Canada Residents – For Candidates and Participants

ghSMART PRIVACY POLICY

June 15, 2023

This ghSMART Privacy Policy (“privacy notice”, “privacy statement”, or “notice”) describes how G. H. Smart & Company, LLC and its affiliates and subsidiaries (collectively “ghSMART”) collect and use personal information about Canadian residents (“Data Subjects”). Our contact information is included at the end of this notice.

Key Elements of this Notice

Accountability

We have designated a privacy officer who is responsible for our compliance with this Notice.  You may contact our privacy ‎‎officer as described below.‎

Scope

This Notice applies only to the personal information that ghSMART collects related to Data Subjects, including personal information collected in the context of conducting, reviewing, assessing, managing, and storing personal information in relation to our proprietary candidate assessments. This Notice is intended to satisfy ghSMART’s applicable privacy obligations under applicable Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act (Canada) (and any successor legislation) and its provincial equivalents.

The categories of personal information that we collect, and our use of personal information, may vary depending upon the position(s) a Data Subject is being considered for, as well as the associated qualifications and responsibilities. For example, ghSMART conducts in-depth verbal interviews or discussions as part of our services (including leadership selection, leadership coaching and development, talent and organizational strategy, team effectiveness, board effectiveness, executive learning, and/or any related services or products). The information in this Notice is intended to provide an overall description of our collection and use of personal information about Data Subjects. Also, in some cases (such as where required by law), we ask for your consent or give you certain choices prior to collecting or using certain personal information.

It is important that you read this notice, together with any other privacy notice we may provide on specific occasions when we are collecting or processing personal information about you, so that you are aware of how and why we are using such information.

What isn’t covered by this Notice? This Notice does not address or apply to our collection of personal information that is not subject to applicable Canadian privacy laws, such as business contact information and certain publicly available data, or the personal information that we collect about residents of countries other than Canada. In addition, the personal information we collect from clients who are not residents of Canada is subject to other notices and not this one.

Your Personal Information

Categories of Personal Information Collected and Disclosed.  The section below generally identifies the categories of personal information that we collect about Data Subjects, as well as the categories of third parties to whom we may disclose this information for a business or commercial purpose:

  • Identifiers: such as a real name, alias, postal address, phone number, unique personal identifier, online identifier, Internet Protocol address, email address
    • Third Party Disclosures for Business or Commercial Purposes: ghSMART client that requested the services, service providers, affiliates and subsidiaries, regulators, government entities and law enforcement, internet service providers required for cloud data storage, email, antivirus protection and standard technology operations, operating systems, and platforms, and others as required by law
  • Protected Classification Information:  Candidate gender.  We will not ask Candidates to identify their gender and we do not ask others about a Candidate’s gender.  Rather, our professionals will note gender based on a Candidate’s outward manifestations and on any statements a Candidate makes during the assessment that clearly indicates gender identity.  We are cognizant of the fact that certain individuals identify as non-binary or transgender.
    • Business Purposes: ghSMART uses gender information to conduct and publish research.  Examples of research topics could include: (a) the manner in which females perform as compared to males in given scenarios, or; (b) the performance of categories of data subjects in varying industries and/or private vs. public companies.   When using gender data for research, ghSMART deidentifies and/or aggregates the data.  ghSMART does not disclose the gender of any specific Candidate through such research.
  • Audio, visual, and other electronic data: interview recordings, transcriptions and other audio recordings (e.g., recorded interview sessions)
    • Third Party Disclosures for Business or Commercial Purposes: ghSMART client that requested the services, service providers, affiliates and subsidiaries, regulators, government entities and law enforcement, internet service providers required for cloud data storage, email, antivirus protection and standard technology operations, operating systems, and platforms, and others as required by law
  • Professional or Employment-Related Information: such as your application responses and cv/Resume, information related to your employment history provided during the recruitment process, including employment verification and references from former employers or colleagues; training; professional experience; contact details of employer; employment appraisal/assessment; details of qualifications; job description tasks and responsibilities; linguistic and job related skills and competencies; details of past and current organizational projects and initiatives; assessment of individual strengths and weaknesses; organizational structure; expressions of opinion or future intentions; reason for leaving prior roles; standardized test scores; volunteer or professional organization memberships
    • Third Party Disclosures for Business or Commercial Purposes: ghSMART client that requested the services, service providers, affiliates and subsidiaries, regulators, government entities and law enforcement, internet service providers required for cloud data storage, email, antivirus protection and standard technology operations, operating systems, and platforms, and others as required by law
  • Education information: such as information about education history or background that is not publicly available personally identifiable information
    • Third Party Disclosures for Business or Commercial Purposes: ghSMART client that requested the services, service providers, affiliates and subsidiaries, regulators, government entities and law enforcement, internet service providers required for cloud data storage, email, antivirus protection and standard technology operations, operating systems, and platforms, and others as required by law
  • Inferences. Inferences drawn from any of the information identified above about Data Subjects reflecting their experiences, preferences, characteristics, behavior and abilities
    • Third Party Disclosures for Business or Commercial Purposes: ghSMART client that requested the services, service providers, affiliates and subsidiaries, regulators, government entities and law enforcement, internet service providers required for cloud data storage, email, antivirus protection and standard technology operations, operating systems, and platforms, and others as required by law

