Back to CAASA Connect PIPEDA Compliant • Updated September 2026

Privacy Policy

Personal Information Protection and Electronic Documents Act (PIPEDA) Compliance

1. Commitment to Privacy

CAASA is dedicated to safeguarding the personal and institutional information of our members. This Privacy Policy details our practices in compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial private-sector privacy legislation.

2. Information Collection and Purposes

We collect personal information solely for purposes directly relevant to facilitating membership and professional interaction across the CAASA network, including:

  • Account Credentials: Work email address, full name, job title, institutional organization, and contact details.
  • Membership Classification: Institutional category (e.g. SFO, Allocator, Fund Manager) to facilitate role-based access control.
  • Activity and Audit Trails: Platform authentication timestamps, consent records, and access logs required for security and regulatory compliance.

3. Consent & Accountability

We obtain your explicit consent prior to collecting or processing your personal information. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice; however, doing so may preclude your continued access to the Platform. CAASA has designated a Chief Privacy Officer responsible for organizational compliance.

4. Disclosure and Third-Party Sharing

CAASA does not sell, rent, or trade personal data to third parties. Member profiles are visible to other verified members within CAASA Connect in accordance with your configured directory visibility settings. We may share data with vetted service providers (e.g., cloud hosting, email dispatch) strictly under confidentiality and data protection agreements.

5. Data Safeguards & Retention

We maintain administrative, technical, and physical security safeguards to protect personal data against loss, theft, unauthorized access, copying, use, or modification. Records are retained only for as long as necessary to fulfill authorized business purposes or satisfy regulatory requirements.

6. Access & Correction Inquiries

You have the right to request access to the personal data we hold about you and to request corrections. Inquiries should be addressed to our Privacy Office at privacy@caasa.org.