Privacy Policy

PRIVACY POLICY

PocketMD Corporation together with our affiliates and partners (“us”, “we”) respect your privacy and collect, use or disclose your personal information (“PI”) and personal health information (“PHI”) only in accordance with our Privacy Policy and applicable federal and provincial privacy legislation (“Privacy Laws”).

This Privacy Policy describes how we collect PI and PHI through: (1) our websites (the “Websites”); (2) our mobile applications (the “Apps”) and (3) our Virtual Care Platforms (collectively, the “Platforms”), how we use PI and PHI and the manner in which PI or PHI may be disclosed or shared by us. The term "you" refers to the person or entity visiting the Platforms, browsing or otherwise using the Platforms, or receiving any services through the Platforms.

This Privacy Policy does not apply to the collection, use and disclosure of PHI by health care professionals ("HCPs") or personal health assistants (“PHAs”) in the course of providing telehealth or telemedicine services (“Health Services”) or assisting with the provision of services (“Support Services”) respectfully. HCPs are subject to their own respective privacy laws and professional requirements that govern how they collect, use and disclose PHI

The Platforms enable HCPs to receive your PI and PHI through the Platforms and to provide Health Services to you. Your use of the Platforms neither establishes nor governs your relationship with the HCP. The Health Services provided to you by HCP form a bilateral contractual relationship between you and HCP and we are not parties to this agreement.

Consent for the collection, use and disclosure of personal information

When you sign up for or use the Platforms we ask you to confirm that you have read and agree to our Privacy Policy. By submitting your PI or PHI through the Platforms, you consent to the collection, use, and disclosure of such information as set out in this Privacy Policy.

What PI and PHI do we collect and use?

Generally, you may browse our Websites or the Apps without providing any PI. You are under no obligation to provide us with PI, with the caveat that your refusal to do so may prevent you from using certain portions of the Websites or the Apps.

As set out above, HCPs and PCAs are responsible for the collection, use and disclosure of PI and PHI as it relates to the provision of Health Services and Support Services and for ensuring that adequate safeguards are in place to protect that information. The following overview provides general information about how PHI or PI is collected and used through the Platforms.


User Accounts

In order to use the Platforms and to receive Health Services and Support Services you will be required to create a user account (the "User Account") through the Platforms and be issued a username and password login credentials ("User ID"). We collect information such as your name, email address, phone number, gender, date of birth and province or territory to create your User Account. If you are issued a User ID, you will be required to keep your User ID secure.

The Health Services and Support Services are also available for use by children at the discretion of the HCP or PHA. For all patients under the age of 18, the holder of the User Account and User ID, must be the patient’s parent or legal guardian. You may be asked to provide PI or PHI about your child in order to register them to use your User Account (“Registered Child”).


Provision of Health Services and Support Services

We collect PI or PHI on behalf of the HSP or PHA when you request Health Services or Support Services to facilitate the provision of those services and to assist you in connecting with the HCP of your choice.

We collect your provincial health card number in order to bill provincial health plans for those services that are eligible for coverage by provincial health plans on behalf of the HCP and/or your financial information to facilitate payments in respect of your use of the Platforms or the receipt of any services through the Platforms.

HCPs and PHAs collect and use PI and PHI about you or a Registered Child in order to provide you or your child with Health Services and/or Support Services. HCPs and PHAs may collect PHI about you verbally or by text, including the reason for your consultation request; relevant health history and present condition or symptoms. The HCP may access PHI that you have entered or uploaded to your profile and medical records or information created during earlier interactions through the Platforms with other HCPs or PHAs.

HCPs and PHAs must comply with professional regulatory requirements, including as it relates to confidentiality and privacy and record keeping, as well as privacy laws.

HCPs may create information such as prescriptions, sick notes and other notes about your interaction with them via the Platforms.


