Redpath Mining Inc. – Global Privacy Policy 

NOTICE NAME: Global Privacy Policy
DATE: June 2023 
VERSION: 2.0 
OWNER: Compliance Officer 

Purpose of document and location to post content 

This Privacy Policy is a public statement that explains how Redpath Group manages personal data and how it applies data protection principles on its external website to website visitor personal information (including but not limited to job applicant personal information and customer information for purchasing a product or service) and to any other personal information (excluding personal information of Redpath's employees, for which a specific Employee Privacy Policy exists). A Privacy Statement posted on an external website is an important way to help Redpath Group to inform individuals about the data that the organization is collecting, using and disclosing.

Please note, Redpath can inform website visitors of the purpose of the cookies up front, after which they must affirmatively opt in to all categories as part of their prior consent, before those cookies can be activated. Redpath may require a separate Cookie Policy for the use of Google Analytics (Reference: https://www.termsfeed.com/blog/cookies-policy-google-analytics)

Redpath Privacy Policy

Introduction

Redpath Group is committed to protecting your privacy. This privacy policy describes why and how we collect, use and share personal data from individuals, and provides information about individuals’ rights with respect to their personal data. We may use personal data provided to us for any of the purposes described in the relevant section of this privacy statement or as otherwise stated at the point of collection.

Please review this privacy policy carefully. By submitting your personal data to us, by registering for or using any of the services we offer, by using our website, or by voluntarily interacting with us, you consent to our collecting, using and disclosing your personal information as set out in this privacy policy, as revised from time to time.

What does Redpath Group consider personal data?

Personal data is any data which is related to an identified or identifiable natural person. The data subjects are identifiable if they can be directly or indirectly identified, especially by reference to an identifier such as a name, an identification number, location data, an online identifier or one of several special characteristics, which expresses the physical, physiological, genetic, mental, 
commercial, cultural or social identity of these natural persons. 

What kind of Personal Data does Redpath collect?

We collect personal information when you contact or communicate with us by phone, mail, e-mail or via our website. When you access, visit or use our website, we can collect the following information:

  • When you register to build a profile to apply for jobs, we can collect your email address, password, your curriculum vitae and any other information you disclose to use.
  • When you log on to access to your account, we collect your email and your password.
  • When you wish to contact us through the online form for a project, we collect your name, phone number, region of residence, email address and any other information you provide to us.
  • Information we automatically collect: Like most websites and other internet services, we may collect certain technical and device information about your use of our website. Such information may include your internet protocol address, information about your device, browser and operating system, and the date and time of your visit.

What are the purposes for the collection, use and disclosure of your personal data?

Redpath Group will process your personal data for the following reasons: 

  • Applying for a job or requesting a service/product. Applicable legal basis under General Data Protection Regulation (“GDPR”): consent
  • For recruitment purposes. Applicable legal basis under GDPR: performance of a contract or a service
  • For completing a service and purchasing a product: Applicable legal basis under GDPR: performance of a contract or a service
  • To deal with inquiries or requests linked to a service or a product, or for one-time or ongoing communications from Redpath Group: Applicable legal basis under GDPR: performance of a contract or a service
  • Monitoring and enhancing the security of our website and other systems to which it may connect, our premises and our assets: Applicable legal basis under GDPR: legitimate interest of Redpath Group
  • Other purposes for which we have obtained your consent, and for such other purposes as may be permitted or required by applicable law.

If you have given Redpath Group consent, you may, at any time, withdraw your consent by contacting Redpath Group as set out below, subject to our retention policies and our legal obligations. In some cases, withdrawal of your consent may result in Redpath Group being unable to provide you with a particular service or product (including but not limited to customer support for sales and consideration of a job application). 

With whom do we share your personal data?

Redpath Group may share your personal data with third parties to assist Redpath Group to administer activities on the website (such as maintenance), to our auditors or other professional advisors, or otherwise for service promotions. Redpath Group may also share personal data with service providers to assist in aggregating personal data. If you have provided Redpath Group with your personal data, that personal data will not be sold.

More specifically, when we engage service providers who manage data on our behalf and/or perform services on our behalf, we will share your personal data with such service providers under the requirement that such personal data is used only to provide services to us. For example, we may engage service providers (i) to outsource the processing of certain interactive website functions such as hosting/infrastructure/storage providers; or (ii) to analyze the website.

If we provide your information to service providers, then we require that the service providers maintain the confidentiality of your personal information and keep your personal information secure. When our service providers no longer need your personal information for those limited purposes, we require that they dispose of the personal information. In some circumstances, we may permit our service providers to retain aggregated, anonymized or statistical information that does not identify you. We do not authorize the service providers to disclose your personal information to unauthorized parties or to use your personal information for their direct marketing purposes. If you would like more information about our service providers, please contact us using the contact information in the "Contacting us about your privacy" section below. Additionally, we may use and disclose your personal information when we believe such use or disclosure is permitted, necessary or appropriate: 

  • under applicable law, including laws outside your country of residence;
  • to comply with legal process;
  • to respond to requests from public and government authorities, including public and government authorities outside your country of residence;
  • to enforce the terms of the agreements for our products and services;
  • to protect our operations or those of any of our affiliates or subsidiaries;
  • to protect our rights, privacy, safety or property, and/or those of our affiliates, you or others; and
  • to allow us to pursue available remedies or limit the damages that we may sustain. 

