Xerox Canada Privacy Code
Xerox Canada Privacy Code
Web Privacy Statement
Customer Opt-Out Preferences
Contact Us
Français

Xerox Canada Ltd. ("Xerox Canada") values its relationship with its customers and employees, and is committed to the protection of their personal information. Accordingly, Xerox Canada adheres to the privacy principles, and accompanying commentary, set out below (the "Privacy Principles"). The Privacy Principles are based on the principles set out in Schedule 1 of the Personal Information Protection and Electronic Documents Act (Canada) (the "Act"). "Personal Information", as used in this Code, means information about an identifiable individual, but does not include the name, title or business address or telephone number of an employee of an organization.

At Xerox, we take your privacy seriously. The following outlines our compliance with PIPEDA and other privacy laws and how we are accountable.

All Xerox Canada employees are required to comply with the law. We have employee training and ongoing refreshers in place. In fact, our privacy training is incorporated into our new employee training process.


If you have any questions re: privacy @ Xerox, you can email us at can.privacy@can.xerox.com. For opt-out preferences, please click here
.


Definitions:
Collection - the act of gathering, recording, acquiring or obtaining personal information from any source, including 3rd parties.

Consent – voluntary agreement for the collection, use, retention or disclosure of personal information for identified purposes.

Disclosure – making personal information available to 3rd parties.

Employee – an employee (former or current) of Xerox Canada.

Personal Information – information about an identifiable customer or employee, but does not include aggregated information that can’t be associated with a specific individual (eg. corporate information).

For a customer, especially in the case of a sole proprietorship, such information could include (but is not limited to) the following:

  • Individual customer’s credit or banking information
  • Customer’s customer’s information (eg. financial, health or education institutions)

For an employee, such information could include (but is not limited to) the following:

  • Information found in personal employment files
  • Medical information
  • Benefits information

Principle 1 - Accountability
Xerox Canada is responsible for all Personal Information under its control.

Accountability for our compliance with the Privacy Principles rests with our Privacy Office, even though other individuals within Xerox Canada have responsibility for the day-to-day collection and use of Personal Information. We are responsible for Personal Information in our possession, including information that has been transferred to a third party for processing. We will use contractual or other means to provide a comparable level of protection when the information is being shared with or processed by a third party.


Principle 2 - Identifying Purposes
We will identify and document the purposes for which we collect, use, or disclose Personal Information at or before the time of collection. The purposes will be limited to those which are related to our business and which a reasonable person would consider appropriate.

Customer Personal Information:

  • Some of the reasons we collect, use, and disclose Personal Information concerning our customers:
    • To provide timely, reliable and value-added services to our customers, such as: special promotions, special pricing initiatives, contests;
    • To establish a customer relationship and to communicate with customers;
    • To develop, implement, market, and manage services for customers;
    • To assist in administrative purposes, to collect unpaid debts, for credit reporting and rating purposes, and to protect the business interests of Xerox Canada and its customers;
    • To manage and promote the business activities of Xerox Canada; and
    • To meet requirements imposed by law.
Employee Personal Information:
  • Some of the reasons we collect, use, and disclose Personal Information concerning our employees:
    • To recruit, train, recognize, and retain a highly qualified and motivated workforce;
    • To establish and maintain harmonious employer-employee relations;
    • To administer Xerox Canada policies and procedures;
    • To manage and promote the business activities of Xerox Canada;
    • To administer compensation and benefits;
    • To develop, manage, and promote employee services; and
    • To meet requirements imposed by law.

    If we plan to use Personal Information we have collected for a purpose not previously identified, we will identify and document this purpose before such use. We will make a reasonable effort, having regard to the circumstances, to specify the identified purposes, orally or in writing, to the individual from whom the Personal Information is collected either before or at the time of collection and before use. We will state the identified purposes in such a manner that an individual can reasonably understand how the information will be used or disclosed.


Principle 3 - Consent
Personal Information will only be collected, used, or disclosed with the knowledge and, where appropriate, consent of the individual. The way in which we seek consent, including whether it is express or implied, may vary depending upon the sensitivity of the information and the reasonable expectations of the individual. An individual can withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. We will inform individuals of any implications of withdrawing consent. Typically, we will seek consent for the use or disclosure of information at the time of collection. In certain circumstances, consent may be sought after the information has been collected but before use (such as where we want to use information for a purpose not previously identified).

We will not, as a condition of the supply of services, require an individual to consent to the collection, use, or disclosure of Personal Information beyond that required to fulfill the explicitly specified and legitimate purposes. In certain circumstances, as permitted or required by law, we may collect, use or disclose Personal Information without the knowledge or consent of the individual. These circumstances include: Personal Information which is subject to solicitor-client privilege or is publicly available as defined by regulation; where collection or use is clearly in the interests of the individual and consent cannot be obtained in a timely way; to investigate a breach of an agreement or a contravention of a law; to act in respect to an emergency that threatens the life, health or security of an individual; for debt collection; or to comply with a subpoena, warrant or court order.


