top of page

Privacy Policy

Defirst Services Financiers Inc.

(Incorporated under the Business Corporations Act (Quebec))

​

PERSONAL INFORMATION PROTECTION POLICY

​

1. Purpose of the Policy

This policy governs the collection, use, disclosure, retention, and destruction of personal information held by Defirst Financial Services Inc., in accordance with Law 25, the Act respecting the protection of personal information in the private sector, and the regulatory requirements of the AMF.

Its objectives are to:

  • Protect the confidentiality and integrity of personal information

  • Ensure responsible and secure data management

  • Inform clients of their rights

  • Define the responsibilities of the firm and its representatives

 

2. Scope

This policy applies to:

  • All personal information held by the firm

  • All clients, prospective clients, representatives, and employees

  • Any information collected verbally, in writing, or electronically

  • All systems, platforms, and tools used by the firm

 

3. Definition of Personal Information​

Personal information is any information that can be used to identify an individual, including:

  • Name, address, and date of birth

  • Social Insurance Number, when legally required

  • Financial information

  • Medical information, when required for an assessment

  • Identity documents

  • Digital data, including IP addresses, recordings, and similar information

 

4. Guiding Principles for the Protection of Personal Information

​

4.1 Minimal Collection​

Only information required for assessment, recommendations, and regulatory compliance is collected.

​

4.2 Informed Consent​

The client must be informed of:

  • The information being collected

  • How it will be used

  • How it will be retained

  • Their rights

 

4.3 Limited Use

Personal information may only be used for its intended purposes, including:

  • Financial analysis

  • Recommendations

  • Product applications and underwriting

  • Regulatory compliance

 

4.4 Restricted Access

Only authorized individuals may access personal information.

​

4.5 Secure Retention

Information is stored in protected environments that comply with Law 25.

​

4.6 Proper Destruction

Personal information must be permanently destroyed using secure and traceable methods.

​

5. Information Collected

​

5.1 Identification Information

  • Name, address, and date of birth

  • Identity documents

  • Contact information

 

5.2 Financial Information

  • Income, assets, and debts

  • Financial objectives

  • Investor profile

 

5.3 Medical Information

Medical information is collected only when required for an assessment or an insurance product application.

 

5.4 Digital Information

  • Electronic communications

  • Communication history

  • Documents submitted

 

6. Security Measures

​

6.1 Information Technology Security

  • Strong passwords

  • Multi-factor authentication

  • Data encryption

  • Firewalls and antivirus software

  • Regular software updates

  • Automated backups

 

6.2 Physical Security

  • Restricted access to office premises

  • Locked filing cabinets

  • Secure destruction of paper documents

 

6.3 Incident Management

Any confidentiality or security incident must be:

  • Documented

  • Assessed

  • Corrected

  • Reported to the person responsible for the protection of personal information

 

7. Client Rights

Clients may:

  • Access their personal information

  • Request that inaccurate information be corrected

  • Withdraw their consent

  • Request the deletion of their information, subject to legal obligations

  • File a complaint with the person responsible for the protection of personal information

 

8. Disclosure of Personal Information

Personal information may only be disclosed:

  • To insurers and partners required for product applications and underwriting

  • To regulatory authorities, including the AMF and FINTRAC

  • To compliant technology service providers

  • With the client’s express consent

No personal information is sold or shared for commercial purposes.

 

9. Retention and Destruction of Personal Information

  • Personal information is retained for a minimum of seven years following the end of the business relationship

  • Information may be retained for a longer period when required by law

  • Information is permanently destroyed through secure methods, including shredding and secure electronic deletion

 

10. Responsibilities

​

10.1 Person Responsible for the Protection of Personal Information

The firm appoints a person responsible for:

  • Overseeing the implementation of this policy

  • Responding to client requests

  • Managing confidentiality and security incidents

  • Ensuring compliance with Law 25

 

10.2 Representatives and Employees

Representatives and employees must:

  • Comply with this policy

  • Protect personal information

  • Report any incident

  • Complete all required training

 

11. Review of the Policy

This policy is reviewed annually or whenever legislative or technological changes occur.

Revised: Aug. 2026

bottom of page