Privacy Policy

Privacy Policy

Effective Date: March 15, 2024

Date of last update: March 15, 2024

1. General Information

a) Introduction

Purpose of this Policy. Privacy is important to Medicart Corporation and its related entities (the “Company“, “We“, “Us“, “Our“). For this reason, We have implemented safeguards and sound management practices for Your Personal Information in accordance with the laws applicable in Quebec and Canada.

Complementary to the Terms and Conditions. This privacy policy (the “Policy“), which should be read in conjunction with Our Terms and Conditions, describes Our practices with respect to the collection, use, disclosure, retention and destruction of Personal Information of individuals receiving Our Services, visitors to this Website and its users (hereinafter “You“, ”  Your”,  “Your“).

Consent. By using https://medicart.com/ and https://epiderma.ca/ (the “Websites“) or any of Our Services, You agree that We may collect, use, disclose, retain and/or destroy (hereinafter “Process” or “Processing“).Your Personal Information in accordance with the terms and conditions described herein. If You do not agree to abide by and be bound by this Policy, You are not permitted to visit, access or use Our Websites or Services, or share Your Personal Information with Us.

Policy Limitations. This Policy does not apply to the Personal Information of the Company’s employees, representatives and consultants, or to any other person affiliated with the Company, as well as to any information that does not constitute Personal Information as defined by the laws applicable in Quebec and Canada.

b) Data Protection Officer

Contact information for the Data Protection Officer. Comments, questions and complaints regarding the Company’s Privacy Policy and practices may be directed to Our Privacy Officer at:

Telephone :       418-781-2700

Email :                [email protected]

Address :            330-2590 boul. Laurier, 3rd Floor, Quebec City, G1V 4M6

2. Definitions

Definitions of certain concepts or expressions. The following concepts and expressions, when they appear with a first letter in capital letters in the Policy, have the meaning ascribed to them below, unless there is an implicit or explicit derogation in the text:

Company“, “We“, “Us“, “Our“: Medicart Corporation.

Service Provider” means any natural or legal person who processes Personal Information on behalf of the Company. These are third-party companies or individuals employed by the Company to facilitate the Services, provide the Services on behalf of the Company, perform services related to the Services, or assist the Company in analyzing the use of the Services.

Cookie Banner“: A pop-up window requesting Your consent to a certain collection of Your Personal Information on the Websites.

Personal information” means any information that relates to a natural person and allows them to be identified, i.e. that directly or indirectly reveals something about the identity, characteristics (e.g., skills, preferences, psychological tendencies, predispositions, mental capacities, character and behaviour of the person concerned) or activities, regardless of the nature of the medium and regardless of the extent of the information. the form in which the information is accessible (written, graphic, audio, visual, computerized or otherwise).

Data Protection Officer“: the person in charge of the application of this Policy and whose contact details are identified in the 1b) Data Protection Officer of this Policy.

Services“: Services refer to the Websites, Our social media pages and any products and services rendered to You there, such as:

  • Our aesthetic services and treatments;
  • Our medical services and treatments;
  • Our virtual clinic;
  • Our online store;
  • Access to your online account;
  • Our scholarships.

Websites“: https://medicart.com/ or https://epiderma.ca/.

Cookies“: Cookies are text files that are placed on Your computer or mobile device. These cookies may contain information about Your search history, the web pages You visit, and Your web browser.

Process”, “Processing”: A concept encompassing any operation that may affect or concern personal information, including: collection, use, retention, destruction, communication or transmission.

You“, “Your“, “Your“: Persons benefiting from Our Services, visitors to the Websites and any customer using the Company’s Services.

3. Processing of Personal Information

3.1 Collection of Personal Information

3.1.1 Means of collection

Various means. We collect Your Personal Information through Our Websites or other technological means in a variety of ways, including:

  • Automatically. When You connect to Our Websites, the device You use to log in to Us will communicate Personal Information to Us;
  • Electronic forms. By completing and providing Us with one of Our electronic forms;
  • Emails Released. Through emails that You provide to Us using one of the email addresses available on Our Websites;
  • Cookies. Through cookies (“Cookies”) including cookies identified in Our Cookie Policy ; and
  • By third parties who collect Your Personal Information on Our behalf that is identified in the 3.2Collection of Personal Information by a Third Party of this Policy.

