Privacy
Privacy Policy
Maison Oolong is committed to protecting the personal information entrusted to us. This policy describes how we collect, use, and protect your information in accordance with Quebec's Act respecting the protection of personal information in the private sector (Law 25), in force since September 22, 2023.
Last updated : 1er mai 2025
Commitment & Identity of the Privacy Officer
Maison Oolong takes the protection of personal information seriously. In accordance with Law 25, we have appointed a Privacy Officer (Responsable de la protection des renseignements personnels — RPRP) who oversees compliance and responds to individual rights requests.
| Organization | Maison Oolong |
| Privacy Officer (RPRP) | [À COMPLÉTER — Nom du RPRP] |
| RPRP email | [email protected] |
| Effective date | 1er mai 2025 |
Personal Information Collected
We collect the following categories of personal information:
- Identity: first name, last name, date of birth
- Contact information: postal address, email, phone number
- Health data (sensitive): pre-treatment medical history, allergies, contraindications, medications — collected exclusively for the safety and personalization of treatments
- Payment information: processed exclusively through Moneris and Shopify Payments. Maison Oolong does not store credit card numbers
- Before/after photographs: if consented to for clinical protocol tracking
- Browsing data: IP address, cookies, site usage statistics (see section 08)
Purposes of Collection
Your personal information is collected for the following purposes:
- Providing medical aesthetic and wellness services
- Clinical monitoring of protocols and results
- Appointment management and invoicing
- Marketing communications (with explicit consent only)
- Improving the website user experience
- Compliance with legal obligations (health record-keeping under Quebec law)
Legal Basis for Processing
- Explicit consent: for sensitive health data and marketing communications
- Performance of contract: for transactional and appointment data necessary to deliver the agreed service
- Legitimate interest: for anonymized website statistics, subject to balancing test
- Legal obligation: for health record-keeping and accounting records
Sharing & Transfer of Data
Maison Oolong does not sell personal information. We share data only with trusted technical subcontractors who have signed data processing agreements compliant with Law 25:
| Subcontractor | Role | Location |
|---|---|---|
| SimplyBook.me | Appointment management | Iceland (GDPR) |
| Moneris | Payment processing | Canada |
| Shopify | E-commerce & retail payments | Canada/USA |
| Netlify | Website hosting | USA |
| Google Analytics | Anonymized traffic statistics | USA |
In accordance with Law 25, any transfer of personal information outside Quebec is subject to a privacy impact assessment (PIA) to verify that the destination jurisdiction offers equivalent protection.
Retention Periods
| Data type | Retention period |
|---|---|
| Medical & clinical data | Minimum 5 years after last treatment (Quebec health record obligations) |
| Billing & invoicing | 6 years (fiscal obligations — Tax Administration Act of Quebec) |
| Marketing consent | Until withdrawal of consent |
| Browsing data (cookies) | Maximum 13 months |
| Before/after photographs | Until withdrawal of consent, or 5 years if part of clinical record |
Your Rights under Law 25
Under Quebec's Law 25, you have the following rights regarding your personal information:
- Right of access: obtain a copy of your personal information held by us
- Right of rectification: correct inaccurate or incomplete information
- Right to withdraw consent: at any time, subject to legal constraints
- Right to data portability: receive your data in a structured, commonly used format
- Right to erasure: subject to applicable legal retention obligations
- Right to de-indexation: have information about you removed from search engine results
- Right to cessation of dissemination: stop the use of your information in certain contexts
- Right to file a complaint: with the Commission d'accès à l'information du Québec (CAI)
How to exercise your rights
Send a written request to [email protected], with proof of identity. We will respond within 30 days of receipt, as required by Law 25.
Security
- TLS 1.3 encryption across the entire site
- Medical data stored in SimplyBook.me (GDPR-compliant)
- Access restricted to authorized practitioners only
- Regular security audits
- Data breach notification procedure within 72 hours, as required by Law 25
Minors
This site and our services are not intended for minors under 14 years of age.
For persons aged 14 to 17, parental or guardian consent is required for both services and the collection of personal data. A parent or guardian must be present or provide written consent prior to any treatment.
Changes to This Policy
This privacy policy may be updated periodically to reflect changes in our practices or applicable law. The date of the last revision is displayed at the top of this page.
In the event of a material change affecting your rights, we will notify you by email using the address on file, at least 30 days before the change takes effect.
Contact
For any question, rights request, or complaint relating to your personal information:
| Privacy Officer (RPRP) | [À COMPLÉTER — Nom] |
| [email protected] | |
| Postal address | [À COMPLÉTER] |
| Commission d'accès à l'information du Québec (CAI) | cai.gouv.qc.ca |