On this Page
1. About this Policy
The Nonprofit Data Capacity Navigator Initiative (the “Initiative”) helps nonprofit organizations understand their data needs and access self-guided assessments, curated resources, cohort-based supports, and tailored advice from nonprofit data and technology experts.
This Policy applies to nonprofit organizations participating in the Initiative, their authorized representatives, Data Capacity Advisors, cohort participants, project partners, and other individuals who interact with the Initiative through its website, assessments, forms, surveys, interviews, focus groups, advisory services, and related activities.
The Initiative is delivered collaboratively by Blueprint-ADE (“Blueprint”), Purpose Analytics, the Canadian Centre for Nonprofit Digital Resilience (“CCNDR”), PolicyWise for Children & Families (“PolicyWise”), and the Tamarack Institute. Together, these organizations are referred to in this Policy as the “Project Partners.”
2. Key Definitions
3. Information We Collect
The Initiative collects a limited amount of Personal Information and a broader range of Project Information about participating organizations and project delivery.
3.1 Personal Information
Personal Information collected through the Initiative may include:
- the name, job title, role, email address, of an Authorized Representative;
- survey or interview responses that can be linked to an identifiable individual;
- opinions, observations, or comments about an identifiable individual contained in case notes, open-text responses, or project communications.
3.2 Service Delivery Project Information
Project Information includes, but is not limited to, the following types of data:
4. How Information Is Collected and Managed
Information is collected directly from Authorized Representatives, DCAs, cohort delivery partners, and other project partners through service delivery, project administration, evaluation, and governance activities.
5. Why We Use Information
5.1 Personal Information
- to communicate with Participants and their representatives;
- to administer registration, scheduling, reminders, and service delivery;
- to match Participants with appropriate supports, DCAs, or cohort opportunities;
- to respond to questions, requests, complaints, or privacy concerns;
- to conduct project evaluation and follow-up activities; and
- to contact individuals about future engagement only where they have asked or agreed to be contacted.
5.2 Service Delivery Project Information
- to assess organizational data needs and maturity;
- to tailor DCA, cohort, self-service, and referral supports;
- to document service delivery, case management, progress, and outcomes;
- to administer, monitor, evaluate, and improve the Initiative;
- to support Governance Committee oversight and project reporting;
- to produce anonymized, aggregated, or synthesized sector-level findings; and
- to support an approved longitudinal study after project delivery using anonymized data.
7. Storage and Security
Personal Information and Project Information may be stored in approved cloud-based systems and organizational storage environments used for surveys, CRM and case management, assessment administration, communications, scheduling, reporting, and project administration. These systems may include Qualtrics, Softr, Data Orchard systems, scheduling and automation tools, and approved organizational cloud storage.
7.1 Personal Information safeguards
The following safeguards are in place for personal data collected and managed through the Initiative.
- role-based access and account controls;
- limiting access to authorized personnel;
- secure transmission and storage practices;
- confidentiality expectations and privacy procedures; and
- incident response and breach-management processes.
7.2 Service Delivery Project Information safeguards
Project Information may not be personal information, but it can still be confidential, commercially sensitive, or capable of identifying a Participant organization. The Initiative therefore applies reasonable access, confidentiality, security, and data-minimization controls to Project Information as well as Personal Information.
No electronic storage or transmission method can be guaranteed to be completely secure. The Initiative nevertheless takes reasonable steps appropriate to the nature and sensitivity of the information.
8. Retention, Access Removal, and Disposal
Information is retained only for as long as necessary for the purpose for which it was collected or created, subject to legal, contractual, funding, audit, and records-management requirements.
8.1 Personal Information
Personal Information is retained only while needed for communication, service delivery, follow-up, evaluation, complaint handling, or another identified purpose. Contact information used for future engagement will be retained only where the individual has agreed to be contacted or where another lawful basis applies. When no longer required, Personal Information will be securely deleted, destroyed, de-identified, or separated from retained Project Information, as appropriate.
8.2 Service-delivery Project Information
Authorization to use disaggregated, non-anonymized, or organization-specific Project Information for DCA services, cohort delivery, or another approved service ends when the relevant service or engagement is completed. At that time, the organization providing the service will stop using the information for that service and securely destroy or return locally retained copies unless retention is legally or contractually required or approved in writing. Continued technical access to Softr for another role does not authorize continued use for a completed service.
