Privacy at ExcelleMD Inc.
Updated: June 7, 2022
1. What information do we collect?
Unless you opt-out, our website uses “Cookies” and other automatic data collection technologies with your consent to collect personal information whenever you visit or interact with the Website, including unique identifiers and preference information such as IP address, technical usage, browser type, time zone settings, language preferences, operating system, unique device identifiers, search history, page response times and length of visit, pages viewed, marketing preferences or navigation and clickstream behavior for online interactions.
These Cookies helps us understand how you use the Website and the content of the Website in order to make improvements. We also may use these Cookies to promote our services through marketing and advertising. These Cookies may be accessed or disclosed to third-parties, such as Google Analytics and Facebook Pixel, for the purpose of analyzing site usage and better serving you relevant advertisements.
You can opt-out of Cookies or prevent third-party websites from accessing our Cookies through the privacy settings on your browser. However, opting-out of our Cookies may disable some of the Website’s features, and may prevent us from providing you with the information and services you have requested.
Website Forms and Patient Portal
When you submit a form on the Website (or send us an e-mail), we will collect some personal information about you, like your name, e-mail, phone number, health care card, address and other information you enter (including any photos you may upload). This information will be used to create a profile with ExcelleMD, verify your identity, respond to your inquiry, or to allow us to follow-up with you directly. This information may also be stored within ExcelleMD’s electronic medical record system if you are a patient of ExcelleMD.
If you sign up to receive direct marketing or promotional communications from ExcelleMD or WELL, we will collect your name and e-mail to inform you about the requested products and services.
At the Clinics, we will collect some personal information about you, like your name, e-mail, phone number, address, and insurance/payment information. This information will be used to create a profile with ExcelleMD, verify your identity, communicate with you, and bill the relevant insurers for the healthcare services provided to you. WELL will also collect, either directly from you and potentially from other health service professionals or resources, personal health information about you. This information can include presenting problems, health
history, health conditions and treatments provided. Only the personal health information necessary to provide you with the requested health services will be collected and stored.
2. Why do we use personal information?
We use your personal information to:
- manage our relationship with you and provide you with the information you request,
- conduct research and evaluate research and development on the Website and at our Clinics including analyzing testing data to improve our services,
- communicate with you regarding inquiries for information, service requests, employment opportunities, or appointment reminders,
- detect, prevent or investigate security breaches,
- process insurance information or other payment information,
- protect our business against error, fraud, theft and damage,
- maintain appropriate records for internal administrative purposes or as required by law,
- review the diagnoses, treatment and services provided to you,
- conduct appropriate consultation and follow-up, and
- book appointments at hospitals and other health services as appropriate as per the order of the consulting physician.
We reserve the right to aggregate and anonymize personal information collected and to use such aggregated information as we see fit.
3. Who do we share the personal information with?
Exceptionally, we may collect, use or disclose personal information without your consent in the following limited circumstances:
- when the collection, use or disclosure of personal information is permitted or required by law or by regulatory proceedings,
- in an emergency that threatens an individual’s life, health, or personal security,
- when we require legal advice from a lawyer,
- to protect ourselves from fraud,
- to a collection agency in order to collect our unpaid accounts; or
- to investigate an anticipated breach of an agreement or a contravention of law.
If we merge with another business, we will inform you of any impact on your personal information.
We only share your personal information with service providers in order to operate the Website. This includes potentially sharing your personal information for:
- providing requested services or information,
- operating and optimizing the Website, or
- customer service.
We may share your personal information, including your personal health information, with service providers in the course of administering health services to you. This includes potentially sharing your personal information to:
- refer you to a specialist or another health professional,
- conduct tests or lab work,
- process payments or to bill the relevant insurance providers, or
- provide you access to requested information or reports via a service provider.
4. How long do we keep personal information?
We retain personal information for as long as required to provide the services for which it was collected, otherwise, in accordance with applicable legal and regulatory requirements.
All personal health information collected at the Clinics will be retained for at least five years, as required by the Collège des médecins du Québec.
5. How do we keep personal information accurate?
We take reasonable steps to ensure that any personal information in our custody is accurate and up to date but we mostly rely on you to notify us of any changes to personal information you provided us.
6. How do we protect your personal information?
We use reasonable and appropriate physical, administrative and technical measures designed to help you secure your personal information against accidental or unlawful loss, access or disclosure. Only staff and service providers who have a legitimate purpose for accessing the personal information collected by us are authorized to do so. Security and data protection training is also provided to all ExcelleMD staff. Unauthorized use of personal information by anyone affiliated with ExcelleMD or WELL is prohibited and constitutes grounds for disciplinary action.
All of our contracts with our third-party service providers, including our EMR providers, contain clauses specifically to address confidentiality and data management, and covenants ensuring compliance with privacy law and the protection of personal health information.
Even though we take all necessary steps to protect your personal information, security breaches cannot be eliminated and we cannot guarantee no breach will ever occur.
7. Where do we store personal information?
All personal information we collect on our Website is collected via secured connections and stored on secure servers in Canada; however, personal information processed by our third-party service providers may be done outside of Canada. While outside of Canada, personal information is subject to that jurisdiction’s laws, which may permit governmental authorities the right to access your personal information.
For more information on our service providers or where we store personal information, contact us at email@example.com.
All personal health information we collect at the Clinic is stored within electronic medical records (EMR). Our agreements with our EMR vendors, and all other third-party service providers used in the operations of the Clinic, ensure that all personal health information remains in Canada and that our vendors comply with all relevant privacy laws and adhere to certain data protection standards.
For more information on our Clinic’s third-party service providers and how your personal health information is protected, contact us at firstname.lastname@example.org.
8. Links to third-party sites
Our Website may lead you to third-party websites, including websites advertising other products or services. Those organizations are separate and distinct from WELL and have their own separate privacy policies. We are not responsible in any way for how any third-party collects, uses or discloses your personal information, so it is important to familiarize yourself with the privacy policies of these websites before providing your personal information to them.
9. Direct marketing
You may sign up to receive marketing or promotional communications from WELL or ExcelleMD. Where you have expressly consented, we may use your personal information to inform you about us and products and services offered by WELL or ExcelleMD, including promotional offers and events.
If you no longer wish to receive marketing or promotional communications from us, you can opt-out at any time by:
- using the unsubscribe feature found in our emails and other electronic communications,
- contacting us via email at email@example.com.
We remove your contact information from our marketing lists within 48 hours as soon as you unsubscribe.
We will obtain the patient’s or physician’s consent to collect, use or disclose personal information (except where we are authorized to do so without consent). Consent can be provided orally, in writing, electronically, through an authorized representative, or it can be implied when the purpose for collecting, using or disclosing the personal information would be considered obvious, and the patient provides personal information for that purpose.
11. Your rights
You also have the right to:
- rescind or withdraw your consent to the use or disclosure of personal information,
- request to access your personal information, including your personal health information,
- request us to restrict our use or disclosure of your personal information,
- object to our use or disclosure of your personal information,
- request that we edit, but not remove, certain information (like an e-mail address),
- request that we transfer to another organization the personal information you have provided us, and
- request us to delete the personal information we hold about you.
Contact us at firstname.lastname@example.org to exercise any of these rights. If you request access to your personal health information, we may refer your request to the relevant healthcare provider to comply with your request. We will respond within 30 days. If we cannot grant your request, for example if you make an access request and providing you access would disclose personal information about another person, we will give reasons.
We will address all requests with equal attention.
12. Contacting us
If after contacting us you are still not satisfied, you have the right to file a complaint with your local privacy authority.