Privacy Notice
At ASASSUR Inc., protecting your personal information is our priority. We collect, use, and share your information only to offer and manage insurance products and services, in accordance with Quebec law and the AMF guidelines. You have the right to access, correct, or withdraw your personal information at any time, subject to legal obligations. Any personal information collected for, hosted by, and used on this website may be governed by the Act respecting the protection of personal information in the private sector of the province of Quebec. ASASSUR has implemented physical, administrative, and technical safeguards to ensure that such information is not used in any way other than intended. Any personal information submitted to ASASSUR Inc. will not be shared with other companies or organizations. For any questions, please contact our Privacy Officer: Ke Mo Huang info@asassur.com 514-748-7165
PRIVACY POLICY AND PROTECTION OF PERSONAL INFORMATION (WEBSITE DISCLOSURE)
Given the nature of our activities, ASASSUR INC. understands the importance of protecting
the personal information it collects in order to provide the services for which it is necessary.
In accordance with the legal framework in force, ASASSUR INC. has implemented a set of
control measures and procedures to ensure sound governance in terms of confidentiality
and protection of the personal information we hold about our prospective customers,
customers, partners, and employees.
By providing us with your personal information, you agree to the terms of this policy and
authorize us to process your information in accordance with it.
Definition of personal information
“Personal or nominative information”: Personal information is any information that concerns a
natural person and allows, directly or indirectly, to identify them (Act respecting the protection of personal information in the private sector, s. 2 (2023/09/25)).
This information may include, but is not limited to, identifying information (e.g., name, address,
telephone number, driver’s license number), financial information (e.g., credit card number),
medical information, information related to professional activities (e.g., employee file), etc.
Consent
No information is collected by ASASSUR INC. without the consent of the customer, agent, or
prospect.
By providing us with your personal information, your consent is effective. Consequently, you
agree to the terms of this policy and authorize us to collect, store, use, and disclose your
information in accordance with the purposes for which it was collected.
Right to withdraw consent to the use or disclosure of information
Subject to certain limitations, you may withdraw your consent to the collection, use, and
disclosure of your personal information. In such circumstances, ASASSUR INC. may not be able
to offer you the product, rate, or service requested for your insurance policy.
➢ For more information, see the Act respecting the protection of personal information in
the private sector (PRIVACY AND ACCESS TO INFORMATION ACT, 2023/09/25, Section 2, s.8.)
Collection and use of information
We only request the essential information we need to respond to your request, including the
following examples:
➢ Conducting a comprehensive analysis of protection needs
➢ Provide an insurance quote for the requested product(s)
➢ Issuing an insurance policy for this purpose, if applicable
➢ Pay for a product or service purchased
Information via third parties
Committed to protecting its customers’ personal information, ASASSUR INC. does not sell,
collect, share, disclose to third parties, or make public any personal information about its
customers, except for the purpose of fulfilling its service mandate, ensuring continuity of service
to its customers, or in the specific context of complying with a court order or responding to an
authorized government agency.
In these circumstances, ASASSUR INC. may collect or transmit information to legitimately
authorized organizations and/or those subject to the regulatory framework in force, or to
specialized suppliers who have formally committed to protecting our firm’s personal
information. Examples include, but are not limited to:
➢ Insurance brokers or claims adjusters;
➢ Insurers, reinsurers, financial institutions, or organizations responsible for their regulation;
➢ Courts
➢ The Central Automobile Claims Database and the Société d’assurance automobile du
Québec or another province;
➢ Credit, risk, and claims data analysis agencies;
➢ Collection agencies;
➢ Delivery partners:
➢ Internal manager or external partner for IT management and/or personal information
and data security;
➢ Legal consultants;
➢ Cloud service providers;
➢ Authorized payment service providers.
Cookies and other technologies
In order to improve the quality of the services offered and the customer experience on the
website, ASASSUR INC. may use cookies and other web analytics technologies to remember
your preferences and interactions with our website. The terms of use are described on our
website.
Retention and destruction of personal information
Our firm retains your personal data in order to fulfill our mandate to you in accordance with
the terms and legal obligations to which we are subject.
Security of personal information
To ensure the security and confidentiality of personal information, ASASSUR INC. adopts rigorous
security measures, including both physical and technological aspects. Here are some
concrete examples:
● Security
● Access controls
● Staff training
● Data encryption
● Intrusion monitoring and detection
● Disaster recovery plans
Although we make every effort to protect your personal data, you should be aware that no
method of transmission over the Internet or electronic storage can guarantee absolute
security.
Commitment of staff and the firm
All employees, suppliers, and partners associated with our firm are contractually bound to
comply with our privacy policy and to protect the personal information held by ASASSUR INC.,
which is for the exclusive use of our firm. This commitment begins when the employee, supplier,
or partner starts working with us and continues indefinitely.
AI : Artificial intelligence
ASASSUR INC. uses certain secure artificial intelligence solutions to optimize and verify the
processing of files. Naturally, no personal data or any identifiable data is processed by the
artificial intelligence.
Data hosting
ASASSUR INC. does business with various web service providers. Some providers may host data
outside the province of Quebec or Canada. In such circumstances, the laws of other provinces
and countries apply.
Accuracy of information
Our staff strives to maintain the accuracy of the information in our client files. You can validate
and update the information in your file with our team of certified professionals.
Right of access and correction
If inaccurate information appears in the file, or if access to personal information is required, a
written request may be sent to the person responsible for protecting personal information in
order to make corrections. In such circumstances, our firm follows the established protocol:
➢ Submit a written request for access or correction
➢ Submit the written request to the firm’s email address or physical address.
➢ You will receive an acknowledgment of receipt
➢ Your identity will be verified
➢ Your request will be processed within 30 days of receipt. (Act respecting the protection of personal information in the private sector section 32)
➢ For more information, see the Act respecting the protection of personal information in
the private sector (PRIVACY AND E-GOVERNMENT ACT, 2023/09/25, Section 2, s.8.)
Quotes
In order to prepare a quote, service offer, or insurance contract, we are required to analyze
the needs of the person concerned as well as all persons involved or mentioned in the process.
Whether requests are made by telephone, in person, or online, the consent of all targeted
individuals must be obtained directly.
