Privacy Policy

Medea Santé

227 Rue Montcalm, Gatineau, Québec J8Y 3B9, Canada

1. Identity and Accountability

Medea Santé is a private medical clinic operating in Québec, Canada.

Per Québec's Act Respecting the Protection of Personal Information in the Private Sector, Medea Santé is responsible for the personal information it collects, uses, holds, communicates, and destroys.

The person exercising the highest authority within the clinic acts as the person in charge of personal information protection unless formally delegated in writing.

Privacy inquiries and requests may be directed to: Info@medeasante.ca

2. Scope

This Privacy Policy applies to personal information collected through:

  • The Medea Santé website
  • Online appointment booking
  • Patient intake forms
  • In-clinic consultations
  • Telehealth services
  • Billing and payment processing
  • Email, SMS, and telephone communications

3. Categories of Information Collected

Medea Santé limits collection to information necessary for defined purposes.

3.1 Contact and Identifying Information

  • Full name
  • Date of birth
  • Address
  • Email address
  • Phone number
  • Emergency contact details
  • Government identifiers where required for identity verification

3.2 Appointment and Administrative Information

  • Booking details
  • Appointment history
  • Referral information
  • Intake questionnaire responses
  • Consent records
  • Administrative notes

3.3 Personal Health Information (Sensitive Information)

Personal health information is considered sensitive. This may include:

  • Symptoms
  • Medical history
  • Diagnoses
  • Prescriptions
  • Laboratory results
  • Imaging results
  • Clinical notes
  • Care plans

Telehealth consultations may involve audio, video, and written communications forming part of the clinical record.

3.4 Billing and Payment Information

  • Invoices
  • Payment status
  • Limited transaction identifiers
  • Insurance information where applicable

Payment card data is processed through secure third-party payment processors. Medea Santé does not intentionally store full payment card numbers on its own systems.

3.5 Technical and Device Information

  • IP address
  • Browser type
  • Device identifiers
  • Access timestamps
  • Security logs

3.6 Communication Records

  • Emails
  • SMS reminders
  • Phone notes
  • Secure portal messages
  • Consent and unsubscribe logs

4. Purpose of Collection

Personal information is collected and used for specific purposes.

4.1 Clinical Care

To assess, diagnose, treat, and monitor patient health.

4.2 Patient Relationship Management

To schedule appointments and communicate operational information.

4.3 Billing and Financial Administration

To issue invoices and process payments.

4.4 Legal and Professional Compliance

To comply with regulatory, professional, and legal obligations.

4.5 Security and Risk Management

To protect clinic systems and prevent unauthorized access.

4.6 Service Improvement

De-identified information may be used internally for quality improvement and operational assessment.

5. Legal Basis and Consent

5.1 Québec Standard

Consent must be clear, free, informed, and given for specific purposes. Sensitive personal health information requires express consent unless a statutory exception applies.

Operational communications related to requested services may rely on implied consent where appropriate.

5.2 Withdrawal

Consent may be withdrawn by contacting Info@medeasante.ca. Withdrawal may affect the clinic's ability to provide care where information is necessary for safe treatment or legal compliance.

5.3 International Users

Where international privacy laws apply, processing is conducted in accordance with applicable lawful bases, including explicit consent for health information where required.

6. Disclosure of Personal Information

Personal information may be disclosed to:

  • Authorized clinic personnel
  • Service providers supporting clinic operations
  • Professional advisors
  • Regulatory authorities
  • Law enforcement where legally required

Service providers are contractually bound to maintain confidentiality and implement appropriate safeguards.

7. Cross-Border Transfers

Personal information may be processed outside Québec depending on service provider infrastructure.

Before communicating personal information outside Québec, Medea Santé conducts an assessment of privacy protections and implements contractual safeguards as required by law.

8. Safeguards

Medea Santé implements safeguards appropriate to the sensitivity of personal health information.

Administrative Safeguards

  • Role-based access control
  • Confidentiality training
  • Written policies and procedures

Technical Safeguards

  • Encryption in transit
  • Secure hosting environments
  • Access controls
  • Audit logging

Physical Safeguards

  • Controlled access to clinic premises
  • Secure storage of paper records

Breach Response

If a confidentiality incident presents a risk of serious injury, Medea Santé will notify affected individuals and the Commission d'accès à l'information in accordance with Québec law.

A confidentiality incident register is maintained.

9. Retention

Clinical records are retained in accordance with Québec professional standards, generally for a minimum of ten years following the last entry.

Non-clinical information is retained only as long as necessary for operational, legal, and accounting purposes.

Information is securely destroyed when no longer required.

10. Individual Rights

Québec and Canada

Individuals may request:

  • Access to personal information
  • Correction of inaccurate information
  • Withdrawal of consent

Requests must be submitted in writing to Info@medeasante.ca. Responses are provided within 30 days.

International Users

Where applicable, additional rights may include:

  • Access
  • Erasure
  • Restriction
  • Portability
  • Objection

11. Cookies and Tracking

Essential cookies are used for website functionality and security.

Where non-essential analytics technologies are used, consent is obtained in accordance with applicable law.

12. Marketing Communications

Commercial electronic messages are sent only with required consent.

Each message includes:

  • Identification of Medea Santé
  • A functional unsubscribe mechanism

Unsubscribe requests are processed within 10 business days.

13. Automated Decision-Making

Medea Santé does not rely exclusively on automated decision-making for clinical determinations.

Where automated tools assist operational processes, individuals may request clarification and human review.

14. Changes to This Policy

This Privacy Policy may be updated periodically. Updates will be posted on the website with a revised effective date.