Privacy Policy

Pause Collective Inc. (“Pause Collective”, “we”, “us”, “our”)

Last updated: August 30, 2026

Pause Collective is committed to protecting privacy as an integral part of the design and delivery of our services. This Policy explains how we collect, use, disclose, retain, safeguard, and dispose of personal information, and how individuals may exercise their privacy rights.

Important legal context. Pause Collective complies with applicable Canadian privacy laws. Depending on the activity, the individuals involved, and where the information is handled, these may include British Columbia’s Personal Information Protection Act (PIPA), the federal Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable privacy laws, including the private-sector privacy laws of Alberta and Quebec where our services involve individuals in those provinces.

Services for British Columbia public bodies. When Pause Collective provides services to a British Columbia public body, including a Crown corporation, ministry, local government, school, health authority, or other public body, personal information may be subject to British Columbia’s Freedom of Information and Protection of Privacy Act (FIPPA). In those circumstances, Pause Collective will comply with applicable FIPPA requirements and the privacy, security, data-location, retention, access, and breach-management obligations contained in its contract with the public body. Where a client’s contractual or legal requirements are more protective than this Policy, those requirements will govern the relevant information.

1. Scope

This Policy applies to personal information under Pause Collective’s control when individuals:

  • use our website, online forms, assessments, or other digital services;

  • contact us by email, telephone, video conference, website form, or in person;

  • participate in our education, advisory, assessment, research, consultation, or workplace programs;

  • receive individual support or participate in interviews, focus groups, surveys, or other engagements delivered by Pause Collective; or

  • otherwise interact with Pause Collective in the course of our business.

This Policy does not replace a client-specific privacy notice, consent form, assessment notice, or contractual privacy schedule. Where we provide a specific notice at the point of collection, that notice should be read together with this Policy.

2. Definitions

Personal information means information about an identifiable individual. Depending on the context, this may include contact details, demographic information, assessment responses, workplace information, communications, billing information, online identifiers, or other information that identifies or can reasonably be linked to an individual.

Sensitive personal information includes information that, because of its nature or context, requires a higher level of protection. For Pause Collective, this may include information about health, menopause or perimenopause symptoms, disability or accommodation needs, employment circumstances, or other private matters shared by an individual.

Business contact information generally means information used to contact an individual in their business or professional capacity. Its treatment depends on the applicable law.

3. Accountability and Privacy Governance

Pause Collective is accountable for personal information under its control. We designate a Privacy Officer who is responsible for overseeing our privacy management program, responding to inquiries and complaints, supporting privacy impact and risk assessments where appropriate, and promoting compliance with this Policy and applicable law.

Our privacy management practices include role-based access, confidentiality expectations, service-provider oversight, privacy and security considerations in the selection of technology, incident response procedures, and periodic review of our practices.

4. Information We Collect

We limit collection to information that is reasonably necessary for identified purposes. Depending on the service, we may collect:

  • Contact and administrative information, such as name, email address, telephone number, organization, role, registration details, and billing information;

  • Service and participation information, such as program registrations, meeting information, preferences, feedback, and communications;

  • Assessment and workplace information, such as responses to a Pause Collective assessment, reported symptoms and impacts, workplace experiences, and information relevant to education, navigation of healthcare conversations, or workplace accommodation discussions;

  • Survey, interview, and focus-group information provided voluntarily as part of an organizational engagement;

  • Technical information, such as IP address, browser or device information, cookie data, and website analytics; and

  • Other information an individual chooses to provide to us.

We seek to avoid unnecessary collection. Individuals should not provide medical records, diagnostic reports, government identifiers, financial account credentials, or other highly sensitive information unless Pause Collective has specifically requested it for a defined and lawful purpose.

5. Purposes for Collection, Use, and Disclosure

We collect, use, and disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances and as permitted by applicable law. These purposes may include:

  • providing and administering requested services, assessments, education, and programs;

  • responding to inquiries and communicating about appointments, services, invoices, confirmations, or follow-up;

  • supporting an individual’s understanding of their reported experience and preparation for discussions with healthcare providers or their employer, where this forms part of the service;

  • conducting surveys, interviews, focus groups, and organizational assessments;

  • preparing de-identified or aggregated findings, reports, recommendations, and program evaluations for organizational clients;

  • maintaining, securing, and improving our services, website, methods, and user experience;

  • meeting legal, regulatory, professional, contractual, insurance, accounting, and record-keeping requirements; and

  • preventing or investigating fraud, misuse, security incidents, or other unlawful activity.