Online quotes (via website)
When a quote request form is submitted via the ASASSUR INC. website, the customer
automatically understands, authorizes, and consents to ASASSUR INC.:
➢ Use their personal information to analyze their protection needs in order to provide an
insurance quote for the requested product;
➢ Communicate with them by phone, email, or other means to discuss their file, provide
them with the requested quote, and, if necessary, discuss other services offered by
ASASSUR INC.;
➢ Use their email address to respond to their request;
Email communication / Online subscription and unsubscription
After you provide your email address to ASASSUR INC., ASASSUR INC. may send you information
by email. You may confirm or withdraw your consent to the use of your email address at any
time by unsubscribing from the distribution list in one of the following ways:
➢ By following a link in the message or email that takes you to the online unsubscribe page
(if applicable)
➢ By contacting the information protection officer at the email address provided at the
bottom of this policy.
In this way, and in accordance with the CPPA ( An Act to promote the efficiency and adaptability of the Canadian economy by regulating certain activities that discourage reliance on electronic means of carrying
out commercial activities, and to amend the Canadian Radio-television and Telecommunications Commission Act, the Competition Act, the Personal Information Protection
and Electronic Documents Act and the Telecommunications Act) section 11.1 ) , you can stop receiving any unsolicited emails
that may have been sent by ASASSUR INC..
Telephone recording, chat
For reasons of information integrity, training, and customer service quality control, all telephone
conversations may be recorded or monitored.
Electronic communication
Like cell phones and standard mail, communication via the Internet or unencrypted email
cannot be completely secure or confidential. Such communications are susceptible to
modification, loss, or interception. ASASSUR INC. declines all responsibility for any damage that
may be caused to a person in connection with us, regardless of the form of communication.
Electronic communication
Like cell phones and standard mail, communication via the Internet or unencrypted email
cannot be completely secure or confidential. Such communications are susceptible to
modification, loss, or interception. ASASSUR INC. declines all responsibility for any damage that
may be caused to a person in connection with us, regardless of the form of communication.
Disclaimer – email
Our customers sometimes send us emails containing personal information. ASASSUR INC.
cannot be held responsible for the loss, interception, hacking, or alteration of any email sent
to us.
Policy changes
As confidentiality and the protection of personal information are of paramount importance to
us, this policy may be amended to reflect internal and/or legal changes.
We invite you to review our privacy policy regularly to stay informed of any changes.
Designated Privacy Officer
Please do not hesitate to contact the privacy officer if you have any questions regarding
confidentiality and the protection of personal information.
Firm
ASASSUR INC.
Privacy Officer
Ke Mo Huang
Last policy update
1st may 2026
Address
500-3055, BLVD SAINT-MARTIN O
City
LAVAL, QUEBEC
Zip code
H7T 0J3
Toll-free phone number
(514) 748-7165
Email
info@asassur.com
TERMS OF USE FOR THE WEBSITE (WEBSITE DISTRIBUTION MODEL)
LEGAL NOTICE
By accessing and using this website, you acknowledge that you have read and agree to the
terms of use associated with it. The terms are described with transparency in mind. Therefore, if
you feel uncomfortable, we invite you to stop using the ASASSUR INC. website and contact
one of our resources who can personally assist you.
Website and consent
By using this website, you agree to be bound by the terms and conditions that govern it, which
are based on the privacy policy also available on our website.
Interpretation and jurisdiction
Access to and use of this site are subject to all applicable laws and regulations in the province
or territory where you reside. It is important to note that not all products, services, and
information are applicable or available throughout Canada or outside Canada. The
information is strictly for informational purposes. It is your responsibility to verify whether the
content of this site applies to your specific situation based on the laws of your country.
Informative website and content
The website provides general information to its customers. The information contained in the
pages of the site is considered reliable, but there is no guarantee that it is up to date at all
times. ASASSUR INC. cannot be held responsible, in whole or in part, for the accuracy and
completeness of the content of the site, nor for any damage this may cause you.
It is recommended that you consult an advisor at ASASSUR INC. to obtain up-to-date advice
and information so that the products and services you choose are appropriate for your specific
situation.
Security
Despite our best efforts, ASASSUR INC. cannot guarantee that hacking, viruses, computer
worms, hyperlinks, Trojan horses, errors or omissions, or any other harmful components will not
cause a breakdown, loss of accessibility, interruption, loss in the transmission of information, or
damage to your computer system. Communication via the internet or unencrypted email
cannot be completely secure.
You are solely responsible for taking appropriate precautions to search for computer viruses or
other destructive properties in order to ensure the adequate protection and backup of your
data or equipment.
Cookies and Web Analytics
In order to improve the quality of the services offered and the customer experience on the
website, information is collected by digital markers (Web Analytics) to keep track of your
interactions with our website.
ASASSUR INC. may use Google Analytics or JavaScript cookies, which you can modify or
disable at any time from your browser, however you may no longer be able to access certain
parts of our website:
➢ Delete, allow, and manage cookies in Chrome
➢ Delete and manage cookies in Microsoft Edge
➢ Clear cookies and site data in Firefox
➢ Clear cookies in Safari on Mac – Apple Support (UK)
➢ Browser add-on to disable Google Analytics.
Intellectual property
Certain names, words, titles, expressions, logos, icons, graphics, or designs contained in the
pages of the site are trade names or trademarks belonging to ASASSUR INC..
The elements contained on this site are for personal use only. Without the written permission of
ASASSUR INC., the content of the site may not be reproduced or used in whole or in part for
any purpose other than personal use.
Disclaimer – website
ASASSUR INC. assumes no responsibility for any loss, damage, lawsuit, claim, or expense, direct
or indirect, arising from the use of this website. The information presented is not guaranteed in
any way, and it remains the responsibility of each individual to consult a competent and
qualified resource at ASASSUR INC. in order to obtain advice and services specific to their
situation.
Users who consult and use this website assume all risks inherent in browsing. Furthermore,
ASASSUR INC. cannot be held liable for any damage caused by hacking, viruses, computer
viruses, hyperlinks, Trojan horses, errors or omissions, or any other harmful component or
information. This limitation of warranty also applies to the interruption or partial or complete
inaccessibility of this site.
Several links to external sources are provided to simplify user navigation, but no guarantee is
offered as to the risks or functioning of these sites.
It is recommended that each user of the website take reasonable precautions to detect the
presence of any harmful components on the website, and more broadly on the internet. It is
the user’s responsibility to back up their computer data before using this website.
