{"id":3684,"date":"2025-08-11T16:12:00","date_gmt":"2025-08-11T20:12:00","guid":{"rendered":"https:\/\/grandio.com\/?page_id=3684"},"modified":"2025-08-13T07:54:14","modified_gmt":"2025-08-13T11:54:14","slug":"privacy-policy","status":"publish","type":"page","link":"https:\/\/grandio.com\/en\/privacy-policy\/","title":{"rendered":"Personal data protection framework policy"},"content":{"rendered":"\n<p>Groupe Grandio<\/p>\n\n\n\n<p>Personal Information Protection Program<\/p>\n\n\n\n<p>Last revised: May 13, 2025<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">1. PREAMBLE<\/h2>\n\n\n\n<p>In the course of their activities, Groupe Grandio (13401537 Canada Inc., hereinafter the \u201cParent Company\u201d), its subsidiaries, affiliated companies, and groups of companies (collectively, \u201cGrandio\u201d) process personal data, including that of their restaurants\u2019 guests, visitors to their websites and apps, loyalty program members, employees, as well as directors and executives. As such, Grandio understands the importance of respecting privacy and protecting the personal data it holds.<\/p>\n\n\n\n<p>To fulfill its obligations under Qu\u00e9bec\u2019s Private Sector Privacy Act, Grandio has adopted the following policy. It outlines the guiding principles applicable to the protection of personal data throughout its lifecycle, the rights of individuals, and the roles of stakeholders in implementing the law at Grandio.<\/p>\n\n\n\n<p>This policy completes the Data Security and Cybersecurity Policy regarding the protection of personal data.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">2. PURPOSE<\/h2>\n\n\n\n<p>This policy:\u00a0<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Outlines the Documentary Framework that applies to personal data held by Grandio;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Establishes Grandio\u2019s principles and governance rules regarding personal data throughout its lifecycle;\u00a0<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Defines the roles and responsibilities of stakeholders in protecting personal data;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Describes the training and awareness-raising activities Grandio provides to its personnel.<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">3. SCOPE<\/h2>\n\n\n\n<p>This policy applies to personal information collected or held by the Parent Company and any affiliated company or group of companies that holds personal data in the frame of its activities. It applies to any person processing personal data on behalf of these companies. When the Parent Company acquires a new company, the latter must implement the personal data protection program no later than six months following the completion of the transaction, with support from the Privacy Protection Committee, if required.<\/p>\n\n\n\n<p>The Parent Company, affiliated companies, and groups of companies include, but are not limited to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>13401537 Canada inc.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Groupe Sportscene inc. et 13668843 Canada inc. (les restaurants La Cage \u2013 Brasserie sportive)<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Restaurants Chez Lionel (Qu\u00e9bec) inc. (les restaurants Chez Lionel \u2013 Brasserie fran\u00e7aise)<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Restaurants IRU (Qu\u00e9bec) inc. (les restaurants IRU Izakaya \u2013 Brasserie japonaise)<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Le Groupe Restos Plaisirs inc. (notamment les restaurants Cochon Dingue, Le Ciel!, Lapin Saut\u00e9, Paris Grill et Caf\u00e9 du Monde)<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>121657245 Canada inc. (le restaurant Moishes)<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>14707923 Canada inc. (le restaurant Gibbys)<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Niji Sushi Bar et Restaurant inc. (les restaurants Niji Sushi)<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>16096018 Canada inc. (les restaurant Il Teatro \u2013 Brasserie Italienne)<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>15679249 Canada inc. (les restaurants Brasseurs du Monde)<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Brasseurs du Monde inc. (la micro-brasserie)<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li>9246-9394 Qu\u00e9bec inc. (La Cage \u2013 Traiteur \u00e9v\u00e8nementiel)<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p>This list is not exhaustive.<\/p>\n\n\n\n<p>Compliance with this policy is mandatory, and Grandio is committed to upholding it.&nbsp;<\/p>\n\n\n\n<p>Any request for an exemption from this policy must be duly justified and submitted to the Privacy Officer for approval, and communicated to the Board of Directors of the Parent Company by the Privacy Officer. A request for an exemption is submitted and processed in accordance with Grandio\u2019s documentary framework, where applicable.