Data Retention Policy
Code for Canada's Data Retention Policy governs the collection, use, storage, and destruction of personal data in compliance with Ontario's Not-for-Profit Corporations Act and Canadian privacy laws including PIPEDA.
Policy Overview
Code for Canada's Data Retention Policy governs the collection, use, storage, and destruction of personal data in compliance with Ontario's Not-for-Profit Corporations Act and Canadian privacy laws including PIPEDA.
Scope
This policy applies to data collected through Code for Canada's website, partner projects, programs (IUR/GRIT), usability testing, and third-party tools.
Purpose
The objectives of this policy are ensuring data is collected for legitimate purposes, retained only as long as needed, protected from unauthorized access, and securely destroyed or anonymized using reasonable efforts once your data is no longer required.
Information Collected
Code for Canada gathers the following categories of information:
- User information (name, email, location, phone)
- Technical data (IP address, browser type, device information)
- Usage data (website interactions, cookies)
- Demographic information (age, race, gender, language, employment)
- Voice or video recordings from meetings and research sessions
- Employment-related information
- Feedback from interviews and workshops
Data Retention Schedule
The following retention periods apply to each data category:
- IUR/GRIT Participants (personal details, accessibility needs): retained until removal is requested
- Contact Information (newsletter signups): 5 years post-interaction
- Usability Research (recordings, transcripts): 2 years post-project
- Demographic Survey Data (race, gender, employment): 2 years post-project
- Technical/Usage Data (IP, browser, cookies): 1 year post-project
- Project Research (recordings, notes): 2 years post-project
Security Measures
Data is encrypted at rest and in transit. Access is managed using role-based permissions and least-privilege principles. Third-party vendors must comply with SOC 2 and ISO 27001 standards.
Backup & Destruction
Google Workspace backups use Spanning (SOC 2 Type II compliant). Data destruction includes secure deletion of digital records, shredding of physical records, and removing identifying information from research data.
Policy Updates
This policy is reviewed annually to maintain compliance with evolving legal, security, and operational standards. Changes become effective upon posting; continued use of our services implies acceptance.
Contact
Questions about this policy should be directed to operations@codefor.ca