Personal Information Protection Policy

Last modification: 2017/12/14

  1. Introduction

    This Personal Information Protection Policy (the "Policy") of Protexio Inc. ("Protexio"), owner and operator of the online platform and mobile application named "Protexio" (collectively, the "Platform"), is modelled after the principles set out in the "Model Code for the Protection of Personal Information" (CAN/CSA-Q830-96).

    Nothing in this Policy has the effect of creating obligations for Protexio beyond those imposed by applicable laws and regulations pertaining to the protection of personal information.

    Protexio recommends that you read this Policy attentively and review it periodically, since it may be subject to modifications for time to time.

    In this Policy, "Personal Information" means any information which relates to a natural person and allows that person to be identified, and "Individual" or "you" refer to you as a customer, customer representative or employee of Protexio or as a user of the Platform or any of the services provided on the Platform (the "Services").

    When you use the Platform or the Services, you agree, without reserve or restriction, to the terms and conditions of this Policy as well as all other regulations, terms, conditions and policies posted on the Platform, namely the Terms of Use accessible at [URL]. If you do not accept the terms and conditions of the Policy and the Terms of Use, please refrain from using the Platform and the Services immediately.

  2. Accountability

    Protexio has designated individual(s) accountable for Protexio's compliance with this Policy. Accountability for Protexio's compliance with this Policy rests with the designated individual(s), even though other individuals working for Protexio may be responsible for the day-to-day collection and processing of Personal Information. Other individuals working for Protexio may be delegated to act on behalf of the designated individual(s).

    The identity of the individual(s) designated by Protexio to ensure Protexio's compliance with this Policy will be disclosed upon request if not specified herein.

  3. Purposes

    The purposes for which Personal Information is collected will generally be determined by Protexio at or before the time of collection.

    Your consent to the collection, use or disclosure of your Personal Information must be manifest, free and enlightened. Such consent will be valid only for the length of time needed to achieve the purposes for which it was requested.

    Protexio may collect your Personal Information for the following purposes:

    Protexio will solicit your consent before using the Personal Information for purposes other than those previously identified, unless the new purposes are provided for by applicable laws or regulations.

    Upon request, Protexio will explain to you the purposes for which the Personal Information is being collected.

  4. Consent

    Your consent to the collection, use and disclosure of your Personal Information will be solicited, except where inappropriate (for example, legal, medical or security reasons may make it impossible or impractical to seek your consent.)

    Generally, Protexio undertakes to seek your consent before or at the time of collection of Personal Information.

    To make the consent meaningful, the purposes for which the Personal Information will be used will be stated in such a manner that you can reasonably understand how the Personal Information may be used or disclosed.

    Protexio will not, as a condition of the supply of a product or service, require your consent to the collection, use or disclosure of Personal Information beyond that required to fulfil the purposes.

    The way in which Protexio seeks consent may vary, depending on the circumstances and the type of Personal Information collected. Protexio will generally seek express consent when the Personal Information is likely to be considered sensitive. Implied consent may generally be appropriate when the Personal Information is less sensitive. Consent can also be given by an authorized representative. Consent will not be obtained through deception.

    You can give consent in many ways. For example:

    You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice.

  5. Limited Collection

    The collection of Personal Information will be limited to the purposes identified by Protexio. Information will be collected by fair and lawful means.

    Personal Information collected may include, but is not limited to, your name and surname, your email address, your age, your medical condition, whether you suffer from any disease, the medications you take and your banking information.

    We could also log information collected through cookies and other tracking technology in order to collect information about your browsing behavior when you visit the Platform, namely your Internet protocol address, length of visits on the Platform, etc. Please note that this information could be linked to your Personal Information, but for Protexio's internal use only. Most Internet browsers automatically accept cookies, but you may change the settings of your browser to reject cookies. If you set your browser to reject cookies, parts of the Platform and/or Services may however not be accessible to you.

    The Platform may contain links to third-party websites, which are not under the control of Protexio. These third-party websites may collect information, such as Personal Information, about you. We invite you to consult the privacy policies applicable to such third-party websites, as they may differ from this Policy.

  6. Limited Use, Disclosure And Retention

    Personal Information will not be held, used or disclosed for purposes other than those for which it was collected, except with your consent or as required by law. Personal Information will be retained only as long as necessary for the fulfilment of those purposes.