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">4. DOCUMENTARY FRAMEWORK<\/h2>\n\n\n\n<p>This policy is the foundational document for Grandio\u2019s compliance program for personal data protection, from which other policies, guidelines, procedures, or documents may derive, covering topics such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Procedures for handling and processing exemption requests;\u00a0<\/li>\n\n\n\n<li>Obtaining valid consent;\u00a0<\/li>\n\n\n\n<li>Conducting privacy impact assessments;\u00a0<\/li>\n\n\n\n<li>Communication between Grandio entities;\u00a0<\/li>\n\n\n\n<li>Disclosure to third parties without consent;\u00a0<\/li>\n\n\n\n<li>Disclosure of personal information outside Quebec;\u00a0<\/li>\n\n\n\n<li>Exercise of individuals\u2019 rights;\u00a0<\/li>\n\n\n\n<li>Retention, archiving, or destruction;\u00a0<\/li>\n\n\n\n<li>Handling of individual complaints.<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<p>Grandio\u2019s compliance program is based on a documentary framework defined as follows:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Framework Policy: Outlines Grandio\u2019s guiding principles for personal data protection and the approval mechanism for documents forming Grandio\u2019s documentary framework.<\/li>\n\n\n\n<li>Internal Policy or Directive: Documents the guiding principles, requirements, and expectations concerning a specific topic, i.e., \u201cwhat to do.\u201d<\/li>\n\n\n\n<li>Procedure, Guide, or Process: Provide a detailed sequence of steps or actions required to implement internal policies or directives, i.e., \u201chow to do it\u201d.\u00a0<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">5. DEFINITIONS<\/h2>\n\n\n\n<p>For the purposes of this policy, the following terms mean:<\/p>\n\n\n\n<p>\u201cJust-in-time notice\u201d: The transparency notice provided to an individual when their personal data is requested.&nbsp;<\/p>\n\n\n\n<p>\u201cDocumentary Framework\u201d: The set of legal governance documents adopted under this policy to implement Grandio\u2019s personal data protection program.&nbsp;<\/p>\n\n\n\n<p>\u201cCAI\u201d: The Commission d\u2019acc\u00e8s \u00e0 l\u2019information du Qu\u00e9bec.&nbsp;<\/p>\n\n\n\n<p>\u201cPrivacy Protection Committee\u201d: The committee established by the Parent Company to ensure compliance with and implementation of personal data protection laws.&nbsp;<\/p>\n\n\n\n<p>\u201cProfessional contact details\u201d: Personal data relating to the performance of a role within a company, such as name, title, position, and the postal address, email address, and telephone number of the workplace.&nbsp;<\/p>\n\n\n\n<p>\u201cLife\u201d: The set of stages involved in processing personal data, including collection, use, disclosure, retention, and destruction.&nbsp;<\/p>\n\n\n\n<p>\u201cPrivacy Impact Assessment (PIA)\u201d: The process aimed at protecting personal data and respecting personal privacy. It is a form of impact analysis, evolves over time, and must be reviewed throughout the project.&nbsp;<\/p>\n\n\n\n<p>\u201cPrivacy incident\u201d: Any unauthorized access, use, or disclosure of personal data under the law, or any loss or other breach of its protection.&nbsp;<\/p>\n\n\n\n<p>\u201cLaw\u201d: The Private Sector Privacy Act (Quebec) and any regulations arising from it.&nbsp;<\/p>\n\n\n\n<p>\u201cData Subject\u201d: A natural person to whom the personal data relates.&nbsp;<\/p>\n\n\n\n<p>\u201cPresident and Chief Executive Officer of the Parent Company\u201d: The person with the highest authority within the parent company.&nbsp;<\/p>\n\n\n\n<p>\u201cProfiling\u201d: The collection and use of personal data to assess an individual\u2019s characteristics, especially for analyzing work performance, economic situation, health, personal preferences, interests, or behavior.&nbsp;<\/p>\n\n\n\n<p>\u201cPersonal data\u201d: Any data relating to an individual that allows them to be identified directly through that data alone or indirectly by combining it with other data.&nbsp;<\/p>\n\n\n\n<p>\u201cPublicly available personal data\u201d: Personal data declared public by any applicable law.&nbsp;<\/p>\n\n\n\n<p>\u201cSensitive personal data\u201d: Personal data which, due to its nature (e.g., medical, biometric, or otherwise personal) or the manner in which it is used or disclosed, gives rise to a high reasonable expectation of privacy.&nbsp; \u201cPrivacy Officer\u201d: The person in the Parent Company and each of its subsidiaries and affiliated companies who ensures compliance with and the implementation of personal data protection laws.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">6. GUIDING PRINCIPLES<\/h2>\n\n\n\n<p>Personal data is protected throughout its lifecycle in accordance with the following principles, except as provided for by law. Professional contact details and publicly available personal data are not subject to these guiding principles<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6.1. Collection<\/h3>\n\n\n\n<p>6.1.1. Grandio collects only the personal data required for its activities. Before collecting personal data, Grandio determines the purposes of its processing.