Profiling, Identification or Location. Our Websites have features that allow you to profile Your activities on Our Websites, to identify You and to locate You. These functions are used by third parties identified in the 3.5Disclosure and Transfer of Personal Information through cookies. We disable these features by default. You can enable them through the Cookie Banner.

3.1.2 Personal Information Collected

Categories of Information Collected. In the course of Our business, We may collect and process different types of Personal Information including the information listed below:

  • identification information and contact information, including your first and last name, postal address, email address, telephone number;
  • demographic information, such as Your age, gender and region of residence;
  •  technical or digital information, including login information and other information about Your activities on the Websites, such as Your IP address, the pages You have visited, the time and date of Your visits, Your number of connections, Your domain name, the address of the referring site (if accessing the Website from another site),  the type of browser You use, Your device’s operating system, and other hardware and software information;
  • consents to the disclosure of Personal Information and the use of certain cookies on Our Websites as well as to the disclosure or use of Your Personal Information;
  •  information necessary for the provision of Our Services, such as information about Services We have rendered to You or which We render to You;
  • information that You choose to provide or transmit to Us, for example, when You fill out an online form, respond to solicitations or surveys, or communicate with one of Our employees or representatives;
  • financial information, such as summary payment information, if You wish to pay for Our Services online.

Restriction to processing, necessary and legitimate purposes. In each case, such Personal Information is processed in accordance with the necessary and legitimate purposes listed in the 3.4Use of Personal Information below.

3.2 Collection of Personal Information by a Third Party

Third Parties Collecting Personal Information on Our Behalf.

Automattic (WooCommerce and WordPress) collects the following Personal Information on Our behalf:

  • identification information and contact information, including your first and last name, postal address, email address, telephone number;
  • demographic information, such as Your age and region of residence;
  •  information necessary for the provision of Our Services, such as information about Services We have rendered to You or which We render to You;
  • information that You choose to provide or transmit to Us, for example, when You fill out an online form, respond to solicitations or surveys, or communicate with one of Our employees or representatives.

Stripe collects financial information for payment for our Services, as follows:

  • identification information and contact information, including your first and last name, postal address, email address, telephone number;
  • financial information, such as summary payment information, if You wish to pay for Our Services online.

3.3 Opting Out of Optional Collection

Refuse to consent. Unless otherwise provided by law or Your contractual obligations, You may refuse or withdraw Your consent to certain specific uses or disclosures of Your Personal Information:

  • by not entering Your Personal Information in Our online forms where the provision of such information is indicated as optional;
  • by selecting “opt-out” in the Cookie Banner; or
  • by communicating a request to Our Privacy Officer using the contact information identified in section 1b) of this policy.

Measures available to opt-out of ways to collect Personal Information. You may also provide Your Personal Information to Us other than through technological means such as Our Websites. You can provide us with the following:

  • By e-mail;
  • By phone; or
  • In person.

3.4 Use of Personal Information

Purposes of Personal Information. We may use Your Personal Information for the purposes described below:

  • operate, maintain, supervise, develop, improve and provide the functionality of Our Websites;
  • Present and provide Our Services to you, including:
    • Our aesthetic services and treatments;
    • Our medical services and treatments;
    • Our virtual clinic;
    • Our online store;
    • Access to your online account;
    • Our scholarships;
  • manage your online account;
  • manage your orders;
  • process an online appointment booking;
  • process a scholarship application;
  • evaluate a job application;
  • carry out Our contractual obligations to You;
  • manage invoicing and process payments;
  • process and resolve queries, complaints and dissatisfactions;
  • developing, improving, and offering new Services;
  • send you messages, updates, security alerts;
  • for marketing and business development purposes, if You have previously consented to the processing of Your Personal Information for such purposes;
  • respond to Your questions and provide You with assistance as needed;
  • conduct research, analysis and statistics in connection with Our Business and Services;
  • detect and prevent fraud, error, spam, abuse, security incidents, and other harmful activities; or
  • for any other purpose imposed or permitted by applicable law.

