Privacy Policy

At WRHN Foundation, we value your privacy and are committed to protecting your personal information with transparency, care, and respect.
This policy outlines how we collect, use, and safeguard your data.
This Privacy Policy will be reviewed regularly and updated as necessary to reflect changes in legislation, technology, or our practices.
Last updated: May 21, 2025
1. Our Commitment to Privacy
The Waterloo Regional Health Network Foundation (WRHN Foundation) is committed to protecting the privacy of all individuals with whom we interact—including donors, employees, volunteers, event participants, and website visitors. We value the trust placed in us and recognize that protecting personal information is essential to maintaining that trust. This Privacy Policy outlines how we collect, use, disclose, and safeguard personal information, both online and offline, in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and other applicable privacy legislation.
2. What Is Personal Information?
“Personal Information” is any information that can be used to identify, distinguish, or contact an individual. This includes names, contact details, opinions, donation history, and financial information. Business contact information and certain publicly available data are not considered personal information.
If an individual uses their personal contact information for business purposes, that contact information may be treated as business, not personal, information.
3. How We Collect Personal Information
a. Offline Interactions
WRHN Foundation collects personal information through donations, event registrations, direct communications, employment or volunteer applications, and surveys.
This may include:
  • Name, address, email, phone number
  • Donation history and preferences
  • Employment or volunteer records
  • Communication and consent preferences
b. Online Interactions (wrhnf.ca and related platforms)
When you visit our website or make a donation or purchase online, we may automatically collect information such as:
  • Device and browser details (IP address, time zone, cookies)
  • Pages visited and referral sources
  • Payment and order information (if a transaction is made)
We use tools like cookies, log files, pixels, and analytics services (e.g., Google Analytics and Shopify) to improve the performance and security of our site.
4. Use of Personal Information
We use personal information to:
  • Process donations and issue tax receipts
  • Communicate with donors and supporters
  • Share updates, campaigns, and opportunities to engage
  • Manage employment and volunteer records
  • Fulfill online purchases (including payment processing and confirmations)
  • Comply with legal and regulatory obligations
  • Enhance our website experience and digital engagement
We will only use personal information for the purposes originally identified or as required by law. If a new purpose arises, we will notify individuals and obtain consent where necessary.
5. Consent
We collect, use, and disclose personal information only with informed, meaningful consent. This consent may be expressed verbally, in writing, electronically, or implied based on the context.
  • All solicitation of former patients includes a clear opt-out mechanism
  • Donor lists are published only with explicit consent
Visitors may withdraw consent at any time, subject to legal or contractual limitations, by contacting us.
6. Third-Party Service Providers
We work with trusted third-party vendors to support functions such as direct mailings, data processing, and online commerce.
  • These partners are required to sign confidentiality agreements and are only provided with the minimum data necessary
  • All data shared is encrypted and destroyed upon project completion
  • We do not rent, sell, or trade personal information with other organizations
7. Safeguards and Security
We employ both physical and electronic safeguards to protect personal information from unauthorized access, loss, or misuse:
  • Locked filing systems for physical records
  • Password-protected and encrypted databases
  • Secure sockets layer (SSL) protection for online transactions
  • Regular system reviews and staff confidentiality agreements
WRHN Foundation is integrated with hospital network infrastructure, including firewalls and internal security protocols.
8. Access and Accuracy
Individuals may request access to their personal information at any time and may request corrections to ensure accuracy and completeness. We will respond to such requests within 30 days, free of charge or at minimal cost.
9. Retention and Destruction
We retain personal information only as long as necessary to fulfill the purposes it was collected for, or as required by law. When no longer needed, information is securely deleted (digital) or shredded (paper).
10. Your Rights and Choices 
You always have the right to:
  • Access the personal data we hold about you
  • Request correction, updating, or deletion
  • Withdraw consent at any time
  • Request data portability or restriction of processing
To exercise these rights, please contact us directly.
11. Guest Wi-Fi Usage
When accessing our guest Wi-Fi network, users may provide personal information (e.g., name, email). This data may be securely shared with the Waterloo Regional Health Network (WRHN) for operational purposes. By connecting to the Wi-Fi, you consent to this use.
12. Challenging Compliance or Making a Complaint
If you have questions, concerns, or wish to challenge our privacy practices, please contact us directly. Valid concerns will be addressed and may result in changes to our practices.