<\/p>\n\n\n\n<p>6.1.2. At the time of collection, and subsequently upon request, Grandio informs individuals of the mandatory content required by law, including the purposes of collection, the use of technologies enabling profiling (if applicable), and the right to withdraw consent to the use or disclosure of personal data by Grandio.<\/p>\n\n\n\n<p>6.1.3. The information referred to in paragraph 6.1.2 is provided in clear and simple terms through a privacy policy or a just-in-time notice.<\/p>\n\n\n\n<p>6.1.4. An individual who provides their personal data after receiving the information in paragraph 6.1.2 is presumed to consent to its use and disclosure for the stated purposes.&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6.2. Use<\/h3>\n\n\n\n<p>6.2.1. Grandio uses personal data only for the purposes for which it was collected. However, Grandio may modify these purposes with the individual\u2019s prior consent.<\/p>\n\n\n\n<p>6.2.2. It may also use the data for other purposes without the individual\u2019s consent in cases permitted by law.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6.3. Disclosure<\/h3>\n\n\n\n<p>6.3.1. Subject to exceptions provided for by law, Grandio may not disclose any personal data without the individual\u2019s consent.&nbsp;<\/p>\n\n\n\n<p>6.3.2. When personal data is disclosed outside Quebec, Grandio conducts a Privacy Impact Assessment (PIA) in accordance with section 7 of this policy.<\/p>\n\n\n\n<p>6.3.3. Grandio maintains a register of any disclosures of personal data without consent. The register records disclosures required by law, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>To a person or organization with the authority to compel Grandio to disclose personal data and who requests it in the course of their duties (e.g., a police officer with a warrant requesting personal data about an employee suspected of fraud);\u00a0<\/li>\n\n\n\n<li>To a person to whom disclosure is required due to an emergency endangering the individual\u2019s life, health, or safety;\u00a0<\/li>\n\n\n\n<li>To a person or organization for the purposes of a mandate or service or business contract (e.g., a payroll service provider);\u00a0<\/li>\n\n\n\n<li>To the other party in a business transaction, if the disclosure is necessary to conclude the transaction (e.g., Grandio sells a subsidiary and must disclose personal data for this purpose);\u00a0<\/li>\n\n\n\n<li>To a person who may use it for study, research, or statistical purposes;\u00a0<\/li>\n\n\n\n<li>To a person authorized by law to collect debts on behalf of others and who requires it for that purpose in the course of their duties;\u00a0<\/li>\n\n\n\n<li>To a person if the information is required to collect a debt owed to Grandio.<br><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">6.4. Retention<\/h3>\n\n\n\n<p>6.4.1. Grandio takes all reasonable measures to ensure that the personal data it holds is up-to-date, accurate, and complete for the purposes for which it is collected or used.<\/p>\n\n\n\n<p>6.4.2. Grandio retains personal data for as long as required to fulfill the purposes for which it was collected, subject to any applicable retention obligations, in accordance with Grandio\u2019s retention schedule.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">6.5. Destruction or Anonymization<\/h3>\n\n\n\n<p>6.5.1. When the purposes for which the personal data was collected are achieved, the information is destroyed or, in some cases, anonymized in accordance with Grandio\u2019s retention schedule and, where applicable, Grandio\u2019s documentary framework.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">7. PRIVACY IMPACT ASSESSMENTS<\/h2>\n\n\n\n<p>7.1. Conducting a Privacy Impact Assessment (PIA) is a process that helps demonstrate that Grandio has met all its obligations regarding the protection of personal data and that all appropriate measures have been taken to effectively protect such data.<\/p>\n\n\n\n<p>7.2. Grandio conducts a PIA, particularly in the following cases:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Before undertaking a project to acquire, develop, or redesign an information system or electronic services product involving personal data;\u00a0<\/li>\n\n\n\n<li>Before disclosing personal data without the consent of individuals to a person or organization wishing to use it for study, research, or statistical purposes;\u00a0<\/li>\n\n\n\n<li>Before disclosing personal data outside Quebec.<br><\/li>\n<\/ul>\n\n\n\n<p>7.3. When conducting a PIA, Grandio considers the sensitivity of the information to be processed, the purposes of its use, its quantity, distribution, and medium (or storage medium), as well as the proportionality of the measures proposed to protect personal data. Grandio also considers the criteria established by law for each PIA.