Privacy Policy

Policy Version: 2025.04 | Last Updated: April 13, 2025

Ontario Compliance: Meets PIPEDA and AODA requirements. We do not process personal health information as defined under PHIPA. Health and accommodation data collected is limited to employment-related documentation and handled in accordance with PIPEDA.

1. Scope & Application

This Privacy Policy governs data collection across Divino Business Solutions Inc.'s digital platforms:

Covered Platforms

Applicable To

  • Job seekers and applicants
  • Corporate clients and partners
  • Employees and contractors
  • Website visitors

AI Resume Screening

  • Purpose: Skills matching and salary benchmarking only
  • Data Used: Anonymized excerpts (no contact details)
  • Consent: By registering on our jobs portal, you consent to the use of automated resume analysis tools for your application. No hiring or screening decision is made solely by AI.
  • Opt-Out: You may withdraw this consent or request exclusion from automated screening by emailing privacy@divinosolutions.com at any time before your application is reviewed by a potential employer.

2. Data Collection

A. Jobs Portal (jobs.divinosolutions.com)

  • Personal Data:
    • Resumes, cover letters, and contact details (Please be aware that by applying for jobs through our portal, your resume and application details may be shared with our corporate clients for job consideration.)
    • Work history, education, and skills assessments
    • Job preferences and salary expectations
  • Automated Data:
    • IP addresses and device/browser information
    • Google Ads cookies (from Google)
    • ATS interactions (e.g., resume views by employers) and data used for platform analytics
  • Sensitive Data (Optional):
    • Diversity/EEO self-identification (voluntary)
    • Disability accommodations requests

Ontario Note: Diversity data is anonymized for reporting under the Employment Equity Act and stored separately from applicant profiles.

EEO and accommodation-related data is collected only with your explicit consent and is never used in hiring decisions.

B. Partners Portal (partners.divinosolutions.com)

  • Payroll Services:
    • Employee SINs and tax forms (T4, ROE)
    • Banking details for direct deposit
    • Hours worked and overtime calculations
  • Employer of Record (EOR):
    • Employment contracts and amendments
    • Benefits enrollment forms
    • Performance evaluations
  • Health & Safety:
    • Workplace incident reports (WSIB)
    • Medical accommodation requests
    • Safety training certifications
  • HR Documents:
    • Disciplinary records
    • Termination notices
    • Grievance filings

We are committed to collecting and retaining only the personal data necessary for the purposes identified in this policy, and to ensuring that the data we hold is accurate and up-to-date.

C. Main Website (divinosolutions.com)

  • Contact Forms:
    • Names, email addresses, and phone numbers
    • Company details (for business inquiries)
    • Service request descriptions
  • Automated Data:
    • IP addresses and device/browser information
    • Heatmaps and session recordings
    • Referral source tracking
    • Google reCAPTCHA (to protect against spam and abuse)
  • Analytics:
    • Google Analytics (anonymized IPs)
    • Bing tools (for website analytics)
  • Marketing:
    • Newsletter signups (double opt-in)
    • Webinar registrations
    • Content download requests

CASL Compliance: Marketing communications include unsubscribe links and honor opt-outs within 48 hours, per Canada's Anti-Spam Legislation.

We may use usability tools that track anonymous website behavior such as mouse movement and page scrolls. These tools do not collect keystrokes or personal information.

3. Legal Basis & Purpose

We collect and process your personal data for the following purposes, based on the legal grounds outlined below:

Data UseLegal BasisDescription
Job matching (ATS)Consent (users) / Legitimate interest (clients)We use automated systems to assess resumes against job postings. These systems generate match scores and suggestions to assist employers in the screening process. These tools do not make final hiring decisions.
Payroll processingContractual necessity / Legal obligationTo fulfill our contractual obligations for payroll services and comply with tax and employment regulations.
Candidate sourcingLegitimate interestTo proactively identify potential candidates for current and future job openings.
Google Ads targetingConsent (cookie banner)To display relevant job advertisements to job seekers on the internet.
Dispute resolutionLegal obligationTo address and resolve any employment-related disputes or grievances.
Providing HR services (EOR, H&S, HR Docs, HRaaS, Recruitment & Staffing, Labour Relations)Contractual necessity / Legitimate interestTo deliver the contracted HR services to our corporate clients and manage our employment relationships.
Processing payments for servicesContractual necessityTo process payments securely through online tools such as Stripe or by issuing client invoices.
Responding to inquiries from the main websiteConsent (contact form submission) / Legitimate interestTo address and respond to inquiries and requests submitted through our website's contact forms.
Website analytics and improvementLegitimate interestTo analyze website traffic, user behavior, and improve the functionality and user experience of our websites.
Marketing communications (newsletter, webinars)Consent (double opt-in)To send promotional and informational materials to users who have explicitly opted in. All messages include an unsubscribe link and can be opted out at any time.

4. Data Sharing

We may share your personal data with the following categories of recipients:

Internal Sharing

Within Divino Business Solutions Inc., your data may be shared between departments to facilitate service delivery and internal operations. For example, candidate data submitted via the jobs portal may be reviewed by our recruitment team through the business services portal.

