Privacy Policy
This Privacy Policy explains how we collect, use, share, store, and protect personal information when you use our website, book or attend training, complete respirator fit testing, request consulting services, or otherwise interact with us.
Scope of This Policy
This policy applies to personal information we handle through our website and business activities, including:
- Online and in-person training registrations
- Respirator fit-testing appointments and records
- Training certificates and certification records
- Online booking and payment systems
- Contact, registration, and digital forms
- Email and telephone communications
- Safety consulting and related client services
- Customer, employer, and participant inquiries
- Website use and related technical information
Our goal is to collect only the personal information reasonably needed to provide our services, operate our business, maintain appropriate records, and meet applicable legal or regulatory requirements.
Personal Information We May Collect
The information we collect depends on how you interact with us. It may include the following.
Contact and identification information
- Name
- Email address
- Telephone number
- Employer or organization
- Job title or role, where relevant
- Address information where it is reasonably required
Booking and registration information
- Course, appointment, or service selected
- Booking date and time
- Participant and employer information
- Registration history
- Attendance information
- Payment status
- Other information required to administer the booking
Training and certification records
When you participate in training, we may maintain information such as:
- Participant name
- Training completed and training date
- Instructor information
- Course results or completion status
- Certification status
- Certificate number and expiry information, where applicable
- Prerequisite or previous-training information where required
- Other records reasonably necessary to administer or verify training
Respirator fit-testing records
Fit-testing records may include:
- Participant name and contact information
- Employer or organization
- Date of the fit test
- Respirator manufacturer, model, and size
- Fit-test method
- Test result
- Certification information
- Other documentation reasonably required to record the fit test
Our routine fit-testing records focus on the respirator, test procedure, result, and certification information. Medical information is not routinely collected as part of that process.
Payment information
When you make a payment, we may receive information such as the payment amount, payment status, transaction reference, and customer details associated with the transaction.
Full payment-card information is generally processed by our payment service provider rather than being stored directly by us.
Forms and communications
We may collect information you provide through contact forms, training forms, fit-testing forms, consulting inquiries, feedback forms, emails, telephone calls, booking conversations, and other communications with us.
Website and technical information
Our website or service providers may automatically collect certain technical information, which may include:
- IP address
- Browser and device type
- Operating system
- Pages viewed
- Referring website
- Date and time of visits
- Website interactions
- Approximate geographic information
- Cookies and similar technologies
More information about these technologies is provided in our Cookie Policy.
How We Collect Personal Information
We may collect personal information in several ways, including:
- Directly from you when you contact or communicate with us
- When you register for training or book a fit-testing appointment
- When you complete a paper or digital form
- When you purchase or pay for a service
- When you participate in training, fit testing, or consulting services
- Automatically when you interact with our website
- Through service providers that support our website and business systems
Where an employer, school, contractor, or other organization arranges training on behalf of participants, we may also receive participant information from that organization for the purpose of registering participants and administering the training relationship.
How We Use Personal Information
We may use personal information to:
- Process registrations and schedule appointments
- Process and confirm payments
- Deliver training, respirator fit testing, and consulting services
- Create and maintain training and certification records
- Issue certificates and other required documentation
- Verify training, attendance, certification, or fit-testing records
- Respond to questions, requests, and customer-service inquiries
- Send booking confirmations, reminders, certificates, and service-related messages
- Manage cancellations, rescheduling, refunds, and credits
- Maintain business, accounting, and financial records
- Improve our services, website, and internal processes
- Protect our website, systems, customers, and business from misuse or fraud
- Meet legal, regulatory, contractual, or record-keeping requirements
- Respond to lawful requests from courts, regulators, or other authorities
We do not use personal information for unrelated purposes unless permitted by law or appropriate consent has been obtained.
Consent and Your Choices
We obtain consent where required. Depending on the nature of the information and the circumstances, consent may be express or implied where permitted by law.
Some information is necessary for us to register a participant, provide training or fit testing, process a payment, issue certification, maintain appropriate records, or otherwise provide a requested service. If required information is not provided, we may be unable to provide that service.
You may withdraw consent where applicable by contacting our Privacy Officer. Withdrawal may be subject to legal, contractual, certification, or record-keeping requirements and may affect our ability to continue providing a service.
Marketing communications
Consent to receive promotional communications is separate from the information needed to book or receive a service.
Where we send commercial electronic messages, we will do so in accordance with applicable requirements, including appropriate consent where required, identification of the sender, and a way to unsubscribe.
Booking confirmations, appointment reminders, certificates, payment messages, and other service-related communications are different from promotional marketing and may be necessary to administer a service you requested.
When We Share Personal Information
We do not sell personal information.
