How Rose Beauty Clinic collects, uses, discloses, stores and protects your personal information and your personal health information — and what you can ask us to do with it.
This document was drafted for Rose Beauty Clinic as a working starting point. No lawyer has reviewed, amended or approved it, and it is published here so it can be read and marked up — not because it is settled. It is not legal advice to you, and it is not yet a reliable statement of the clinic’s legal position.
Before anyone relies on it, the clinic’s own counsel must review it and confirm every factual claim in it against how the clinic actually operates — its vendors, its retention schedule, its fees and its insurance. The retention periods, the list of service providers and the description of where information is stored must be checked against the clinic's actual contracts before this page is treated as accurate.
This policy explains what Rose Beauty Clinic does with information about you. It covers this website and its booking flow, the client portal, email, SMS and phone contact with the clinic, the paper and electronic records we keep about your care, and the records we keep about payments.
It applies to clients and prospective clients, to anyone who writes to us or books a consultation, to visitors to this website, and — in the parts that concern them — to people who apply to work here.
It does not cover other organisations’ websites we link to, our practitioners’ own records held outside the clinic, or the independent obligations a regulated health professional owes you through their college.
Two different privacy laws apply to a clinic like ours, and which one applies depends on the information, not on the department holding it.
We collect only what we need for the purposes in § 5. In practice that is:
Personal health information is held to a higher standard than the rest, and is treated differently inside our systems. It includes:
We do not collect information because it might one day be useful. Each category below has a purpose and a basis, and when the purpose ends the retention clock in § 10 starts.
| Purpose | What we use | Basis |
|---|---|---|
| Deciding whether a treatment is safe for you | Medical profile, consultation notes | Your express consent at intake; PHIPA |
| Providing treatment and keeping the clinical record | Health information, treatment records, consents | Consent, and the record-keeping duties of a regulated health professional |
| Booking, confirming, reminding and rescheduling | Contact details, appointment history | Necessary to provide the service you asked for; PIPEDA |
| Taking payment, issuing invoices and receipts | Payment records | Necessary to complete the transaction; tax law |
| Product safety, adverse-event reporting and recalls | Lot and batch numbers, treatment records | Legal obligation under Canada's food and drug legislation |
| Answering questions and handling complaints | Correspondence, support threads | Your consent; our legitimate interest in resolving them |
| Sending you marketing | Contact details, per-channel consent flags | Your express opt-in consent; CASL |
| Keeping records and the premises secure | Sign-in events, audit log, security logs | PHIPA safeguard duties; our legitimate interest |
| Meeting a legal, regulatory or college obligation | Whatever the obligation specifies | Law |
You give express consent to the collection of health information at intake, and again on a version-controlled consent form before each treatment. Between the practitioners actually involved in your care, information is shared on implied consent — the “circle of care” — because a nurse who is about to inject you needs to know what the physician found.
Marketing consent is separate from all of that. It is recorded per channel, it is off unless you turn it on, and refusing it changes nothing about your treatment or your price.
You can withdraw consent at any time — by email, by phone, in the portal, or in writing at the clinic. Two honest limits apply.
To stop marketing immediately: reply STOP to any text message, or use the unsubscribe link in any marketing email.
Photographs are the only reliable way to judge whether a treatment worked, to plan the next session, and to notice a change that neither of us would otherwise see. They are part of your clinical record. They are also the single most sensitive thing we hold, so consent for them is handled separately from everything else.
On a written, version-numbered photo release that names which of the three uses you agree to, signed and dated by you. We record which version you signed. A verbal agreement in the treatment room is not enough and is not used.
In your clinical record, access-restricted by role, with every access logged. A photograph marked for the record only can never surface in a public part of this website — that is enforced in the software, not by a habit. Whether a photograph is visible to you in the client portal is a separate switch again, so you see what we intend you to see and nothing by accident.
Write to the Privacy Officer at any time, naming the photographs or simply all of them. Within 30 days we will remove them from this website, from the social accounts we control, and from any material still in production. What we cannot do, and will not promise: recall printed material already distributed, or retrieve a copy someone else has already saved or reshared. The photographs remain in your clinical record, because that record must be retained under § 10 — but they stop being used for teaching or publication from the moment you tell us.
We do not use client photographs in paid advertising unless you have given separate written consent naming that use specifically.
We do not sell personal information. We do not rent or trade client lists. We do not upload client lists to advertising platforms. The complete list of who receives information, and why, is below.
| Who | What they receive | Why |
|---|---|---|
| Our practitioners and clinical staff | Health information, on a role basis | To assess, treat and follow up with you |
| Payment processor (Stripe) | Name, email, amount; card details you enter directly with them | To take deposits and payments. Card data never reaches our systems |
| Email provider (Resend) | Name, email address, message content | Booking confirmations, receipts, aftercare, and marketing you opted into |
| SMS provider (Twilio) | Mobile number, message content | Appointment reminders and the two-way messaging you start |
| Platform and hosting (Convex, Vercel) | The clinic record system and this website | To run booking, the client record and the site itself |
| Another health professional treating you | The minimum necessary | With your consent, or within the circle of care |
| Manufacturers and Health Canada | Lot numbers and adverse-event detail; de-identified where it can be | Mandatory safety reporting and product recalls |
| Our accountant and auditor | Financial records | Tax filing and audit |
| Insurers and legal advisors | Only what a specific claim requires | To advance or defend a claim |
| A regulatory college | Records it has statutory power to compel | Professional oversight of our practitioners |
| Police, a court or a public authority | Only what the instrument compels | A warrant, summons, order, or where the law requires it |
| A purchaser, if the clinic is sold | Records subject to confidentiality and PHIPA transfer rules | Continuity of your care |
Every service provider above works under a written agreement that limits them to providing the service to us, forbids them from using your information for their own purposes, and requires a comparable level of protection.
