Privacy Principles
1. Accountability
The RVH Foundation is responsible for the personal information in its custody or under its control including information that has been disclosed or transferred to an agent on behalf of the foundation for the purposes of the foundation, and has designated a Chief Privacy Officer (CPO) who is accountable for the organization’s compliance with the privacy principles and provincial legislation.
2. Identifying Purposes
The RVH Foundation will identify the purposes for which personal information is collected; used and disclosed at or before the time the information is collected.
The RVH Foundation collects and uses personal information for the following purposes:
- To process donations
- To provide tax receipts
- To conduct research and generate statistics/reports
- To communicate news and updates, charitable promotions and upcoming events, charitable stories, as well as other forms of communications including mail appeals.
- To provide support and help to our donor population
- To provide high quality interactions with our donor population
3. Consent for Collection, Use, and Disclosure
Before, or at the time of collection, the RVH Foundation will identify the purposes for which personal information is collected, used disclosed and retained. The knowledge and consent (expressed or implied) of the individual are required for the collection, use, or disclosure of personal information, subject to specific exceptions.
The RVH Foundation collects personal information only for the following purposes:
- To process donations
- To process event related registrations
- To administer to volunteer network
- To ensure donors are kept informed about the programs, services and activities of Royal Victoria Regional Health Centre and the RVH Foundation, including the use and impact of their support
- To seek the support of individuals and organizations in carrying out the mission of the foundation.
If you do not wish to receive communications from the RVH Foundation, you may unsubscribe at any time by following the directions provided with the communications.
4. Limiting Collection
The RVH Foundation limits the collection of personal information to that which is reasonably necessary for the identified purpose, and the foundation will only record information by fair and lawful means. The amount and type of information recorded by the foundation will be limited to the minimum amount necessary to satisfy the intended purposes for the information; and as much as possible, personal information will be collected directly from the individual or organization.
When receiving patient mail lists from Royal Victoria Regional Health Centre, the RVH Foundation will only be provided a name and mailing address. Personal health information and alternative means of communication including telephone and email addresses will not be made available to the foundation.
Information will be collected by fair and lawful means.
5. Limiting Use, Disclosure, and Retention
Personal information shall not be used or disclosed for purposes other than those for which it was collected, except with the consent of the individual or as required by law. Personal information shall be retained only as long as necessary for the fulfillment of those purposes.
- The RVH Foundation does not use or disclose personal information for purposes other than those for which it was collected, except with the consent of the individual or organization or as permitted by law.
- The RVH Foundation does not disclose personal banking information provided by donors, except to the appropriate banking institutions or payment processing providers in order to complete a payment or gift transaction.
- The RVH Foundation may be required to disclose personal information to satisfy a law, regulation or government request, or to satisfy a subpoena, search warrant or legitimate court order.
- The RVH Foundation may need to share personal information with third parties engaged to assist the RVH Foundation in carrying out our mission. Such third parties are contractually bound to protect your personal information, as noted in “Accountability”.
- The RVH Foundation will retain personal information only as long as necessary for the fulfillment of the purposes for which it was collected and for legal or business purposes.
- The RVH Foundation will maintain reasonable and systematic controls for information and records retention and destruction.
- The RVH Foundation may retain personal information in order to best meet the needs of its relationship with the individual or organization
6. Accuracy
Personal information shall be as accurate, complete and up-to-date as is necessary for the purposes for which it is to be used.
An individual may request to have his or her information updated at any time. The foundation may retain the original information as needed, and for reference purposes only.
7. Safeguards
Personal information will be protected by security safeguards appropriate to the sensitivity of the information, regardless of the format in which it is stored.
- The RVH Foundation ensures reasonable efforts to protect personal information from loss, theft, unauthorized access, copying, use, modifications, disclosure and destruction by establishing and maintaining appropriate security safeguards appropriate to the sensitivity level of the information.
- RVH Foundation staff and its representatives are governed by a strict code of conduct, and adhere to strict privacy and confidentiality expectations.
- Gifts and registrations processed through CANADAHELPS donation portal adheres to Payment Card Industry Data Security Standards (PCI DSS) and uses the facilities of a PCI DSS compliant payment processor to securely store payment card details. CANADAHELPS uses Secure Sockets Layer (SSL) technology to help ensure the safety and security of online donations. SSL technology enables encryption of sensitive information.
- Gifts and registrations processed through BLACKBAUD donation portals also adhere to industry-standard SSL encryption techniques to ensure that credit card information, passwords, and personal information are processed securely. An encryption engine has also been installed on the BLACKBAUD database server to ensure data is securely stored.
- The RVH Foundation uses the Raiser’s Edge database to securely store donor information. Database files are stored by BLACKBAUD in a world class data centre, which is monitored 24/7/365, properly configured and compliant with industry standards like PCI DSS and SOC.
- Access to database records is granted to employees and representatives of the RVH Foundation only, and security levels are granted based on a need for access.
- Hard files are located in locked filing cabinets in restricted access offices.
8. Openness
The RVH Foundation will make readily available to individuals specific information about its privacy policies and procedures relating to the management of personal information.
9. Individual Access
Upon request, an individual will be informed of the existence, use, and disclosure of his or her personal information and will be given access to the information. An individual shall be able to challenge the accuracy and completeness of the information and have it amended as appropriate.
Inquiries can be directed to:
The RVH Foundation
Attention: Chief Privacy Officer
201 Georgian Drive
Barrie, ON L4M 6M2
Or call: 705.739.5600
Or email: foundation@rvh.on.ca
10. Challenging Compliance
Any questions or concerns regarding the RVH Foundation's compliance to the Privacy Policy or about our privacy practices may be directed to our Privacy Officer, as noted above.