External Sharing

  • Clients: We only share candidate profiles with potential employer clients after you submit your application or profile through the jobs portal.
  • Vendors and Service Providers: We engage trusted third-party vendors to help us deliver services. These vendors may process personal data on our behalf, under strict confidentiality and security requirements:
    • HubSpot: For CRM and communication tracking.
    • Google Cloud, Namecheap: For hosting and infrastructure.
    • AI Tools: Used for automated resume screening to assist with candidate-job matching.
    • Stripe: For secure payment processing. View Stripe's Privacy Policy
    • Other essential vendors: Including IT providers and analytics platforms, for secure and compliant business operations.
    • We maintain Data Processing Agreements (DPAs) with all third-party processors who handle personal data to ensure compliance with applicable privacy laws.
  • Legal and Regulatory Authorities: We may disclose your data when required by law or in response to valid legal processes (e.g., tax compliance, government requests, or investigations). This may include disclosure to the Canada Revenue Agency (CRA), WSIB, or similar entities.

5. International Transfers

As a business with international operations and clients, your personal data may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws in your jurisdiction. We only transfer data internationally when necessary to provide our services or support platform functionality.

Safeguards for Transfers

  • European Union (EU): For transfers of personal data from the EU to countries outside the EU that have not been deemed to provide an adequate level of data protection, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. These clauses provide contractual safeguards to ensure that your data is protected to the same standards as within the EU.
  • Canada (PIPEDA): When transferring personal data to our vendors in the United States, we ensure that these transfers comply with PIPEDA requirements. Canada has recognized the data protection laws of the United States as providing an adequate level of protection in certain circumstances.
  • Other Jurisdictions: For transfers to other countries, we ensure all international data transfers are done in accordance with applicable privacy laws, using contract clauses or technical controls where appropriate.

Data Storage Locations

Our primary data storage is located on servers in Canada. However, for business continuity and disaster recovery purposes, we may also maintain backups of data on servers in the United States and the European Union. We select data centers with robust security measures in place.

Ontario-Specific Note: We prioritize using Canadian-hosted vendors, such as AWS Canada Central Region, where feasible, to adhere to data residency considerations. We also conduct annual audits of our U.S. vendors to assess their compliance with the CLOUD Act.

6. Security Measures

We are committed to protecting the security of your personal data. We implement a combination of technical and organizational safeguards designed to prevent unauthorized access, use, disclosure, alteration, or destruction of your information.

Technical Measures

  • Data Encryption: All data stored in our systems is encrypted at rest and in transit using AES-256, as provided by Google Cloud and Firebase.
  • Multi-Factor Authentication (MFA): MFA is enabled for all administrator accounts that access Firebase or Google Cloud services.
  • Secure Hosting: Our infrastructure is hosted on Google Firebase, which includes built-in protections like automated SSL, request validation, and threat detection.
  • App Protection: Firebase security rules and environment-based access controls are used to protect access to Firestore, Realtime Database, and Storage.
  • Vulnerability Management: We rely on Google's infrastructure-level protections and conduct internal reviews of critical code to reduce security risk.
  • Keystroke Logging: Prohibited across all company devices.

Organizational Measures

  • Access Control: Access to production systems is limited to authorized personnel (internal team members only) on a need-to-know basis.
  • Confidentiality: While we do not currently use formal NDAs, all employees are informed of their responsibility to handle user data with care and discretion.
  • Vendor Certifications: Our infrastructure providers, including Firebase, are compliant with internationally recognized standards such as SOC 2 and ISO 27001.
  • Team Training: Team members with system access are regularly informed of data security practices and policies.

Breach Response

In the event of a data breach involving personal data, we will notify affected individuals and relevant authorities as required by applicable laws. Under GDPR, this may include notification within 72 hours. Under PIPEDA, we will notify as soon as feasible. Breach handling procedures are based on incident severity and nature of affected data.

Note: We do not process any personal health information as defined under PHIPA.

Employee Monitoring (Ontario ESA Compliant)

  • We do not use screen recordings or tracking software on employees or their devices.
  • Keystroke logging and screenshot capture tools are strictly prohibited.
  • Monitoring is limited to account-level access logs and basic Google Workspace audit trails for security purposes only.

7. User Rights

We respect your rights regarding your personal data. Depending on your location and applicable laws (including PIPEDA, GDPR, and CCPA), you may have the following rights:

Access and Correction

  • Jobs Portal Users: You can access and update your profile information, including your resume and contact details, through your account dashboard.
  • Partners Portal Clients: You can review certain account data via your client dashboard.
  • For other access or correction requests, please email privacy@divinosolutions.com. We verify your identity by confirming your registered email address.

Deletion (Right to Erasure)

In certain circumstances, you may request the deletion of your personal data by emailing privacy@divinosolutions.com. We will review and process your request as required by law.

Data Portability

We currently do not offer automated data export, but you may request data deletion at any time.

Objection to Automated Processing

We use automated systems to assist in resume screening, but no decisions are made solely by AI. You may request a review by emailing us at privacy@divinosolutions.com.