Changes to the terms and conditions
The terms and conditions of use of our website and the privacy and personal information
protection policy may be subject to change to reflect internal and/or legal changes.
We invite you to regularly review our terms of use to stay informed of any changes.
For further information, please consult the PRIVACY AND PERSONAL INFORMATION PROTECTION
POLICY, also available on our website.
PROCEDURE – PROTECTION OF PERSONAL INFORMATION (PRIVATE SECTOR)
ASASSUR INC. has standardized several document templates for confidentiality commitments
regarding personal information and information belonging to the firm. Other documents not
listed are also available, such as employment contracts and contractual agreements with
suppliers.
CONNECTION WITNESSES (also known as COOKIES)
website is accessed. This makes it possible to manage or accept cookies.
Upon request, users can also set their preferences in terms of cookies in a more comprehensive menu.
To facilitate access to the browser cookie consent menu, an icon remains accessible at the
bottom of the page throughout the website.
COLLECTION – ACCESS – COMMUNICATION OF PERSONAL INFORMATION (outil-renseignements-personnels-procedure-fr.pdf (chad.ca) + LPRPSP (UPDATED 202309) )
Essentially, our firm acts with complete transparency regarding the information it may hold on
a data subject, who may, upon request, obtain a copy in writing and in an intelligible form (https://www.legisquebec.gouv.qc.ca/fr/document/lc/ccq-1991, section 38).
Among the procedures put in place for collection and with a view to ensuring transparency
in our practice, our firm informs the person concerned (PRIVATE SECTOR PERSONAL INFORMATION PROTECTION ACT, 2023/09/25, Section 2, art.8.):
1° the purposes for which the information is being collected;
2° the means by which the information is collected;
3° the rights of access and rectification provided for by law;
4° their right to withdraw their consent to the disclosure or use of the information
collected. (09/2023)
EXAMPLE: LIMITING ACCESS TO CONFIDENTIAL INFORMATION
You must take measures to restrict access to the information contained in your files, whether in
paper or digital form. Your employees should only have access to the information they need
to perform their duties.
EXAMPLE: An accounting department employee should only have access to the information
necessary for billing purposes and not to the entire file prepared by the damage insurance
representative.
EXAMPLE: You already insure automobiles and want to offer home insurance services. It is
recommended that you obtain consent and information related to bank withdrawals.
COMMUNICATION OF PERSONAL INFORMATION NECESSARY FOR THE PURPOSES OF A
COMMERCIAL TRANSACTION
In the event that our firm plans to transfer volume, or acquire or sell clients, our approach will
be governed by various procedures, including the following:
PROCEDURES – COMMERCIAL TRANSACTIONS — Appendix
-Letter Notifying of a New Commercial Transaction: — (Appendix – A)
-Evaluation of privacy policies of external suppliers/partners:
-Letter Volume transfer between insurers: — (Appendix – A)
-Letter of commitment from a technology service provider to
respect the security of personal and confidential information — (Appendix – J.1)
-Letter of commitment from a service provider to respect the
security of personal and confidential information — (Appendix J.2)
-Conducting a PIA: — (Appendix – U)
CONSENT (personal-information-tool-procedure-en.pdf (chad.ca) + PIPEDA (UPDATED 202309)) (APPENDIX – W DISCLOSURE FORM)
For the purposes of transparency and accessibility to clients, information explaining the
concept of consent has been made available in the privacy policy, which is available on the
firm’s website. Our firm refers to it through various means of communication to enable clients
to refer to it.
Although consent is addressed in the policy, client consent is obtained through the disclosure
of the following four elements:
1. The identity of the individuals or companies to whom the insured authorizes the collection
or disclosure of personal information. (Example: for the Central Automobile Claims
Database (CACD) of the Groupement des assureurs automobiles);
2. The nature of the information exchanged, for example, the insured’s auto insurance claims
history;
3. The use that will be made of the information collected or disclosed, such as setting the
insurance premium;
4. The period of validity of the consent, for example, one year.
Verbal consent (by telephone):
➢ Standard internal form for obtaining consent + note in the file
• Internal consent form (automated verbal telephone message)
• Internal formula referring to the website’s privacy policy.
• Internal consent form (verbal consent given by individuals)
• TEMPLATE (APPENDIX W)
Written consent:
➢ Consent form (provided directly or available on the website).
• Internal automated consent form (telephone/website/email) (Written)
• Confirmation of consent accepted in the client file (traceability) from the firm’s
website
➢ Website: Hyperlink to the privacy policy
➢ Telecommunications system: See reference to our privacy policy.
RETENTION OF PERSONAL INFORMATION – (POPULARIZED)
Storage locations for personal information within the firm
Locations cited in the BCP – No personal information stored externally.
CLIENT FILE
Each file must be kept in its entirety in APPLIED EPIC for a minimum period of five (5) years,
starting from the later of the following events:
➢
The permanent closure of the file,
➢ The date of the last service provided to the client,
➢ The expiration date without renewal,
➢ The replacement of the last product sold to that customer.
During the first five (5) years
Representatives are advised to have any non-certified person with access to their files sign a
confidentiality agreement. If the firm or professional does business with an archiving company,
they must ensure that their contract contains such a clause.
After five (5) years
Whether stored on paper or digitally (https://www.mesprocedures.ca/) , files must be destroyed securely. Paper documents must be shredded before being sent for recycling, and computer files must be irreversibly erased from the hard drive, ideally by professionals who guarantee permanent deletion, particularly with regard to computer equipment and digital virtual spaces.
Categorization and retention periods for personal information (https://www.mesprocedures.ca/)
CATEGORIES OF INFORMATION Retention Periods
Firm employees 7 years after termination of employment
Board members 7 years after the end of their term
Members of the organization Varies depending on the type of personal information
Customers Varies depending on the type of personal information
*For more details, refer to the complete inventory of personal information held.
*Please note that specific retention periods may apply.
DESTRUCTION OF PERSONAL INFORMATION
PAPER DESTRUCTION
All paper documentation is handled by Jing Zhu Huang, which shreds and handles it at the
offices of ASASSUR INC. and collects the sealed boxes designed for this purpose.
DIGITAL
All digital documentation is handled in house, by Ke Mo HUANG, which archives and/or
destroys it.