Platform Services

There are a number of optional services that may be provided through the Platforms, where authorized. We may collect and use your PHI or PHI to provide you with services that you request us to perform on your behalf, e.g., securely faxing your prescription to your chosen pharmacy, a summary report about your Healthcare Services to a physician of your choice; open an account for you with a prescription delivery service; and, where available, securely transmit your information to the prescription delivery service (collectively, "Platform Services").


How do we use your PI and PHI?

We use your PI and PHI for the purposes for which it was collected, as well as other purposes for which you have given consent. In addition to those purposes set out above, this includes, but is not limited to, the following purposes:

Administration of your User Account

Marketing: In accordance with anti-spam laws, we obtain your consent in order to send you commercial electronic messages.We do not share email addresses or other contact information with third parties without your permission.

Notifications: We will ask you if you wish to receive notifications about services that you request. If you agree, we will send you email or text messages to we notify you about the status of your consultations and other requests, such as prescription orders.

We also may use your PI or PHI to comply with our legal obligations, resolve disputes, and enforce our agreements and as required and/or permitted by applicable privacy laws.


Disclosing PI or PHI to third parties

We will not disclose, share, sell or rent your PI or PHI with or to any third party, except with your written consent or as required or permitted by privacy laws. We may disclose your PI or PHI as we deem necessary, in our sole discretion, to comply with any applicable law, regulation, legal process or governmental request.

In some instances we may retain other companies and individuals to perform functions on our behalf, including, but not limited to website developers, service and technology providers. Third parties may be provided with access to your PI or PHI to perform the functions for which they have been retained. Our agreements with third parties will not permit them to use your PI or PHI for any other purposes and commit them to comply with applicable data privacy standards.

We have partnered with third parties that license our Platforms, including telemedicine platforms accessible through the apps of such third parties and content and services that support such apps. To use our Platforms as provided under license by such third parties, you must agree to all of the terms and policies such third parties impose upon such Platforms and such third parties bear all liabilities for your use of the Platforms, including as it relates to your PI and PHI

Only HCPs and PSAs have access to your PI and PHI. HCPs and PHAs may disclose PHI about you, including to your emergency contact, if they believe that you are dealing with a medical emergency during a consultation and disclosure is necessary in order to eliminate or reduce the risk of serious harm.


Security Safeguards

All PI and PHI collected on the Platforms is securely and digitally stored on servers physically located in Canada. The Platforms are secured through encryption technologies and only you and your HCPs and PHAs have access to your PI and PHI. PHI created in connection with the provision of Health Services is managed by the HCP in accordance with applicable privacy legislation. The Platforms are licensed by us to your HCP and are used by your HCP to communicate with you.

We use physical, organizational and technical industry-standard security safeguards commensurate to the sensitivity of data collected, used or disclosed such as encryption in transit and at rest. We use a variety of technologies and procedures to help protect the security of your PI and PHI from unauthorized access, use, or disclosure.

We have implemented and maintain reasonable and appropriate security measures, procedures and practices to protect against the loss and unauthorized access, use, modification, destruction or disclosure of your PI and PHI while it is our custody or under our control.

Although we use advanced encryption technology and other security protocols to protect your PI and PHI and the privacy of the Health Services and Support Services with HCPs and PHAs, in using the Platforms there are inherent risks to any technology however remote that could cause security protocols to fail or to be breached and which could result in the unauthorized collection, use or disclosure of your PI and/or PHI.


Retention of PI and PHI

We will retain your PI and PHI on the Platforms until such time as you or we terminate your User Account. On termination, you will have an opportunity to print or make copies of any PI or PHI held in the Platforms, provided that we have the appropriate authorization from the applicable HCP and/or PHA relating to the Health Services or Support Services.


How can I access or correct my PI or PHI?

You can add, edit, or delete optional information appearing in your User Account at any time in your account settings. You can edit, but not remove, certain information (like an email address or any information pertaining to the cumulative patient profile).