Sources of Personal informationIn general, we may collect personal information from the following categories of sources:

  • Directly from the individual
  • ghSMART client that requested the services
  • Individual participants necessary for the completion of our Statement of Work
  • Publicly available information and sources, in accordance with applicable law

Purposes of Collection, Use and Disclosure.

In this section we outline the purposes for which we may collect and process your personal information.

I. For the Purpose of Employment Assessment, Leadership Development or Consulting Services

More specifically, we use your personal data described above for the following purposes:

To carry out the instructions of the Client Company to which we have contractual obligations

  • Acknowledging your application;
  • Determining and providing statements of opinion about your suitability for roles; Checking the validity of your qualifications and previous employment history;
  • Fulfilling the deliverables of our client agreements as part of our consulting services which may include assessments, leadership development, coaching, training and any related services or products.

To comply with record keeping obligations under laws applicable to ghSMART

  • To comply with record keeping obligations for external financial statement audits to substantiate our business transactions;
  • To comply with record keeping obligations for tax records to support our tax returns.

To enable effective management and financial reporting

  • Managing and reporting on our performance of consulting services which may include assessments, leadership development, coaching, training and any related services or products.

II. For the Purpose of General Administration

More specifically, we use your personal data described above for the following purposes:

To carry out the instructions of the Client Company to which we have contractual obligations

  • Administering the contract we have with the Client mentioned above;
  • Meeting arrangement/travel/scheduling;
  • Facilitating other administrative purposes for normal business practices, such as internal reporting, and complying with policies and procedures.

To comply with record keeping obligations

  • Facilitating other administrative tasks, such as accounting, audit, tax.

To enable effective management and financial reporting

  • Administering the contract we have with the Client mentioned above;
  • Business management and planning;
  • Overseeing compliance with legal and regulatory requirements, including monitoring compliance with applicable privacy laws;
  • Facilitating other administrative purposes for normal business practices, such as internal reporting, and complying with policies and procedures.

III. For the Purpose of Aggregated Analysis and Research

More specifically, we use your personal data described above for the following purposes:

To carry out the instructions of the Client Company to which we have contractual obligations

  • To improve our consulting business practices and products related to the services we provide to the Client Company.

To provide training to our consultants and to improve our consulting business practices and products

  • To improve our consulting business practices and products related to the services we provide to our clients generally;
  • To provide training to our internal consultant team and evaluate the quality of our services and products.

Providing information about our products, services, and events to prospective clients or candidates for employment

  • Findings that are aggregated and/or deidentified/anonymized may be used in publications, editorial content or communications related to our services and products.

To conduct and publish research:  ghSMART conducts research to educate and inform the company, our clients, and society at large about historical trends and experiences of candidates and executives from a career performance perspective.

  • Examples of research topics could include: (a) the manner in which females perform as compared to males in given scenarios, or; (b) the performance of categories of data subjects in varying industries and/or private vs. public companies.   When using gender data for research, ghSMART deidentifies and/or aggregates the data.  ghSMART does not disclose the gender of any specific Candidate through such research.

Change of purpose

We will only use your personal information for the purposes for which we collected it as described above, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal information for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so (and we will seek your consent where required by law). Please note that we may collect and process your personal information without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

Cross-border transfers of personal information

We may transfer the personal information we collect about you to jurisdictions outside of your jurisdiction of residence, including to other Canadian jurisdictions and jurisdictions outside of Canada, namely, the United States, Australia, European Economic Area and the United Kingdom, where ghSMART has administrative services, subcontractors, service providers, client consultants and client leadership. You acknowledge that the governments, courts or law enforcement or regulatory agencies in those jurisdictions may be ‎able ‎to obtain disclosure of that personal information through the laws of the foreign jurisdiction‎.

