Privacy Policy

PIPEDA
BC PIPA
GDPR
Effective Date: March 6, 2026
Last Reviewed: March 6, 2026
Document Reference: ISPO-PP-01 Rev 01

#101-9 Burbidge Street, Coquitlam, B.C. V3K 7B2, Canada
604-472-3800

Table of Contents

1. Introduction

AMPCO Manufacturers Inc. (“Ampco,” “we,” “us,” or “our”) is a precision manufacturer based in Coquitlam, British Columbia, Canada. We produce labels, decals, membrane switches, and printed circuit board assemblies for automotive and industrial customers.

This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you visit our website at ampcomfg.com, interact with our blog, or engage with us through business inquiries, customer orders, or supplier relationships.

We are committed to complying with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia’s Personal Information Protection Act (PIPA), and, where applicable, the European Union’s General Data Protection Regulation (GDPR) and other relevant data protection laws.

Privacy Officer: Ampco has designated a Privacy Officer responsible for our compliance with applicable privacy legislation. If you have questions or concerns about how we handle your personal information, please contact our Privacy Officer using the details in Section 18.

2. Definitions

Term
Definition
Personal Information / Personal Data
Any information about an identifiable individual, as defined under PIPEDA, BC PIPA, and GDPR. This includes information that can directly or indirectly identify a natural person.
Processing
Any operation performed on personal data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, alignment, combination, restriction, erasure, or destruction.
Data Controller
The entity that determines the purposes and means of processing personal data. For the purposes of this policy, Ampco is the data controller.
Data Processor
An entity that processes personal data on behalf of the data controller, such as our service providers.
Data Subject / You
The individual whose personal data is being processed, including website visitors, customers, business contacts, and prospective partners.
Consent
Any freely given, specific, informed, and unambiguous indication of your wishes by which you agree to the processing of your personal data.
Service
The website, blog, and related business services provided by Ampco.
Cookie
A small data file placed on your device by our website to enable functionality and analytics.

3. Information We Collect

3.1 Information You Provide Directly

We may collect the following personal information when you contact us, submit an inquiry, request a quote, or engage in a business relationship:

  • Name (first and last)
  • Email address
  • Phone number
  • Company name and job title
  • Mailing address (city, province/state, postal/ZIP code, country)
  • Content of your inquiry or message

3.2 Information Collected Automatically

When you visit our website, we automatically collect certain technical data, including:

  • IP address
  • Browser type and version
  • Operating system
  • Pages visited, time and date of visit, and time spent on pages
  • Referring URL
  • Unique device identifiers and other diagnostic data

3.3 Location Data

We may collect approximate location data (such as city or region) derived from your IP address. We do not collect precise GPS location data through our website. If we ever enable precise location services, we will obtain your explicit consent first.

3.4 Business Customer Data

In the course of our B2B operations, we collect business contact information from our customers, suppliers, and partners as necessary to fulfill orders, manage contracts, and maintain our business relationships. This may include names, business email addresses, phone numbers, and shipping/billing addresses associated with purchase orders.

Data Minimization: We limit our collection of personal information to what is necessary and proportionate for the identified purposes. We do not collect personal information indiscriminately, and we regularly review our data collection practices to ensure they remain appropriate.

4. Lawful Basis for Processing

We process your personal information only when we have a valid legal basis to do so. The table below maps each processing activity to its lawful basis under GDPR Article 6 and the corresponding Canadian privacy law authority.

Processing Activity
Lawful Basis (GDPR)
Canadian Authority
Responding to inquiries and quote requests
Implied consent (PIPEDA s. 6.1)
Legitimate interest / Pre-contractual steps (Art. 6(1)(b))
Fulfilling customer orders and contracts
Performance of contract (Art. 6(1)(b))
Consent not required for purposes integral to contract
Sending marketing communications
Consent (Art. 6(1)(a))
Express consent (CASL / PIPEDA)
Website analytics and improvement
Legitimate interest (Art. 6(1)(f))
Implied consent (PIPEDA s. 6.1)
Complying with legal obligations
Legal obligation (Art. 6(1)(c))
Consent not required (PIPEDA s. 7)
Maintaining website security
Legitimate interest (Art. 6(1)(f))
Implied consent (PIPEDA s. 6.1)
Managing supplier and partner relationships
Legitimate interest (Art. 6(1)(f))
Reasonable purpose (PIPEDA Principle 2)

Where we rely on legitimate interest, we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms. You may contact us to request details of any such assessment.

5. How We Use Your Information

We use the personal information we collect for the following specific purposes:

  • To respond to your inquiries, provide quotes, and facilitate business discussions
  • To process and fulfill customer orders, including shipping, invoicing, and quality follow-up
  • To communicate with you about changes to our services, products, or policies
  • To provide customer support and resolve issues
  • To improve our website, products, and services through aggregated analytics
  • To monitor and maintain the security and integrity of our website
  • To detect, prevent, and address technical issues or fraudulent activity
  • To comply with applicable legal, tax, and regulatory obligations
  • To send you marketing communications about products and services similar to those you have previously inquired about, where you have provided consent or where permitted by law

We will not use your personal information for purposes materially different from those stated above without first obtaining your consent or providing you with notice as required by law.