COMPUTER EQUIPMENT
All destruction of computer equipment is handled in house, by Ke Mo HUANG, which applies a
secure procedure.
ANONYMIZATION OF PERSONAL INFORMATION
Personal information should only be anonymized if the organization wishes to retain and use it
for serious and legitimate purposes.
RIGHT OF ACCESS & RIGHT TO DE-INDEXING – CORRECTION OF ONE’S FILE
The purpose of the deindexing process is to address our customers’ concerns and fears
regarding confidentiality and the protection of personal information. Customers may request
access to their personal information and the contents of their file.
✓ Access is free of charge (Act respecting the protection of personal information in the private sector, section 33) (fees may apply).
✓ Personal information must be provided in a written and intelligible transcription in a
structured and commonly used technological format. (Act respecting the protection of personal information in the private sector, section 33)
Scope
Requests for de-indexing/deletion of personal information concern information published on
our online platforms, including our website, mobile applications, databases, or other digital
media used by our customers. (Bill 25 | MesProcédures (mesprocedures.ca))
PROCEDURE FOR PROCESSING DEINDEXING REQUESTS AND EXERCISING THE RIGHT OF ACCESS
TO PERSONAL INFORMATION BY THE INDIVIDUAL CONCERNED (https://chad.ca/actualites/2023/09/modernisation-de-la-protection-des-renseignements-personnels-des-outils-mis-a-jour/)
❑ Receive, guide, and assist a client in:
o Complete a written request
o Direct them to the appropriate channel (Private Sector Protection of Personal Information Act, section 30) : Info@asassur.com
❑ The personal information protection officer must record all requests for deindexing anddeletion of personal information, as well as the actions taken to respond to them, in a dedicated tracking system. (Loi 25 | https://www.mesprocedures.ca/)
❑ Acknowledge receipt of the written request sent to the requester.
❑ Identity verification: The individual’s identity must be reasonably verified before processing the request.
❑ The privacy officer must respond in writing to the request for access or correction, diligently and no later than 30 days from the date of receipt (Act respecting the protection of personal information in the private sector, section 32) of the request.
PRIVACY INCIDENT MANAGEMENT PROCEDURE
Our firm has implemented a security incident and personal information breach management
plan to ensure proactive incident management while continuously improving security
practices.
Scope
Concerned with the security of personal information, the scope of this procedure includes all
networks and systems under our firm’s management as well as stakeholders (clients, partners,
employees, subcontractors, specialized suppliers) who access these systems.
Example of confidentiality indicents: https://chad.ca/actualites/2023/09/modernisation-de-la-protection-des-renseignements-personnels-des-outils-mis-a-jour/ (French)
Management tools
Our firm has implemented various initiatives to optimize the management of different potential
confidentiality incident scenarios:
✓ BCP (business continuity plan) including:
o Several specific response plans tailored to different types of confidentiality
incidents.
o A list of initial actions to be taken according to each scenario
✓ Confidentiality incident log (English | Commission d’accès à l’information du Québec) (APPENDIX – I)
✓ Procedure for notifying the CAI (CAI: Commission d’accès à l’information)
o Notification when assessing potential serious harm
o Deadline for notifying the CAI and authorities depends on the potential harm
• (notify as soon as possible)
o Notification form for the CAI to be completed
NOTIFICATION FORM FOR THE CAI: CONFIDENTIALITY INCIDENT (032023 – FRENCH) (APPENDIX–I)
✓ Corrective measures to prevent recurrence
ASSESSMENT OF PRIVACY FACTORS (Privacy Impact Assessment | Commission d’accès à l’information du Québec (gouv.qc.ca) )2023/09/22))
(EXAMPLE: ACQUISITION OR SALE OF CUSTOMER BASE – TECHNOLOGY PROJECT, SOFTWARE CHANGE – EPIC)
Various activities or projects involving personal information may be subject to further
assessment, for which the firm has implemented a privacy impact assessment.
Many Guide are accessible on protocol based on the CAI portal Commission à l’accès de
l’information du Québec.
Some activities that may be subject to the PIA (PRIVACY ACT IN THE PRIVATE SECTOR, s.17.) :
➢ The sale or acquisition of business volume (clientele) or firms
o Acquisition of nominative lists
➢ The redesign or integration of computer system data
➢ Entrusting a person or organization outside Quebec with the task of collecting, using,
communicating, or storing such information on behalf of a third party individual or
organization.
o Example: A CLOUD provider storing firm data in a hosting center outside Quebec
CAI EFVP guidance document for reference (APPENDIX – U)
➢ Privacy Impact Assessment | Commission d’accès à l’information du Québec
(gouv.qc.ca) (french)
Free PIA report template: CY-CLIC
➢ PIA – CY-clic: (french)
—
—
—
Appendix
ASASSUR INC.
500-3055, BLVD SAINT-MARTIN O
LAVAL, QUEBEC
H7T 0J3
Tel: (514) 748-7165
[Date]
Notice to customers of ASASSUR INC. acquiring customers from the firm XXX-FIRMNAME-XXX
To the distinguished clients of XXX-NAME OF FIRM SOLD-XXX,
We are very excited to announce that ASASSUR INC. has acquired the firm XXX-FIRMNAME
XXX.
For XX years, XXX-NAME OF FIRM SOLD-XXX has provided quality service to a growing client
base. The owner(s) wanted to ensure that their clients would continue to receive outstanding,
professional service and support for their current and future needs.
With this in mind, quality customer service is at the heart of ASASSUR INC.’s values. Our passion
for insurance and the close, privileged relationship we have developed with our customers
guide our daily practices. We are therefore delighted to continue providing you with our
services.
We would like to thank you in advance for your trust, your open-mindedness, and your
commitment to making ASASSUR INC. what it is today and what it will be tomorrow.
See you soon!
Signatures: Yu Huang ASASSUR INC. and Owner
XXX-NAME OF CABINET SOLD-XXX
ASASSUR INC.
Notice to our customers – Transfer of volume to another insurer
Notice to our valued customers,
500-3055, BLVD SAINT-MARTIN O
LAVAL, QUEBEC
H7T 0J3
Tel: (514) 748-7165
[Date]
ASASSUR INC. would like to inform you of an operational change aimed simply at offering you
the best quality of service.
With this in mind, we would like to inform you that XXX-INSURER2-XXX will now be the insurer
associated with your file and will therefore replace XXX-INSURER1-XXX.