3.5 Access, Disclosure and Transfer of Personal Information

Access and Communication. We may transfer, disclose or allow access to Your Personal Information to Our employees as well as Our Service Providers, who need the information to help Us operate Our Websites, perform Our Services, carry out Our business or serve You.

3.5.1 Access to Personal Information within the Company

Limiting Access to Personal Information. Your Personal Information is accessible only to Our directors, employees or representatives who are required to have access to Your Personal Information in order for them to perform their duties. As such, Your Information may be accessible to:

  • Our Privacy Officer;
  • Our IT services (“Information Technology”);
  • Our customer service;
  • Our sales service;
  • Our finance department;
  • Our marketing department;
  • Our human resources (in the case of applying for a job);
  • Our operations; and
  • Our clinics.

3.5.2 Disclosures of Personal Information

Protective measures when communicating to third parties. We only share Your Personal Information with Our Service Providers if they have previously agreed in writing to ensure the confidentiality of Your Personal Information in accordance with applicable laws and Our Information Governance Program through the implementation of various information protection and governance measures. These measures are proportionate to the sensitivity of the Personal Information being processed or disclosed. Without limitation, Our Service Providers may only use Your Personal Information confidentially as directed by Us and only for the purposes for which it was provided. In addition, We only provide Our Service Providers with the Personal Information necessary for the performance of their mandate or contract and We require such Service Providers to destroy the Personal Information appropriately upon termination of the contract or as soon as its use is no longer required.

Our Service Providers. Although We try to avoid sharing Your Personal Information with third parties, We may use Service Providers to perform various services on Our behalf, such as IT management and security, marketing, and data analysis, hosting and storage. We have defined below some cases in which such sharing may take place:

Please note that this Cookie may collect Personal Information that can identify You and that it can perform profiling of Your activities on the web (targeted advertising);

This Cookie communicates to Google for the purposes identified in Our Cookie Policy ;

  • We use YouTube to present Our products and Services. For more information, you can consult Google’s privacy policy ;
  • We use Google Ads to analyze the audience of Our Services, compile statistics and converse with customers and prospects. For more information, see Google’s privacy policy and their table of advertising and measurement cookies;

Please note that this Cookie can identify You and profile Your activities on the web in order to provide You with advertising that would meet Your interests (targeted advertising);

This Cookie communicates to Google for the purposes identified in Our Cookie Policy ;

  • We use the services of Microsoft (Bing) Ads to collect and store data in order to create usage profiles using pseudonyms. For more information, see Microsoft’s privacy policy ;

This Cookie communicates to Microsoft for the purposes identified in Our Cookie Policy ;

  • We use the services of Meta (Facebook Pixel) to help understand and serve ads, compile statistics and communicate with customers and prospects. For more information, see Meta’s privacy policy;

Please note that this Cookie can identify You and profile Your web activities for the purpose of providing You with advertising that would be relevant to Your interests (targeted advertising);

This Cookie communicates to Meta for the purposes identified in Our Cookie Policy ;

  • We use Automattic‘s services (WooCommerce and WordPress) for certain Online Services, including booking appointments, shopping on our store, and processing payments. For more information, see Automattic‘s privacy policy.

All categories of Personal Information identified in the 3.1Collection of Personal Information may be communicated or stored through this service.

  • We use Stripe‘s services as an online payment processor. For more information, see Stripe’s privacy policy.
  • We use the services of Usercentrics (Cookiebot) for the management of cookies. For more information, you can consult the privacy policy of Usercentrics ;
  • We use the Meta Group’s Facebook and Instagram  social media services  to communicate about Our Services. For more information, see  Meta’s privacy policy;
  • We use the services of the social network LinkedIn to communicate about Our Services. For more information, you can consult LinkedIn privacy policy;
  • We use the services of Mynjob for the management of our human resources. For more information, you can consult Mynjob’s privacy policy.

