EmTé inc.
Privacy policy.
EmTé inc. is committed to protecting the personal information entrusted to it, in accordance with the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1). This policy explains what we collect, why, with whom, and the rights available to you.
Person in charge of the protection of personal information
Title: President of EmTé inc. The function of person in charge of the protection of personal information is exercised by the person exercising the highest authority within the business (section 3.1 of the Act). This person approves our governance rules and oversees privacy impact assessments, incidents, requests to exercise rights and complaints.
Dedicated email: confidentialite@emte.ca · Address: 204, rue du Saint-Sacrement, bureau 300, Montréal (Québec) H2Y 1W8.
Personal information governance
Our internal governance rules are proportionate to the size of the business and approved by the person in charge of the protection of personal information. Only people who need the information to perform their duties have access to it, and every subcontractor is bound by a written agreement setting out measures to protect its confidentiality. In summary:
- Roles: the person in charge grants and revokes access, approves providers, keeps the register of confidentiality incidents and handles requests and complaints.
- Staff and contractors: anyone working for EmTé inc. accesses only the information needed for their task, signs a written confidentiality undertaking and reports any suspected incident without delay; their access is removed when their work ends.
- Life cycle: we collect the minimum needed, use information only for the stated purposes, keep it according to the rules in the “Retention and destruction” section, then securely destroy or anonymize it.
- Providers: the applicable rules are described in the “Hosting and providers” section.
- Review: these rules and this policy are reviewed at least once a year and whenever our activities or providers change significantly.
Information we collect
When you fill out the website form, we collect what you enter in it: your name, your company name (optional), your message and the contact detail you choose for the reply, either a business email address or a phone number. To block automated submissions, the form measures completion time and includes a hidden field. To limit repeated submissions, your IP address is converted into a one-way fingerprint, held temporarily in memory, and is never recorded or added to the email.
When you call or text us at 438 231-3683, our cloud telephony provider (a company based in the United States) keeps your number, the date and length of calls, the texts exchanged and, if you leave a voicemail, the recording of that message and its automatic transcription into text. We do not record phone conversations; if this were to change, you would be told at the start of the call. When you email us, your message is received in our business mailbox.
For the operation of the website, minimal technical data is processed by the hosting provider (server logs, IP address transmitted by your browser, device type), for the short period needed for security and troubleshooting.
Purposes and consent
The information you send us is used only to answer your request, to schedule a call and to follow up on our business relationship. Technical data needed to operate the website is used for security, limiting abusive submissions and troubleshooting. By sending the form, you consent to the processing of your request. Optional audience measurement requires a separate choice: sending the form does not activate it. We do not sell or rent your information, we do not use it for advertising purposes and we do not subscribe you to any newsletter.
Hosting and providers
The website is hosted and served by a cloud infrastructure and content delivery provider. Form messages are relayed, without being stored by the form, through a function operated by that host in its Montréal (Canada) region, then sent through a secure interface to our business email provider. Calls and texts to 438 231-3683 are routed through our cloud telephony provider. Appointment booking, when offered, uses an online scheduling service. Each provider obtains only the information needed for its function.
These providers may process information outside Quebec, including in the United States or in other regions of Canada. Processing outside Quebec is subject to applicable legal requirements for assessing safeguards and establishing contractual protections. We do not claim that all data resides in Canada. The providers and subcontractors used in a client engagement are identified in the data processing addendum signed with that client.
Apart from the automatic voicemail transcription provided by our telephony provider described above, we do not submit the requests you send us through the website, by email, by phone or by text message to any artificial intelligence tool.
Cookies and audience measurement
The website sets no cookies, except in one case: if the website is under a cyberattack, our hosting provider may ask visitors to complete an anti-bot check; a browser that passes it then receives a technical session cookie, strictly necessary for that protection, which avoids repeating the check for up to one hour. No measurement, advertising or profiling cookies are used. Your language choice is carried in the page address (/fr or /en) and is not stored.
When online call booking is offered, it takes place on a scheduling provider’s page, outside our website. That page may use its own cookies; the provider’s privacy policy is available there. The information you enter (name, email and, where applicable, phone number and notes) is recorded in our business account with that provider and used only to schedule and hold the call.