6. Consent

6.1 How We Obtain Consent

We obtain consent for the collection, use, and disclosure of your personal information in a manner appropriate to the sensitivity of the information:

  • Express consent: For sensitive information or marketing communications, we obtain your explicit, opt-in consent (e.g., checking a consent box, signing a form, or providing written agreement).
  • Implied consent: For less sensitive information where the purpose would be obvious to a reasonable person (e.g., providing your email address when sending us an inquiry), your consent may be implied by your actions.

6.2 Withdrawing Consent

You have the right to withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice. To withdraw consent:

  • For marketing emails: click the “unsubscribe” link in any marketing email
  • For other purposes: contact our Privacy Officer at privacy@ampcomfg.com

We will inform you of the implications of withdrawing consent. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Important: In certain circumstances, we may continue to process your information without consent where permitted by law, such as to comply with a legal obligation or to fulfill a contractual commitment.

7. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Our retention periods are guided by the following:

Data Category
Retention Period
Basis
Website analytics data
26 months
Legitimate interest; industry standard
Business inquiry records
3 years after last contact
Legitimate interest in maintaining business relationships
Customer order and contract records
7 years after completion
Tax, legal, and regulatory obligations (CRA requirements)
Marketing consent records
Duration of consent + 3 years
Legal obligation to demonstrate valid consent
Supplier and partner contact data
Duration of relationship + 3 years
Contractual and legitimate interest

When personal information is no longer needed, we securely delete or anonymize it in accordance with our Information Security Management System (ISMS) data disposal procedures.

8. International Data Transfers

8.1 Transfers from the EU/EEA

Canada has been recognized by the European Commission as providing an adequate level of data protection for transfers of personal data from the EU/EEA to organizations subject to PIPEDA. Where we engage service providers located in countries without an adequacy decision, we implement appropriate safeguards, including EU Standard Contractual Clauses (SCCs), to ensure your data remains protected.

8.2 Transfers Outside Canada

In accordance with BC PIPA Section 33.1, we notify you that some of your personal information may be disclosed to service providers located outside of Canada for the purposes of providing our services. Before any such transfer, we ensure that:

  • The service provider is contractually bound to protect your personal information to a standard comparable to Canadian privacy law
  • Appropriate technical and organizational safeguards are in place
  • The transfer is necessary for the identified purposes

Currently, Ampco may transfer personal information to service providers in the following countries: Canada (domestic), the United States, and India. If this list changes materially, we will update this policy accordingly.

9. Disclosure of Personal Data

9.1 Business Transactions

If Ampco is involved in a merger, acquisition, or asset sale, your personal data may be transferred to the acquiring entity. We will provide notice before your personal data is transferred and becomes subject to a different privacy policy.

9.2 Legal Requirements

We may disclose your personal data when we have a good faith belief that such action is necessary to:

  • Comply with a legal obligation, court order, or government request
  • Protect and defend the rights or property of Ampco
  • Prevent or investigate possible wrongdoing in connection with our services
  • Protect the personal safety of our users or the public

9.3 With Your Consent

We may disclose your personal information for purposes not described in this policy only with your express consent.

10. Third-Party Service Providers

We engage third-party companies and individuals to help us provide, maintain, and improve our services. These service providers have access to your personal data only to the extent necessary to perform their designated tasks and are contractually obligated to protect it.

10.1 Categories of Service Providers

Category
Purpose
Data Shared
Web analytics (e.g., Google Analytics)
Analyzing website traffic and usage patterns
Usage data, IP address, device identifiers
Cloud hosting and infrastructure
Hosting our website and business applications
All data processed through our systems
IT managed services
Security monitoring, network management
System logs, technical data
Email and communication tools
Business communications
Contact information, message content
Shipping and logistics
Order fulfillment
Name, address, order details

10.2 Data Processing Agreements

We maintain written data processing agreements with all service providers who process personal information on our behalf. These agreements require service providers to process data only on our instructions, implement appropriate security measures, and notify us promptly of any data breaches.

10.3 Google Analytics

We use Google Analytics to analyze website usage. Google Analytics collects data through cookies and similar technologies. Google may use this data to contextualize and personalize advertisements on its own network. You may opt out of Google Analytics by installing the Google Analytics Opt-Out Browser Add-on. For more information, see Google’s Privacy Policy.

11. Data Security

The security of your personal information is important to us. We implement and maintain appropriate administrative, technical, and physical safeguards designed to protect your personal information against unauthorized access, disclosure, alteration, or destruction.