All categories of Personal Information identified in the 3.1Collection of Personal Information may be communicated or stored through this service.

  • We use Twitter (X) to present Our products and Services. For more information, you can consult the privacy policy of Twitter (X);
  • We use Tik Tok to present Our products and Services. For more information, you can consult Tik Tok’s privacy policy;
  • We use Microsoft services (Outlook and Microsoft Office suite) to store Our documents and emails. For more information, see Microsoft’s privacy policy  ;

All categories of Personal Information identified in the 3.1Collection of Personal Information may be communicated or stored through this service.

  • We use Cossette services for marketing and advertising. For more information, you can consult Cossette’s privacy policy;
  • We use Adviso services for marketing and advertising. For more information, you can consult Adviso’s privacy policy;
  • We use the services of Pantheon to host Our Websites. For more information, see Pantheon’s privacy policy;

All categories of Personal Information identified in the 3.1Collection of Personal Information may be communicated or stored through this service.

  • We use Veeam services to store our data. For more information, see Veeam’s privacy policy.

All categories of Personal Information identified in the 3.1Collection of Personal Information may be communicated or stored through this service.

  • We use Metatracer on Our digital systems to facilitate the detection and management of Your Personal Information and that of Our employees, all to ensure Our compliance with privacy laws.

Metatracer collects, as Personal Information, only identifying information.

3.5.3 Communication outside Quebec

Disclosure of Personal Information Outside Quebec. We may disclose Your Personal Information outside of Quebec and mandate an entity located outside of Quebec to collect, use or retain Your Personal Information on Our behalf.

Protections when communicating outside Quebec. Before disclosing Your Personal Information to third parties outside of Quebec, We conduct a Privacy Impact Assessment to assess the risks that may affect the security of Your Personal Information. This assessment also identifies appropriate security measures that will reduce or eliminate these risks. The disclosure will then be the subject of a written agreement obliging these third parties to comply with such measures.

3.5.4 Complying with Legislation, Responding to Legal Requests, Preventing Harm and Protecting Our Rights

Specific Disclosures of Your Personal Information. We may disclose Your Personal Information when We believe that such disclosure is authorized, necessary or appropriate, including:

  • to respond to requests from public and government authorities, including public and government authorities outside Your country of residence;
  • to protect Our business;
  • to comply with legal process;
  • to protect Our rights, the privacy of Our employees, officers and directors, Our safety and Our property;
  • to protect Your privacy and rights, or the privacy and rights of third parties;
  • to allow Us to pursue available remedies or limit the damages We may sustain; and
  • where it is consistent or required to do so under applicable laws, including laws outside Your country of residence.

3.5.5 Business Transaction

Possibility of commercial transactions. We may share, transfer or communicate, in strict accordance with this Policy and the provisions of the Act respecting the protection of personal information in the private sector, CQLR c P-39.1 (the “Private Sector Act“) and the An Act to modernize legislative provisions as regards the protection of personal information, S.S. 2021, c 25 (the “Bill 25“) (assented to September 22, 2021), Your Personal Information in the event of a sale, transfer or assignment, in whole or in part, of the Company or Our assets (for example, as a result of a merger, consolidation, change of control, reorganization, bankruptcy, liquidation or other business transaction, including in connection with the negotiation of such transactions). In this case, We will notify You before Your Personal Information is transferred and is governed by a different privacy policy.

3.6 Consent

Consents to the Collection, Use or Disclosure of Personal Information. Unless otherwise required by law, the Company obtains Your consent for the collection, use and disclosure of your Personal Information by Us. However, if You provide Us with Personal Information about other individuals, You must ensure that You have given them due notice that You are providing their information to Us and that you have obtained their consent to such disclosure.

