1. Purpose
CCNI is licensedto sell medical cannabis as defined in the Cannabis Act (the “Cannabis Act”). CCNI is committed to receive, collect, and safeguard the Personal Information of our employees, patients, physicians, customers, and other stakeholders (the “Users”).
This policy describes CCNI’s personal data management practices in relation to
- Your registration as a client
- The purchase of regulated medical cannabis products
- Browsing of CCNI’s website and its affiliated entities
- Subscription to CCNI’s newsletter
For the purposes of this Privacy Policy, all data collected by CCNI will not be disclosed to a third party, unless required to do so by law. All Personal Information will be held on the highest levels of confidentiality and security consistent with this policy.
Our websites may contain links to third party websites, applications and services. The content and practices of other websites are governed by the privacy policies of those websites. The Company recommends you review the privacy statements of those websites to understand their information practices.
The Company will ensure that all employees and third party service providers are aware of the importance of maintaining the confidentiality of personal information, and the access to information is under the condition of employment or provision of services.
Your privacy is of utmost importance to our company. Please take the time to get to know our practices, and feel free to contact our Privacy Officer at info@buymedicalcannabiscanada.ca or by phone (905) 946-8444 if you have any further questions.
2. What is Personal Information/Data?
Personal Information or Personal Data refers to information about an identified or identifiable individual. For the purposes of this Privacy Policy, the term “personal information or data” also encompasses “personal health information” as set out in Ontario’s Personal Health Information Protection Act, 2004 (PHIPA).
This may include information relating to not only the individual’s contact information, name, address, phone, email address, date of birth, gender, but also individual’s physical health, mental health, health providers, health card number, health care services, etc. that you have chosen to provide electronically, i.e. through the Patient Registration Application Form.
The use or disclosure of your collected personal information will be held effective without your knowledge or consent in limited circumstances where we are required to do so by law. We will cooperate and take appropriate measures to ensure the sensitivity of releasing your personal information in response to a court order, subpoena, search warrant, law or regulation is met and understood.
3. How do we obtain your consent to collect your Personal Information?
By using this website or by otherwise providing personal information to the Company, you agree to this Privacy Policy and that we may collect, use and disclose your personal information in accordance with it. You may withdraw your consent at any time in writing. Please contact our Privacy Officer at info@buymedicalcannabiscanada.ca or by phone at (905) 946-8444 to find out how to withdraw your consent. We will obtain your consent before collecting, using, or disclosing your personal information for new purposes unrelated to the purposes described in this Privacy Policy.
Typically, we will seek your consent at the time we collect your personal information. Your consent may be implied, deemed (using an opt-out mechanism), or express. Implied consent can be reasonably inferred from your action (e.g. entering into an agreement with us or providing payment) or inaction. Express consent can be given orally, electronically or in writing.
The Company will primarily most often collect personal information directly from you. In cases where personal information is required held by a third party, such as the medical practitioners, we will obtain your consent apply to before seeking this information. In some cases, consent may be implied by your actions. Where we obtain your personal information directly from a third party, we will take reasonable steps to ensure that the third party has represented to us that it has the right to disclose your personal information to us.
Personal data collected on this website may also be combined with information you provide us through other sources such as medical practitioners, other Company websites, product registration, call centers, or in conjunction with events such as trade shows, training seminars, and conferences. Information that you supply will relate to the relationship that the Company has with you or your organization.
4. What Personal Information do we collect?
The Company only collects the amount and type of Personal Information that is necessary for the purposes for which the Personal Information is collected. What follows is the type of Personal Information that we may collect, depending on your relationship with the Company and how you use our services.
A. PERSONAL INFORMATION OF EMPLOYEES
- The following list includes, but is not limited to, the Personal Information that may be collected by the Company respecting employees:
- Contact information, including name, home address, telephone number, email address;
- criminal background check(s);
- Employment information, including resume (which may include educational background, work history, and references), reference information and interview notes, letters of offer and acceptance of employment, policy acknowledgment forms, background verification information, workplace performance evaluations, emergency contacts;
- Benefit information, including forms relating to applications or changes to health and insurance benefits including medical and dental care, life insurance, short and long- term disability; and
- Financial information, including pay cheque deposit information and tax-related information, and Social Insurance Number or other required government issued identification.
