Skip to main content
Back to home page

Privacy Policy

Last updated 14 February 2026

How Envision collects, uses, discloses, and protects personal information, and the commitments we make to everyone whose information we handle.

01. Introduction

Envision collects, uses, and safeguards personal information in the course of operating its design-build business, delivering digital donor recognition walls, interactive displays, and related platforms and services to its clients. Protecting the personal information entrusted to us, whether it belongs to our employees, our clients, our clients' donors and patrons, or our vendors and partners, is fundamental to maintaining trust and meeting our legal obligations.

This Privacy Policy describes how Envision collects, uses, discloses, retains, and protects personal information, and is supported by Envision's internal information-security policies.

02. Purpose

This policy is intended to:

  • Establish a consistent, organization-wide standard for the responsible handling of personal information.
  • Support Envision's compliance with applicable privacy legislation, including Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), applicable provincial privacy laws, and, where relevant to Envision's United States operations, applicable U.S. state privacy laws.
  • Ensure that personal information is collected only for legitimate business purposes, with appropriate consent, and protected throughout its lifecycle.
  • Define how individuals may exercise their rights with respect to their personal information.
  • Reduce the risk of privacy breaches and ensure a consistent response when incidents occur.

03. Scope

This policy applies to all personnel performing work at or on behalf of Envision. It applies to all personal information that Envision collects, uses, or discloses, in any format, electronic, paper, or information shared orally or visually, and regardless of where it is stored or processed.

04. Definitions

Personal Information
Information about an identifiable individual. This includes name, contact details, identifiers, employment information, financial information, and any other data that, alone or combined with other information, can identify a person. It does not include the business contact information of an individual used solely to contact them in a business capacity, except where applicable law provides otherwise.
Sensitive Personal Information
A subset of personal information that warrants a higher degree of protection, such as financial account details, government-issued identifiers, and Protected Health Information.
Protected Health Information (PHI)
Any information about health status, provision of health care, or payment for health care that can be linked to a specific individual.
Consent
Voluntary agreement to the collection, use, or disclosure of personal information. Consent may be express or implied depending on the sensitivity of the information and the circumstances.
Data Subject / Individual
The identifiable person to whom personal information relates.
Personal Information Bank
Any collection of personal information that is organized and retrievable by an identifier (e.g., a CRM record, a payroll file, a donor list).
Privacy Breach
The loss of, unauthorized access to, or unauthorized collection, use, disclosure, or disposal of personal information.
Service Provider / Third Party
A vendor, contractor, or affiliate that processes personal information on Envision's behalf or that connects to Envision systems under a third-party agreement.

05. Accountability

Envision is responsible for personal information under its control and has designated a VP, Technology and Innovation who is accountable for compliance with this policy.

The accountable role is responsible for maintaining and reviewing this policy; responding to privacy-related inquiries, access requests, and complaints; overseeing privacy awareness across the organization; coordinating the response to privacy breaches; and reviewing new projects, systems, and vendor relationships that involve personal information.

06. Collection of Personal Information

Identifying Purposes

Envision identifies the purposes for which personal information is collected at or before the time of collection. Personal information is collected only for purposes that a reasonable person would consider appropriate in the circumstances, including:

  • Recruiting, onboarding, administering, and supporting employees and contractors.
  • Delivering, installing, and supporting projects and platforms for clients, including donor recognition systems.
  • Managing client, donor, vendor, and partner relationships and communications.
  • Processing payments, invoicing, and maintaining accounting records.
  • Operating, securing, monitoring, and improving Envision's systems and services.
  • Meeting legal, regulatory, contractual, and audit obligations.

Limiting Collection

Envision limits the collection of personal information to what is necessary for the identified purposes. Information is collected by fair and lawful means and is not collected indiscriminately. Where personal information is collected on behalf of a client (for example, donor information used to populate a recognition display), Envision collects and uses that information only in accordance with the agreement with that client and treats it as confidential.

Personal Information Envision Commonly Handles

The categories below are illustrative and not exhaustive. They are presented to help recognize personal information and apply the correct safeguards.

Employee / HR
Contact details, payroll and banking details, government identifiers, performance and benefits records.
Client contacts
Names, business contact details, project correspondence.
Donor / patron data
Donor names, gift levels, recognition text, and images supplied by the client.
Vendor / partner
Contact details, banking and remittance details.
Financial
Invoicing, payment, and account information.

07. Consent

Envision obtains the individual's consent to the collection, use, or disclosure of personal information, except where the law permits or requires otherwise. The form of consent sought is appropriate to the sensitivity of the information:

  • Express consent is obtained for sensitive personal information, including financial and health-related information.
  • Implied consent may be relied upon for less sensitive information where the purpose is obvious and the individual voluntarily provides the information for that purpose.

