Applicable Privacy Legislation
What is Personal Information?
What Personal Information do we Collect?
We collect and maintain different types of personal information in respect of the individuals with whom we interact. This includes:
∙ personal contact and identification information, such as your name, address, telephone number, date of birth, gender e-mail address, and unique lifetime identifier number (ULI);
∙ business contact and identification information, including name, address, telephone number, e-mail address, and unique professional and/or organizational identifier;
∙ information concerning the use, operation and development of the Solution; and
∙ relationship information, including information related to your agreements, consents, preferences, feed-back and information requested by or provided to you.
As a general rule, Brightsquid collects personal information directly from you. In most circumstances where the personal information that we collect about you is held by a third party, we will obtain your permission before we seek out this information from such sources (such permission may be given directly by you, or implied from your actions).
With respect to health information shared with your healthcare practitioner through the Solution, we note that each healthcare practitioner is independent of Brightsquid and is responsible for obtaining and managing your consent in relation to their collection and use of your information.
From time to time, we may utilize the services of third parties in our business and may also receive personal information collected by those third parties in the course of the performance of their services for us or otherwise. Where this is the case, we will take reasonable steps to ensure that such third parties have represented to us that they have the right to disclose your personal information to us.
Where permitted or required by applicable law or regulatory requirements, we may collect information about you without your knowledge or consent.
Why Do We Collect Personal Information?
The Solution (and its related services) generally enables the exchange of sensitive information between users. Brightsquid collects personal information to enable us to manage, maintain, and develop the Solution, our business and operations, including:
∙ to operate the Solution, including the support, maintenance and development of same;
∙ to establish, maintain and manage our relationship with you so that we may provide you with, or receive from you, the products and services that have been requested;
∙ to be able to review the products and services that we provide to you so that we may understand your requirements for our products and services and so that we may work to improve our products and services;
∙ to be able to review the products and services that we obtain from you so that we may work with you and so that you may understand our requirements for such products and services;
∙ to be able to comply with your requests (for example, if you prefer to be contacted at a business or personal email address or telephone number and advise us of your preference, we will use this information to contact you through those means);
∙ to protect us against error, fraud, and inappropriate access;
∙ to enable us to comply with applicable law or regulatory requirements; and
∙ any other reasonable purpose to which you consent.
A more detailed description of the data usage and sharing associated with the specific features, modules, applications and/or services of or related to the Solution for which you may subscribe or use are available on request.
How Do We Use and Disclose Your Personal Information?
We may use and disclose your personal information:
∙ for any additional purposes for which we have obtained your consent to the use or disclosure of your personal information.
We may use or disclose your personal information without your knowledge or consent where we are permitted or required by applicable law or regulatory requirements to do so.
We may use de-identified information created by us from your personal information without restriction.
When do we Disclose Your Personal Information?
We may share your personal information with our employees, contractors, consultants and other parties who require such information to assist us with managing our relationship with you, including: third parties that provide services to us or on our behalf; third parties that assist Brightsquid in the provision of services to you; and third parties whose services we use to conduct our business.
For example, Amazon Web Services may provide certain information technology and data processing services to us from time to time so that we may operate our business, and as result, your personal information may be collected, used, processed, stored or disclosed in Canada.
Further, your personal information may be disclosed:
∙ to comply with valid legal processes such as search warrants, subpoenas or court orders;
∙ to protect the rights and property of Brightsquid;
∙ during emergency situations or where necessary to protect the safety of a person or group of persons;
∙ where the personal information is publicly available; or
∙ with your consent.
Your Consent is Important to Us
Brightsquid practices privacy by design and privacy by default in the design, development and operation of the Solution and our services. We strive to collect the minimum amount of personal information necessary and to retain it no longer than necessary to meet our contractual obligations or as required by law.
Accordingly, it is important to us that we collect, use or disclose your personal information where we have your consent to do so. Depending on the sensitivity of the personal information, your consent may be express, deemed (using an opt-out mechanism), or implied. Express consent will generally be through an overt opt-in process, and can be given orally, electronically or in writing. Implied consent is consent that can reasonably be inferred from your action or inaction. For example, when you enter into an agreement with us, we will assume your consent to the collection, use and disclosure of your personal information for purposes related to the performance of that agreement and for any other purposes identified to you at the relevant time.
As we have described above, we may collect, use or disclose your personal information without your knowledge or consent where we are permitted or required to do so by applicable law or regulatory requirements.
You may change or withdraw your consent at any time, subject to legal or contractual obligations and reasonable notice, by contacting our Privacy Officer using the contact information set out below. All communications with respect to such withdrawal or variation of consent should be in writing and addressed to our Privacy Officer.
How is Your Personal Information Protected?
Brightsquid endeavors to maintain physical, technical and procedural safeguards that are appropriate to the sensitivity of the personal information in question. These safeguards are designed to prevent your personal information from loss and unauthorized access, copying, use, modification or disclosure.
The protection of personal information is of paramount concern to Brightsquid, and Brightsquid is prepared to take appropriate and timely steps in the event of any incidents involving personal information in accordance with applicable privacy laws. Correspondingly, please advise our Privacy Officer immediately of any incident involving the loss of or unauthorized access to or disclosure of personal information that is in our custody or control.
Updating Your Personal Information
It is important that the information contained in our records is both accurate and current. If your personal information happens to change during the course of our relationship, please keep us informed of such changes.
In some circumstances we may not agree with your request to change your personal information and will instead append an alternative text to the record in question.
You can ask to see your personal information. If you want to review, verify or correct your personal information, please contact our Privacy Officer. Please note that any such communication must be in writing.
When requesting access to your personal information, please note that we may request specific information from you to enable us to confirm your identity and right to access, as well as to search for and provide you with the personal information that we hold about you. We may charge you a fee to access your personal information; however, we will advise you of any fee in advance. If you require assistance in preparing your request, please contact the office of our Privacy Officer.
Your right to access the personal information that we hold about you is not absolute. There are instances where applicable law or regulatory requirements allow or require us to refuse to provide some or all of the personal information that we hold about you. In addition, the personal information may have been destroyed, erased or made anonymous in accordance with our record retention obligations and practices. We generally retain your information as long as reasonably necessary to provide you with the Solution and related services or to comply with applicable law.
In the event that we cannot provide you with access to your personal information, we will endeavor to inform you of the reasons why, subject to any legal or regulatory restrictions.
Inquiries or Concerns?
Brightsquid Privacy Officer
Brightsquid Secure Communications Corp
282, 3553-31st St. NW Calgary AB
T2L 2K7 CANADA