...

Introduction and Scope

Donya Medical Spa (“we,” “us,” or “our”) is dedicated to protecting the privacy and confidentiality of our clients’ information. This Privacy Policy outlines our practices regarding the collection, use, and disclosure of your personal information in compliance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and Ontario’s Personal Health Information Protection Act (PHIPA).

This document should be read in conjunction with our separate Legal Terms and Conditions, which govern your use of our website and services.

1. Information We Collect

We collect information necessary to provide you with safe, effective, and personalized services.

a. Personal Information (PI)

This includes identifiable information such as your name, email address, telephone number, and mailing address, which you provide when booking appointments, contacting us, or subscribing to communications.

b. Personal Health Information (PHI)

As a medical spa, we are a Health Information Custodian under PHIPA. We collect necessary health information to ensure your safety and the efficacy of our treatments. This PHI may include, but is not limited to:

c. Derivative and Technical Data

Information automatically collected when you access our Site, such as your IP address, browser type, and browsing behavior. This data is used for analytics and advertising purposes.

2. Use of Your Information

Your information is used for specific, defined purposes:

3. Confidentiality and Disclosure of Your Information

Your Personal Health Information is held in the strictest confidence. It will not be disclosed to third parties without your express written consent, except in the rare and specific circumstances where we are legally and/or ethically required to do so, such as:

If such a situation arises, we will only disclose the minimum information necessary and, where possible, we will discuss the situation with you before any disclosure is made.

4. Data Retention, Storage, and Security

We retain client records containing PHI for a minimum of **10 years after the date of your last treatment**, or for 10 years after a minor client turns 18, to comply with professional and legal requirements.

We use third-party software for booking, client management, and communications. We take care to select reputable providers with strong security and privacy practices. Your data may be stored on secure servers located within Canada or in other jurisdictions, such as the United States, under strict privacy safeguards. We have implemented robust administrative, technical, and physical security measures to protect your information.

5. Your Privacy Rights

As a client, you have the right to:

6. Tracking Technologies (Cookies, Analytics, Ads)

Our website utilizes third-party services and tracking technologies, including cookies, for analytics and advertising. These include Google Analytics, Google Ads, Meta Ads, and Microsoft Clarity. You can manage cookies through your browser settings.

7. On-Premise Media and Intellectual Property

For security, our premises may be monitored by video surveillance. For marketing, our staff may capture photos or videos (“Assets”) only with your express, prior, written consent. These Assets are the property of Donya Medical Spa and may not be used without permission.

8. Third-Party Content and External Links

Our Site may contain links or content from third parties. We are not responsible for their privacy practices. If you believe any content on our site infringes on your rights, please contact us for immediate removal.

9. Contact Us

If you have any questions, concerns, or requests regarding this policy, please contact our designated Privacy Officer:

Donya Medical Spa Privacy Officer
10341 Yonge St Unit 4 Room 2
Richmond Hill, ON L4C 3C1
Email: [email protected]
Phone: (647) 372-0217