UnionForge
Privacy Policy
How OPSEU Local 277 ("Peel Paramedic Union") collects, uses, and protects personal information in UnionForge.
Effective: July 21, 2026This policy describes how OPSEU Local 277 ("Peel Paramedic Union", "we", "us") handles personal information in UnionForge (the "Service").
1. Who we are
UnionForge is an internal web application operated by Peel Paramedic Union for authorized users. Access is invite only. The Service is intended for local union leaders of paramedic unions across Canada. It is not a public consumer service and is not intended for the general public.
2. Personal information we collect
Depending on how you use the Service, we may collect:
- Account information — email address, name, preferred name, password (stored as a one-way hash), role, Local affiliation, optional phone, pronouns, bio, position, and certification level
- Team roster contacts — names, emails, phones, and related details entered for Local team lists
- User-generated content — comments, peer-help messages, pulse posts, feedback, and free-text notes on grievances, labour orders, H&S orders, and related casework
- Documents — collective agreements, MOUs, grievance, labour-order, H&S-order, and rights/interest arbitration PDFs, and feedback screenshots uploaded to the Service. Uploaded casework documents and related records may contain member names and other identifying details that users choose to enter or upload
- Security and audit data — invite and password-reset tokens, event log entries (who did what and when), and optional web-push subscription details (endpoint keys and user agent)
- Usage data — technical and interaction information collected through analytics cookies when you consent to them, used to understand how the Service is used
Users should enter and upload only information that is appropriate for legitimate union operations.
3. How we use personal information
- Authenticate users and enforce role-based access
- Operate collective-agreement intelligence and casework workflows
- Send transactional email (invites, password resets, admin alerts)
- Deliver optional browser push notifications you enable
- Process document text with AI to extract clauses and wages and to generate briefings, subject to human review
- Analyse Service usage to improve reliability, usability, and operations
- Maintain security, audit trails, and service reliability
We do not sell personal information. We do not use it for third-party advertising.
4. Canadian privacy law
We handle personal information in the Service in accordance with applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) where it applies, and with our obligations as a union organization operating this internal tool. Member and casework information is treated as sensitive operational data: access is limited by role, and uploads and notes should be limited to what union work requires.
5. Third parties and processors
We rely on the following categories of service providers to operate the Service:
- Hosting — application, database, and uploaded files hosted on our infrastructure provider (currently Hostinger)
- AI processing — Google Gemini receives document text (and, where used, related excerpts) solely to support extraction, OCR, and briefing features; results are reviewed by humans before trusted categories are applied
- Email — transactional messages via SMTP (Hostinger mail)
- Web push — if you enable notifications, push delivery services (for example browser vendor push networks) receive the subscription endpoint needed to deliver messages
- Analytics — when you accept analytics cookies, usage data may be processed by analytics service providers acting on our instructions to measure and improve the Service
6. International transfers
The Service's application, database, and uploaded files are hosted in the United States. Document text processed through Google Gemini may be transmitted to and processed on Google's infrastructure, which may be located outside Canada. These transfers are necessary to operate the Service (hosting, AI-assisted extraction and briefings, and related infrastructure). We rely on our service providers' contractual and technical safeguards for the personal information they process on our behalf.
7. AI processing
Certain features use Google's generative AI API (Gemini) as a processor on our behalf. When you use document extraction, OCR, or AI-assisted briefing features, relevant document text or excerpts are sent to the API solely to provide those features. Outputs are subject to human review. Unrecognized categories are held in an admin Suggestions workflow and are not written directly into the trusted category taxonomy.
AI processing is purpose-limited to operating those features. Google processes such requests subject to Google's applicable API terms and privacy practices. We do not use Gemini to sell personal information or to serve third-party advertising.
8. Cookies and similar technologies
We use cookies and similar technologies to operate the Service, keep it secure, and—where you consent—measure how it is used. On your first visit you may choose Essential only or Accept all. Essential cookies are required for authentication, security, and display preferences and cannot be disabled while using the Service. Analytics cookies are set only if you choose Accept all. Theme preference is also kept in your browser's local storage and mirrored in essential cookies so the correct theme loads on first paint.
| Category | Purpose | Consent |
|---|---|---|
| Essential | Session, CSRF, and callback cookies used for sign-in and security; theme preset and light/dark mode so the correct appearance loads without a flash | Always active |
| Preferences | Theme preset and light/dark mode (local storage, mirrored in essential cookies) | Always active |
| Analytics | Measure usage and performance to improve the Service | Accept all |
Your choice is stored so we can honour it on return visits. Clearing site data in your browser will reset the consent prompt.
9. Retention
We retain account, casework, and document data for as long as needed for union operations, legal obligations, and dispute resolution, or until accounts and records are removed or anonymized by authorized administrators. Operational history (including case files and related discussion) may be retained longer than an individual login account where it remains necessary for Local records and continuity.
10. Account deletion — what is removed and what is kept
You may request deletion of your account by contacting us at the privacy email below or, if you are signed in, through in-app Feedback. Authorized administrators process deletion requests. In the Service, account deletion is an anonymization process designed so that removing a person's login identity does not break operational history or the user interface.
What is removed
- Account access ends (the account can no longer be used to sign in)
- Identifying profile fields on the account are scrubbed or replaced (for example, the display name becomes "Deleted user" and the email address is freed for reuse)
- Personal ephemera tied only to that login is permanently deleted, including notifications, watches, proposal-cart items, push subscription details, feedback votes and email mutes, and password-reset tokens for that user
What is kept
- Work product and collaboration history remain for operational continuity, including grievances, labour orders, H&S orders, comments, peer-help threads, pulse posts, feedback items and attachments, event logs, invites sent, and uploaded files
- Authorship of retained content is shown as "Deleted user" rather than under the former personal name
- Team roster entries are separate from login accounts: if a roster row was linked to the account, that link is cleared, but roster name/contact fields are not automatically erased and may need to be edited separately by authorized users
Deleting a user account therefore does not automatically erase casework records or uploaded documents (including grievances and related files that contain member names). Those records remain part of Local operational history unless separately removed by authorized administrators in the ordinary course of records management.
11. Security
We use access controls (including role-based permissions), encrypted transport (HTTPS), hashed passwords, and event logging to help protect the Service and the personal information it holds. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Your rights
Subject to applicable Canadian privacy law (including PIPEDA), you may request access to, or correction of, personal information we hold about you. Authorized users can update many profile fields in-app. You may also request account deletion as described above.
If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada or your provincial privacy commissioner.
13. Children
The Service is intended for local union leaders and invited users in connection with paramedic union work. It is not directed at children, and we do not knowingly collect personal information from children through the Service.
14. Contact
Privacy questions, access or correction requests, and account-deletion requests should be directed to:
Signed-in users may also use in-app Feedback to reach administrators.
15. Changes to this policy
We may update this Privacy Policy from time to time. The effective date at the top will change when we do. Continued use of the Service after an update constitutes acceptance of the revised policy.