The ASASSUR INC. team will remain your point of contact for all matters related to your file.
Therefore, this change does not require any action on your part.
However, if you have any questions, please do not hesitate to contact your usual contact
person or one of our team members, who will be happy to assist you.
We thank you in advance for your trust and understanding.
We look forward to continuing to serve you.
____________________________________
Yu Huang
ASASSUR INC.
APPENDIX – I: CONFIDENTIALITY INCIDENT LOG TEMPLATE
WITH TECHNOLOGY) TO RESPECT THE PROTECTION OF PERSONAL AND CONFIDENTIAL
INFORMATION OF ASASSUR INC.
ASASSUR INC.
500-3055, BLVD SAINT-MARTIN O
LAVAL, QUEBEC
H7T 0J3
Tel: (514) 748-7165
LETTER OF COMMITMENT FROM XXX-IT-SUPPLIER-XXX (TECHNOLOGY SERVICE) TO RESPECT THE
PROTECTION OF PERSONAL AND CONFIDENTIAL INFORMATION OF ASASSUR INC.
[Date]
XXX-IT-PROVIDER-XXX
Address
City
Postal
ASASSUR INC. engages XXX-IT-PROVIDER-XXX [describe the scope of the mandate]. (the “Subject”)
XXX-IT-PROVIDER-XXX hereby undertakes to ASASSUR INC. to ensure the protection and confidentiality of
personal information and all information relating to the company, its customers, and its employees to
which it may have access through the services offered, with the same level of security that it applies to
protect its own confidential information of a similar nature, but in any case, to a degree at least equal
to a reasonable standard of security, and undertakes to use personal information solely in the course of
its duties.
The terms personal and confidential information include, but are not limited to: financial and
administrative information, computer programs, marketing strategies, know-how, customer and/or
employee lists, and any other information that a reasonable person would consider to be confidential
in light of its content or the circumstances of its disclosure. Confidential information may also be included
in any verbal or written communication, regardless of format or medium, even if such communications
are not identified as confidential or provided under the seal of confidentiality.
Furthermore, acting also as a technology provider, XXX-IT-PROVIDER-XXX undertakes to disclose all
known or potential security breaches in order to implement appropriate measures with ASASSUR INC. to
ensure the protection of personal and confidential information. Similarly, as soon as XXX-SUPPLIER-XXX
has reason to believe that a confidentiality incident involving personal information has occurred, it
undertakes to immediately notify ASASSUR INC. in writing.
XXX-IT-PROVIDER-XXX undertakes not to copy, reproduce, or use personal information in any way or for
any reason other than to pursue the Purpose. Furthermore, no personal information or confidential
information relating to the activities of ASASSUR INC. may be disclosed to third parties without the prior
authorization of an authorized representative of ASASSUR INC..
XXX-IT-PROVIDER-XXX may, however, disclose confidential information to its employees, officers,
directors, and representatives to the extent that such persons need to know such information in
connection with the Purpose. XXX-IT-PROVIDER-XXX undertakes to ensure that its employees respect the
confidentiality of personal information to which they have access in the course of their duties.
POLICY & PROCEDURE GUIDE – – – – –
XXX-IT-PROVIDER-XXX undertakes to:
Use personal information solely for the purposes of achieving the Purpose and, when personal
information is no longer necessary for achieving the Purpose or in the event of the termination of
contractual activities, destroy the personal information;
Comply with all instructions regarding the processing of personal information;
Not subcontracting the processing of personal information without first obtaining the written approval
of an authorized representative of ASASSUR INC.;
Implement the necessary security and protection measures to protect personal information, taking
into account its sensitive nature, the reason for which it is to be used, and the quantity, distribution,
and format of the personal information; and
Immediately notify ASASSUR INC. if it receives a request for access to personal information from a
customer of ASASSUR INC., a government agency, or another regulatory body, so that the Parties are
able to respond to the request satisfactorily and within thirty (30) days;
In the event of termination of contractual activities, XXX-SUPPLIER-IT-XXX and all of its resources that have
had access to ASASSUR INC.’s information remain bound by this confidentiality agreement, without any
time limit.
This agreement may only be amended, modified, terminated, canceled, or reformulated by a written
document signed by an authorized representative of each party.
The supplier acknowledges that failure to comply with this commitment will immediately give rise to all
appropriate legal remedies. Consequently, ASASSUR INC. may seek legal redress for damages caused
by XXX-SUPPLIER-IT-XXX or arising from such a breach, without prejudice to any rights and remedies of
ASASSUR INC., or seek a court injunction.
This agreement shall come into force upon signature.
____________________________________________
Authorized representative XXX-SUPPLIER-IT-XXX
Title:
APPENDIX – J.2: LETTER OF COMMITMENT FROM EXTERNAL SUPPLIERS OF OTHER EXTERNAL
SERVICES TO COMPLY WITH THE PROTECTION OF PERSONAL AND CONFIDENTIAL
INFORMATION OF ASASSUR INC.
ASASSUR INC.
500-3055, BLVD SAINT-MARTIN O
LAVAL, QUEBEC
H7T 0J3
Tel: (514) 748-7165
LETTER OF COMMITMENT FROM EXTERNAL SUPPLIER OF OTHER EXTERNAL SERVICES TO RESPECT THE
PROTECTION OF PERSONAL AND CONFIDENTIAL INFORMATION OF ASASSUR INC.
[Date]
EXTERNAL-SUPPLIER-OTHERS
Address
City
Postal
ASASSUR INC. engages EXTERNAL-SUPPLIER-OTHERS [describe the scope of the mandate].(the “Subject”)
EXTERNAL-OTHER-SUPPLIER hereby undertakes to ASASSUR INC. to ensure the protection and
confidentiality of personal information and all information relating to the company, its customers, and its
employees to which it may have access through the services offered, with the same level of security
that it applies to protect its own confidential information of a similar nature, but in any case, to a degree
at least equal to a reasonable standard of security, and undertakes to use personal information solely in
the course of its duties.
The terms “personal information” and “confidential information” include, but are not limited to: financial
and administrative information, computer programs, marketing strategies, know-how, customer and/or
employee lists, and any other information that a reasonable person would consider to be confidential
in light of its content or the circumstances of its disclosure. Confidential information may also be included
in any verbal or written communication, regardless of format or medium, even if such communications
are not identified as confidential or provided under the seal of confidentiality.