To ensure that your personal information receives an adequate level of protection we have put in place relevant appropriate measures to ensure that your personal information is treated by those outside your jurisdiction in a way that is consistent with and which respects the laws on personal information. You can contact us if you require further information about these protective measures.

We may also transfer your personal information as permitted or required by law.

Other Disclosures

In addition to the purposes described above, we may disclose your personal information to a third party without your consent if permitted or required ‎by applicable law. We may also disclose your personal information, in accordance with applicable law, in ‎connection with ‎a corporate re-organization, a merger or amalgamation with another entity, or a sale of ‎all or a ‎substantial portion of our assets, provided that the disclosed information continues to be used ‎solely for ‎the purposes permitted by this notice by the entity acquiring the information.‎

The period for which data is stored 

The information we collect during the ghSMART service process will form part of our records and as such will be retained as required by legal, accounting, reporting standards as reflected in the ghSMART corporate records retention policy applicable to our business. ghSMART may also be required to retain this information based on statute of limitations for specific jurisdictions, as well as government record retention requirements for tax purposes. ghSMART reviews the data to determine that the policy for data storage is in line with our stated purposes for which we may process your data. In some circumstances, we may aggregate or deidentify your personal information so that it can no longer be associated with you, in which case we may continue to use such information without further notice to you.

Security

We protect the personal information in our custody or control using reasonable physical, ‎‎organizational and electronic security arrangements.  We ‎regularly review our practices to ensure they align with reasonable industry practices appropriate to ‎‎the level of sensitivity to safeguard personal information against loss or theft, unauthorized access, ‎‎alteration or disclosure.‎

However, no method of transmission over the Internet, or method of electronic storage, is completely ‎secure. As ‎such, despite our safeguards and protocols, we cannot fully guarantee the security of your ‎personal ‎information and you should always exercise caution when disclosing personal information ‎over the ‎Internet (including by email).‎

Accuracy

We will make a reasonable effort to ensure that personal information we are using or disclosing is ‎‎accurate and complete.  ‎With respect to personal information that we collect directly from you, we rely on you to provide complete and accurate information. You may request corrections to your personal information as described below.

How to Exercise Available Rights.

If you think we may have incorrect personal information, or would like a copy of the personal information we hold on you, or to exercise any other data protection right available under applicable laws, please contact dataprotection@ghsmart.com or call +1 877 294 3368.

We will take steps to verify your request by matching the information provided by you with the information we have in our records. This may include your first and last name, email address, physical address, telephone number, and information about your relationship with us or other information needed to verify your identity. You must provide us with this information via the above phone number or email address to verify your request.  We will process your request based upon the personal information in our records that is linked or reasonably linkable to the information provided in your request. We may need to request additional specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another security measure designed to ensure that personal information is not disclosed to any person who has no right to receive it. If we are unable to adequately verify a request, we will notify the requestor.  Authorized agents may initiate a request on behalf of another individual; authorized agents will be required to provide proof of their authorization and we may also require that the relevant consumer directly verify their identity and the authority of the authorized agent.

If a challenge regarding the accuracy of personal information is not resolved to your satisfaction, we ‎‎will annotate the personal information under our control with a note that the correction was requested ‎but ‎not made.‎

In some situations, we may not be able to provide access to certain personal information (for example, if ‎‎disclosure would reveal personal information about another individual, or the personal information is ‎‎protected by solicitor/client privilege).  We may also be prevented by law from providing access to certain personal ‎‎information.‎

Changes to this privacy notice

Any changes we make to our privacy notice in the future will be posted on this page and, where appropriate, notified to you by e-mail. Please check back frequently to see any updates or changes to our privacy notice.

Contact details 

If you have any questions about this privacy notice or how we handle your personal information, please contact: dataprotection@ghsmart.com or +1 877 294 3368.

Mail address:

G. H. Smart & Company, LLC
203 North LaSalle Street
Suite 2100
Chicago, IL 60601
The United States of America

G. H. Smart & Company Canada, ULC
885 West Georgia Street
Suite 1480
Vancouver
British Columbia
V6c 3e8
Canada