Privacy Policy
Date of last update: February 1, 2025
Governance policy for personal information (PI) held by the omicron clinic and privacy policy
Par « renseignements personnels », on entend tout renseignement qui concerne une personne physique et permet, directement ou indirectement, de l’identifier. Les coordonnées strictement professionnelles (titre, adresse d’employeur, numéro de téléphone professionnel) ne sont généralement pas considérées comme des renseignements personnels.
Par « candidat », on entend toute personne ayant soumis sa candidature à un poste au sein du Groupe Omicron, ou ayant été approchée dans le cadre d’une démarche de recrutement.
Please read these terms and conditions of use (the «Terms») of Clinique Omicron carefully.
Clinique Omicron operates this website, including all of its pages, subdomains, electronic forms, digital tools, appointment scheduling interfaces, virtual service platforms, and social media pages and accounts (collectively, the «Site»).
These Terms and Conditions set forth the terms and conditions under which you may access, view and use the Site and all material presented or made available on the Site, including, without limitation, text, general information, medical content of an informative nature, images, videos, forms, questionnaires, interfaces, software and all other digital elements (the «Content»).
By accessing or using the Site, the user, understood as any individual or legal entity who browses, consults or uses the Site in any manner whatsoever (the ’User«), agrees to be bound by all of these Terms, as well as the Privacy Policy, the Terms of Sale, if applicable, and any other policy or legal notice published by Clinique Omicron and incorporated by reference (collectively, the »Legal Notices«).
The terms «you» and «your» refer to the User.
These Terms are legally binding on the User and Clinique Omicron. By accessing, browsing or using the Site or any of its content, forms, features or digital services, you acknowledge that you have read, understood and agree to be legally bound by these Terms, regardless of whether you create an account, book an appointment or use medical services.
If you do not agree to these Terms, you must not access or use the Site.
Clinique Omicron reserves the right to modify these Terms at any time by updating this posting. Your continued use of the Site following the posting of changes constitutes your express acceptance of the Terms as modified. You are responsible for regularly reviewing this section for any updates.
By using the Site, you represent and warrant that you have the legal capacity to accept and be bound by these Terms. When you use the Site on behalf of a third party, a minor or a dependent, you declare that you are legally authorized to do so and that you accept responsibility in this respect.
3.1 Quality of care
- Providing care in accordance with professional standards: Clinique Omicron is committed to ensuring that all health care professionals, including physicians, nurses, psychologists and other specialists, perform their duties in accordance with the ethical standards of their respective professional orders (CMQ, OIIQ, OPQ, etc.).
- Virtual consultations are conducted in such a way as to guarantee a quality of service equivalent to that of a face-to-face consultation, within the technological and clinical limits inherent in remote care.
3.2. Protection of Personal Information
- Clinique Omicron is responsible for the security, confidentiality and integrity of personal data collected during teleconsultations, in accordance with the Act Respecting the Protection of Personal Information in the Private Sector (Quebec) and the Personal Information Protection and Electronic Documents Act (PIPEDA).
- Rigorous cyber-security measures (data encryption, authentication protocols, access control) are in place to protect sensitive information against unauthorized access, loss or accidental disclosure.
3.3 Transparent information on teleconsultation limitations
- Clinique Omicron undertakes to clearly inform patients of the limitations of virtual consultations, including:
- The absence of a complete physical examination may affect the diagnosis;
- The impossibility of managing certain emergency situations remotely;
- The need, in some cases, to recommend in-person consultation or referral to specialized services.
- Patients are advised that virtual care may not be appropriate for all medical conditions and that it is their responsibility to disclose all relevant information to ensure proper evaluation.
3.4. Responsibility in the event of a medical emergency
- Clinique Omicron specifies that teleconsultation services are not intended for the management of medical emergencies.
- In the event of serious symptoms (chest pain, respiratory distress, signs of stroke, etc.), the patient should immediately contact emergency services (dial 9-1-1) or go to the nearest hospital.
3.5. Limitation of liability clause
_”La Clinique Omicron ne saurait être tenue responsable des conséquences médicales liées à des consultations virtuelles lorsque des limitations inhérentes à ce mode de prestation ont été clairement communiquées au patient.”_
3.6. Organizational and logistical adjustments
Clinique Omicron reserves the right to modify the time, date or professional responsible for a teleconsultation, notably for reasons of clinical triage, punctual unavailability or operational reassignment.