Criteria for Consent Required. We will seek Your manifest, free, informed and specific purpose consent before using or disclosing Your Personal Information for purposes other than those set forth herein. We will also seek Your explicit consent whenever Sensitive Personal Information is involved in any of the Company’s processing activities. We will ask for Your consent for each of the specific purposes in plain and clear terms, distinct from any other information that is disclosed to You.

BY USING OUR WEBSITES, SUBMITTING YOUR PERSONAL INFORMATION BY EMAIL OR USING AN ONLINE FORM, YOU CONSENT TO THIS PRIVACY POLICY AND TO THE COLLECTION AND PROCESSING OF YOUR PERSONAL INFORMATION IN ACCORDANCE WITH THE PRIVACY POLICY.

Refusal to Use the Websites. If You do not consent, please stop using the Websites. Except where otherwise required by law, You may withdraw Your consent at any time upon reasonable notice. Please note that if You choose to withdraw Your consent to the collection, use or disclosure of Your Personal Information, certain features of Our Websites may no longer be available to You or We may no longer be able to offer You some of Our services.

3.7 Retention of Personal Information

Retention of Personal Information. Subject to applicable laws, We retain Your Personal Information only for as long as necessary to fulfill the purposes for which it was collected, unless You consent to Your Personal Information being used or processed for another purpose.

Additional Information. For more information on the periods for which Your Personal Information is retained, please contact Our Privacy Officer using the contact information provided in the section 1b) – Privacy Officer of this Policy.

4. Your rights

List of rights. As a data subject, You may exercise the rights set out below by contacting Our Privacy Officer in writing using the contact details provided in Article 1b) – Data Protection Officer of the Policy. Please note that We may ask You to verify Your identity before responding to any of these requests.

  • You have the right to be informed of the Personal Information We hold about You, its use, disclosure, retention and destruction, subject to the exceptions provided by applicable law;
  • You have the right to access Your Personal Information, to request a copy of the documents containing Your Personal Information, subject to the exceptions provided by applicable law, and to obtain, where applicable, additional details about how We use, disclose, retain and destroy it by sending a written request to Our Privacy Officer at the contact information identified in the section 1b) – Data Protection Officer of this Policy;
  • You have the right to have the Personal Information We hold about You corrected, amended and updated if it is incomplete, ambiguous, not current or inaccurate by sending a written request to Our Privacy Officer at the contact information identified in the section 1b) – Data Protection Officer of this Policy;
  • You have the right to withdraw or modify Your consent to the collection, use and disclosure of some of Your Personal Information collected (as identified in the 1Collection of Personal Information of this Policy) at all times, subject to applicable legal and contractual restrictions;
  • You have the right to request that We cease disseminating Your Personal Information and to de-index any link to Your name that provides access to such information if such disclosure would contravene the law or a court order;
  • You have the right to request that Your Personal Information be disclosed to You or transferred to another organization in a structured and commonly used technological format;
  • The right to be notified of a privacy incident involving Your Personal Information that could cause You serious harm. To this end, we keep a record of all privacy incidents and assess the harm they may cause; and
  • You have the right to file a complaint with the Commission d’accès à l’information, subject to the conditions set out in applicable law.

5. Questions and Complaints

Complaints Process. You may address any complaints about Our privacy practices and policies by contacting Our Privacy Officer using the contact information identified in the 1b) – Data Protection Officer.

Questions. You may also contact Our Privacy Officer with any questions relating to this Privacy Policy using the contact details identified in the 1b) – Data Protection Officer.

Need to identify You. In order to comply with Your request, You may be asked to provide an appropriate identification document or to otherwise identify You.

6. Cookies and Other Similar Technologies

Use of Cookies. Cookies are small text files that are stored on Your device or browser. They collect certain information when You visit the Websites, including Your language preference, browser type and version, the type of device You are using, and Your unique device identifier. If some cookies are deleted after the end of Your browser session, other cookies are stored on Your device or on Your browser in order to allow Your browser to be recognized the next time You visit the Websites.  We use cookies and other similar collection technologies such as pixels (collectively, “Cookies”) to help Us operate, protect and optimize the Websites and Services We offer.