    According to applicable laws, Protexio may be required to retain, in whole or in part, your Personal Information for a longer period than what Protexio would have normally decided. However, Protexio will limit the access to such Personal Information so that it will only be used to satisfy its legal obligations.

    Protexio will not disclose your Personal Information to a third person, without your consent or if such disclosure or use is provided by applicable law. For instance, Protexio's authorized employees, mandataries, agents or any supplier of Protexio with whom Protexio has a contract of employment or service, may have access to Personal Information without your consent, if the Personal Information is needed for the performance of their respective duties or the carrying out of their respective mandates or contracts.

  7. Accuracy

    Personal Information will be as accurate, complete and up-to-date as is necessary for the purposes for which it is to be used.

    Protexio will not routinely update Personal Information, except if necessary to fulfil the purposes for which the Personal Information was collected. The extent to which Personal Information will be accurate, complete and up-to-date will depend on (i) your data entries or (ii) the data generated by your use of the Platform and the Services.

  8. Safeguards

    Personal Information will be protected by security safeguards according to their degree of sensitivity.

    Protexio will take the necessary and reasonable security measures to ensure the protection of the Personal Information collected, used, disclosed, held or destroyed, according to the sensitivity level of the Personal Information, the purposes for which it is to be used, the quantity and distribution of the Personal Information and the medium on which it is stored.

    The methods of protection include:

    Protexio will make its employees aware of the importance of maintaining the confidentiality of Personal Information, and special care shall be taken in the disposal or destruction of Personal Information, to prevent unauthorized parties from gaining access to the Personal Information.

    Your Personal Information shall be stored in a secure way on the servers associated to the Platform. If your Personal Information is stored on Protexio's services providers' servers, these providers will be subject to strict contractual obligations, requiring them to maintain the confidentiality of all Personal Information and to use such information only for the provision of their services.

    Given the public nature of Internet, you acknowledge and understand that the security of communications via Internet cannot be guaranteed. Protexio may not guarantee, and may not engage its liability in any way for any violation of confidentiality, and any piracy, virus, loss, theft or modification of the information transmitted or stored on Protexio's systems or via cloud computing. Further, by communicating your Personal Information to Protexio, you consent that your Personal Information may be transferred outside the jurisdiction of Canada, due to the reality of cloud computing.

    In order to insure an additional level of security of your Personal Information, Protexio recommends that you never disclose your account identifiers, since they may give access to your Personal Information. Protexio also recommends that you close your access session and close your browser or mobile application window, after your use of the Platform.

    It is your responsibility to maintain the confidentiality of your account identifiers. As such, you are responsible for any activity occurring from your account or with your account identifiers.

    If you believe that the confidentiality of your user account or your account identifiers has been compromised in any way, please contact us immediately at info@protexio.ca.

    Notwithstanding the foregoing, Protexio may rely on the authority of any person having access to a user account or using the information giving access to such account, and in no event shall we be held responsible for any fees, civil liability or damage arising from : (i) an action or omission on our part regarding such stipulation; (ii) the compromise of the confidentiality of a user account or information giving access to such account; (iii) the unauthorised access to a user account or unauthorised use of information giving access to such account.

  9. Openness

    Protexio is open about its practices with respect to the management of Personal Information. You will be able to obtain information about such practices without unreasonable effort and such information will be available in a generally understandable and accessible form.

    The information provided shall include:

  10. Individual Access

    Generally and upon request, Protexio shall give you access to your Personal Information. You may be required to provide information to allow Protexio to provide you with an account of the existence, use and disclosure of your Personal Information.

    No request for access, rectification or deletion may be considered unless it is made in writing, by you, and unless you can prove that you are the individual concerned by the request (or such individual's representative, heir, successor, liquidator of its succession, or beneficiary of life insurance or of a death indemnity).

    Protexio will respond to a request for access or rectification within a reasonable time after the receipt of such request. The requested information will be provided in a form that is generally understandable.

    In certain situations, Protexio may not be able to communicate all the Personal Information it holds about you. However, these situations are meant to be limited and specific and the reasons for denying access will be provided to you upon request. For example, if providing the information is too costly, if the information contains references to other individuals, if the information cannot be disclosed for legal, security or commercial reasons, or if the information is subject to solicitor-client or litigation privilege.

    Reasonable fees may be required for the transcription, reproduction or transmission of Personal Information.

  11. Challenging Compliance

    You may forward your complaints and requests for information concerning Protexio's policies and practices regarding the protection of Personal Information at:info@protexio.ca.