Principle 4 - Limiting Collection
We will limit the amount and type of Personal Information collected to that which is necessary for our identified purposes and we will only collect Personal Information by fair and lawful means

Principle 5 - Limiting Use, Disclosure, and Retention
Personal Information will not be used or disclosed for purposes other than those for which it was collected, except with the consent of the individual or as required by law. Personal Information will be retained only as long as necessary to fulfill the identified purposes (and in compliance with our Corporate Retention Policies).

Personal Information which has been used to make a decision about an individual will be retained long enough to allow the individual access to the information after the decision has been made and, in the event of an access request or a challenge, long enough to exhaust any recourse an individual may have under the law. Where Personal Information is no longer required to fulfill the identified purposes, it will be destroyed, erased, or made anonymous.


Principle 6 - Accuracy
We will use our best efforts to ensure that Personal Information is as accurate, complete, and up-to-date as is necessary for the purposes for which it is to be used. We will use our best efforts to ensure that Personal Information that is used on an ongoing basis, including information that is disclosed to third parties, and information that is used to make a decision about an individual, is accurate, complete, and up-to-date.


Principle 7 - Safeguards
We will protect Personal Information with safeguards appropriate to the sensitivity of the information. Our safeguards will protect Personal Information against loss or theft, as well as unauthorized access, disclosure, copying, use or modification, regardless of the format in which the information is held. We will make our employees aware of the importance of maintaining the confidentiality of Personal Information, and will exercise care in the disposal or destruction of Personal Information to prevent unauthorized parties from gaining access to the information (and in compliance with our Corporate Retention Policies).

Our methods of protection will include: physical measures (for example, locked filing cabinets and restricted access to offices), organizational measures (for example, security clearances and limiting access on a "need-to-know" basis), and technological measures (for example, the use of passwords and encryption).


Principle 8 - Openness
Upon written request, we will inform an individual of the existence, use, and disclosure of his or her Personal Information and we will give the individual access to that Personal Information. An individual can challenge the accuracy and completeness of his or her Personal Information and have it amended as appropriate. For more detailed information, see our Individual Access policy.


Principle 9 - Individual Access
Upon written request, we will inform an individual of the existence, use, and disclosure of his or her Personal Information and we will give the individual access to that Personal Information. An individual can challenge the accuracy and completeness of his or her Personal Information and have it amended as appropriate. For more detailed information, see our Individual Access policy.


Principle 10 - Challenging Compliance
Any individual can address a challenge concerning our compliance with any of the privacy laws, via the following channels:

Post:
Xerox Canada Ltd.
5650 Yonge Street
North York, ON M2M 4G7 – Attn, Privacy Office

Email:
Can.privacy@xerox.com

Phone:
1800-ASK-Xerox (1800-275-275-9376) choose your language preference and then prompt 4.

We will investigate all written complaints. If we find a complaint to be justified, we will take all appropriate measures.


Individual Access Policy
We will respond to an individual's written request within a reasonable time (generally within 30 days). We may require an individual to provide sufficient information to permit us to provide an account of the existence, use, and disclosure of Personal Information. While our response will typically be provided at no cost to the individual, depending on the nature of the request and the amount of information involved, we reserve the right to impose a cost. In these circumstances, we will inform the individual of the approximate cost to provide the response and proceed upon payment by the individual of the cost.

Where possible, we will indicate the source of the information. In providing an account of third parties to which we may have disclosed Personal Information about an individual, we will attempt to be as specific as possible. When it is not possible to provide a list of the organizations to which we have actually disclosed Personal Information, we will provide a list of organizations to which we may have disclosed the information.

If an individual successfully demonstrates the inaccuracy or incompleteness of Personal Information, we will amend the information as required. If a challenge is not resolved to the satisfaction of the individual, we will record the substance of the unresolved challenge. Where appropriate the amended information or the existence of the unresolved challenge, as the case may be, will be transmitted to third parties having access to the information in question. In certain situations, we may refuse a request or not be able to provide access to all the Personal Information we hold about an individual. Exceptions to the access requirement will be limited and specific, as permitted or required by law. Where permitted, the reasons for denying access will be provided to the individual upon request. Exceptions may include: information that contains references to other individuals or contains confidential or sensitive commercial information, where such information cannot be severed from the record; information collected in the course of investigating a breach of an agreement or in the course of a formal dispute resolution process; and information that is subject to solicitor-client privilege.