<\/p>\n\n\n\n<p>7.4. All PIAs are conducted in accordance with Grandio\u2019s documentary framework.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">8. RIGHTS OF DATA SUBJECTS<\/h2>\n\n\n\n<p>8.1. At the request of a data subject, Grandio must inform them of:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The personal data collected from them;\u00a0<\/li>\n\n\n\n<li>The categories of persons within Grandio who have access to this data;\u00a0<\/li>\n\n\n\n<li>The retention period for this data;\u00a0<\/li>\n\n\n\n<li>The contact details of Grandio\u2019s Privacy Officer.<br><\/li>\n<\/ul>\n\n\n\n<p>8.2. To the extent provided by law, any data subject about whom Grandio holds personal data has the following rights:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The right to withdraw consent to the use and disclosure of personal data collected by Grandio;\u00a0<\/li>\n\n\n\n<li>The right to access personal data held by Grandio and obtain a copy in an electronic or other format;\u00a0<\/li>\n\n\n\n<li>Unless it poses significant practical difficulties, at the request of a data subject, Grandio shall communicate computerized personal data collected from them in a structured, commonly used technological format;\u00a0<\/li>\n\n\n\n<li>The right to have incomplete or inaccurate personal data held by Grandio rectified;\u00a0<\/li>\n\n\n\n<li>The right to request the deletion of data in certain circumstances or to submit written comments to Grandio;\u00a0<\/li>\n\n\n\n<li>The right to be informed, where applicable, that personal data is used to make a decision based on fully automated processing;\u00a0<\/li>\n\n\n\n<li>The right to request that Grandio cease disseminating data or de-index any hyperlink associated with their name, under certain conditions.<br><\/li>\n<\/ul>\n\n\n\n<p>8.3. The Privacy Officer shall respond in writing to requests to exercise the rights outlined in paragraph 8.1 promptly and, in any case, no later than 30 days from the date of receipt of the request.<\/p>\n\n\n\n<p>8.4. Any request to exercise rights is handled in accordance with Grandio\u2019s documentary framework. conform\u00e9ment au cadre documentaire de Grandio.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">9. PERSONAL DATA SECURITY<\/h2>\n\n\n\n<p>9.1. Grandio implements reasonable security measures to ensure the confidentiality, integrity, and availability of personal data collected, used, disclosed, retained, or destroyed. These measures take into account the sensitivity of the data, the purpose of its collection, and its quantity, location, and medium.\u00a0<\/p>\n\n\n\n<p>9.2. Grandio manages its personnel\u2019s access rights to ensure that only personnel subject to a confidentiality agreement (where applicable) and requiring access to it to perform their duties have access to personal data.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">10. PRIVACY INCIDENT<\/h2>\n\n\n\n<p>10.1. Any privacy incident is handled in accordance with Grandio\u2019s documentary framework.<\/p>\n\n\n\n<p>10.2. In accordance with the law, Grandio maintains a privacy incident register.<\/p>\n\n\n\n<p>10.3. If a privacy incident poses a risk of serious harm to individuals, Grandio promptly notifies them and the CAI.<\/p>\n\n\n\n<p>10.4. The register is maintained for five years following the date of the last incident or the end of the period of the last incident.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">11. TRAINING AND AWARENESS-RAISING ACTIVITIES<\/h2>\n\n\n\n<p>11.1. Grandio provides training and awareness-raising activities to its personnel regarding personal data protection.\u00a0<\/p>\n\n\n\n<p>11.2. Failure to complete the required training and awareness-raising activities violates Grandio\u2019s documentary framework, and individuals may face sanctions depending on the nature and severity of the violation.des sanctions.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">12. ROLES AND RESPONSIBILITIES<\/h2>\n\n\n\n<p>12.1. The protection of personal data held by Grandio relies on the commitment of all those who process such data, particularly the following stakeholders:<\/p>\n\n\n\n<p>12.2. President and Chief Executive Officer:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ensures compliance with the law and its implementation;<\/li>\n\n\n\n<li>Ensures that the Privacy Officer is provided with adequate resources to fulfill their mandate and implement Grandio\u2019s personal data protection program.<br><\/li>\n<\/ul>\n\n\n\n<p>12.3. Board of Directors of the Parent Company:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Approves this policy and any significant amendments thereto, based on the Privacy Officer\u2019s recommendation;<\/li>\n\n\n\n<li>Receives and reviews the Privacy Officer\u2019s report;<\/li>\n\n\n\n<li>Is informed of Grandio\u2019s personal data protection activities and takes appropriate actions to maintain an acceptable level of risk for Grandio.