Effective date: August 5, 2026
The Volunteer Ambulance Services Society ("VASS", "we") runs this website to support our volunteers and the communities they serve. This policy explains, in plain language, what personal information we handle, why, and what we do — and deliberately don't do — with it. We follow the ten fair information principles of Canada's federal privacy law (PIPEDA) and Canada's Anti-Spam Legislation (CASL) for our newsletter.
Who is responsible
Our privacy contact is the society administrator, reachable at vass@badplan.ca. Send any privacy question, access request, correction, deletion request, or complaint there. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada.
What we collect, and why
- Member accounts — name, username and email address, provided when you sign up. Used to give volunteers access to the members-only area. New accounts are reviewed by an officer before activation.
- Society roster — member names, roles, certifications, contact details, hub assignment, and an optional photo, maintained by society officers. The roster is our official membership record. It is never visible to the public: every roster page, hub crew list, and member photo requires a volunteer login, and those pages tell search engines not to index them.
- Newsletter — your email address and name. The newsletter is members-only: you are subscribed only if you expressly opted in during signup (the box is never pre-checked) and an officer has approved your membership. Every issue contains an unsubscribe link that works immediately. The list lives on our own server and is never sold, shared, or used for anything but the society newsletter.
- Volunteer applications — the application form you complete is used once, to fill out the official Yukon EMS application PDF, and is emailed directly to the co-superintendents of the hub you choose (who pass it to Yukon EMS as part of the intake process). The application is not stored on this website — not in our database and not on disk. We keep only a minimal log entry (your name, email, chosen hub, and the date) so officers know an application was forwarded. We never ask for your Social Insurance Number or signature online; those are completed in person with your superintendent.
- Awards, elections and meeting agendas — members can nominate others for service awards and stand for the board in elections; these record the member's name and the nomination reason or candidate statement, visible only to logged-in members. Members may also suggest and rank agenda topics for the Annual General Meeting. Voting is a secret ballot: how any individual voted — and who suggested an agenda topic — is never recorded against them or shown to anyone. Only the anonymous totals appear, and only after a vote closes.
- Meeting minutes — minutes of AGM, board, and committee meetings record who was present and who sent apologies, the names of the members who moved and seconded motions, the decisions taken, and any action items (including the member each is assigned to). They may also note non-member guests who attended. Draft minutes are visible only to the board; once approved they are visible to logged-in members. Minutes are never public and are not indexed by search engines. They form part of the society's permanent governance record.
- Committees — the members who hold committee positions, and their terms, are listed to logged-in members as part of the society's governance records.
- Openings (positions) — if you apply to a members-only opening (for example, to help run an election), your name, email, and message are emailed to that posting's contact and kept for the board to review.
- Login-security logs — to protect accounts from password-guessing attacks, we record login attempts, including the IP address, username tried, and time. These are used only for security and are deleted automatically after 90 days.
- Technical logs — like any web server, ours keeps short-lived connection and mail-delivery logs used for security and troubleshooting.
Cookies
We use only the two cookies the site needs to function: a session cookie (so you stay logged in) and a security (CSRF) cookie. There are no analytics, no advertising trackers, and no third-party cookies.
Disclosure
We do not sell, rent, trade, or share personal information with anyone. The only routine disclosures are the ones you initiate: your volunteer application is emailed to the co-superintendents of the hub you selected (who forward it within Yukon Emergency Medical Services for intake), and an application to an opening is emailed to that posting's contact.
Where your information is stored
Our website, its database, and our newsletter are hosted on a secure private server located in Vienna, Austria (in the European Union). This means your personal information is stored outside Canada and, while it is there, may be subject to the laws of Austria and the European Union — including access by courts or public authorities in that jurisdiction under their laws. We chose a reputable provider, the server is under our own control, and the information is protected in transit and at rest as described under Safeguards. If you have any concern about your information being stored this way, contact us at vass@badplan.ca.
How long we keep things (retention)
- Volunteer applications: not retained (see above). The minimal forwarding log is deleted automatically after 12 months.
- Opening applications: deleted automatically after 12 months.
- Login-security logs: deleted automatically after 90 days.
- Roster, minutes, committee, awards and election records: kept as the society's permanent governance records, accessible only to logged-in volunteers. Individual votes and the authorship of AGM agenda suggestions are never retained (secret ballot).
- Accounts: kept while you are a member; deactivated when you leave and deleted on request.
- Newsletter list: until you unsubscribe.
- Backups: kept for 14 days, then deleted automatically.
- Server and mail logs: rotated automatically after a few weeks.
Safeguards
The site is served exclusively over encrypted connections (HTTPS/TLS), mail is sent over encrypted channels, members-only content requires individual logins, member photos, training files, and meeting minutes are only served to authenticated volunteers, award, election and agenda votes are secret, and administrative access is limited to designated officers and board members.
If something goes wrong (data breaches)
We work to keep your information safe, but no system is perfect. If a breach of our security ever exposes your personal information and it creates a real risk of significant harm to you, we will notify you as soon as we reasonably can, tell you what happened and what information was involved, and explain the steps you can take to protect yourself. Where the law requires it, we will also report the breach to the Office of the Privacy Commissioner of Canada, and we keep a record of breaches as required.
Your rights
You may ask us at any time what personal information we hold about you, ask us to correct it, or ask us to delete it (we will, unless a society record such as the roster is required to be kept). Email vass@badplan.ca and we'll respond promptly.
Changes
If this policy changes, the new version will be posted here with an updated effective date.
Public award nominations
If you nominate someone for an award through our public nomination page, the contact details you provide (name, email, phone) are used only so the board can follow up about your nomination. They are visible to board members only and are never published.