In such cases, the patient will be offered an equivalent alternative within a reasonable period of time. No reimbursement will be made if the consultation can be satisfactorily rescheduled. Refunds will only be made in the event of a complete cancellation with no alternative offered.
Clinique Omicron has established these limitations of liability in order to clearly define the obligations of the clinic and patients in the context of teleconsultations. These limitations are intended to protect the clinic while informing the patient of the risks inherent in the use of virtual health services.
4.1. Limitations Related to Information Provided by the Patient
- Responsibility for information provided: Clinique Omicron cannot be held responsible for medical decisions made on the basis of incomplete, inaccurate or omitted information provided by the patient.
- Duty of disclosure: The patient is responsible for providing complete, accurate and up-to-date medical information at the time of consultation. Omission of important details can compromise diagnostic accuracy and quality of care.
- Mandatory clause:_ “Le patient reconnaît que l’exactitude du diagnostic repose sur la véracité et l’exhaustivité des informations qu’il fournit lors de la téléconsultation.”
4.2. Limitations due to technical constraints
- Technical incidents: Clinique Omicron is not responsible for service interruptions, Internet connection problems, software failures, or any other technical problems related to the patient's equipment or technological environment.
- Impact on quality of care: If consultation is interrupted due to technical difficulties, the clinic will do its utmost to re-establish communication, but cannot guarantee immediate continuity of service.
- Safety clause:_ “La Clinique Omicron ne peut être tenue responsable des pertes de données ou des interruptions de service causées par des incidents technologiques indépendants de sa volonté.”
4.3. Limitations inherent to teleconsultation
- Lack of direct physical examination: Teleconsultation has clinical limitations, including the impossibility of performing a full physical examination when necessary for a precise diagnosis.
- In-person consultation recommendation: In cases where a physical assessment is deemed essential, the healthcare professional will recommend that the patient consult in person.
- Disclaimer:_ “La Clinique Omicron décline toute responsabilité pour les conséquences médicales résultant de l’absence de suivi médical en personne lorsque celui-ci est recommandé.”
4.4. Limitations in the event of a medical emergency
- No management of emergencies: Teleconsultation services are not intended for the management of medical emergencies. In the event of an emergency (severe chest pain, breathing difficulties, signs of stroke, etc.), the patient must immediately contact emergency services (9-1-1) or go to the nearest hospital.
– Clause de limitation : “La Clinique Omicron ne peut être tenue responsable des conséquences résultant du recours inapproprié aux services de téléconsultation pour des situations nécessitant des soins d’urgence immédiats.”
4.5. Acceptance of Limitations of Liability
Before confirming a teleconsultation appointment, the patient must read and explicitly accept this section.
- Acceptance clause:_ “En confirmant mon rendez-vous de téléconsultation, je reconnais avoir lu, compris et accepté les limitations de responsabilité de la Clinique Omicron, y compris celles liées aux informations fournies, aux limitations techniques et aux contraintes médicales inhérentes aux soins virtuels.”
Afin d’assurer la conformité légale et déontologique des services de téléconsultation offerts par la Clinique Omicron, un consentement spécifique est requis pour chaque spécialité. Ce consentement garantit que les patients sont informés des particularités de chaque discipline et des cadres réglementaires applicables.
5.1. General and specialist medicine
- Compliance with the Collège des Médecins du Québec (CMQ) : All remote medical consultations are carried out in accordance with the CMQ's ethical standards, particularly with regard to diagnosis, prescription and remote follow-up.
- Limitations of virtual medical consultations: Patients are informed that certain medical conditions may require in-person examination, physical tests or further investigations.
- Consent clause:_ “Je reconnais que les consultations médicales à distance respectent les normes du CMQ et que, si nécessaire, un suivi en personne pourra m’être recommandé.”
5.2. Nursing care
- Supervision by the Ordre des Infirmières et Infirmiers du Québec (OIIQ) Remote nursing care is governed by OIIQ guidelines, including clinical assessment, intervention under collective prescription and remote follow-up management.
– Responsabilités du patient : Le patient s’engage à fournir des informations précises sur son état de santé, nécessaires à une évaluation adéquate à distance.
- Consent clause:_ “J’accepte que mes soins infirmiers soient réalisés selon les standards de l’OIIQ et je comprends que des limitations peuvent exister en l’absence d’un examen physique.”
