Confidentiality and personal information protection policy

General information

At Med Express Inc., we place great importance on protecting the personal information of our customers, employees and contractors. In accordance with the law on the protection of personal information in the private sector, we are committed to preserving the confidentiality of personal information collected in the course of our activities. Our privacy policy is intended to inform you about our practices for collecting, using, disclosing, retaining and protecting your personal information. By providing us with your personal information, you agree to the terms of this policy and authorize us to process your information in accordance with it.

Consent

Commitment to privacy

We are committed to protecting the privacy of our users. We collect and use personal information only with their explicit consent and in compliance with applicable laws.

Acceptance of the terms of our policy

By accessing our website www.medexpress.ca or by providing us with personal information, you agree to the terms of our privacy policy. This includes your consent to the collection and use of your personal information in accordance with this policy.

Right to withdraw consent

You have the right to withdraw your consent at any time. However, this is subject to certain legal or contractual restrictions. We will inform you of the possible consequences of this withdrawal, such as the inability to provide certain products or process certain requests. Your decision to opt out will be recorded in our records.

Exceptions to the need for consent

In certain exceptional circumstances, we may collect, use or disclose personal information without first obtaining your consent. This may occur in situations where legal, medical or security requirements make obtaining your consent impossible or impractical. These situations include, but are not limited to, cases of suspected breach of contract, fraud prevention or detection, or law enforcement needs.

Collection of personal information

We collect personal information through various means, such as:

  • Emails and communications with our customer service
  • Online application forms
  • Mobile application offered to our customers
  • Cookies and similar technologies on our website
  • Application on our various display sites
  • Connected objects

We may also collect information through third parties, such as:

  • A recruitment portal that allows candidates to submit their CV and personal data
  • Professional social networks like LinkedIn for recruiting or marketing needs
  • A subcontractor or consultant who provides part of the services we offer to our customers
  • A customer satisfaction survey company that collects feedback on our products or services
  • An online payment service provider to process financial transactions
  • A cloud computing company storing customer data
  • A company analyzing user behavior on our website
  • An IT security service provider that monitors threats and protects data
  • A logistics provider managing the delivery of products and collecting information about recipients

We are committed to being transparent about the use of these technologies and respecting our customers' privacy choices.

Types of Personal Information Collected

We collect various types of data, including but not limited to:

  • Personal identifiers (name, postal address, email, telephone number)
  • Hiring information (date of birth, SIN)
  • Financial information (specimen check, banking information, credit card)
  • Demographics (age, place of residence)

Use of personal information

We use your personal information for a range of essential activities:

  • Responses to requests : To respond effectively to your requests and queries.
  • Transaction management : Processing payments and issuing commission reports or pay stubs
  • Human resources management : For internal management and administration of human resources, recruitment, employment contracts and service agreements.
  • Improved user experience : Operating, maintaining and improving our website, personalizing your online experience, and providing requested services and information.
  • User account management : Management of your user account to access various features of our site.

These uses are intended to enrich your experience with our services and to facilitate effective interaction with our organization.

We offer various options to allow you to control and limit the collection of your personal information. These options include:

  • Communication choice : You can choose to receive our communications by different means (telephone, SMS, email), or to refuse them completely.
  • Cookie management : Our site allows you to refuse or personalize the use of cookies. Please note that blocking certain cookies may affect the accessibility and functionality of our site.
  • Granular consent : In the majority of situations, when we collect information for specific purposes, you have the option to consent only to certain uses of your data.

It is important to note that some of these options may limit your access to all features of our service. For example, by refusing certain cookies, certain parts of our website may not function as intended, or by choosing not to create an account, certain personalization features may not be available.

Sharing and disclosure of personal information

Personal information collected by our organization is accessible to specific categories of our staff and certain partner organizations, for the purpose of providing our services effectively. For example :

  • Customer service : Accesses contact information to respond to requests.
  • IT department : Accesses technical data for support and maintenance.
  • Marketing department : Uses data for advertising campaigns and market research.​

 We ensure that this information is used exclusively for the purposes stated and in compliance with confidentiality. Data transfers outside Quebec are carried out within the framework of international collaborations, while ensuring adequate protection of information in accordance with current laws.

  • Delivery partners : Receive addresses for order delivery.
  • Payment service providers : Access financial information for processing transactions.
  • Persons responsible for personal information and data security : Access information to ensure data security and protection against unauthorized access or cyberattacks.
  • Legal consultants : Use data to ensure compliance with applicable laws and regulations.
  • Cloud Service Providers : Host data on secure servers, allowing storage and retrieval of information.
  • Research and development partners : Access certain data to collaborate on new innovations or service improvements.
  • Collection agencies : In cases of non-payment, certain information may be shared with external collection agencies.

Links to other websites

Our website may contain links to third party websites

When you follow these links, you will leave our website. Information exchanged at that time is no longer subject to our privacy policy. We recommend that you review the privacy statements of other websites you visit before providing any information.

