a. explain what Personal Information we collect and why we collect it;
b. explain the choices you can make about how your information is collected and used;
c. explain how we use Personal Information that we collect;
d. implement methods to protect Personal Information; and
e. establish methods to receive and respond to complaints and inquiries.
The Company’s websites may contain links to third party websites, applications and services. The information practices or the content of such other websites are governed by the privacy statements and policies of those websites. The Company encourages you to review the privacy statements and policies of those websites to understand their information practices.
Your privacy matters to the Company. Please take the time to get to know our practices, and if you have any questions, contact our Privacy Officer at [email protected]
2. What is Personal Information or Personal Data?
Personal Information or Personal Data refers to any information about an identified or identifiable individual.
The term “personal information” has the same meaning as set out in the federal Personal Information Protection and Electronic Documents Act (PIPEDA), which means any information about an identifiable individual including contact information, name, address, phone number, email address, gender, date of birth, and any other data about yourself that you choose to provide electronically through the Website or otherwise, i.e. through the Patient Registration Application Form.
The term “personal health information” has the same meaning as set out in Ontario’s Personal Health Information Protection Act, 2004 (PHIPA) and includes information relating to your physical or mental health, as well as your health history, medical records, prescriptions and your health card number.
Any data that has been collected in which all personal identifiers have been removed, such that the information could not reasonably be used to identify the individual, is not considered personal information or personal health information. This type of anonymized information may be used for research purposes.
We may use or disclose your collected personal information without your knowledge or further consent in limited circumstances where we are required to do so by law. In certain limited circumstances, we may be required to release your personal information in response to a court order, subpoena, search warrant, law or regulation. We will cooperate in responding to such requests, taking appropriate measures to ensure that the requester understands the sensitive nature of the personal information they may receive.
3. How do we obtain your consent to collect your Personal Information?
Typically, we will seek your consent at the time we collect your personal information. Your consent may be implied, deemed (using an opt-out mechanism) or express. Implied consent can be reasonably inferred from your action (e.g. entering into an agreement with us or providing payment) or inaction. Express consent can be given orally, electronically or in writing.
The Company will most often collect personal information directly from you. In cases where personal information is held by a third party, we will obtain your consent before seeking this information. In some cases, consent may be implied by your actions. Where we obtain your personal information directly from a third party, we will take reasonable steps to ensure that the third party has represented to us that it has the right to disclose your personal information to us.
Personal data collected on this website may also be combined with information you provide us through other sources such as other Company websites, product registration, call centres, or in conjunction with events such as trade shows, training seminars and conferences. Information that you supply will relate to the relationship that the Company has with you or your organization.
4. What Personal Information do we collect?
The Company only collects the amount and type of Personal Information that is necessary for the purposes for which the Personal Information is collected. What follows is the type of Personal Information that we may collect, depending on your relationship with the Company and how you use our services.
a. Personal Information of Employees
The following list includes, but is not limited to, the Personal Information that may be collected by the Company respecting employees:
- contact information, including name, home address, telephone number, email address;
- criminal background check(s);
- employment information, including resume (which may include educational background, work history, and references), reference information and interview notes, letters of offer and acceptance of employment, policy acknowledgment forms, background verification information, workplace performance evaluations, emergency contacts;
- benefit information, including forms relating to applications or changes to health and insurance benefits including medical and dental care, life insurance, short and long- term disability; and
- financial information, including pay cheque deposit information and tax-related information, and Social Insurance Number or other required government issued identification.
b. Personal Information of Patients
The following list includes the type of Personal Information that may be collected respecting Users that register with the Company as patients (“Patients”) and utilize the Company’s services for medical cannabis in accordance with the Cannabis Act and its regulations (the “Legislation”):
- name, date of birth, gender, home address, telephone number, email address;
- credit card or other financial information;
- health care information, including health card number, any relevant diagnosis or primary condition, information respecting the health care services provided to you, and information about your health status;
- insurance coverage and payment information, if applicable;
- information in connection with the products or services you inquire about or purchase from us; and
- usage data respecting use of the Company’s website(s) through the website(s) (or through third-party services employed by the website(s)) which can include the IP addresses or domain names of the computers utilized by the User; the URI addresses; the time of the request; the method utilized to submit the request to the server; the size of the file received in response; the numerical code indicating the status of the server’s answer (successful outcome, error, etc.); the country of origin; the features of the browser and the operating system utilized by the User; the various time details per visit (e.g., the time spent on each page within the website(s)); and the details about the path followed within the website(s) with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.
c. Personal Information of Physicians
The following list includes the type of Personal Information that may be collected respecting individuals that register with the Company as physicians that prescribe medical cannabis (“Physicians”):
- contact information, including name, email address, and phone number; and
- usage data respecting use of the Company’s website(s) through the website(s) (or through third-party services employed by the website(s) which can include the IP addresses or domain names of the computers utilized by the User; the URI addresses; the time of the request; the method utilized to submit the request to the server; the size of the file received in response; the numerical code indicating the status of the server’s answer (successful outcome, error, etc.); the country of origin; the features of the browser and the operating system utilized by the User; the various time details per visit (e.g., the time spent on each page within the website(s)); and the details about the path followed within the website(s) with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.