8.3 Governance and project-delivery Project Information
Aggregated, de-identified, synthesized, or project-level information used for governance, delivery, monitoring, evaluation, and reporting may be retained until the end of project delivery, unless an earlier date applies.
8.4 End of project and Future use for research purposes
Access to Softr will be removed when the Initiative ends or when a Project Partner’s or DCA’s participation ends, whichever occurs first. Summary analysis will be maintained after the end of the project by Project Partners and the Project Partners reserve the right to use the data for research purposes after project end.
Raw DMA information retained or managed by Blueprint, Purpose Analytics, or Data Orchard remains subject to the applicable Data Orchard privacy policy and contractual arrangements. Anonymized Data Maturity Data will be used for future data analysis by Project Partners.
9. Consent, Organizational Authorization
9.1 Personal Information
Participation is voluntary. By submitting Personal Information, an individual agrees to its collection, use, and sharing as described in this Policy and in any collection, notice presented at the time the information is requested. Consent may be withdrawn by contacting the Initiative, subject to legal, contractual, operational, and record-keeping limitations. Withdrawal may affect the Initiative’s ability to provide a requested service; the Initiative will explain this where applicable.
9.2 Service Delivery Project Information and Organizational Authorization
An Authorized Representative who provides Project Information confirms that they are authorized to provide that information on behalf of the Participant organization. Participants should not provide information about clients, service users, employees, or other individuals unless it is necessary, authorized, and appropriate for the Initiative.
A Participant may ask to correct inaccurate organizational information or request that the Initiative stop using information for a particular optional activity. Some information may need to be retained for contractual, legal, audit, evaluation, or project-integrity purposes, and information already anonymized or included in aggregate analysis may not be capable of removal.
10. Access and Correction Requests
Individuals may request access to or correction of their Personal Information held by the Initiative, subject to applicable limitations. Participant organizations may request correction of inaccurate Project Information about their organization. Requests should be directed to the contact listed at the end of this Policy.
11. Privacy and Security Incidents
11.1 Incidents involving Personal Information
The Initiative will assess, contain, investigate, document, and respond to any actual or suspected unauthorized access, use, disclosure, alteration, loss, or destruction of Personal Information. Affected individuals and regulators will be notified where required by applicable law or where notification is otherwise appropriate based on the risk of harm.
11.2 Incidents involving Project Information
Incidents involving confidential or organization-specific Project Information will also be assessed, contained, investigated, and addressed. Affected Participant organizations or Project Partners may be notified where appropriate, even where the incident does not involve Personal Information.
Project Partners and service providers are expected to promptly report suspected incidents and cooperate with the Initiative’s breach-response process.
11.3 Incidents involving Data Maturity Assessment Information
Incidents involving Data Maturity Assessment data specifically are governed by Data Orchard’s own privacy policy and Data Orchard’s contractual obligations to Blueprint, rather than by Section 11 of this Policy. Data Orchard is contractually required to notify Blueprint/the Project Partners promptly of any incident affecting DMA data, and the Initiative will then apply this Policy’s incident process.
12. Privacy Standards and Legal Requirements
The Initiative aims to follow recognized Canadian privacy principles, including accountability, identifying purposes, consent where appropriate, limiting collection, limiting use and retention, safeguards, openness, individual access, and complaint handling. The Project Partners will comply with privacy, confidentiality, electronic communication, and data-protection requirements that apply to their activities.
The Initiative is committed to protecting Personal Information and Project Information in accordance with applicable Canadian privacy laws and recognized privacy best practices. Where applicable, the Initiative follows the principles set out in the Personal Information Protection and Electronic Documents Act (PIPEDA) and complies with Canada’s Anti-Spam Legislation (CASL) for electronic communications and provincial privacy legislation where appropriate.
13. Policy Updates
This Privacy Policy may be updated from time to time to reflect changes to the Initiative, project partners, systems, applicable legal requirements, or information management practices. The most current version will be available on the Initiative website and will indicate the date it was last updated. Where appropriate, participants may also be notified of material changes.
14. Contact and Complaints
If you have any questions, requests, or concerns about this Privacy Policy or how your Personal Information or Project Information is collected, used, shared, or protected, please contact:
Blueprint-ADE
Privacy Contact: Alberta Johnson, Manager of Data Capacity
Email: ajohnson@blueprint-ade.ca
Phone: 647-956-1408
If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada or another applicable privacy regulator.