Withdrawal of Consent

You can withdraw your consent to receive marketing emails by using the unsubscribe link in any message. For other types of consent, please email privacy@divinosolutions.com.

California Residents - Sale of Personal Info

Divino Business Solutions Inc. does not sell personal information as defined under the California Consumer Privacy Act (CCPA).

Cookie & Tracking Preferences

By continuing to use our website, you consent to our use of cookies as outlined in our privacy policy. If you wish to opt out, you may disable cookies in your browser settings.

Accessibility (AODA Compliance)

We are committed to providing accessible information. This policy is available in alternate formats, such as Braille or audio, upon request by contacting privacy@divinosolutions.com.

8. Retention Periods

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws and regulations. Most data is stored securely using Firebase Authentication, Firestore, and Google Cloud services. Data may be retained beyond the stated periods unless a valid deletion request is submitted as outlined in Section 7.

Below is a summary of our data retention practices:

Data TypeRetention PeriodReason
Job applications2 years after last login or application submissionTo consider you for future job openings and as per internal policy.
Payroll records7 yearsCompliance with Canada Revenue Agency (CRA) regulations.
Client contracts10 years post-terminationFor legal and contractual obligations.
Health and safety reports25 yearsCompliance with Ontario's Occupational Health and Safety Act (OHSA).
Training certificatesDuration of employment + 5 yearsTo demonstrate compliance with training requirements.
Work schedules3 yearsCompliance with Ontario's Employment Standards Act (ESA).
Payroll disputes7 yearsCompliance with Ontario's Employment Standards Act (ESA).
Contact form submissions1 yearFor responding to inquiries and record-keeping.
Marketing communication recordsUntil consent is withdrawnTo manage subscriptions and preferences.

In certain cases, data may be deleted automatically based on inactivity, or upon verified user request in accordance with Section 7.

9. Cookies & Tracking

We use cookies and similar tracking technologies across our websites and portals to improve functionality, enhance user experience, analyze traffic, and serve relevant advertisements.

By continuing to use our websites, you consent to the use of cookies and similar technologies as outlined in this policy. A cookie banner is displayed to notify users of this practice.

We rely on implied consent under Canadian law (PIPEDA). If you do not wish to accept cookies, you may adjust your browser settings to limit or block them.

Essential Cookies

These cookies are necessary for the basic operation of our websites and portals. They enable core functionality such as page navigation, secure login, and access to account features.

  • Session cookies for secure access to the jobs and partners portals

Advertising Cookies

These cookies are used to deliver relevant ads and measure ad performance. They are typically placed by trusted third-party networks.

  • Google Ads: Used for personalized job-related advertising. Learn More
  • LinkedIn Insights Tag: Used for conversion tracking and retargeting on our corporate website. Learn More

Analytics Cookies

These cookies help us understand how visitors interact with our websites. We use this data to improve performance, navigation, and content delivery.

  • Google Analytics 4 (GA4): Collects anonymized traffic and behavior data. Learn More
  • Hotjar: Used for heatmaps and user interaction insights (anonymized). Learn More
  • Microsoft Clarity: Provides anonymous session recordings and heatmaps. Learn More

10. Children's Privacy

Our services are not intended for individuals under the age of 16. While we do not actively restrict access, we do not knowingly collect or store personal information from anyone under 16 years old without parental consent.

If you are a parent or guardian and believe that your child has submitted personal information to us without your consent, please contact us immediately at privacy@divinosolutions.com. We will promptly review and delete any such data as required by applicable law.

We do not use behavioral advertising or profiling technologies for users known to be under the age of 16.

11. Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable legal requirements, or updates to our services. The “Last Updated” date at the top of this policy reflects the most recent version.

Notification of Changes

If we make material changes to this policy, we will notify users either by email (if available) or by posting a notice on our website prior to the changes taking effect. In the event of material changes, we may ask users to re-consent to the updated policy.

Version History

A version history of this policy will be maintained in the footer of our website for transparency.

Acceptance of Changes

By continuing to use our services after the updated Privacy Policy has been posted, you acknowledge and accept the revised terms. If you do not agree to the changes, you may stop using our services at any time.

Consent Expiry: User consent will automatically expire after one (1) year. We will re-prompt users for consent when required by law or after significant updates.

12. Contact

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please do not hesitate to contact us:

Data Protection Officer (DPO):privacy@divinosolutions.com

Phone: +1 (519) 502-2187

Address:
#2-120 Main Street,
Cambridge, ON N1R 1V7
Canada

Subprocessor List

We utilize the following subprocessors to assist in providing our services. These entities may process personal data on our behalf:

  • Google Cloud Hosting
  • Internal Proprietary Software
  • HubSpot
  • Google Analytics
  • Firebase (Auth, Firestore, Realtime Database, Storage)
  • Stripe (for payment processing)
  • QuickBooks
  • Google Gemini & ChatGPT (for AI ATS checker)
  • Google Workspace
  • Microsoft 365
  • Independent Analytics
  • Wordpress

For more information, please also review our Terms of service and Employee Policy.