In addition, we may transfer your personal information and other information to a third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, brands, affiliates, subsidiaries or other assets.

If we intend to disclose your personal information to another type of third party, we will identify that third party and the purpose for the disclosure, and obtain your consent. 

Where is your personal data located?

Your personal data may be stored and processed in any country where we have facilities or in which we engage third party service providers, such as Canada, United States, South Africa and the European Union. As a result, your personal information may be transferred to countries outside your country, state, or province of residence, which may have different data protection rules than in your country, state, or province of residence. While such information is outside of your country, it is subject to the laws of the country, state, or province in which it is located, and may be subject to disclosure to the governments, courts or law enforcement or regulatory agencies of such other country, pursuant to the laws of such country. However, we will ensure that there are adequate safeguards in place to protect your personal data that comply with our legal obligations and our practices regarding your personal information will at all times continue to be governed by this privacy policy and by applicable laws.

Further details of the transfers described above and the adequate safeguards used by Redpath Group in respect of such transfers are also available from us by contacting privacy@redpathmining.com

Does Redpath Group use cookies?

Redpath Group uses cookies and other tracking technologies to collect and analyze statistics relating to this website. Cookies are small data files transferred to your computer's hard-drive by a website. They keep a record of your preferences, making your subsequent visits to the site more efficient. We may also use them, with your consent, to identify you for purposes such as managing your preferences, locating or profiling purposes. Data used for analytics may be processed by an organization external to Redpath Group. Examples of tracking include the number and frequency of visits, the average length of visits and which pages are viewed during a visit as well as the types of browsers and the Internet Protocol Addresses of visitors' computers.

Cookies or similar technologies may be stored locally on mobile devices or on computer servers operated or controlled by our third-party service providers. In addition, when you visit our website, our systems automatically collect your IP address and the type of browser that you use. We may employ third party service providers to place advertisements about our products, services and applications on other websites. The use of cookies or other similar technologies by such third parties is governed by their privacy policies. You may limit the automatic collection of certain information on our website by deciding not to activate the cookies using your browser options. Please be aware that disabling cookies may prevent you from using specific features on our website. We may use cookies and log files to track user information. For more information, please refer to the Cookies Policy.

How long does Redpath Group retain your data?

Redpath Group is subject to a wide variety of laws regulating its business. Redpath Group complies with its obligations by enforcing its regional Data Retention Policies, and retaining personal data required to meet region-specific obligations, until the regional legal obligation to retain personal data no longer exists or there is no other valid business purpose for retention of the personal data, at which time Redpath Group will dispose of such information securely in accordance with its Data Retention Policy and regional retention requirements to comply with local legislation.

Data subject rights

You may request details of personal data which we hold about you. If you would like a copy of your personal data, please write to the contact address below. If you believe that any personal data, we are holding on you is incorrect or incomplete, please contact us as soon as possible, as outlined below. We will promptly correct any personal data found to be incorrect.

In situations where this applies, you may have additional rights, including the following: 

  1. The right to withdraw consent to processing where processing is based on consent;
  2. The right to object to the unlawful processing of personal data, under certain conditions;
  3. The right to have your personal data erased or deleted, subject to certain conditions;
  4. The right to request a restriction of the processing of personal data, under certain conditions, for example, if you believe that Redpath Group has exceeded the legitimate basis for the processing, that the processing is no longer necessary, or that the personal data is inaccurate;
  5. The right to data portability or transferability of personal data in a structured, commonly used and machine-readable format, under certain conditions; and
  6. The right to object to decisions made by automated means that have legal effect on you or similarly affect you significantly, under certain conditions.

To exercise any of these rights, please contact us by following the instructions provided in the "Contacting us about your privacy?" section.

Redpath Group is entitled to refuse access to your personal data in certain situations as provided by Applicable Privacy Laws.

If you have any complaints regarding Redpath Group’s privacy practices, you may have the right to lodge a complaint with the appropriate national data protection authority. 

How does Redpath Group protect your personal data?

Redpath Group is committed to ensuring that your personal data is secure. In order to prevent unauthorized access or disclosure, we have put in place appropriate technical and organizational measures to safeguard and secure the personal data we process. We have also taken steps to ensure that the only personnel who are granted access to your personal information are those with a business 'need-to-know' or whose duties reasonably require such information. Redpath Group exercises care in the secure transmission of your personal data to international countries; however, no transmission of data over the Internet is completely secure. Redpath Group cannot guarantee that data disclosed through the Internet cannot be intercepted by malicious third parties. However, Redpath Group has taken the steps that are reasonably available to Redpath Group to protect any personal data that you have provided to us, including, in its disposal or destruction in due course.

If, despite all our efforts, a data breach does occur, Redpath Group shall do everything in its power to limit the damage. In case of a data breach which is likely to result in a high risk of harm, and depending on the circumstances, we will inform you about remedial actions to prevent any further damage. We always inform the relevant supervisory authority or authorities without undue delay.

Contacting us about your privacy

If you have any questions regarding our privacy practices, please contact: 
Chief Compliance Officer and Privacy Officer
email: privacy@redpathmining.com

We may change this Privacy Notice when it is appropriate to do so, such as when there are changes to legislative requirements. 
Policy History/Revision Dates 
Origination Date: June 2021 
Last Amended Date: June 2023 

READ GLOBAL PRIVACY POLICY