B. PERSONAL INFORMATION OF PATIENTS
The following list includes the type of Personal Information that may be collected respecting users that register with the Company as patients (“Patients”) and utilize the Company’s services for medical cannabis in accordance with the Cannabis Act and its regulations (the “Legislation”):
- name, date of birth, gender, home address, telephone number, email address;
- credit card or other financial information;
- health care information, including health card number, any relevant diagnosis or primary condition, information respecting the health care services provided to you, and information about your health status;
- insurance coverage and payment information, if applicable;
- information in connection with the products or services you inquire about or purchase from us; and
- usage data respecting use of the Company’s website(s) through the website(s) (or through third-party services employed by the website(s)) which can include the IP addresses or domain names of the computers utilized by the User; the URL addresses; the time of the request; the method utilized to submit the request to the server; the size of the file received in response; the numerical code indicating the status of the server’s answer (successful outcome, error, etc.); the country of origin; the features of the browser and the operating system utilized by the User; the various time details per visit (e.g., the time spent on each page within the website(s)); and the details about the path followed within the website(s) with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.
C.PERSONAL INFORMATION OF PHYSICIANS
The following list includes the type of Personal Information that may be collected respecting individuals that register with the Company as physicians that prescribe medical cannabis (“Physicians”):
- contact information, including name, email address, and phone number;
- details relating to professional status and qualifications to prescribe medical cannabis and
- usage data respecting use of the Company’s website(s) through the website(s) (or through third-party services employed by the website(s) which can include the IP addresses or domain names of the computers utilized by the User; the URL addresses; the time of the request; the method utilized to submit the request to the server; the size of the file received in response; the numerical code indicating the status of the server’s answer (successful outcome, error, etc.); the country of origin; the features of the browser and the operating system utilized by the User; the various time details per visit (e.g., the time spent on each page within the website(s)); and the details about the path followed within the website(s) with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment.
D.PERSONAL INFORMATION OF ALL USERS (INCLUDING PATIENTS AND PHYSICIANS)
The following list includes the type of Personal Information that may be collected from users that utilize services provided by the Company, which may include a Patient or Physician (“Users”):
- contact information, including name, date of birth, gender, home address, telephone number, email address;
- credit card or other financial information;
- usage data respecting use of the Company’s website(s) through the website(s) (or through third-party services employed by the website(s)) which can include the IP addresses or domain names of the computers utilized by the Users; the URL addresses; the time of the request; the method utilized to submit the request to the server; the size of the file received in response; the numerical code indicating the status of the server’s answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the website(s)) and the details about the path followed within the website(s) with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User’s IT environment; and
- other information as necessary to maintain our business relationship with you, such as information related to your preferences, feedback and information requested or provided by you.
Unless specified otherwise, all Personal Information requested by the Company is mandatory in order for the Company to provide its services to the User. As such, failure to provide this Personal Information may affect the ability for a User to utilize the Company’s services. In cases where we have stated that the Personal Information is not mandatory to utilize the service, Users are free to not communicate this Personal Information without any impact on the User’s ability to use the Company’s services. Any questions respecting what information is mandatory can be directed to our Privacy Officer at info@buymedicalcannabiscanada.ca or by phone at (905) 946-8444.
The Company may also collect Personal Information for the purpose of evaluating market trends and other activities relating to our business. To provide you with timely, valuable information, we may also ask you to provide us with information regarding your professional interests and experiences with our products or services. Providing us with this information is optional.
5. Why do we collect
When prescribing medical cannabis, personal information is required to meet regulatory requirements
6. How do we use your personal information?
We collect your Personal Information to operate, maintain, enhance and provide all features of the Company’s services, to send you marketing communications, to respond to comments and questions, to provide support to Users of the Company’s services and, from time to time, in medical and academic research. We also use select information to comply with Health Canada rules and regulations. We use information collected from cookies and other technologies to improve your experience and the overall quality of our services and website.
What is a Cookie?
Cookies are small amounts of text or software code, which is often a unique and anonymous identifier that is stored on your computer and only with your permission. Cookies help facilitate your experience on the Sites by updating things like your date and time of visit and general interaction on the Sites.
How do I consent to or block Cookies?
When you access BMCC’s Sites you will be asked to consent to BMCC’s use of the Cookies described in this Cookie Policy.
If you wish to block Cookies you may activate the relevant settings in your browser. If you are unsure how to do this please visit here.
