Privacy policy
1. Introduction
Go Rampe is committed to protecting privacy and personal information in accordance with Québec’s Act respecting the protection of personal information in the private sector (Law 25).
This privacy policy complements the consent management mechanisms (CMP) already in place on our site. The preferences you express through our consent manager are directly integrated into the processing activities described below. The privacy settings applied stem from the configurations resulting from the self-assessment carried out by our organization through the Normi platform, in accordance with the requirements of Law 25.
2. Identification of the organization
- gorampe.com
- 1405 Rue Thomas Powers Succursale Levis G7A 4X6
- mlacasse@gorampe.com
- (450) 565-5677
These contact details also serve as the administrative point of contact for any question relating to the protection of your personal information. You may contact us for clarification on our privacy practices or for any request related to your rights.
3. Person in charge of the protection of personal information
- Marc Lacasse
- mlacasse@gorampe.com
- +1 888-957-2673
The person in charge of the protection of personal information acts as the coordination point for all access, rectification and deletion requests. They also oversee the management of privacy incidents, the conduct of internal audits and the updating of data protection practices within the organization.
4. Personal information collected
The categories of personal information collected may vary depending on the features you use on our site. Some data comes directly from your interactions with our consent manager (CMP). The categories below correspond to the options selected during our compliance self-assessment and reflect the processing actually implemented.
- Contact details (required): Email, phone, address
- Identity data: Last name, first name, date of birth
- Browsing data: Pages visited, duration, device
- Preferences: Language, communication preferences
5. Collection methods
We collect your personal information through various means. Automatic collection is limited to what is strictly necessary for the technical operation of our services. Analytics and tracking cookies respect the preferences you have set through our consent manager. Technical logs (server logs) are used exclusively for security and diagnostic purposes and are not exploited for commercial purposes.
- Online forms and direct interactions with our services
- Cookies and similar technologies, according to your consent preferences
- Technical logs (server logs) for security and diagnostic purposes
- Integrated third-party services, to the extent authorized by your consent
6. Purposes of collection
Each purpose of collection is associated with a specific legal or operational basis. Data processing is configured according to the choices expressed through our consent manager. The personalization of your experience remains strictly limited to the settings you have authorized.
- Compliance with our legal obligations: Comply with our legal obligations
- Security and fraud prevention: Ensure the security of our systems
- Analysis and improvement: Improve our services and our website
- Communication with you: Respond to your requests and contact you
- Personalization of the experience: Personalize your experience
- Provision of our services: Provision of our services and products
- Account management: Management of your customer account
7. Disclosure to third parties
Our service providers and partners are selected according to rigorous security and compliance criteria regarding the protection of personal information. Any disclosure of information to third parties is strictly limited to the purposes described in this policy.
- Competent authorities where required by law
- Service providers (hosting, payment, analytics)
8. Security measures
The security measures implemented are proportional to the sensitivity level of the personal information processed. In addition to the technical measures listed below, logical and organizational access controls are applied to limit access to information to authorized persons only, within the scope of their duties. The certifications and standards mentioned reflect the practices of our hosting and infrastructure providers.
- Regular security audits
- Regular secure backups
- Staff training in data protection
- Data encryption (HTTPS, encryption at rest)
- Intrusion monitoring and detection
- Access control and secure authentication
- Incident response plan
9. Retention of information
The retention period of your personal information is determined based on the nature of the commercial or contractual relationship and the applicable legal obligations. At the end of the retention period, your information is securely deleted or, where appropriate, irreversibly anonymized so that it can no longer be associated with an identifiable person.
- Retention period: 3 years
- Hosting: Canada
10. Your rights
In accordance with Law 25, you have the following rights concerning your personal information:
- Right of access — obtain confirmation that we hold your information and access it
- Right of rectification — have inaccurate or incomplete information corrected
- Right to erasure — request the deletion of your information when the legal conditions are met
- Right to portability — receive your information in a structured, commonly used technological format
- Right to withdraw consent — withdraw your consent at any time through our consent manager
Requests to exercise rights are processed according to a structured internal process. Depending on the nature of the request, identity validation may be required to protect your information against unauthorized access. This verification aims to ensure that the request comes from the person concerned or their authorized representative.
To exercise your rights, contact: mlacasse@gorampe.com
Response time: 30 days
11. Privacy incident
In the event of a privacy incident involving your personal information, our organization applies a structured process comprising the following steps:
- Detection and assessment — Rapid identification of the incident, assessment of its scope and of the risk of serious injury to the persons concerned.
- Containment and analysis — Immediate measures to limit the impact of the incident, root-cause analysis and detailed documentation of the circumstances.
- Notification — When an incident presents a risk of serious injury, the Commission d’accès à l’information du Québec and the persons concerned are notified within a maximum of 72 hours, in accordance with Law 25.
- Remediation — Implementation of corrective measures to prevent recurrence of the incident and strengthening of security controls.
12. Complaint
Our organization favours internal resolution of any concern related to the protection of your personal information. We invite you to first contact our person in charge of the protection of personal information to attempt to resolve the situation.
If you believe your rights have not been adequately respected after this step, you may file a complaint with the Commission d’accès à l’information du Québec:
13. Changes to this policy
We reserve the right to modify this privacy policy. Updates may result from technological changes in our systems, from changes to the applicable legislative or regulatory framework, or from the integration of new features within our consent manager (CMP). The date of the last update will always be indicated at the top of this document. In the event of a substantial change, we will inform you by appropriate means.
Last updated: August 11, 2026
Generated with Normi
Your entrance is an obstacle — we have the solution.
- Free assessment
- Clear answer
- Often installed in a day