Induscoat
Privacy and personal information

Privacy Policy

This policy explains, in practical terms, what happens to personal information when you visit induscoat.com, choose a language or contact the Induscoat network about an industrial project.

Last reviewed

Published information · updated as practices change

Section 1

Scope and accountable organization

This policy applies to the public website induscoat.com and to personal information received after a visitor chooses to send an inquiry using the contact options presented on the site. It does not automatically govern a separate website, customer portal, supplier, employer or contractual relationship that publishes its own privacy notice.

Induscoat is based in Montréal, QC, Canada. This identifies the brand’s operating base; it is not a complete legal or postal address and does not, by itself, identify the organization legally responsible for a particular inquiry.

Induscoat is presented here as a brand and coordinated network. The organization responsible for handling a particular inquiry is the regional operator or other Induscoat organization identified in the reply and, if the relationship continues, in the quotation, order or contract. contact@induscoat.com is the initial privacy contact and will route a request to the responsible organization without changing your substantive rights.

Section 2

How the contact workflow works

The website contact form is a draft generator. Validation and formatting occur in your browser, then your own email application opens a pre-filled message. Until you review the draft and press Send, the form content is not submitted to an Induscoat web endpoint and Induscoat has not received it.

After you send the email, your email provider and the receiving mail systems process the message and its routing metadata. The responsible Induscoat organization may then store the correspondence in business email, customer relationship, quotation or project records as needed to answer and manage the request. Attachments can contain sensitive operational information; send only material you are authorized to disclose.

Section 3

Information that may be processed

The information depends on how you use the site. You can read public pages without creating an account. When you contact us, the content is generally supplied directly by you; technical request and security data are generated through normal website and email operation.

  • Identity and contact details: name, business email, company, country and any signature details you include.
  • Inquiry details: industry, product range, message, equipment, service conditions, drawings, photographs and other attachments you decide to send.
  • Communication and relationship records: date, recipients, replies, meeting or quotation history and actions needed to follow up.
  • Technical request data: IP address and request headers handled by network infrastructure, requested URL, timestamp, browser or device class and security events, depending on hosting configuration.
  • Language and audience data: selected language, an approximate country code and, in Canada, a province code used at the root entry page, plus privacy-preserving audience measurements when analytics is enabled.
Section 5

Audience measurement, language and georouting

When configured, the site loads Plausible Analytics for cookie-free audience measurement. The implementation does not create advertising profiles or send contact-form fields. Custom conversion events are limited to a supported language, a site-controlled canonical path and a structural context such as the type of call-to-action. The analytics service may process normal request information to produce aggregate statistics in accordance with its documentation and the selected hosting configuration.

On a visit to the exact root URL, the hosting edge can provide an approximate ISO country code and, for Canada, a province code. The application uses this signal only to choose an initial language. It does not request GPS or other precise location, and its georouting logic does not retain the country or province. Infrastructure providers may nevertheless process request data in technical logs under their own retention and security settings. An explicit language choice is remembered by the NEXT_LOCALE cookie for up to 12 months.

Section 6

Recipients and service providers

Access is limited according to need. Information may be received by the regional operator or other Induscoat organization assigned to the inquiry, and by personnel involved in technical assessment, sales, project delivery, administration, security or legal compliance. It may also be processed by providers supporting hosting, content delivery, cybersecurity, audience measurement, email, communications, document storage or business records.

Providers receive only the information reasonably required for their task and are expected to act under applicable confidentiality, security and data-protection obligations. Information may also be disclosed where lawfully required, to protect rights or safety, investigate abuse, establish or defend legal claims, or support a corporate transaction with appropriate safeguards. Induscoat does not sell personal information and does not disclose it to third parties for cross-site behavioural advertising.

Section 7

International processing and transfers

Because induscoat.com serves several regions and website, email and business-service providers may operate internationally, information can be processed outside your province, state or country. Privacy laws and public-authority access rules can differ in those locations.

The responsible organization must assess and document transfers when required and use measures appropriate to the applicable law and risk, such as contractual protections, access controls, data minimization and a transfer or privacy impact assessment. For transfers from Quebec, the applicable assessment and written agreement requirements are considered before communication outside Quebec. For EEA data, an applicable GDPR transfer mechanism and supplementary measures are used where required. Moroccan transfers can require CNDP formalities under Law No. 09-08; no authorization or receipt number is represented on this page unless one is specifically identified in the relevant notice.