The EXTERNAL SUPPLIER-OTHERS undertakes not to copy, reproduce, or use personal information in any
way or for any reason other than to pursue the Purpose. Furthermore, no personal information or
confidential information relating to the activities of ASASSUR INC. may be disclosed to third parties without
the prior authorization of an authorized representative of ASASSUR INC..
EXTERNAL-SUPPLIER-OTHERS may, however, disclose confidential information to its employees, officers,
directors, and representatives to the extent that such persons need to know such information in
connection with the Purpose. EXTERNAL-SUPPLIER-OTHERS undertakes to ensure that its employees
respect the confidentiality of personal information to which they have access in the course of their
duties.
EXTERNAL-OTHER-SUPPLIER undertakes to: –
Use personal information solely for the purpose of fulfilling the Purpose and, when personal information
is no longer necessary for fulfilling the Purpose or in the event of the termination of contractual
POLICY & PROCEDURE GUIDE – – – –
activities, destroy the personal information;
Comply with all instructions regarding the processing of personal information;
Not subcontract the processing of personal information without first obtaining the written approval of
an authorized representative of ASASSUR INC.;
Implement the necessary security and protection measures to protect personal information, taking
into account its sensitive nature, the reason for which it is to be used, and the quantity, distribution,
and format of the personal information; and
Immediately notify ASASSUR INC. if it receives a request for access to personal information from a
customer of ASASSUR INC., a government agency, or another regulatory body, so that the Parties are
able to respond to the request satisfactorily and within thirty (30) days;
In the event of termination of contractual activities, EXTERNAL-SUPPLIER-OTHERS and all of its resources
that have had access to ASASSUR INC.’s information remain bound by this confidentiality agreement,
without any time limit.
This agreement may only be amended, modified, terminated, canceled, or reformulated by a written
document signed by an authorized representative of each party.
The supplier acknowledges that failure to comply with this commitment will immediately give rise to all
appropriate legal remedies. Consequently, ASASSUR INC. may seek legal redress for damages caused
by EXTERNAL-SUPPLIER-OTHERS or arising from such a breach, without prejudice to any rights and
remedies of ASASSUR INC., or seek a court injunction.
This agreement shall come into force upon signature.
____________________________________________
Authorized representative EXTERNAL-OTHER-SUPPLIER
Title:
➢ Privacy Impact Assessment | Commission d’accès à l’information du Québec
(gouv.qc.ca)
➢ Support Guide – Conducting a Privacy Impact Assessment (French)
➢ The CAI publishes a highly anticipated guide on privacy impact assessments |
Resources | Fasken
➢ Presentation title (associationrideau.ca) (French)
Free PIA report template: CY-CLIC
➢ PIA – CY-clic: (French)
PREVIOUS VERSION (February 2026)
Given the nature of our activities, ASASSUR understands the importance of protecting the personal information it collects in order to provide the services for which it is necessary.
In accordance with the legal framework in force, ASASSUR has implemented a set of control measures and procedures to ensure sound governance in terms of confidentiality and protection of the personal information we hold about our prospective customers, customers, partners, and employees.
By providing us with your personal information, you agree to the terms of this policy and authorize us to process your information in accordance with it.
Definition of personal information
“Personal or nominative information”: Personal information is any information that concerns a natural person and allows, directly or indirectly, to identify them[1] .
This information may include, but is not limited to, identifying information (e.g., name, address, telephone number, driver’s license number), financial information (e.g., credit card number), medical information, information related to professional activities (e.g., employee file), etc.
Consent
No information is collected by ASASSUR without the consent of the customer, agent, or prospect.
By providing us with your personal information, your consent is effective. Consequently, you agree to the terms of this policy and authorize us to collect, store, use, and disclose your information in accordance with the purposes for which it was collected.
Right to withdraw consent to the use or disclosure of information
Subject to certain limitations, you may withdraw your consent to the collection, use, and disclosure of your personal information. In such circumstances, ASASSUR may not be able to offer you the product, rate, or service requested for your insurance policy.
Ø For more information, see the Act respecting the protection of personal information in the private sector[2]
Collection and use of information
We only request the essential information we need to respond to your request, including the following examples:
Ø Conducting a comprehensive analysis of protection needs
Ø Provide an insurance quote for the requested product(s)
Ø Issuing an insurance policy for this purpose, if applicable
Ø Pay for a product or service purchased
Information via third parties
Committed to protecting its customers’ personal information, ASASSUR does not sell, collect, share, disclose to third parties, or make public any personal information about its customers, except for the purpose of fulfilling its service mandate, ensuring continuity of service to its customers, or in the specific context of complying with a court order or responding to an authorized government agency.
In these circumstances, ASASSUR may collect or transmit information to legitimately authorized organizations and/or those subject to the regulatory framework in force, or to specialized suppliers who have formally committed to protecting our firm’s personal information. Examples include, but are not limited to:
Ø Insurance brokers or claims adjusters;
Ø Insurers, reinsurers, financial institutions, or organizations responsible for their regulation;
Ø Courts
Ø The Central Automobile Claims Database and the Société d’assurance automobile du Québec or another province;
Ø Credit, risk, and claims data analysis agencies;
Ø Collection agencies;
Ø Delivery partners:
Ø Internal manager or external partner for IT management and/or personal information and data security;
Ø Legal consultants;
Ø Cloud service providers;
Ø Authorized payment service providers.
Cookies and other technologies
In order to improve the quality of the services offered and the customer experience on the website, ASASSUR may use cookies and other web analytics technologies to remember your preferences and interactions with our website. The terms of use are described on our website.
Retention and destruction of personal information
Our firm retains your personal data in order to fulfill our mandate to you in accordance with the terms and legal obligations to which we are subject.
Security of personal information
To ensure the security and confidentiality of personal information, ASASSUR adopts rigorous security measures, including both physical and technological aspects. Here are some concrete examples:
● Security
● Access controls
● Staff training
● Data encryption
● Intrusion monitoring and detection
● Disaster recovery plans
Although we make every effort to protect your personal data, you should be aware that no method of transmission over the Internet or electronic storage can guarantee absolute security.