Some Uses of Cookies. If some of the Cookies We use are deleted after the end of Your browser session, other Cookies are stored on Your device or browser in order to allow Us to recognize Your browser the next time You visit the Websites. In particular, they make it possible to ensure the functioning of the Websites, to improve the browsing experience of users and to provide certain data that allows Us to better understand the traffic and interactions that take place on Our Websites as well as to detect certain types of fraud. Cookies do not cause any damage to Your device and cannot be used to extract Your Personal Information.

Possible configuration of the browser. You can set Your browser so that you are informed about the placement of Cookies when You visit the Websites, so that You can decide, in each case, whether to accept or refuse the use of some or all of the Cookies. Please note that disabling Cookies on Your browser may adversely affect Your browsing experience on the Websites and prevent You from using some of its features.

Cookie Policies. To find out more about how We use Cookies, you can see Our Cookie Policy“.

7. Security measures

Purposes of Our Security Measures. We have implemented physical, technological and organizational security measures designed to adequately protect the confidentiality and security of Your Personal Information against loss, theft or unauthorized access, breach, disclosure, copying, communication, use or modification. These measures include, but are not limited to:

  • Administrative measures. On the administrative side, the adoption of a series of measures, policies and procedures as part of the implementation of our information governance program that include:
  • regulate the access, disclosure, retention, de-identification, including destruction or anonymization of Personal Information;
  • determine the roles and responsibilities of Our employees throughout the life cycle of Personal Information and documents;
  • establish procedures for managing and responding to confidentiality incidents;
  • govern the process of requests and complaints relating to the protection and handling of Personal Information.
  • Technical measures. On the technical level, the use of several means such as:
  • the use of a secure server and Secure Socket Layer (SSL) technology;
  • encrypting Our databases and Our service providers’ databases;
  • limitation of access privileges to Personal Information in accordance with the 5.1Access to Personal Information within the Company;
  • the use of backup systems;
  • the use of network monitoring software;
  • the use of a firewall system;
  • the use of encryption and segregation of duties, access controls and internal audits.

Incomplete list of measures. We have not exhaustively listed the set of measures We put in place given the public nature of this Policy.

It is impossible to guarantee a complete absence of risk. Despite the measures described above, We cannot guarantee the absolute security of Your Personal Information. If You have reason to believe that Your Personal Information is no longer protected, please contact Our Privacy Officer immediately using the contact information provided in the section 1(b) – b) Data Protection Officer above.

8. Changes to this Privacy Policy

Right to change this Policy. We reserve the right to change this Policy at any time in accordance with applicable law. If we make any changes, We will post the revised Privacy Policy and update the date in the footer of the Privacy Policy. We will reasonably inform You prior to the effective date of the new version of Our Policy. If You do not agree to the new terms of the Privacy Policy, We invite You to stop using Our Websites and Services. If You continue to use Our Websites or Services after the new version of Our Policy comes into effect, then Your use of Our Websites and Services will be governed by that new version of the Policy.

9. Links to third-party websites

Liability of Third Party Websites. From time to time, We may include references or links on Our Websites to websites, products or services provided by third parties (“Third Party Services“). These Third-Party Services, which are not operated or controlled by the Company, are governed by privacy policies that are entirely separate and independent from ours. We therefore assume no responsibility for the content and activities of these sites. This Policy applies only to the Website and the Services offered by Us.

10. Individuals under the age of 14

Consent of minors under the age of 14. We do not knowingly collect or use Personal Information from anyone under the age of 14. If You are under the age of 14, You must not provide Your Personal Information to Us without the consent of Your parent or guardian. If You are a parent or guardian and become aware that Your child has provided Personal Information to Us without consent, please contact Us using the contact information provided in Section 1(b) above to request that We delete that child’s Personal Information from Our systems.

11. Applicable Laws

Laws of Quebec and Canada. The laws of Canada and Quebec, excluding its conflict of law rules, will govern this Agreement and Your use of the Websites. Your use of the Websites may also be subject to other local, provincial, national or international laws.

Medicart takes good care of you