Section 8

Retention and disposal

There is no single retention period for every record. The responsible organization keeps personal information only as long as reasonably necessary for the stated purpose and any applicable legal, accounting, warranty, safety, limitation-period, dispute or evidentiary requirement. Criteria include whether the inquiry remains active, whether a quotation, customer or project relationship followed, the sensitivity and quantity of the information, the risk of keeping it, and mandatory recordkeeping rules.

The NEXT_LOCALE language preference expires after a maximum of 12 months unless it is replaced by a later choice or deleted sooner. When other information is no longer required, it is deleted, anonymized or securely disposed of according to the systems and legal obligations concerned. Backup copies can remain for a limited operational cycle and are protected from ordinary use until overwritten or restored for a legitimate recovery purpose.

Section 9

Security and confidentiality incidents

Reasonable administrative, technical and physical measures are selected according to the nature of the information and risk. Measures can include restricted access, secure transport, provider and configuration review, system updates, input limits, monitoring, backups, confidentiality duties and incident procedures. No internet or email system is completely risk-free; avoid sending information that is not necessary and contact us if a safer exchange method is required for technical files.

Suspected loss, unauthorized access, use or disclosure is assessed under the incident process of the responsible organization. Where the applicable threshold is met, affected people and regulators are notified within the period required by law, records are maintained for the legally required duration and measures are taken to reduce the risk of recurrence. Notification rules and thresholds vary by jurisdiction.

Section 10

Your privacy rights

Depending on the applicable law and subject to its conditions and exceptions, you may ask whether information about you is held; obtain access and information about its use and disclosure; correct inaccurate or incomplete information; withdraw consent for future processing; object to certain processing; request deletion, erasure, restriction or portability; or make a complaint without retaliation. We may need enough information to verify identity and locate the relevant records. We will explain a full or partial refusal and available recourse where the law requires it.

  • Quebec: the Act respecting the protection of personal information in the private sector, as amended by Law 25, can provide rights of access, rectification, withdrawal, cessation of dissemination or de-indexing in defined cases and, subject to legal conditions, portability. A written access or rectification response is generally due within 30 days.
  • Canada: where PIPEDA applies, its ten fair-information principles include accountability, identified purposes, valid consent, limiting collection, use, disclosure and retention, accuracy, safeguards, openness, individual access and the right to challenge compliance. Access requests are generally answered within 30 days, subject to lawful extensions and exceptions.
  • Morocco: Law No. 09-08 can provide rights of information, access, rectification, updating, erasure or blocking and objection, subject to the statutory rules. A valid rectification request is generally handled within ten clear days under that law. Applicable declarations, authorizations and international-transfer formalities fall to the responsible organization; a CNDP reference is provided only where one exists and must legally appear.
  • European Economic Area: where the GDPR applies, rights can include access, rectification, erasure, restriction, objection, portability, withdrawal of consent and a complaint to a supervisory authority. A request is normally answered without undue delay and within one month, subject to permitted extension.
Section 11

Questions, concerns and regulatory complaints

Please contact us first so the responsible organization can identify the record, investigate and respond. This does not limit your right to contact the competent authority. Depending on where you are and which law applies, that may include Quebec’s Commission d’accès à l’information, the Office of the Privacy Commissioner of Canada, Morocco’s Commission Nationale de contrôle de la protection des Données à caractère Personnel, or the data-protection supervisory authority in the EEA country where you live, work or believe an infringement occurred.

Section 12

Children, automated decisions and advertising

The site is intended for business and industrial audiences and is not directed to children. We do not knowingly seek personal information from children through the inquiry form. If you believe a child submitted information, contact us so the responsible organization can assess and remove it where appropriate.

The public website does not use personal information to make decisions producing legal or similarly significant effects, does not conduct automated credit or eligibility scoring, and does not build behavioural advertising profiles. Technical recommendations and commercial decisions involve human review. Aggregate audience measurements can be used to understand content performance but are not used to decide whether a person receives a product, price or service.

Section 13

Policy changes and contact

This policy is reviewed when data practices, services or legal requirements materially change. The date at the top identifies the latest published review. A material change will be explained on this page and, when the law requires it, brought to affected people’s attention through an additional notice or renewed choice. Earlier processing remains governed by the notice and law applicable at that time.

For a privacy question, request or concern, write to contact@induscoat.com. Include enough context to identify the responsible organization, but do not place unnecessary confidential or identity information in the first email. This page provides transparent operational information; it is not individualized legal advice.

Primary legal and regulatory sources used to frame this page.

Privacy and legal questions

Need clarification about this document?

Contact Induscoat to exercise a right, report an accessibility barrier or ask how this policy applies to your situation.

Write to Induscoat