d. Personal Information of All Users (Including Patients and Physicians)
The following list includes the type of Personal Information that may be collected from Users that utilize services provided by the Company, which may include a Patient or Physician:
- contact information, including name, date of birth, gender, home address, telephone number, email address;
- credit card or other financial information;
- usage data respecting use of the Company’s website(s) through the website(s) (or through third-party services employed by the website(s)) which can include the IP addresses or domain names of the computers utilized by the Users; the URI addresses; the time of the request; the method utilized to submit the request to the server; the size of the file received in response; the numerical code indicating the status of the server’s answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the website(s)) and the details about the path followed within the website(s) with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment; and
- other information as necessary to maintain our business relationship with you, such as information related to your preferences, feedback and information requested or provided by you.
Unless specified otherwise, all Personal Information requested by the Company is mandatory in order for the Company to provide its services to the User. As such, failure to provide this Personal Information may affect the ability for a User to utilize the Company’s services. In cases where we have stated that the Personal Information is not mandatory to utilize the service, Users are free to not communicate this Personal Information without any impact on the User’s ability to use the Company’s services. Any questions respecting what information is mandatory can be directed to our Privacy Officer at [email protected]
The Company may also collect Personal Information for the purpose of evaluating market trends and other activities relating to our business. To provide you with timely, valuable information, we may also ask you to provide us with information regarding your professional interests and experiences with our products or services. Providing us with this information is optional.
5. How do we use your Personal Information?
We collect your Personal Information to operate, maintain, enhance and provide all features of the Company’s services, to send you marketing communications, to respond to comments and questions, to provide support to Users of the Company’s services and, from time to time, in medical and academic research. We use information collected from cookies and other technologies to improve your experience and the overall quality of our services and website.
For example, when a User registers as a Patient with the Company, the Company collects and retains Personal Information such as the individual’s name and contact information. The Company will use this information to:
- confirm the individual’s registration status and to maintain the individual’s account;
- fill orders made online and provide other information requested by you;
- establish, maintain and manage our relationship with you so we can provide you with products and services as requested and in line with your needs and preferences;
- distribute medical cannabis to you;
- provide you with information about our products and services, including the latest news on Company activities and initiatives, information about new products and services, product updates, technical support issues, events and special offers;
- recommend products, services or programs on our Website(s) by providing customized content on our Website(s) or otherwise;
- obtain and process payments for medical cannabis dispensed to you, which includes providing necessary information to our third party service providers (please see Third Party Service Providers section below);
- seek reimbursement from your insurer;
- enable us to comply with applicable laws and specifically the requirements of the federal Cannabis Act and Regulations.
At the time of collection, the Company will document the purposes for which the information was collected. Upon request, the Company will explain the purposes for which the information is being collected, or refer the User requesting the purposes to a designated person within the Company who will explain the purposes of collection.
6. How do we collect your Personal Information?
We collect information in the following ways:
a. Information you give us: Some of our services require you to sign up for an account. When you do, we will ask for Personal Information, including your name, birth date, email address, phone number and other applicable information to create your account. Some of our services will also require you to provide us with your Personal Information in order to obtain a product or receive information from us, such as newsletters or other email messages containing information of a commercial or promotional nature.
b. Information from Physicians about Patients: If you are registered as a Patient with the Company, your Personal Information, including your name, date of birth, gender, email address, phone number and health information may be collected directly from a Physician who provides the Company with a complete Medical Document on your behalf. This information will not be collected from your Physician without your consent.
d. Google Analytics: Google Analytics is a web analysis service provided by Google Inc. (“Google”) that is used on the Company’s website(s). Google utilizes the data collected to track and examine the use of the Company’s website(s), to prepare reports on the Company’s website(s) activities and to provide the Company with other services related to website and Internet use. Google may use the data collected to contextualize and personalize the advertisements of its own advertising network.
7. Who has access to your Personal Information within the Company?
Only those employees and contracted individuals of the Company who require access for business reasons or whose duties reasonably so require shall be granted access to Personal Information about Users.
8. Disclosure of your Personal Information Outside of the Company
The Company may disclose your Personal Information with third party companies, organizations and individuals outside of the Company if:
a. You have provided your consent: We will share Personal Information with companies, organizations or individuals outside of the Company when we have your consent to do so.
c. To comply with a legal obligation: The Company may disclose Personal Information if required to do so pursuant to any applicable law, regulation, legal process or enforceable governmental request. For example, it may be necessary for the Company to disclose Personal Information to law enforcement officials, regulatory bodies, or government agencies for the purposes of investigating or preventing drug, fraud, or other offences as may be required or permitted by applicable laws. Additionally, under the Legislation and other applicable laws, the Company may be required to disclose some of a User’s Personal Information to government officials, law enforcement personnel, or competent authorities of foreign governments. This information includes:
- an individual’s given name, surname, date of birth and gender;
- contact information including the individual’s mailing address, phone number, and email address;
- the given name, surname, date of birth and gender of one or more persons who are responsible for the individual, as well as contact information for such persons;
- a valid prescription or other medical document issued by an authorized medical practitioner;
- the given name, surname, professional status and address of the health care practitioner who issued a prescription or other medical document on behalf of the Individual;
- if applicable, the consent of the health care practitioner to receive shipments on the individual’s behalf; order details about the product sold or provided, including the quantity ordered; and the address to which the product is to be shipped.