Audience measurement is off by default. The script for our host’s web statistics service, which uses no measurement cookies, is loaded only after your express permission. To turn it on, open “Audience measurement: your choices” in the footer and select “Accept”. “Refuse” lets you use the website without this measurement; you can change your choice or withdraw permission in the same place. Withdrawal stops new events from being sent but does not undo statistics already transmitted. To count visitors without tracking them, the tool derives from the technical data of the request a hash that is valid for a single day: it is reset automatically and cannot recognize a visitor from one day to the next or across websites. For each permitted page view, the tool records the public page address without its query parameters or fragment; not-found pages and custom events are excluded. It also processes the referral, date and time, an approximate location derived from the IP address (country, region, city), the operating system and browser with their versions, and the device type. We only view aggregate statistics, we build no individual profile and we install no advertising tracker. Your browser’s Global Privacy Control or Do Not Track signal overrides saved permission: the script is not loaded while the signal is present, and no new event is sent if it appears after loading.
To remember your permission or refusal, we keep only that choice, its version and its dates in your browser’s local storage, without a visitor identifier and without sending it to our statistics service. The choice remains valid for up to 180 days from your last decision; visits do not extend that period. At expiry, measurement turns off and the expired preference is removed at the next check or visit. If local storage is unavailable, your choice applies only to the current page: each new page stays unmeasured until you give permission again. Without JavaScript, no measurement is loaded. These choices do not stop technical logs needed for security and operation, described above.
Retention and destruction
Requests received through the website, by email, by text message or by phone that do not lead to an engagement are reviewed at least quarterly. We delete information once the purposes for which it was collected have been fulfilled, unless a legal obligation or the defence of our rights justifies keeping it. Where deletion must be carried out by a provider, we request it. Archiving a conversation does not mean deleting it. Certain recovery or backup copies and providers’ technical data follow separate retention periods: their erasure does not necessarily coincide with deletion in our tools. Information related to a client is kept for the duration of the engagement; contracts, invoices and supporting documents are then kept for six years after the end of the last taxation year to which they relate, as required by tax laws, or longer in the event of an audit, objection, appeal or dispute. Other engagement information is deleted once it is no longer needed for our contractual or professional obligations or for the defence of our rights. At the applicable deadline, the information is securely destroyed or anonymized according to the process provided by law. A deletion request may be refused or deferred when a legal obligation requires retention.
Security
We apply measures proportionate to the sensitivity and the context: encryption in transit, individual accounts and revocable access, minimal permissions. The website has no database: it consists of static pages, and the form relays your message without storing it. Information retained by the email, telephony, security, audience measurement and, when offered, scheduling services is described in the preceding sections. No system is presented as invulnerable.
Passwords must not be sent to us by email or included in project documents. We favour named invitations and revocable access; any temporary exception is replaced as soon as the platform allows it.
Automated decisions
This website makes no automated decision about you. When a solution implemented for a client uses personal information to produce an automated decision, recommendation or content, the role of the people involved, the information to be provided and the avenues for contesting it are defined according to the context and the applicable law.
We do not use a client’s confidential data to train a general model and we do not authorize its use for that purpose at a provider without express written authorization and a prior assessment.
Your rights
Under the conditions provided by law, you may request access to your information, its rectification or, where the right applies, its communication in a structured, commonly used technological format. You may also withdraw consent or request the cessation of dissemination, de-indexing or deletion where such a remedy is applicable.
Write to confidentialite@emte.ca. We may verify your identity, and certain legal obligations may limit the request. We respond within thirty days of receiving the request. Any refusal states its reasons and tells you the available recourse and its time limit. If we refuse your request, do not answer it within that time or our response does not satisfy you, you may file an application for the examination of a disagreement with the Commission d’accès à l’information du Québec (Quebec’s privacy regulator, cai.gouv.qc.ca) within thirty days of the refusal or of the expiry of the time limit to respond.
Complaints
To file a complaint about the handling of your information, write to confidentialite@emte.ca describing the situation and the outcome you are seeking. We confirm receipt, verify the facts, document the decision and respond in writing. If the review requires more time, we keep you informed of its progress. You may also file a complaint with the Commission d’accès à l’information du Québec and, where the federal Act (PIPEDA) applies, with the Office of the Privacy Commissioner of Canada (priv.gc.ca).
Confidentiality incidents
In the event of a confidentiality incident, we take reasonable measures to reduce the risk of injury and to prevent new incidents of the same nature, and we record it in our incident register, even when it does not present a risk of serious injury. When the incident presents a risk of serious injury, we promptly notify the Commission d’accès à l’information and the persons concerned, as required by law. Where the federal Act (PIPEDA) applies, we also make the reports it requires to the Office of the Privacy Commissioner of Canada.
Changes
We may update this policy. The date of the last update is shown below. Every change will be announced in a notice available on the website that states its purpose and effective date. Where needed to reach the individuals concerned, we will also use another appropriate means of communication.
Last updated: October 5, 2026 · NEQ 1180780612 · confidentialite@emte.ca