In connection with the provision of Health Services, you have additional rights under applicable privacy laws. You may request access or correction to your health records, withdraw your consent or request limits on the collection, use or disclosure of your PHI for health care purposes by contacting your HCP.


Children

We are committed to protecting the privacy of children. The Platforms are not intended or designed for children. We do not collect PI from any person we actually know is a child. Where applicable, a Registered Child may use the Platforms through their parent or legal guardian.


Cookies

A "cookie" is a data element that a website can send to your browser, which may then be stored on your system. The Platforms use different kinds of cookies and/or use services which use “cookies”. The cookies used by the Platforms do not contain any PI or PHI about you, but they may identify your specific computer or mobile device. We do not save PI or PHI on cookies without your permission.

We use cookies for a variety of purposes, including evaluating usage of the Platforms, to improve our Platform and to compile reports on Platform activity. We may also use cookies to track activity and click-through behavior to better understand your preferences and browsing habits, and to provide a more personalized experience while visiting the Platforms, and for more personalized email alerts.

Most browsers accept cookies automatically, but can be configured not to accept them or to indicate when a cookie is being sent. You may refuse the use of cookies by selecting the appropriate settings on your browser. However, please note that if you do this, you may not be able to use the full functionality of the Platforms.


Analytics and Interest-Based Advertising

Our third party vendors or service providers may also use cookies and web beacons to measure the effectiveness of our ads and to determine the content and advertising to offer you based on your interests. To support these activities, we, our service providers, and business partners may use information about your visits to our Platforms. You may opt out of other third-party vendor's use of cookies by disabling cookies on your browser. Please note that even if you choose to disable cookies you will still see advertisements while browsing online. However, the advertisements may be less relevant to you and your interests.

We may also use third-party service providers to monitor and analyze the use of our Platforms. Google Analytics is a web analytics service offered by Google Inc. (“Google”) that tracks, monitors and reports traffic on our Platform. Google tracks information like (i) your IP address; (ii) the type of web browser and operating system being used; (iii) the pages of the Platform that you visit; and (iv) other websites you may have visited before visiting our Platform.

Google may also transfer this information to other third parties where they are required to do so by law, or where such third parties process the information on their behalf. You can opt-out of having your activity on the Platforms made available to Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents the Google Analytics JavaScript (ga.js, analytics.js, and dc.js) from sharing information with Google Analytics about a visitor’s activity. For more information on Google’s privacy practices, please visit: https://policies.google.com/technologies/partner-sites.


Anti-spam

Where applicable, we will seek your express consent to contact you, including by way of commercial electronic messages. This consent is sought by PocketMD and you can contact us at team@pocketmd.ca. You can unsubscribe at any time from receiving commercial electronic messages by following the instructions in the message.

Even if you have opted out of receiving marketing communications from us, please be aware that we may still contact you for other purposes. For example, we may contact you to provide communications you have consented to receive, regarding the services we provide to you, or if you contact us with an inquiry.


Third- Party Sites

The Platforms may contain links to other third-party sites. When you click on one of these links you are visiting a website operated by someone other than us and the operator of that website may have different privacy policies. We are not responsible for the individual privacy practices of those sites. We encourage you to investigate the privacy policies of these third-party operators.


Governing Law

All matters relating to your access or use of the Platforms shall be governed by the laws of the Province of Ontario and the laws of Canada applicable therein, without regard to principles of conflicts of law. You agree and hereby submit to the exclusive jurisdiction of the courts of the province you reside in with respect to all matters relating to your access and use of the Platforms, as well as any dispute that may arise therefrom.


Contacting us

Should you have any questions or concerns about this Privacy Policy or our practices, you may contact us at team@pocketmd.ca

You may also contact the Office of the Privacy Commissioner of Canada or provincial

Information and Privacy Commissioner (as applicable) with any questions or concerns


Revisions to this Privacy Policy

We reserve the right to change this Privacy Policy at any time and such modifications shall be effective immediately, as of the date indicated below