Some of the providers in § 8 store or process information on servers outside Canada, principally in the United States. This is true of our payment, email, SMS, database and hosting providers.
What we do to limit it:
You may ask our Privacy Officer where a particular category of your information is held, and by whom. We will answer specifically.
Retention is not a preference; for most of what we hold it is set by law or by a professional college. These are the periods we work to.
| Record | Kept for | Why |
|---|---|---|
| Clinical record — notes, treatment records, consents, photographs | 10 years from the last entry, or until 10 years after your 18th birthday, whichever is later | Ontario record-retention requirements for regulated health professionals |
| Audit log of access to your record | With the clinical record, for the same period | PHIPA safeguard, and the evidence that access was appropriate |
| Invoices, receipts, refunds and tax records | 6 years from the end of the tax year they relate to | Canada Revenue Agency |
| Appointment and cancellation history | With the clinical record | Continuity of care and the cancellation policy |
| Marketing consent, unsubscribes and the suppression list | Until you withdraw; the suppression entry is then kept indefinitely | So that a later import cannot resurrect an unsubscribe (CASL) |
| Support enquiries and message threads | 3 years | Complaint handling and follow-up |
| Website, sign-in and security logs | 12 months | Investigating abuse and security incidents |
| Unsuccessful job applications | 12 months | Future openings, and defending a human-rights complaint |
| Video surveillance, where used | 30 days, unless a specific incident requires longer | Premises security |
At the end of a period we securely destroy the record or irreversibly de-identify it. Paper is cross-cut shredded; electronic records are deleted from live systems and from backups on the backup provider’s cycle.
The controls below are the ones that actually exist in our systems, not aspirations.
No system is perfectly secure, and we will not claim ours is. What we will say is that we test these controls, log the exceptions, and act on what the log shows.
If health information is stolen, lost, or used or disclosed without authority, PHIPA requires us to tell you at the first reasonable opportunity, and to tell you that you may complain to the Information and Privacy Commissioner of Ontario. We will also notify the Commissioner where the regulations require it, and we report breach statistics to the Commissioner annually.
For information governed by PIPEDA, we report to the Office of the Privacy Commissioner of Canada and notify you where a breach of our security safeguards creates a real risk of significant harm, and we keep a record of every breach — reportable or not — for at least 24 months.
Where a regulated professional’s conduct is implicated, we notify their college where the law requires it. In every case we contain first, investigate, and tell you what happened, what information was involved, what we have done, and what you can do.
You have the right to see and to have a copy of the personal health information we hold about you. Ask in writing — an email to the Privacy Officer is enough. We will verify your identity, then respond within 30 days, or tell you within 30 days that we need the further extension PHIPA allows and why.
We may charge a reasonable fee to recover the cost of copying and sending a large record. We will give you a written estimate before we begin, and you can withdraw or narrow the request when you see it.
Refusals are narrow and we have to justify them — for example where granting access could reasonably be expected to result in a risk of serious harm, where the information is subject to legal privilege, or where it contains another person’s information that cannot be severed. If we refuse, we tell you which part we are withholding, on what ground, and that you may complain to the Information and Privacy Commissioner of Ontario.
If you believe a record is inaccurate or incomplete, tell us and we will correct it. If we decide not to — a clinical opinion recorded at the time is generally not corrected out of the record, because the record has to show what was believed when the decision was made — we will tell you why, and we will attach your written statement of disagreement to the file so that anyone reading it later reads both.
Another person can make a request on your behalf with your written authorisation, or as your substitute decision-maker.
Email marketing and SMS marketing are two separate switches. Both start off. You can change either at any time in the client portal, by replying STOP to a text, by using the unsubscribe link in any marketing email, or by telling us.
Every commercial message we send identifies the clinic, gives a physical address and a way to contact us, and carries an unsubscribe mechanism that stays valid for at least 60 days. We act on unsubscribes immediately in practice, and in any case well within the 10 business days the law allows.
We do not target advertising using your health information, and we do not share client information with advertising networks.
This website sets a small number of cookies and stores a small amount of data in your browser. What each one is, how long it lasts, and how to refuse it is set out in full in our cookie notice.
We do not run advertising trackers on this site, and no cookie set by this site carries health information.
Cosmetic injectable and energy-based treatments are not offered to anyone under 18, and we do not knowingly collect information about under-18s for that purpose.
Where a treatment we offer is appropriate for someone under 18, Ontario sets no fixed age of consent to health care: a young person capable of understanding the treatment and its consequences may consent for themselves under the Health Care Consent Act, 1996. We assess capacity, and we involve a parent or guardian where the young person is not capable, or asks us to.
We do not send marketing to anyone we know to be under 18.
Every version of this policy is dated. When we make a change that materially affects how we handle your information, we will post the new version here at least 30 days before it takes effect and email clients who have an address on file.
Continuing to use the clinic after a change takes effect does not, on its own, amount to consent to a new purpose. Where a change needs your consent, we will ask for it.
Earlier versions are available from the Privacy Officer.
Start with our Privacy Officer, whose details are below. We acknowledge a privacy complaint within five business days and aim to give you a substantive answer within 30 days. If we cannot, we will tell you why and when you will hear from us.
You do not have to come to us first, and complaining never affects your care.
Write to the Privacy Officer about anything in this policy: to see your record, to correct it, to withdraw a consent, to ask where your information is held, or to complain. Mark your message for their attention.