Should you not consent to BMCC’s use of Cookies you may find that the Sites may not work as intended or your access of the Sites is limited.
What Cookies does BMCC Use?
These cookies are used to distinguish users and expedite user experience on the Sites. The information from these Cookies is only stored as long as necessary and not longer than 30 days .
You will be notified of one or more specific purposes of collection at the time of providing your Personal Information, and asked for your consent to the collection and use of your Personal Information for those purposes. If your Personal Information is to be utilized for any purpose besides that outlined at the time of collection, you will be notified of that new purpose and asked for consent prior to the Company using your Personal Information for that new purpose, except as otherwise permitted by the applicable legislation and this Privacy Policy.
For example, when a User registers as a Patient with the Company, the Company collects and retains Personal Information such as the individual’s name and contact information. The Company will use this information to:
- confirm the individual’s registration status and to maintain the individual’s account;
- fill orders made online and provide other information requested by you;
- establish, maintain and manage our relationship with you so we can provide you with products and services as requested and in line with your needs and preferences;
- distribute medical cannabis to you;
- provide you with information about our products and services, including the latest news on Company activities and initiatives, information about new products and services, product updates, technical support issues, events and special offers;
- recommend products, services or programs on our Website(s) by providing customized content on our Website(s) or otherwise;
- obtain and process payments for medical cannabis dispensed to you, which includes providing necessary information to our third party service providers (please see Third Party Service Providers section below);
- seek reimbursement from your insurer;
- enable us to comply with applicable laws and specifically the requirements of the federal Cannabis Act and Regulations.
At the time of collection, the Company will document the purposes for which the information was collected. Upon request, the Company will explain the purposes for which the information is being collected, or refer the User requesting the purposes to a designated person within the Company who will explain the purposes of collection.
7. How do we collect your personal information?
We collect information in the following ways:
- Information you give us: Some of our services require you to sign up for an account. When you do, we will ask for Personal Information, including your name, birth date, email address, phone number and other applicable information to create your account. Some of our services will also require you to provide us with your Personal Information in order to obtain a product or receive information from us, such as newsletters or other email messages containing information of a commercial or promotional nature.
- Information from licenced medical practitioners about Patients: If you are registered as a Patient with the Company, your Personal Information, including your name, date of birth, gender, email address, phone number and health information may be collected directly from a licenced medical practitioner who provides the Company with a complete Medical Document on your behalf. This information will not be collected from your licenced medical practitioner without your consent as may be required for regulatory compliance.
- Cookies and similar technologies: The Company uses cookies or other tracking tools to provide services required by the User, if consented to by the User.
- Google Analytics: Google Analytics is a web analysis service provided by Google Inc. (“Google”) that is used on the Company’s website(s). Google utilizes the data collected to track and examine the use of the Company’s website(s), to prepare reports on the Company’s website(s) activities and to provide the Company with other services related to website and Internet use. Google may use the data collected to contextualize and personalize the advertisements of its own advertising network.
Google Analytics processes information in the USA. The Personal Information collected by Google includes cookies and usage data. We encourage you to review the Privacy Policy for Google Analytics if you would like any further details regarding how they process Personal Information.
8. Who has access to your personal information within the company?
Only employees and contracted individuals of the Company who require access for business or regulatory reasons shall be granted access to Personal Information about Users.
9. Disclosure of your personal information outside of the company
The Company may disclose your Personal Information with third party companies, organizations and individuals outside of the Company if:
- You have provided your consent: We will share Personal Information with companies, organizations or individuals outside of the Company when we have your consent to do so.
- For external data processing: We may provide Personal Information to certain third party agents or service providers to process for us, in order to carry out the requested services or as necessary for otherwise lawfully processing Personal Information. For example, the Company may share your Personal Information with payment processors so that these payment processors can provide services on our behalf. The Company shall ensure that any such parties accessing Personal Information do so in compliance with our Privacy Policy and any other appropriate confidentiality and security measures to reasonably ensure the protection of Personal Information.