11.1 Our Safeguards Include

  • Administrative: Information security policies, employee training, access controls based on the principle of least privilege, and regular security reviews
  • Technical: Encryption of data in transit and at rest, multi-factor authentication, network segmentation, continuous monitoring, and vulnerability management
  • Physical: Secured facilities with access controls, visitor management, and environmental protections

11.2 Information Classification

All personal information is classified and handled in accordance with Ampco’s Information Classification Policy, which is part of our broader Information Security Management System (ISMS). Data is categorized by sensitivity and handled according to the corresponding protection level.

While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is completely secure. We continuously evaluate and improve our security practices.

12. Breach Notification

In the event of a breach of security safeguards involving personal information under our control, Ampco will follow our Incident Response Plan and comply with all applicable breach notification requirements.

12.1 Canadian Requirements (PIPEDA s. 10.1 & BC PIPA s. 29.1)

  • We will assess whether the breach creates a real risk of significant harm to affected individuals
  • If significant harm is likely, we will notify the Office of the Privacy Commissioner of Canada (OPC) and/or the BC Office of the Information and Privacy Commissioner (OIPC) as applicable
  • We will notify affected individuals as soon as feasible, providing a description of the breach, the types of information involved, and steps they can take to reduce harm
  • We maintain a record of every breach of security safeguards, regardless of whether notification thresholds are met
  •  

12.2 GDPR Requirements (Art. 33–34)

For breaches involving personal data of EU/EEA data subjects:

  • We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to rights and freedoms
  • Where the breach is likely to result in a high risk to individuals, we will notify affected data subjects without undue delay

13. Your Privacy Rights

Depending on your location and the applicable law, you have certain rights regarding your personal information. We honour these rights regardless of your location and will respond to legitimate requests within the timeframes required by law.

13.1 Rights Under All Applicable Laws

Right
Description
Access
You can request a copy of the personal information we hold about you, provided in a structured, commonly used, and machine-readable format.
Correction
You can request that we correct inaccurate or incomplete personal information.
Deletion
You can request that we delete your personal information, unless we have a legal obligation to retain it.
Withdraw Consent
You can withdraw previously given consent to the collection, use, or disclosure of your personal information.

13.2 Additional Rights Under GDPR (EU/EEA Residents)

If you are a resident of the European Union or European Economic Area, you have the following additional rights:

  • Right to Restriction: You can request that we restrict the processing of your personal data in certain circumstances
  • Right to Data Portability: You can request to receive your personal data in a structured, machine-readable format and transfer it to another controller
  • Right to Object: You can object to processing based on legitimate interest, including profiling. We will cease processing unless we demonstrate compelling legitimate grounds
  • Right Not to Be Subject to Automated Decisions: You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects

13.3 Canadian Privacy Rights (PIPEDA & BC PIPA)

13.4 How to Exercise Your Rights

To exercise any of these rights, please contact our Privacy Officer using the details in Section 18. We will respond to your request within 30 days. In complex cases, we may extend this by up to two additional months, and we will inform you of any such extension within the initial 30-day period. We may need to verify your identity before processing your request.

14. Children’s Privacy

Our website and services are intended for business use and do not target anyone under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal data from a child without verified parental consent, we will take steps to delete that information promptly.

15. Cookies and Tracking Technologies

We use cookies and similar tracking technologies on our website. Cookies are small data files placed on your device that help us provide and improve our services.

15.1 Types of Cookies We Use

Cookie Type
Purpose
Duration
Strictly Necessary
Essential for website functionality and security. Cannot be disabled.
Session
CPerformance / Analytics
Help us understand how visitors use our website through aggregated data.
Up to 26 months
Preference
Remember your settings and display preferences.
Up to 12 months

15.2 Managing Cookies

You can control cookies through your browser settings. Most browsers allow you to refuse all cookies, accept only certain cookies, or be notified when a cookie is set. Please note that disabling cookies may affect the functionality of our website.

16. Links to Other Sites

Our website may contain links to third-party websites that are not operated by us. We have no control over the content, privacy policies, or practices of third-party sites. We strongly encourage you to review the privacy policy of every website you visit. A link from our website does not imply endorsement of the linked site.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make changes:

  • We will update the “Effective Date” and “Last Reviewed” dates at the top of this page
  • For material changes, we will provide prominent notice on our website and, where feasible, notify you by email
  • We will maintain an archive of previous versions upon request

Your continued use of our website after any changes constitutes acceptance of the updated policy.

18. Contact Us

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have a complaint about our handling of your personal information, please contact us:

Privacy Officer — AMPCO Manufacturers Inc.
Email: privacy@ampcomfg.com
Phone: 604-472-3800
Mail: #101-9 Burbidge Street, Coquitlam, B.C. V3K 7B2, Canada

If you are not satisfied with our response, you have the right to file a complaint with the applicable regulatory authority:

This Privacy Policy is governed by the laws of British Columbia and the federal laws of Canada applicable therein. This document was last reviewed and approved by management on March 6, 2026. Document reference: ISPO-PP-01 Rev 01.