<br><\/li>\n<\/ul>\n\n\n\n<p>12.4. Privacy Protection Committee:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Approves this policy and all documents forming Grandio\u2019s documentary framework, as well as any significant amendments, based on the Privacy Officer\u2019s recommendation;\u00a0<\/li>\n\n\n\n<li>Receives and reviews any issues related to personal data protection submitted by the Privacy Officer.<br><\/li>\n<\/ul>\n\n\n\n<p>12.5. Privacy Officer:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ensures compliance with the law and its implementation across Grandio;\u00a0<\/li>\n\n\n\n<li>Is responsible for the application and implementation of this policy and other documents forming Grandio\u2019s documentary framework;\u00a0<\/li>\n\n\n\n<li>Designs Grandio\u2019s documentary framework and makes appropriate updates;\u00a0<\/li>\n\n\n\n<li>Recommends to the Board of Directors of the Parent Company any documents related to the personal data protection program or any issues deemed appropriate;\u00a0<\/li>\n\n\n\n<li>Supports the Parent Company\u2019s teams, as well as affiliated companies and groups, in implementing the program, including acting as a point of contact for associated questions;<\/li>\n\n\n\n<li>Where necessary, produces a report on activities related to Grandio\u2019s personal data protection program and submits it to the Board of Directors of the Parent Company as part of the quarterly risk management report;\u00a0<\/li>\n\n\n\n<li>Oversees the coordination of the Privacy Protection Committee\u2019s response to a privacy incident and the maintenance of the privacy incident register;\u00a0<\/li>\n\n\n\n<li>Receives and processes data subjects\u2019 rights requests and ensures that responses comply with Grandio\u2019s documentary framework;\u00a0<\/li>\n\n\n\n<li>Is consulted from the outset of Privacy Impact Assessments (PIAs) and may suggest measures to mitigate personal data protection risks.<br><\/li>\n<\/ul>\n\n\n\n<p>12.6. Any person processing personal data on behalf of Grandio:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Acts with caution and integrates the principles and guidelines set out in the documentary framework into their activities;\u00a0<\/li>\n\n\n\n<li>When collecting personal data from individuals, ensures consent is obtained in accordance with the law and documented as per the documentary framework;\u00a0<\/li>\n\n\n\n<li>Accesses only the data required to perform their duties;\u00a0<\/li>\n\n\n\n<li>Stores records in a manner that restricts access to authorized persons only;\u00a0<\/li>\n\n\n\n<li>Must refrain from disclosing personal data obtained in the course of their duties unless duly authorized;\u00a0<\/li>\n\n\n\n<li>Must not retain personal data after the end of their employment or contract and must comply with their confidentiality obligations;\u00a0<\/li>\n\n\n\n<li>Retains and destroys personal data in accordance with Grandio\u2019s documentary framework;\u00a0<\/li>\n\n\n\n<li>Participates in personal data protection awareness-raising and training activities intended for them;\u00a0<\/li>\n\n\n\n<li>Identifies situations requiring a PIA and completes the appropriate documentary framework documents;<\/li>\n\n\n\n<li>Immediately reports any breach, privacy incident, or other situation or irregularity that could compromise the security, integrity, or confidentiality of personal data to the Privacy Officer;<\/li>\n\n\n\n<li>Immediately reports any request to exercise rights or complaints regarding Grandio\u2019s personal data protection practices to the Privacy Officer.<br><\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">13. COMPLAINT MANAGEMENT<\/h2>\n\n\n\n<p>Any complaint regarding Grandio\u2019s personal data protection practices or compliance with legal requirements concerning personal data is forwarded to the Privacy Officer, who shall respond within thirty (30) days.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">14. SANCTIONS<\/h2>\n\n\n\n<p>Compliance with this policy and all other documents forming the governance framework is mandatory across Grandio. Personnel who fail to comply may face disciplinary measures ranging from a disciplinary notice to termination or, for consultants, contractual sanctions and penalties, which may include, among other things, contract termination and claims for damages. Additional training and awareness-raising may also be provided in cases of non-compliance.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">15. REVIEW<\/h2>\n\n\n\n<p>To keep pace with changes in applicable personal data protection laws and to improve Grandio\u2019s personal data protection program, this policy may be updated as needed, at least every three years.\u00a0<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">16. RESPONSIBILITY<\/h2>\n\n\n\n<p>This policy is the responsibility of the Privacy Officer.