Commitment of staff and the firm
All employees, suppliers, and partners associated with our firm are contractually bound to comply with our privacy policy and to protect the personal information held by ASASSUR, which is for the exclusive use of our firm. This commitment begins when the employee, supplier, or partner starts working with us and continues indefinitely.
AI : Artificial intelligence
ASASSUR uses certain secure artificial intelligence solutions to optimize and verify the processing of files. Naturally, no personal data or any identifiable data is processed by the artificial intelligence.
Data hosting
ASASSUR does business with various web service providers. Some providers may host data outside the province of Quebec or Canada. In such circumstances, the laws of other provinces and countries apply.
Accuracy of information
Our staff strives to maintain the accuracy of the information in our client files. You can validate and update the information in your file with our team of certified professionals.
Right of access and correction
If inaccurate information appears in the file, or if access to personal information is required, a written request may be sent to the person responsible for protecting personal information in order to make corrections. In such circumstances, our firm follows the established protocol:
Ø Submit a written request for access or correction
Ø Submit the written request to the firm’s email address or physical address.
Ø You will receive an acknowledgment of receipt
Ø Your identity will be verified
Ø Your request will be processed within 30 days of receipt.[3]
Ø For more information, see the Act respecting the protection of personal information in the private sector[4]
Quotes
In order to prepare a quote, service offer, or insurance contract, we are required to analyze the needs of the person concerned as well as all persons involved or mentioned in the process.
Whether requests are made by telephone, in person, or online, the consent of all targeted individuals must be obtained directly.
Online quotes (via website)
When a quote request form is submitted via the ASASSUR website, the customer automatically understands, authorizes, and consents to ASASSUR:
Ø Use their personal information to analyze their protection needs in order to provide an insurance quote for the requested product;
Ø Communicate with them by phone, email, or other means to discuss their file, provide them with the requested quote, and, if necessary, discuss other services offered by ASASSUR;
Ø Use their email address to respond to their request;
Email communication / Online subscription and unsubscription
After you provide your email address to ASASSUR, ASASSUR may send you information by email. You may confirm or withdraw your consent to the use of your email address at any time by unsubscribing from the distribution list in one of the following ways:
Ø By following a link in the message or email that takes you to the online unsubscribe page (if applicable)
Ø By contacting the information protection officer at the email address provided at the bottom of this policy.
In this way, and in accordance with the CPPA[5] , you can stop receiving any unsolicited emails that may have been sent by ASASSUR.
Telephone recording, chat
For reasons of information integrity, training, and customer service quality control, all telephone conversations may be recorded or monitored.
Electronic communication
Like cell phones and standard mail, communication via the Internet or unencrypted email cannot be completely secure or confidential. Such communications are susceptible to modification, loss, or interception. ASASSUR declines all responsibility for any damage that may be caused to a person in connection with us, regardless of the form of communication.
Disclaimer – email
Our customers sometimes send us emails containing personal information. ASASSUR cannot be held responsible for the loss, interception, hacking, or alteration of any email sent to us.
Policy changes
As confidentiality and the protection of personal information are of paramount importance to us, this policy may be amended to reflect internal and/or legal changes.
We invite you to review our privacy policy regularly to stay informed of any changes.
Designated Privacy Officer
Please do not hesitate to contact the privacy officer if you have any questions regarding confidentiality and the protection of personal information.
Firm | ASASSUR |
Privacy Officer | Ke Mo Huang |
Last policy update | 13 février 2026 |
Address | 3055 Saint-Martin O, Suite 500 |
City | LAVAL, QUEBEC |
Zip code | H7T 0J3 |
Toll-free phone number | 514-748-7165 |
TERMS OF USE FOR THE WEBSITE (WEBSITE DISTRIBUTION MODEL)
LEGAL NOTICE
By accessing and using this website, you acknowledge that you have read and agree to the terms of use associated with it. The terms are described with transparency in mind. Therefore, if you feel uncomfortable, we invite you to stop using the ASASSUR website and contact one of our resources who can personally assist you.
Website and consent
By using this website, you agree to be bound by the terms and conditions that govern it, which are based on the privacy policy also available on our website.
Interpretation and jurisdiction
Access to and use of this site are subject to all applicable laws and regulations in the province or territory where you reside. It is important to note that not all products, services, and information are applicable or available throughout Canada or outside Canada. The information is strictly for informational purposes. It is your responsibility to verify whether the content of this site applies to your specific situation based on the laws of your country.
Informative website and content
The website provides general information to its customers. The information contained in the pages of the site is considered reliable, but there is no guarantee that it is up to date at all times. ASASSUR cannot be held responsible, in whole or in part, for the accuracy and completeness of the content of the site, nor for any damage this may cause you.
It is recommended that you consult an advisor at ASASSUR to obtain up-to-date advice and information so that the products and services you choose are appropriate for your specific situation.
Security
Despite our best efforts, ASASSUR cannot guarantee that hacking, viruses, computer worms, hyperlinks, Trojan horses, errors or omissions, or any other harmful components will not cause a breakdown, loss of accessibility, interruption, loss in the transmission of information, or damage to your computer system. Communication via the internet or unencrypted email cannot be completely secure.
You are solely responsible for taking appropriate precautions to search for computer viruses or other destructive properties in order to ensure the adequate protection and backup of your data or equipment.
Cookies and Web Analytics
In order to improve the quality of the services offered and the customer experience on the website, information is collected by digital markers (Web Analytics) to keep track of your interactions with our website.
ASASSUR may use Google Analytics or JavaScript cookies, which you can modify or disable at any time from your browser, however you may no longer be able to access certain parts of our website:
Ø Delete, allow, and manage cookies in Chrome
Ø Delete and manage cookies in Microsoft Edge
Ø Clear cookies and site data in Firefox
Ø Clear cookies in Safari on Mac – Apple Support (UK)
Ø Browser add-on to disable Google Analytics.
Intellectual property
Certain names, words, titles, expressions, logos, icons, graphics, or designs contained in the pages of the site are trade names or trademarks belonging to ASASSUR.
The elements contained on this site are for personal use only. Without the written permission of ASASSUR, the content of the site may not be reproduced or used in whole or in part for any purpose other than personal use.
Disclaimer – website
ASASSUR assumes no responsibility for any loss, damage, lawsuit, claim, or expense, direct or indirect, arising from the use of this website. The information presented is not guaranteed in any way, and it remains the responsibility of each individual to consult a competent and qualified resource at ASASSUR in order to obtain advice and services specific to their situation.
