Roji films Inc.
Personal information governance policy
Roji films Inc. 4388 Rue Saint-Denis, Suite 200 #301, Montreal, Quebec H2J 2L1, Canada [email protected]
In force: 24 September 2026
Language. This policy is drawn up in French. The French version, "Politique de gouvernance des renseignements personnels", is the original. This English version is a translation provided for convenience. If the two versions differ, the French version prevails.
This policy sets out how Roji films Inc. governs the personal information it holds, as required by section 3.2 of Quebec's Act respecting the protection of personal information in the private sector. What we collect and why is described in our privacy notice. This policy covers how we handle it inside the company.
1. Who is responsible
Rabia Rahou, President of Roji films Inc., is the person in charge of the protection of personal information and approves this policy. This person is the only one with access to the personal information the company holds, and answers requests and complaints at [email protected]. If the company takes on staff or contractors, their access is limited to what their work needs, granted in writing, removed when the work ends, and they are made aware of this policy before they receive any access.
2. What we hold, and the rule of minimum
We collect only what a stated purpose needs, and we decide what to collect before we build a form, a feature or a tool, not after. Anything that could locate or profile a person is off by default. We do not buy personal information and we do not collect it from third parties. When a purpose ends, the information collected for it ends with it.
3. Keeping and destroying
Each kind of record has a retention period, published in the privacy notice. A scheduled job deletes records automatically every day once their period has passed. When information is destroyed, it is deleted from the database, and exports or copies made for a task are deleted when the task is done. Where the law requires us to keep proof, such as proof of email consent under Canada's Anti-Spam Legislation, we keep the smallest record that serves as proof, in a form that does not reveal more than needed, and we delete it at the end of its period.
4. Before a new project, system or supplier
Before we acquire, develop or overhaul a system or an electronic service that handles personal information, or before we communicate personal information outside Quebec, we carry out a privacy impact assessment proportionate to the sensitivity of the information, its purpose, its quantity, its distribution and its medium. For a supplier outside Quebec, the assessment also covers the protection it offers and the legal framework where it operates. We keep a written record of each assessment and review it when the system or supplier changes. Our current suppliers (Cloudflare, Resend and Zoho) have been assessed.
5. Confidentiality incidents
Anyone who notices a possible incident (unauthorised access, use, disclosure or loss of personal information) reports it at once to the person in charge. We then:
1. take reasonable measures to reduce the risk of harm and to prevent a repeat; 2. assess whether the incident presents a risk of serious injury, considering the sensitivity of the information, its possible misuse and the likely consequences; 3. if it does, promptly notify the Commission d'accès à l'information, the people affected and, where PIPEDA applies, the Office of the Privacy Commissioner of Canada; 4. record every incident, serious or not, in our register of incidents, and keep each entry for at least five years.
6. Requests and complaints
Anyone can ask to see, correct, receive or delete their personal information, withdraw consent, or complain, by writing to [email protected]. Requests are free. We confirm receipt, may verify the person's identity, and answer in writing within 30 days. A refusal gives its reasons and explains how to challenge it, including before the Commission d'accès à l'information. We handle each complaint once, in writing, and use what we learn to correct our practices.
7. Security
Access to systems is protected by authentication and limited to the person in charge. Tokens and codes are stored as hashes, network addresses are not stored with registrations or visits, and connections are encrypted. We apply security fixes as they become known and review our sites' security at least once a year.
8. Awareness and review
The person in charge keeps up to date with the obligations that apply to the company, and anyone given access to personal information is informed of this policy first. We review this policy at least once a year, and whenever our activities change in a way that affects personal information. The date at the top shows when it last changed.
Contact
[email protected], or the postal address above.