5.3. Psychology
- Compliance with the standards of the Ordre des Psychologues du Québec (OPQ) Remote psychological interventions comply with OPQ guidelines, ensuring the confidentiality of exchanges and the effectiveness of remote follow-up.
- Risks and limits of remote consultations: Patients are informed of the limits of online psychological consultations, particularly in the event of an acute crisis requiring immediate in-person intervention.
- Consent clause:_ “Je consens à recevoir des services psychologiques à distance conformément aux normes de l’OPQ, en comprenant les limites et les risques associés à ce mode d’intervention.”
5.4. Nutrition
- Practices governed by the Ordre des Diététistes-Nutritionnistes du Québec (ODNQ) : Our nutrition consultations follow the ODNQ's professional standards, guaranteeing the quality of nutritional advice provided remotely.
– Responsabilités du patient : Le patient reconnaît que l’efficacité des recommandations dépend de la communication précise de ses antécédents médicaux, de ses habitudes alimentaires, et de ses objectifs de santé.
- Consent clause:_ “Je consens à recevoir des conseils nutritionnels à distance dans le respect des normes de l’ODNQ, en comprenant que ces services ne remplacent pas des consultations médicales spécialisées si nécessaires.”
5.5. Other Health Professions
- Compliance with the guidelines of the respective professional orders : For other healthcare professionals (occupational therapists, physiotherapists, social workers, etc.), services are rendered in compliance with the ethical rules and regulatory frameworks of their respective professional orders.
- Consent clause : “Je consens à recevoir des services à distance fournis par des professionnels de la santé, conformément aux normes en vigueur de leurs ordres professionnels respectifs.”
5.6. Global Acceptance of Consent
- Acceptance clause:_ “En confirmant mon rendez-vous, je reconnais avoir lu, compris et accepté les conditions spécifiques de consentement applicables à la spécialité de la consultation. Je comprends les limites et les responsabilités associées aux soins virtuels.”
La Clinique Omicron s’engage à traiter toutes les plaintes de manière confidentielle, impartiale et efficace afin de garantir la satisfaction des patients et le respect des normes professionnelles. La gestion des plaintes suit un processus structuré, permettant à chaque patient d’exprimer ses préoccupations en toute transparence.
6.1. Dépôt d’une Plainte à la Clinique Omicron
- Form of complaint :
Complaints must be formulated in writing, en précisant le motif, la date de l’incident, les professionnels concernés, ainsi que toute information pertinente permettant d’évaluer la situation.
- Contact details for complaints :
E-mail : plainte@cliniqueomicron.ca
Telephone (for assistance with procedure): 514-606-3350
- Complaints handling process :
1. Acknowledgement of receipt within 5 working days of receipt of complaint.
2. Assessment of the complaint by an internal complaints management committee.
3. Written response to complainant within 20 working days, specifying findings and corrective measures envisaged, if any.
6.2. Complaints to the competent professional bodies
If the complaint concerns the professional conduct of a Clinique Omicron employee, the complainant may also contact the appropriate professional association directly:
- Medicine (CMQ):
Collège des Médecins du Québec - www.cmq.org
- Nursing Care (OIIQ) :
Ordre des Infirmières et Infirmiers du Québec - www.oiiq.org
- Psychology (OPQ) :
Ordre des Psychologues du Québec - www.ordrepsy.qc.ca
- Nutrition (ODNQ):
Ordre des Diététistes-Nutritionnistes du Québec - www.odnq.org
- Other health professions :
The complainant can consult the website of the professional association concerned to find out about the specific procedure.
6.3. Additional right of recourse
In the event of dissatisfaction after the complaint has been handled by Clinique Omicron or the relevant professional association, the patient may also contact :
- The Commission des droits de la personne et des droits de la jeunesse (CDPDJ) if the complaint concerns fundamental rights issues.
- The Commission d'accès à l'information (CAI) if the complaint concerns the protection of personal information.
6.4. Commitment of Clinique Omicron
La Clinique Omicron s’engage à :
- Ensure the confidentiality of information exchanged in connection with the complaint.
- Protect patients who make complaints from any form of reprisal.
- Implement corrective actions, where necessary, to improve service quality.