Users who consult and use this website assume all risks inherent in browsing. Furthermore, ASASSUR cannot be held liable for any damage caused by hacking, viruses, computer viruses, hyperlinks, Trojan horses, errors or omissions, or any other harmful component or information. This limitation of warranty also applies to the interruption or partial or complete inaccessibility of this site.
Several links to external sources are provided to simplify user navigation, but no guarantee is offered as to the risks or functioning of these sites.
It is recommended that each user of the website take reasonable precautions to detect the presence of any harmful components on the website, and more broadly on the internet. It is the user’s responsibility to back up their computer data before using this website.
Changes to the terms and conditions
The terms and conditions of use of our website and the privacy and personal information protection policy may be subject to change to reflect internal and/or legal changes.
We invite you to regularly review our terms of use to stay informed of any changes.
For further information, please consult the PRIVACY AND PERSONAL INFORMATION PROTECTION POLICY, also available on our website.
POLICY – COMPLAINT HANDLING AND DISPUTE RESOLUTION[6]
Description of the complaint handling and dispute resolution policy[7]
The complaint handling and dispute resolution policy allows customers of ASASSUR, Damage Insurance Firm to ensure that any complaint received is analyzed and responded to in a fair and free process in accordance with the Regulation respecting the handling of complaints and the resolution of disputes in the financial sector.
What is a complaint?
A complaint expresses:
Ø A criticism or dissatisfaction with our services or a product we offer; and
Ø An expectation on your part that we take action to remedy the situation.
Example:
When you request a refund or want ASASSUR to take action to resolve the situation that led to your complaint.
How to file a complaint?
If you have any questions or wish to make your complaint in writing (ideally) or verbally, you can contact us in any of the following ways that suit you:
By mail or in person:
ASASSUR
Attn: Complaints Manager: Ke Mo Huang
3055 Saint-Martin O, Suite 500,
Laval, Quebec
H7T 0J3
Our office hours:
Monday to Friday: [9:00 a.m. – 17:00 p.m.]
Saturday and Sunday: [Closed]
Email:
By phone or in person:
Office phone: 514-748-716
Fax line: 514-221-4698
You can also fill out the complaint form[8] provided online by the Autorité des marchés financiers (AMF) (the “Authority”) and we remain available to assist you.
DOWNLOAD HERE: COMPLAINT FORM (OFFICIAL AMF)
STEPS IN THE COMPLAINT PROCESS
ASASSUR can handle certain complaints using a simplified process. This process is explained further in this policy. If we are unable to resolve your complaint using this process, or if the nature or complexity of your complaint does not lend itself to this process, it will be handled according to the following steps:
1) Receipt of the complaint
Within 10 days of submitting your complaint, you will receive an acknowledgment of receipt.
2) Analysis of the complaint
We will analyze your complaint in order to fully understand your expectations of ASASSUR. In order to avoid additional delays, we may need to contact you for further information.
3) Final written response
Within 60 days* of submitting your complaint, you will receive a final written response explaining:
ü How your complaint was analyzed;
ü The considerations that led to our response;
ü And, if possible, the proposed solution to resolve your complaint.
*Additional extension
If the processing of your complaint is more complex or requires more time, ASASSUR will notify you in writing, specifying the reasons for the additional delay of up to 30 days.
4) Evaluation of the offer and resolution of the complaint
Take the time to review our firm’s final response.
However, ASASSUR must receive your response within 30 days, unless we have received a written request from you for a reasonable extension of the deadline. You may send us one of the following responses:
– Your acceptance of the offer from ASASSUR;
– Your rejection of the offer from ASASSUR;
– Your presentation of a counteroffer.
Once we have reached an agreement with you on how to resolve your complaint, ASASSUR will follow through with the agreed-upon resolution within 30 days, unless a different timeframe has been agreed upon with you in your best interest.
If ASASSUR does not receive a response or follow-up from you within the established complaint handling process deadlines, ASASSUR may be forced to close your complaint file.
5) Review of the complaint file by the Authority
As required, ASASSUR creates a file for each complaint in which we keep all information and documents relevant to the handling of your complaint.
You may contact us to request that your complaint file be reviewed by the AMF at any time if you are dissatisfied with how we have handled your complaint or with the response we have provided.
ASASSUR will forward your complaint file to the Authority within a maximum of 15 days of your request. After reviewing the file, the Authority will offer dispute resolution services if it deems it appropriate. This right of transfer by the complainant expires one (1) year after the date of receipt of the final response.
SIMPLIFIED PROCESSING PROCEDURE (FOR CERTAIN COMPLAINTS)
We may process and resolve certain complaints using a simplified process. This applies to complaints for which we are able to offer:
ü A satisfactory solution (acceptance of solution or explanations)
ü A resolution within 20 days.
ü Assistance from a member of our customer service team (e.g., during a phone call).
If we are unable to offer you a solution or provide you with explanations that resolve your complaint through this simplified process, we will inform you in writing.
ü Your complaint will then be processed according to the steps outlined above.
ü The time we take to try to resolve your complaint through a simplified process does not affect our obligation to provide you with our final written response within the required time frame.
Reference
This policy has been drafted in accordance with the regulatory framework provided for in the Act respecting the distribution of financial products and services and the Regulation respecting the handling of complaints in the financial sector.
—
Update
This policy is subject to change in accordance with AMF guidelines. It is currently in effect and was last updated on May 2026. The 2nd section above was last updated on February 2026. In case of discrepancies, the most recent version of the update takes precedence over any older versions.
[1] Act respecting the protection of personal information in the private sector, s. 2 (2023/09/25)
[3] Act respecting the protection of personal information in the private sector section 32
[5] An Act to promote the efficiency and adaptability of the Canadian economy by regulating certain activities that discourage reliance on electronic means of carrying out commercial activities, and to amend the Canadian Radio-television and Telecommunications Commission Act, the Competition Act, the Personal Information Protection and Electronic Documents Act and the Telecommunications Act) section 11.1
[6]Complaint Handling | AMF: Policy Summary Template (Updated 20250601)
[7] Complaint handling | AMF: Policy summary template (Updated 20250601)
[8] Complaint FormHeader of the AMF complaint form: Complaint form (lautorite.qc.ca) (20240901 no changes 20250601) (