If we wish to use personal information for a new purpose that is not reasonably connected with the original purpose, we will identify the new purpose and obtain consent where required.

6. Consent and Choices

We obtain meaningful consent where consent is required by law. The form of consent may be express or implied depending on the sensitivity of the information, the reasonable expectations of the individual, and the circumstances. We will seek express consent for the collection, use, or disclosure of sensitive personal information, including health-related information, unless another form of consent, or an exception to consent, is permitted by applicable law.

An individual may withdraw consent to future collection, use, or disclosure, subject to legal, contractual, or operational restrictions and reasonable notice. Withdrawal of consent may affect our ability to provide a requested service. We will explain material consequences where appropriate.

We do not rely on a general statement that use of our website constitutes consent to every practice described in this Policy. Where specific consent is required, we will seek it in an appropriate manner.

7. Individual Assessments, Health-Related Information, and Employer Clients

Confidentiality is particularly important when employees participate in Pause Collective services through their employer. Unless the individual has expressly consented, or disclosure is otherwise authorized or required by law, Pause Collective will not provide an employer with an identifiable individual’s assessment responses, reported symptoms, private health-related information, or the substance of confidential one-to-one discussions. Where a service is designed to be confidential, we will also not confirm to an employer whether an identifiable individual has participated, unless participation information is reasonably required to administer the program and individuals are told this at the time of collection.

Where an organizational client receives results from surveys, assessments, interviews, focus groups, or similar activities, Pause Collective will normally provide aggregated or de-identified information designed to reduce the risk that an individual can reasonably be identified. We may establish minimum reporting thresholds or suppress small-group results where appropriate.

Pause Collective’s services are educational and advisory unless a particular service is expressly identified otherwise. Individuals remain responsible for obtaining medical diagnosis, treatment, or clinical advice from qualified healthcare providers.

8. Disclosure and Service Providers

Pause Collective does not sell or rent personal information. We may disclose personal information:

  • to service providers that perform functions on our behalf, such as secure cloud hosting, email, scheduling, video conferencing, survey or assessment platforms, accounting, or technology support, where the information is necessary for those services;

  • to independent contractors, subject-matter experts, and medical or clinical advisors who assist us in developing or delivering our services, where the information is necessary for that purpose and subject to appropriate confidentiality and privacy obligations;

  • to an organizational client where the individual has consented to the disclosure or where the disclosure is otherwise permitted or required by law or contract;

  • to professional advisers, insurers, auditors, or legal counsel where reasonably necessary and subject to appropriate confidentiality obligations;

  • where required or authorized by law, court order, subpoena, regulatory process, or lawful investigation; or

  • where permitted by law to address an emergency, protect health or safety, prevent fraud, or respond to a security incident.

We require service providers to protect personal information through contractual, technical, and organizational safeguards appropriate to the sensitivity of the information and the nature of the service.

9. Cross-Border Processing and British Columbia Public-Sector Information

Some technology or service providers may process or store personal information outside British Columbia or outside Canada. When that occurs, information may be subject to the laws of the jurisdiction in which it is processed or stored. Pause Collective assesses cross-border processing and uses contractual and security measures appropriate to the circumstances.

For information handled on behalf of a British Columbia public body, Pause Collective will follow the public body’s instructions and applicable FIPPA and contractual requirements concerning storage, access, disclosure, and processing inside or outside Canada. We will not move or permit access to such information outside an approved location where doing so would contravene those requirements.

10. Cookies, Website Analytics, and Electronic Communications

Our website may use cookies and similar technologies for essential site functionality, security, preferences, and analytics. Depending on the technology used, these tools may collect IP address, device or browser information, pages visited, referral information, and interaction data.

Where required, we will provide appropriate notice or choice regarding non-essential cookies. Browser settings may also permit users to block or delete cookies, although doing so may affect website functionality.

