Privacy Policy
Merlin Shredding Inc. respects the privacy rights of our customers and is committed to protecting their personal information.
Last updated: 14 September 2026.
Applicable privacy law
Our privacy practices are informed by Alberta's Personal Information Protection Act (PIPA), the Protection of Privacy Act (POPA) and the Access to Information Act (ATIA) where public bodies are served. POPA and ATIA took effect on 11 June 2025 and replaced FOIP. The federal Personal Information Protection and Electronic Documents Act (PIPEDA) applies where applicable. The Alberta Health Information Act (HIA) applies where health custodians are served.
Information we handle
We use information submitted through our public contact channels to respond to enquiries and provide services. Customer material for destruction is handled at the customer's premises: it is not stored, staged or processed at a Merlin premises, and only destroyed material returns to our yard. Service records include the customer and service address, date and time of destruction, type and quantity of material, vehicle or unit, operator and a unique reference. A Certificate of Destruction and service receipt are issued for every service.
Safeguards
Customer material is never left unattended or unsecured; it remains under the direct control of an Access Individual or locked in a service vehicle. Merlin's containers are locking. Customer information is accessed only when needed for the job and through Merlin systems, not personal devices, personal email, personal cloud storage or removable media. Devices are locked when unattended and multi-factor authentication is enabled where supported.
Access, correction and complaints
Kathy Jackson, Dispatch Manager, is Merlin's Data Protection Officer. Contact her through admin@merlinshredding.com or (403) 340-2401. If an individual asks Merlin directly about access to or correction of information held for a customer organisation, the request is referred to the Data Protection Officer the same day. Merlin is a service provider rather than the controller of that information: the Data Protection Officer acknowledges the individual, does not disclose or act on the information, and refers the individual to the customer organisation that holds it. The request and referral are recorded. Privacy complaints and suspected breaches may be sent to the Data Protection Officer through the same mailbox or phone number.
Records retention
Certificates of Destruction and service receipts, identifier logs and opt-out agreements, product and specialty destruction agreements, and written communications of the Data Protection Officer and i-SIGMA Certification Compliance Officer are retained for three years. Incident records, including data-subject requests, are retained for a minimum of 24 months.