- To comply with a legal obligation: The Company may disclose Personal Information if required to do so pursuant to any applicable law, regulation, legal process or enforceable governmental request. For example, it may be necessary for the Company to disclose Personal Information to law enforcement officials, regulatory bodies, or government agencies for the purposes of investigating or preventing drug, fraud, or other offences as may be required or permitted by applicable laws. Additionally, under the Legislation and other applicable laws, the Company may be required to disclose some of a User’s Personal Information to government officials, law enforcement personnel, or competent authorities of foreign governments. This information includes:
- an individual’s given name, surname, date of birth and gender;
- contact information including the individual’s mailing address, phone number, and email address;
- the given name, surname, date of birth and gender of one or more persons who are responsible for the individual, as well as contact information for such persons;
- a valid prescription or other medical document issued by an authorized medical practitioner;
- the given name, surname, professional status and address of the health care practitioner who issued a prescription or other medical document on behalf of the Individual;
- if applicable, the consent of the health care practitioner to receive shipments on the individual’s behalf; order details about the product sold or provided, including the quantity ordered; and the address to which the product is to be shipped.
- For Legal Reasons: The Company may also disclose Personal Information to establish or exercise our legal rights or defend against legal claims or in connection with an emergency that warrants use or disclosure of the information.
- For Purposes of Contracts: The Company may disclose Personal Information for executing a contract to which a User is part or to take steps at the request of the User prior to entering into a contract.
- For other reasons authorized by law: We will share Personal Information with companies, organizations or individuals outside of the Company if disclosure of the information is reasonably necessary for other reasons authorized by law.
We may share non-personally identifiable (anonymized) information publicly and with our partners. For example, we may share anonymized information publicly to show trends about the general use of our services.
The Company shall not otherwise disclose Personal Information to third parties for commercial or other reasons, except as may be specifically required to comply with applicable laws or where you have provided your consent.
In any case, the Company will gladly help to clarify the specific legal basis that applies to the disclosure of Personal Information, and in particular whether the provision of Personal Information is a statutory or contractual requirement or a requirement necessary to enter into a contract.
10. Your rights respecting your personal information
You have a right to request your personal information. To do so, you must submit your request in writing, which should detail your full name, address, and what information you are requesting. Information can only be provided to an identifiable individual and not to any other person. We will advise if we have the requested information and we will provide it within 30 days of a request.
11. How can you contact us?
If you have questions about our Privacy Policy or have a concern or complaint about privacy, confidentiality, or our information handling practices; please contact our Privacy Officer at info@buymedicalcannabiscanada.ca or by phone at (905) 946-8444 for more information.
The Company shall maintain procedures for receiving and responding to complaints or inquiries about policies and practices relating to the handling of Personal Information.
The Company shall inform individuals who make inquiries or lodge complaints of the existence of relevant complaint procedures.
The Company shall investigate all complaints made through the proper complaint procedure. Where complaints are justified, the Company will take the necessary steps to remedy the contravention.
The individual(s) appointed by the Company as responsible for compliance with this Privacy Policy shall investigate all complaints concerning compliance. The individual(s) appointed as responsible for compliance may seek external advice where appropriate prior to providing a final response to individual complaints.
12. Do we transfer the data internationally?
If you are utilizing services or visiting the Company’s website(s) from outside of Canada please be aware that you may be sending information (including Personal Information) to Canada where our servers are located. That information may then be transferred within Canada or back out of Canada to other countries outside your country of residence, depending on the type of information and how it is stored by us. These countries may not necessarily have data protection laws as comprehensive or protective as those in your country of residence; however, our collection, use and disclosure of your Personal Information will at all times continue to be governed by this Privacy Policy.
13. How long is your personal data retained?
Personal Information and Personal Data shall be stored for as long as required by the purpose for which it has been collected, used or disclosed.
Personal Information or Personal Data which the Company no longer needs to retain shall be destroyed, erased or made anonymous in a secure manner in accordance with the Company’s policies respecting the destruction of records. The Company shall use care in the disposal or destruction of information so as to prevent unauthorized parties from gaining access to the information. The right to access, the right to erasure, the right to rectification and the right to portability cannot be enforced after the information has been destroyed.
14. Changes to this privacy policy
CCNI reserves the right to amend the Privacy policy in response to changes in CCNI’s services or changes in the applicable law. Prior to making any amendments to the Privacy Policy, a notice will be given either via email, a sign-in notification, or other means before the change becoming effective. Your access to the website or uses of CCNI’s services after the amended policy will be understood to be your agreement to the CCNI’s new Terms and Conditions, and the collected, use, and disclosure of your Personal Information will be applied in accordance with the amendment of this policy.