Commercial electronic messages will be sent in accordance with applicable Canadian anti-spam requirements. Individuals may unsubscribe from marketing communications using the method provided in the message. We may still send service or transactional communications where permitted.

11. Safeguards

We use reasonable administrative, technical, and physical safeguards appropriate to the sensitivity, amount, format, location, and use of personal information. Safeguards may include:

  • need-to-know and role-based access controls;

  • strong authentication and password practices, including multi-factor authentication where appropriate;

  • encryption or other secure transmission and storage controls where appropriate;

  • confidentiality obligations for personnel and contractors;

  • vendor due diligence and contractual privacy and security requirements;

  • secure disposal or deletion processes;

  • back-up, logging, monitoring, and incident-response measures appropriate to our systems; and

  • additional controls for sensitive assessment, health-related, workplace, and public-sector information.

No method of transmission or storage is completely secure. We therefore use a risk-based approach and continually seek to improve safeguards as technologies, services, and risks evolve.

12. Retention and Secure Disposal

We retain personal information only for as long as reasonably necessary to fulfill the purposes for which it was collected and to meet legal, contractual, accounting, insurance, dispute-resolution, and record-keeping requirements.

Retention periods may vary by record type and client engagement. Where personal information is used to make a decision directly affecting an individual, we will retain it for any minimum period required by applicable law (generally at least one year). Information held on behalf of a public body will be retained and disposed of in accordance with the public body’s instructions, applicable FIPPA requirements, and the governing contract.

When information is no longer required, we securely delete, destroy, or de-identify it in a manner appropriate to its sensitivity and format.

13. Accuracy

We make reasonable efforts to ensure personal information is accurate and complete where it is likely to be used to make a decision affecting an individual or disclosed to another organization. Individuals are encouraged to advise us if their personal information changes or they believe information we hold is inaccurate.

14. Access and Correction

Subject to exceptions under applicable law, an individual may request access to personal information about them under Pause Collective’s control and information about how it has been used or disclosed. An individual may also request correction of inaccurate or incomplete personal information.

Requests should be made in writing to our Privacy Officer with enough detail to identify the individual and the information requested. We may need to verify identity before responding. We will respond within the time required by applicable law, subject to lawful extensions.

If Pause Collective holds information solely as a service provider for a client and the information remains in the client’s custody or control, we may direct the individual to the client or assist the client in responding, as required by law and contract.

15. Privacy Breaches and Incident Response

Pause Collective maintains procedures to identify, contain, investigate, document, and remediate suspected or confirmed privacy and security incidents. We will notify affected clients, individuals, regulators, or other parties where required by applicable law or contract.

Where PIPEDA applies, we will assess whether a breach creates a real risk of significant harm, make required reports and notifications as soon as feasible, and maintain required breach records. Where we handle information for a British Columbia public body, we will promptly notify the public body of a suspected or confirmed breach and cooperate with its assessment and any notifications required under FIPPA.

16. Privacy Impact and Risk Assessments

Pause Collective may conduct privacy impact, security, or vendor risk assessments when introducing new services, technologies, assessments, or information-handling practices, particularly where sensitive information or public-sector information is involved. When working for a public body, we will provide reasonable assistance with the client’s privacy impact assessment or related compliance process where required by the engagement.

17. Questions, Complaints, and Privacy Officer

Questions, access or correction requests, consent withdrawals, and privacy complaints should be directed to:

Privacy Officer, Pause Collective Inc.
Email:
privacy@pausecollective.ca
Phone: 604-803-1670

We will review and respond to privacy concerns in a fair and timely manner. If an individual is not satisfied with our response, they may have the right to contact the Office of the Information and Privacy Commissioner for British Columbia, the Office of the Privacy Commissioner of Canada, or another applicable privacy regulator, depending on the law and circumstances that apply.

18. Changes to This Policy

We may update this Policy from time to time to reflect changes in our services, practices, technologies, contractual requirements, or applicable law. The current version will be posted with its effective or “Last updated” date. Material changes will be communicated in an appropriate manner where required.

19. Third-Party Websites

Our website may contain links to websites or services operated by third parties. Their privacy practices are governed by their own policies and are not controlled by Pause Collective. We encourage individuals to review the privacy information provided by those third parties.