The Association of Chartered Loss Prevention Specialists of Canada is committed to
protecting the personal information of its members, applicants, certification holders,
partners, learners, and visitors to our website. This Privacy Policy explains how we collect,
use, store, share, and safeguard your personal information in accordance with the Personal
Information Protection and Electronic Documents Act of Canada, the principles of the
General Data Protection Regulation, and recognized international privacy standards.
We collect only the information necessary to support membership administration,
certification services, professional development, communication, and website
functionality. This includes:
- Contact information such as name, address, email, and telephone
-
Membership and certification information such as applications, renewal records, CPD
-
submissions, and declarations
-
Payment information processed securely through approved third-party payment providers
-
Website usage data including IP address, browser type, cookies, and analytics
-
Voluntary information such as survey responses or uploaded documents
We do not collect more information than is required for legitimate organizational purposes.
Personal information is used to:
- Administer membership and certification programs
-
Verify identity and eligibility for certification
-
Maintain accurate records for CPD and professional standing
-
Communicate updates, notices, training opportunities, and compliance requirements
-
Improve website performance and user experience
-
Meet legal and regulatory obligations
-
Protect the integrity of the profession and the safety of the public
We do not sell or commercialize personal information.
We process personal information under the following lawful bases:
- Consent
-
Performance of a contract
-
Compliance with legal obligations
-
Legitimate organizational interests such as credential verification, fraud prevention, and professional regulation
Personal information is stored securely in Canada or in trusted international data centres
that comply with equivalent privacy protections. Retention periods depend on membership
and certification status and legal requirements. Records are retained only as long as
necessary.
We may share information with:
- Payment service providers
-
Learning management system providers
-
Accreditation bodies
-
Government or regulatory authorities when legally required
We do not share personal information with unrelated third parties.
Subject to applicable law, individuals have the right to:
- Access their personal information
-
Request correction or updates
-
Withdraw consent
-
Request deletion when appropriate
-
Restrict or object to processing
-
Request information on data handling practices
We use administrative, technical, and organizational safeguards consistent with ISO 27001
and recognized cybersecurity practices to prevent unauthorized access, disclosure, loss,
or misuse.
We may update this Privacy Policy periodically to reflect operational or legal changes.