Security of personal information

Security measures for the protection of personal information

To ensure the security and confidentiality of personal information, Med Express Inc. adopts rigorous security measures, including both physical and technological aspects. Here are some concrete examples:

  • Physical security : Use of electronic locking systems and security locks for access to desks, cabinets and filing cabinets, installation of surveillance cameras, and restriction of access to areas where personal data is stored.
  • Access controls : Limiting access to personal data to authorized employees only.
  • Staff training : Regular staff awareness of data security best practices.
  • Data encryption : Protection of sensitive data using advanced encryption techniques.
  • Intrusion monitoring and detection : Implementation of systems to monitor any suspicious activity and detect potential intrusions.
  • Disaster Recovery Plans : Developing plans to quickly restore data in the event of an incident such as an outage or cyberattack.

These measures are intended to protect personal information from unauthorized access, use or disclosure, and to maximize its integrity and confidentiality. Although we will do everything possible to protect your personal information, it is important to remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. We therefore cannot guarantee their absolute security.

Staff and Board Engagement

Each employee, director, independent contractor or advisor working on our board committees agrees to respect the personal information we collect. In addition, these people undertake to maintain the confidentiality of information specific to our activities and not to disclose it or make personal use of it or for the benefit of others. This commitment exists when the employee, director, volunteer, independent contractor or advisor takes office and continues indefinitely.

Retention and destruction of personal information

We will only retain your personal data for as long as necessary for the purposes set out in this privacy policy. We will retain and use it as necessary to comply with our legal obligations, to resolve disputes, and to enforce our legal policies.

We will also retain usage data for internal analytics purposes. This data is generally retained for a shorter period of time, unless it is used to strengthen the security or improve the functionality of our website, or we are legally obliged to retain it for a longer period.


Your rights

Recognition and respect of your rights 

As part of our privacy policy, we recognize and respect the fundamental rights of those affected by the personal information we hold. These rights include:

  • Right of access : Individuals have the right to see the personal information we hold about them. For example, a customer may request to see the data collected when registering for our service.
  • Right of rectification : If information is inaccurate or incomplete, data subjects can request it to be updated. For example, an employee may request correction of their incorrect mailing address in our records.
  • Right to deindexation : Individuals may request that their personal information be removed from the distribution or that any hyperlink associated with their name be deindexed, in the event that this distribution causes them harm or is in violation of the law or a court order. This right to erasure or forgetting allows individuals to control the availability of their personal information on the internet.
  • Right to file a complaint : If there are concerns about the processing of their data, individuals can file a complaint in accordance with our established process.

Subject to applicable laws, upon receipt of a written request from an individual and after verifying their identity, we will inform the individual if we hold personal information about them and disclose that information to them.

We may refuse an individual access to their information in accordance with applicable laws, in which case we will provide reasons for the refusal.

To facilitate these rights, the contact details of our Privacy Officer are clearly provided for any questions or concerns. These measures ensure that individuals can exercise their rights with confidence and transparency.

Policy Changes

This policy may be updated to reflect changes in our practices or legal requirements. Changes will be published on our website. We encourage you to review this Privacy Policy periodically to stay informed of any changes.

Contact

Any requests or questions about this privacy policy can be sent to the person responsible for the protection of personal information:

Claudine Picard, Director of Human Resources 
MedExpress

6405, Zéphirin Paquet
Quebec (Quebec) G2C 0M2
418 651-1868 p. 121

Right to portability

The right to portability allows any person to obtain communication, in a structured and commonly used technological format, of computerized personal information that they have provided to a public body, for example during the electronic provision of services. A person may The right to portability allows any person to obtain communication, in a structured and commonly used technological format, of computerized personal information that they have provided to a public body, for example during the electronic provision of services. A person may request access to their personal information for their own use with the aim, in particular, of keeping it in a private storage space or of communicating it to a third party of their choice. Furthermore, at the request of the person concerned, the information may also be communicated to any person or organization authorized by law to collect it.

Personal information covered by this right

The right to portability is limited to computerized personal information collected from an individual. Therefore, personal information collected in paper format is not covered by this right.

The notion of “computerized personal information” covers personal information that the person has provided directly to a public body, such as that which he or she would have deposited in his or her electronic file. This also covers personal information collected indirectly from the person, for example that generated by their activity, such as purchase or travel history.

Exclusion of certain information

Personal information created or inferred from the personal information of the individual concerned is not covered, as it is not collected from the individual. This could be, for example, a user profile created from the analysis of their activities on the web.

REQUEST ACCESS TO YOUR PERSONAL INFORMATION

Any requests or questions can be sent to the person responsible for the protection of personal information whose contact details are below. Any request will be carefully studied in accordance with the Law and will be responded to within 30 days of receipt. 

Claudine Picard, Director of Human Resources 
Med Express

6405, Zéphirin Paquet
Quebec (Quebec) G2C 0M2
418 651-1868 p. 121
rh@medexpress.ca 

Document 

PDF version