Acceptance clause:_
_“En utilisant les services de la Clinique Omicron, je reconnais avoir été informé des procédures de gestion des plaintes et des recours disponibles auprès des ordres professionnels compétents.”_
La Clinique Omicron se réserve le droit de modifier la présente politique de consentement aux soins virtuels à tout moment, afin de s’adapter aux évolutions législatives, réglementaires, technologiques, ou organisationnelles.
7.1. Frequency and Terms of Revision
- The policy may be revised periodically, at least once a year, or more frequently if significant changes occur in the regulatory framework or in the Clinic's practices.
– Des modifications ponctuelles peuvent également être apportées sans préavis en cas d’urgence légale ou réglementaire.
7.2. Notification of Modifications
- Publication on website: All changes will be clearly indicated on the official website of Clinique Omicron, in the section dedicated to privacy and consent policies.
- Updated revision date: The date of the last update will be displayed at the top of the policy for transparency.
- Direct communication: In the event of substantial changes affecting patients' rights or obligations, specific notification may be sent by e-mail or posted in the clinic's official communications.
7.3. Implicit acceptance of the New Conditions
- Continued use of Clinique Omicron's services after publication of the changes constitutes implicit acceptance of the new conditions by the patient.
- Patients are encouraged to consult this policy regularly to stay informed of any updates.
Acceptance clause:_
_“En poursuivant l’utilisation des services de la Clinique Omicron après la publication de modifications à la présente politique, je reconnais avoir pris connaissance des changements et je les accepte sans réserve.”_
If you have any questions, concerns or complaints about this Virtual Care Consent Policy, the handling of your personal information, or your privacy rights, please contact Clinique Omicron's Privacy Officer :
- Responsible for the protection of personal information :
E-mail : protectionrenseignements@cliniqueomicron.ca
Telephone: 514-606-3350
The Manager is available to respond to your requests for access, rectification, withdrawal of consent, as well as for any question relating to the management of confidentiality incidents.
Clinique Omicron Inc. undertakes to keep personal information only as long as necessary for the purposes for which it was collected, in accordance with applicable legal, regulatory and ethical requirements. Strict security measures are in place to ensure the confidentiality, integrity and protection of data throughout its life cycle.
9.1. Shelf life
The length of time personal information is kept varies according to the nature of the data and the associated legal obligations:
- Patient medical information :
- In accordance with the requirements of the Collège des médecins du Québec, medical records are kept for a minimum of 10 years from the last date of intervention in the file or, in the case of minors, until they reach the age of 18, plus an additional 10 years.
- Employee information :
- Employee files are kept for a minimum period of 6 years after the end of the employment relationship, in compliance with tax and labor laws.
- Administrative and financial information :
- Accounting, tax and contractual documents are kept for the period prescribed by applicable laws, generally 7 years.
In some cases, longer retention periods may apply due to specific obligations, such as litigation, regulatory investigations or research needs, subject to appropriate safeguards.
9.2 Secure destruction methods
Once the retention period has expired or the personal information is no longer required, Clinique Omicron securely destroys it to prevent unauthorized access, loss or accidental disclosure.
Secure destruction methods include :
- Physical destruction: shredding of paper documents, secure destruction of physical storage media (hard disks, USB sticks).
- Secure electronic deletion: permanent deletion of electronic files using specialized software to ensure that data cannot be recovered.
- Backup deletion: deletion of data backups in accordance with the clinic's security protocols.
Information destruction is carried out by authorized employees or service providers specialized in secure document management, under contractual confidentiality agreements.
9.3. Data anonymization (if applicable)
In certain situations, rather than destroying personal information, Clinique Omicron may choose to anonymize it in order to use it for research, statistical analysis or service improvement purposes. Anonymization consists in irreversibly transforming data so that it can no longer be associated with an identifiable person, either directly or indirectly.
Anonymization practices :
- Comply with recognized security standards to ensure that data cannot be re-identified.
- Are used only where relevant, in particular for scientific research projects, statistical reports or internal performance analyses.
- Subject to rigorous risk assessment before use.
Data anonymization offers an effective way of retaining information for useful purposes, while protecting the privacy of the individuals concerned.
Clinique Omicron Inc. attaches the utmost importance to protecting the personal information it holds. We have implemented rigorous physical, administrative and technological security measures to prevent unauthorized access, loss, theft, disclosure, modification or destruction of data.