d. For Legal Reasons: The Company may also disclose Personal Information to establish or exercise our legal rights or defend against legal claims or in connection with an emergency that warrants use or disclosure of the information.
e. For Purposes of Contracts: The Company may disclose Personal Information for executing a contract to which a User is part or to take steps at the request of the User prior to entering into a contract.
f. For other reasons authorized by law: We will share Personal Information with companies, organizations or individuals outside of the Company if disclosure of the information is reasonably necessary for other reasons authorized by law.
We may share non-personally identifiable (anonymized) information publicly and with our partners. For example, we may share anonymized information publicly to show trends about the general use of our services.
The Company shall not otherwise disclose Personal Information to third parties for commercial or other reasons, except as may be specifically required to comply with applicable laws or where you have provided your consent.
In any case, the Company will gladly help to clarify the specific legal basis that applies to the disclosure of Personal Information, and in particular whether the provision of Personal Information is a statutory or contractual requirement or a requirement necessary to enter into a contract.
9. How is your Personal Information secured?
The Company is committed to protecting the confidentiality and security of all Personal Information against loss and unauthorized access, disclosure, modification or destruction, and therefore has security safeguards appropriate to the sensitivity level of the information in place.
The Company will ensure that all employees and third party service providers with access to information of individuals shall be required as a condition of employment or provision of services to respect the confidentiality of such information and that all employees and third party service providers are aware of the importance of maintaining the confidentiality of such information as part of training requirements.
10. Your rights respecting your Personal Information
Users may exercise certain rights regarding their Personal Information processed by the Company. In particular, Users have a right to:
a. Withdraw their consent at any time: Users have the right to withdraw consent where they have previously given their consent to the collection, use, disclosure or other processing of their Personal Information. Users may withdraw their consent by contacting our Privacy Officer at [email protected]
b. Access their Personal Information: Individuals are entitled, with certain legal restrictions, to access and review their Personal Information held by the Company. The Company will make the following information available upon request:
- The name or title, and the address of the person accountable for the Company’s policies and practices and to whom complaints or inquiries can be forwarded;
- The means of gaining access to Personal Information held by the Company;
- A general description of the type of Personal Information held by the Company, including a general account of its use;
- A copy of any information available explaining the Company’s policies, standards or codes; and
- What Personal Information is made available to related organizations.
The Company reserves the right to refuse to provide access to Personal Information in circumstances during which the Company is permitted by law to refuse access, including where providing access would reveal Personal Information about a third party, if the release of the Personal Information could affect the security of an individual, or if the Personal Information is subject to privilege.
Requests for access to Personal Information should be made to our Privacy Officer at [email protected]
c. Request Corrections to Personal Information: Accurate Personal Information is required for efficient and effective delivery of product and services. Individuals may contact our Privacy Officer at [email protected] to modify or correct any Personal Information. Corrections will be made within a reasonable timeframe.
d. Object to Processing of their Personal Information: Users have the right to object to the processing of their Personal Information or Personal Data in certain circumstances where Personal Information is being processed on a basis other than consent. In particular, Users can object to processing of their Personal Information for purposes of direct marketing at any time.
e. Restrict the processing of their Personal Information: Users have the right, under certain circumstances, to restrict the collection, use, disclosure or other processing of their Personal Information, meaning Users can limit how the Company uses their Personal Information or Personal Data.
f. Have their Personal Information deleted or otherwise removed: Users have the right, under certain circumstances, to obtain the erasure of their Personal Information or Personal Data from the Company. If required to erase Personal Information or Personal Data, the Company will do so without delay.
g. Have their Personal Information transferred to another Controller: Users have the right to receive their Personal Information or Personal Data in a structured, commonly used and machine readable format and, if technically feasible, to have it transmitted to another Controller (as defined in GDPR) without any hindrance, under certain circumstances.
h. Lodge a complaint: Users have the right to bring a claim before their competent data protection authority.
11. How can you contact us?
The Company shall maintain procedures for receiving and responding to complaints or inquiries about policies and practices relating to the handling of Personal Information.
The Company shall inform individuals who make inquiries or lodge complaints of the existence of relevant complaint procedures.
The Company shall investigate all complaints made through the proper complaint procedure. Where complaints are justified, the Company will take the necessary steps to remedy the contravention.
12. Do we transfer the data internationally?
13. How Long is Your Personal Data Retained?
Personal Information and Personal Data shall be stored for as long as required by the purpose for which it has been collected, used or disclosed.
Personal Information or Personal Data which the Company no longer needs to retain shall be destroyed, erased or made anonymous in a secure manner in accordance with the Company’s policies respecting the destruction of records. The Company shall use care in the disposal or destruction of information so as to prevent unauthorized parties from gaining access to the information. The right to access, the right to erasure, the right to rectification and the right to portability cannot be enforced after the information has been destroyed.