We may share personal information only where reasonably necessary, including:
- With service providers that support our business operations
- To process payments and administer bookings
- To administer training, certification, or fit-testing records
- With an employer or organization that arranged training, where appropriate
- With your consent
- Where required or permitted by applicable law
- In response to lawful court orders, warrants, regulatory requests, or similar legal processes
- Where reasonably necessary to investigate fraud, misuse, safety concerns, or security incidents and legally permitted to do so
- As part of a legitimate business transaction where appropriate privacy safeguards are used
We limit disclosures to the information reasonably necessary for the purpose involved.
Third-Party Service Providers
We rely on third-party technology and service providers to operate parts of our website and business. Depending on the service, these may include:
- Squarespace Website hosting, website functionality, and website analytics.
- BookWhen Online course and appointment booking.
- Stripe Payment processing.
- Jotform Digital forms and information collection.
- Google services Business technology, analytics, and related services where used.
- SiteDocs Digital safety-management systems where relevant to a client service.
We may also use other providers for email, cloud storage, accounting, training administration, customer communication, and other business technology.
We provide these organizations only with the information reasonably necessary for the services they perform. Third-party providers also operate under their own terms, systems, and privacy practices.
Processing outside Ontario or Canada
Some service providers may process or store personal information outside Ontario or outside Canada. When that occurs, information may be subject to the laws of the jurisdiction where it is processed or stored.
We remain responsible for taking reasonable steps to protect personal information under our control when we use service providers.
Employer- or Organization-Arranged Training
Employers, schools, contractors, and other organizations sometimes register or pay for training on behalf of participants.
Where reasonably necessary to administer that training relationship, we may provide the arranging organization with information such as:
- Attendance information
- Training completion status
- Certification status
- Training date
- Certificate documentation
- Certification expiry information, where applicable
Paying for or arranging training does not automatically entitle an organization to unrelated personal information about a participant.
How Long We Keep Personal Information
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected or for related legitimate business purposes.
Retention periods may vary depending on the type of information and may reflect:
- Training and certification record requirements
- Service and customer-support needs
- Contractual obligations
- Accounting and financial record requirements
- Legal or regulatory obligations
- The need to verify previous training, certification, or fit-testing records
When information is no longer reasonably required, we take appropriate steps to securely delete, destroy, or anonymize it.
How We Protect Personal Information
We use reasonable administrative, technical, and physical safeguards appropriate to the nature of the information we handle. These may include:
- Password and account-access controls
- Multi-factor authentication where available and appropriate
- Restricted access to personal information
- Secure cloud and technology service providers
- Secure payment-processing services
- Device-security measures
- Staff privacy and information-handling procedures
- Appropriate handling and storage of paper records
- Secure disposal of records that are no longer required
No method of electronic transmission or storage can be guaranteed to be completely secure. We therefore cannot guarantee absolute security, but we take reasonable steps to protect the information under our control.
Privacy and security incidents
If we become aware of a privacy or security incident involving personal information, we will take reasonable steps to identify and contain the issue, determine what information may have been affected, assess the risk of harm, take appropriate corrective action, and document the incident.
Where required by applicable law, we will notify affected individuals and report qualifying incidents to the appropriate regulator.
Accessing or Correcting Your Information
You may contact our Privacy Officer to request information about the personal information we hold about you, including how it has been used or disclosed, subject to applicable law.
You may also ask us to correct personal information that is inaccurate, incomplete, or outdated. Where appropriate, we will update the relevant records.
Before providing access to personal information, training records, certificates, or similar documentation, we may take reasonable steps to verify your identity.
Requests to access information, correct records, withdraw consent, or raise a privacy concern should be directed to our Privacy Officer using the contact information below.
Participants Under the Age of Majority
Our services and website are not primarily directed at children. However, some training participants may be under the age of majority, including participants registered through schools, pre-apprenticeship programs, employers, or other educational programs.
Personal information relating to younger participants is handled in the context of the training or service being provided and in accordance with applicable privacy requirements.
Cookies and Website Analytics
Our website may use cookies, analytics tools, and similar technologies to operate the website, understand how visitors use it, improve performance, and support other website functions.
For more information about the types of cookies and similar technologies used on our website and the choices available to you, please review our Cookie Policy.
Changes to This Privacy Policy
We may update this Privacy Policy as our business, services, technology, service providers, or legal requirements change.
The effective date and last-updated date shown at the top of this page will be updated when appropriate. If a material change affects how existing personal information is used, we will assess whether additional notice or consent is required.
Applicable privacy requirements
This policy is intended to reflect applicable Canadian privacy requirements, including the Personal Information Protection and Electronic Documents Act (PIPEDA) where it applies.
Nothing in this policy limits privacy rights or protections available under applicable law.
Questions, Requests, or Privacy Concerns
If you have a question about this policy, want to access or correct your personal information, wish to withdraw consent where applicable, or have a privacy concern or complaint, please contact:
Privacy Officer
StartSafe Training & Consulting, Inc.
Kingston, Ontario
Email: admin@startsafetraining.com
Phone: 613-531-3698
We will review privacy questions and complaints and take appropriate steps to address them in accordance with applicable privacy requirements.