Where Envision processes personal information on behalf of a client, the client is responsible for obtaining any consent required from the individuals concerned, and Envision relies on the client's representation that appropriate consent has been obtained. An individual may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice; Envision will explain the implications of withdrawal where relevant.

08. Use, Disclosure, and Retention

Limiting Use and Disclosure

Personal information is used and disclosed only for the purposes for which it was collected, except with the individual's consent or as required or permitted by law. Personal information is not sold. Internal access to personal information is restricted to those whose duties require it.

Disclosure to Service Providers

Envision may engage third-party service providers to process personal information on its behalf (for example, cloud hosting, backup, and accounting platforms). Before any non-public personal information is shared, the engagement is subject to a signed third-party agreement, and the provider must offer a comparable level of protection. Connectivity and access follow the least-access principle, and in no case does Envision rely solely upon the third party to protect Envision data.

Disclosure Required by Law

Envision may disclose personal information without consent where required or authorized by law, such as in response to a valid legal demand. Such disclosures are reviewed by the VP, Technology and Innovation in consultation with senior leadership before any information is released.

Retention

Personal information is retained only as long as necessary to fulfill the identified purposes or to meet legal, regulatory, contractual, or audit requirements. When personal information is no longer required, it is securely disposed of.

09. Accuracy

Envision makes reasonable efforts to keep personal information as accurate, complete, and up to date as necessary for the purposes for which it is to be used. Information is updated when an individual notifies Envision of a change or when an inaccuracy is identified. Individuals may request correction of their personal information as described in the Individual Access and Correction section.

10. Safeguards

Envision protects personal information using physical, organizational, and technological safeguards appropriate to the sensitivity of the information. These include, but are not limited to:

  • Access controlled through individual, authenticated logins, with sensitive personal information encrypted using proven, industry-standard methods.
  • Endpoint protection, regular security patching, and controlled remote access.
  • Logging and monitoring of security-related events, with regular, tested backups.
  • Facilities and restricted areas protected by physical access controls, with paper records stored securely and disposed of by secure means.
  • Access granted on a need-to-know basis and reviewed periodically, with privacy and security awareness guidance for personnel and non-disclosure agreements where appropriate.
  • Secure offboarding to ensure timely removal of access when personnel depart.

11. Individual Access and Correction

Subject to applicable law and any legal or contractual restrictions, an individual may request access to the personal information Envision holds about them, ask how it has been used and to whom it has been disclosed, and request correction of inaccurate or incomplete information.

Making a Request

  1. Submit a written request to the VP, Technology and Innovation using the contact information below, providing enough detail to locate the information (for example, your name and the nature of the records sought).
  2. Envision verifies the requester's identity before disclosing any personal information.
  3. Envision responds within the timeframe required by applicable law (generally within 30 days under PIPEDA), or explains any permitted extension.
  4. Where access is denied in whole or in part (for example, to protect the personal information of others or where disclosure is restricted by law), Envision provides the reasons in writing.

Where Envision processes personal information on behalf of a client, access and correction requests relating to that information are referred to the client, who is the appropriate party to respond.

12. Privacy Breach Management

Envision treats a privacy breach as a security incident, managed under its internal incident-response process, with the additional steps below.

Reporting a Suspected Breach

Anyone who becomes aware of a suspected or actual privacy breach must report it immediately to the VP, Technology and Innovation. Early reporting is essential, and individuals will not be penalized for reporting in good faith.

Containment and Assessment

  • Contain the breach by isolating affected systems or recovering records.
  • Assess the scope, the categories and sensitivity of the information involved, the cause, and the number of individuals affected.
  • Evaluate the real risk of significant harm to affected individuals.

Notification

Where a breach creates a real risk of significant harm, Envision will notify affected individuals and the appropriate regulatory authority (such as the Office of the Privacy Commissioner of Canada) as soon as feasible, and will notify any other organizations that may be able to reduce the risk of harm. Where the breach involves client-confidential information, the affected client will be notified in accordance with the applicable agreement. Envision maintains a record of all breaches as required by law.

Remediation

Following any breach, Envision identifies and implements corrective measures to prevent recurrence, which may include changes to safeguards, processes, training, or vendor arrangements.

13. Compliance and Review

The VP, Technology and Innovation reviews this policy at least once a year, or sooner when there are significant changes to Envision's operations, systems, vendor relationships, or applicable law.

14. Contact and Complaints

Questions, access requests, and complaints regarding the handling of personal information may be directed to Envision's VP, Technology and Innovation:

VP, Technology and Innovation, Envision info@envisioncreates.com +1 416 694 8516 750 Millway Avenue, Unit 7, Concord, ON L4K 3T7

If you are not satisfied with Envision's response, you may escalate the matter to the appropriate privacy regulator, such as the Office of the Privacy Commissioner of Canada.