consent, either explicitly or implicitly. Participation in our data collection activities is voluntary. You may choose not to answer specific questions, withdraw from a survey, unsubscribe from communications, or stop participating at any time.

Who we share information with

We do not sell, rent, or license personal information in our custody or control.

We may share summarized, non-identifiable data for reporting, research, evaluation, knowledge sharing, funding, advocacy, or other purposes related to our mission. Information is combined so that individuals cannot be identified.

We may use non-identifying quotes or examples to illustrate findings. We will not identify individuals or organizations without consent.

We may share (disclose) information:

  • With your consent.
  • Without your consent for the reasons listed in the Personal Information Protection Act section 20.
  • With service providers who help us manage data through their software.
  • To comply with legal obligations, court orders, or lawful requests from regulatory authorities.

Service providers are only authorized to access information as necessary to provide services on our behalf and may not use it for their own marketing or commercial purposes.

Protecting your information

We protect and secure all information in our custody or control. We keep personal information confidential and private.

We use a combination of technical and organizational measures to keep your data safe from unauthorized access, use, disclosure, loss, or misuse.

Our safeguards include:

  • Encryption of information in transit and, where appropriate, at rest.
  • Data minimization, collecting only the information necessary for a specific purpose.
  • Staff training on privacy, security, and data management practices.
  • Confidentiality agreements for employees, contractors, and volunteers with access to information.
  • Access controls that limit access to authorized individuals who require it for their work.

Information in our custody or control may be stored and managed using secure digital platforms and cloud-based systems that support our operations, communications, reporting, analysis, and evaluation.

We use software and tools from different service providers that provide enterprise-grade security and complies with different security certifications including SOC1, SOC2, and ISO27001 and that comply with Canadian privacy regulations or similar.

Service providers used by PolicyWise may include website management tools, analytics services, customer relationship management systems, survey platforms, productivity software, and donation management systems. We assess service providers to ensure they meet appropriate privacy and security standards. Whenever feasible, we prioritize Canadian data residency; however, some service providers may store or process information in other countries.

We retain personal information only for as long as necessary for the specific purposes for which it was collected and to meet legal, regulatory, and operational requirements. When information is no longer required, it is securely deleted, destroyed, anonymized, or de-identified, as appropriate.

De-identified, aggregated, or summarized information may be retained in accordance with our retention and disposition schedule and applicable laws and regulations.

Breaches and incident response

We take reasonable steps to protect personal and non-personal information from unauthorized access, loss, misuse, disclosure, or alteration. In the event of a privacy or security breach involving personal information, we will assess the situation and take appropriate steps to contain, investigate, and address the issue.

Where required by applicable privacy laws or where there is a real risk of significant harm, affected individuals or organizations may be notified of the breach and provided with relevant information about the steps being taken in response. We may also contact the Information and Privacy Commissioner of Alberta, as appropriate.

We will also work with any relevant third-party service providers involved to address and mitigate the impact of the breach where applicable.

Your rights

Subject to applicable laws, you have the right to:

  • Access and correct your personal information;
  • Request deletion of your personal information (with some legal exceptions);
  • Withdraw or change your consent or request removal of your personal information;
  • File a complaint with the appropriate privacy authority if you believe your rights have been violated.

Some rights may be limited where the information has been anonymized, aggregated, or cannot be reasonably linked to an individual (also called “non-personal information”).

We seek to respond to access requests within the timeframes established by the Personal Information Protection Act section 28.

Updates

This policy may be updated from time to time to reflect changes in applicable laws, regulations, best practices, technologies, systems, and our policies and practices. Updated versions of this policy will be posted on our website.

This policy was last updated on July 22nd, 2026.

Contact us

If you have any questions, concerns, or comments about this privacy policy, please contact our Privacy Officer at info@policywise.com or by phone Monday to Friday 9 am to 3 pm at 780-944-8630.