1. Our PIPEDA commitment
How gojiCare aligns with the Personal Information Protection and Electronic Documents Act (PIPEDA) and provincial equivalents.
Scope of this policy
[v1 placeholder. pending legal review by gojiCare counsel] This policy applies to all personal information collected by gojiCare through the website, the intake questionnaire, the patient portal, customer-support channels, and any other interaction with our service.
Fair information principles
[v1 placeholder. pending legal review by gojiCare counsel] We follow the ten fair-information principles set out in PIPEDA: accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance.
Provincial health-information laws
[v1 placeholder. pending legal review by gojiCare counsel] Where provincial legislation applies. including PHIPA in Ontario, HIA in Alberta, PHIA in Nova Scotia and Manitoba, the Act respecting the protection of personal information in the private sector in Quebec, and others. we apply the standard most protective of you.
2. Information we collect
The categories of personal information gojiCare collects and the source of that information.
Account information
[v1 placeholder. pending legal review by gojiCare counsel] When you create an account we collect your name, email address, phone number, postal code, date of birth, and a hashed password.
Health information
[v1 placeholder. pending legal review by gojiCare counsel] During intake we collect health-history information, current medications, allergies, presenting concerns, lifestyle factors, and any photos or test results you submit. This is sensitive personal health information and receives the highest level of protection.
Technical information
[v1 placeholder. pending legal review by gojiCare counsel] We collect device, browser, and approximate-location information automatically through cookies and server logs. See section 8 for cookie details.
3. How we use your information
The specific purposes for which we use your personal and health information.
Delivering clinical care
[v1 placeholder. pending legal review by gojiCare counsel] The licensed Canadian provider reviewing your intake uses your health information to assess eligibility, prescribe (or decline to prescribe), and adjust your treatment plan. The dispensing pharmacy uses the prescription to fill and ship your medication.
Operating your account
[v1 placeholder. pending legal review by gojiCare counsel] We use account information to authenticate you, process payments, fulfill shipments, send shipment notifications, and provide customer support.
Service improvement
[v1 placeholder. pending legal review by gojiCare counsel] We use de-identified usage data to understand how the service is used and to improve it. We do not use your identifiable health information for product analytics or marketing.
5. How long we keep your information
Retention periods for the different categories of information we hold.
Clinical records
[v1 placeholder. pending legal review by gojiCare counsel] Clinical records are retained for the period required by the regulator of the prescribing province (typically ten years from the most recent encounter, or longer for minors). This period applies regardless of whether your account is active.
Account data
[v1 placeholder. pending legal review by gojiCare counsel] Account profile data is retained while your account is active and for a limited period thereafter so we can respond to inquiries, comply with tax and audit obligations, and resolve disputes.
Requesting deletion
[v1 placeholder. pending legal review by gojiCare counsel] You can request deletion of non-clinical account data at any time (see section 7). Clinical records subject to a regulator-mandated retention period cannot be deleted before that period expires.
6. How we protect your information
The administrative, technical, and physical safeguards we use to protect your information.
Encryption
[v1 placeholder. pending legal review by gojiCare counsel] Personal and health information is encrypted in transit (TLS 1.2+) and at rest. Database backups are encrypted with separate keys.
Access controls
[v1 placeholder. pending legal review by gojiCare counsel] Access to identifiable health information is limited to the clinical and operational staff who need it to deliver your care. Access is logged and audited.
Data residency
[v1 placeholder. pending legal review by gojiCare counsel] Personal health information is stored in Canadian data centres operated by Canadian-jurisdiction providers. Cross-border processing, where it occurs at all, is limited to non-health metadata required for service operation and is disclosed in advance.
Incident response
[v1 placeholder. pending legal review by gojiCare counsel] If a privacy breach occurs that creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada (and the relevant provincial regulator) without undue delay, as required by law.
7. Your privacy rights
The rights you can exercise over your information and how to do so.
Right of access
[v1 placeholder. pending legal review by gojiCare counsel] You have the right to access the personal information we hold about you. Submit a request to privacy@gojicare.ca and we will respond within thirty (30) days.
Right of correction
[v1 placeholder. pending legal review by gojiCare counsel] You may ask us to correct inaccurate or incomplete personal information. Some clinical records can only be amended with an addendum rather than a deletion, in line with regulator requirements.
Right to withdraw consent
[v1 placeholder. pending legal review by gojiCare counsel] You can withdraw consent to most uses of your information at any time, subject to legal or contractual restrictions. Withdrawing consent for clinical processing will end your access to ongoing clinical care through gojiCare.
Right to complain
[v1 placeholder. pending legal review by gojiCare counsel] If you believe we have not handled your information properly, contact privacy@gojicare.ca first so we can investigate. You also have the right to file a complaint with the Office of the Privacy Commissioner of Canada or your provincial commissioner.
9. How to reach our privacy team
Who to contact at gojiCare for any privacy question or request.
Privacy officer
[v1 placeholder. pending legal review by gojiCare counsel] Privacy questions, access requests, and complaints can be sent to our Privacy Officer at privacy@gojicare.ca. We will acknowledge your request within ten (10) business days and respond substantively within thirty (30) days.
Mailing address
[v1 placeholder. pending legal review by gojiCare counsel] Written correspondence may be sent to: gojiCare. Privacy Officer, [mailing address pending]. Please do not include unsolicited health information in physical mail.
10. Changes to this policy
How this privacy policy may be updated and how you will be notified.
Updates
[v1 placeholder. pending legal review by gojiCare counsel] We may revise this policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision.
How you will be notified
[v1 placeholder. pending legal review by gojiCare counsel] For material changes that affect how your information is used, we will notify you in advance by email or through the patient portal. Continued use of the service after the effective date constitutes acceptance of the revised policy.