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">17. ENTRY INTO FORCE<\/h2>\n\n\n\n<p>This policy comes into force upon its adoption by the Board of Directors of the Parent Company, based on the Privacy Officer\u2019s recommendation.<\/p>\n\n\n\n<p>Effective Date: March 28, 2024.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Groupe Grandio Personal Information Protection Program Last revised: May 13, 2025 1. PREAMBLE In the course of their activities, Groupe Grandio (13401537 Canada Inc., hereinafter the \u201cParent Company\u201d), its subsidiaries, affiliated companies, and groups of companies (collectively, \u201cGrandio\u201d) process personal data, including that of their restaurants\u2019 guests, visitors to their websites and apps, loyalty program [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-3684","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.2 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Personal data protection framework policy - Grandio<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/grandio.com\/politique-de-confidentialite\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Personal data protection framework policy - Grandio\" \/>\n<meta property=\"og:description\" content=\"Groupe Grandio Personal Information Protection Program Last revised: May 13, 2025 1. PREAMBLE In the course of their activities, Groupe Grandio (13401537 Canada Inc., hereinafter the \u201cParent Company\u201d), its subsidiaries, affiliated companies, and groups of companies (collectively, \u201cGrandio\u201d) process personal data, including that of their restaurants\u2019 guests, visitors to their websites and apps, loyalty program [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/grandio.com\/politique-de-confidentialite\/\" \/>\n<meta property=\"og:site_name\" content=\"Grandio\" \/>\n<meta property=\"article:modified_time\" content=\"2025-08-13T11:54:14+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"15 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/grandio.com\/politique-de-confidentialite\/\",\"url\":\"https:\/\/grandio.com\/politique-de-confidentialite\/\",\"name\":\"Personal data protection framework policy - Grandio\",\"isPartOf\":{\"@id\":\"https:\/\/grandio.com\/en\/#website\"},\"datePublished\":\"2025-08-11T20:12:00+00:00\",\"dateModified\":\"2025-08-13T11:54:14+00:00\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/grandio.com\/politique-de-confidentialite\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/grandio.com\/en\/#website\",\"url\":\"https:\/\/grandio.com\/en\/\",\"name\":\"Grandio\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/grandio.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Personal data protection framework policy - Grandio","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/grandio.com\/politique-de-confidentialite\/","og_locale":"en_US","og_type":"article","og_title":"Personal data protection framework policy - Grandio","og_description":"Groupe Grandio Personal Information Protection Program Last revised: May 13, 2025 1. PREAMBLE In the course of their activities, Groupe Grandio (13401537 Canada Inc., hereinafter the \u201cParent Company\u201d), its subsidiaries, affiliated companies, and groups of companies (collectively, \u201cGrandio\u201d) process personal data, including that of their restaurants\u2019 guests, visitors to their websites and apps, loyalty program [&hellip;]","og_url":"https:\/\/grandio.com\/politique-de-confidentialite\/","og_site_name":"Grandio","article_modified_time":"2025-08-13T11:54:14+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"15 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/grandio.com\/politique-de-confidentialite\/","url":"https:\/\/grandio.com\/politique-de-confidentialite\/","name":"Personal data protection framework policy - Grandio","isPartOf":{"@id":"https:\/\/grandio.com\/en\/#website"},"datePublished":"2025-08-11T20:12:00+00:00","dateModified":"2025-08-13T11:54:14+00:00","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/grandio.com\/politique-de-confidentialite\/"]}]},{"@type":"WebSite","@id":"https:\/\/grandio.com\/en\/#website","url":"https:\/\/grandio.com\/en\/","name":"Grandio","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/grandio.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/grandio.com\/en\/wp-json\/wp\/v2\/pages\/3684","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/grandio.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/grandio.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/grandio.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/grandio.com\/en\/wp-json\/wp\/v2\/comments?post=3684"}],"version-history":[{"count":7,"href":"https:\/\/grandio.com\/en\/wp-json\/wp\/v2\/pages\/3684\/revisions"}],"predecessor-version":[{"id":3738,"href":"https:\/\/grandio.com\/en\/wp-json\/wp\/v2\/pages\/3684\/revisions\/3738"}],"wp:attachment":[{"href":"https:\/\/grandio.com\/en\/wp-json\/wp\/v2\/media?parent=3684"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}