10.1. Physical, administrative and technological measures
To ensure the security of personal information, Clinique Omicron applies a comprehensive security framework, including :
- Physical measurements
- Secure access control to facilities (electronic keys, access cards, video surveillance)
- Secure workspaces for managing sensitive files
- Lockable filing cabinets for confidential paper documents
- Administrative measures
- Internal information security and data management policies
- Employee awareness and ongoing training on the protection of personal information
- Confidentiality agreements signed by all personnel, including employees, consultants and subcontractors
- Regular security risk assessments of personal information
- Technological measures
- Encryption of sensitive data, both in transit and at rest, particularly in electronic medical records
- Firewalls, antivirus and intrusion detection solutions to protect IT systems
- Regular data backups with secure restoration mechanisms
- Using two-factor authentication (2FA) to access critical systems
10.2 Access management and system protection
Access to personal information is limited to authorized persons who need it to perform their duties. Clinique Omicron implements strict procedures to manage access rights:
- Logical access control
- Assign individual user accounts with complex logins and passwords
- Manage access privileges according to employee roles and responsibilities (principle of least privilege)
- Quick access deactivation for employees or partners no longer connected with the clinic
- Securing systems and networks
- Continuous monitoring of system activity to detect any suspicious activity
- Regular software and operating system updates to correct vulnerabilities
- Secure mobile devices and remote connections via virtual private networks (VPNs)
10.3 Managing confidentiality incidents
Despite the security measures in place, confidentiality incidents can occur. Clinique Omicron has established an incident management process to respond quickly and effectively:
- Detecting and reporting incidents
- Obligation for all employees to immediately report any suspicious incident (unauthorized access, loss of data, theft of equipment, etc.).
- Designated point of contact: the Privacy Officer is responsible for incident management.
- Risk assessment
- Incident analysis to determine the nature and extent of the data breach
- Assessing the risk of harm to those concerned
- Corrective measures
- Contain the incident to limit its impact (disable compromised accounts, restore data from backups)
- Implementation of patches to prevent recurrence of the incident
- Incident notification
- Notification of those concerned when an incident presents a serious risk of harm, with recommendations for mitigating the impact
- Declaration of the incident to the Commission d'accès à l'information du Québec (CAI) if required by law
- Post-incident follow-up
- Full documentation of the incident and actions taken
- Revision of safety policies and procedures as necessary
This security framework reflects Clinique Omicron's commitment to proactively protect personal information and respond appropriately to any threats to data confidentiality.
Clinique Omicron Inc. recognizes and respects the rights of individuals with respect to the protection of their personal information. In accordance with applicable laws, in particular the Act respecting the protection of personal information in the private sector, each individual has several rights aimed at ensuring control of his or her personal information.
11.1. Right of access
Any person has the right to ask whether Clinique Omicron holds personal information about him or her and, if so, to obtain a copy. This right includes :
- Access to information held, whether in paper or electronic format
- Knowledge of the categories of people within the clinic who have access to this information
- Information on the purpose of data collection and use
To exercise this right, the person concerned must submit a written request to the Privacy Officer. The Clinic will respond to the request within 30 days of receipt.
11.2. Right of rectification
Individuals have the right to request the correction of inaccurate, incomplete, equivocal or outdated personal information. This includes :
- Correction of factual errors (name, address, date of birth, etc.)
- Add additional information to complete an incomplete file
- Deleting incorrect information
The request for rectification must be submitted in writing and accompanied by the evidence necessary to justify the corrections requested. Clinique Omicron undertakes to make the corrections within a reasonable time and to inform third parties who have had access to the erroneous data, if applicable.
11.3 Right of deletion (within legal limits)
Data subjects may request the deletion of their personal information when:
- The information is no longer required for the purposes for which it was collected.
- Consent has been withdrawn and there is no legal basis for retaining the data
- The information has been collected, used or disclosed in a manner that does not comply with the law.
However, this right of deletion may be limited by legal or regulatory obligations, in particular :
- The need to keep medical records for minimum periods prescribed by law
- Tax, legal or contractual obligations requiring data to be kept for a certain period of time
11.4. Right to withdraw consent
Individuals have the right to withdraw their consent to the collection, use or disclosure of their personal information at any time. Withdrawal of consent :
- Has no retroactive effect on treatments performed prior to withdrawal
- May limit the Clinic's ability to provide certain services if the information is essential to their provision
Withdrawal of consent must be made in writing. The clinic will inform the person concerned of the possible consequences of such withdrawal.
11.5. Right to data portability
Data subjects may request to receive their personal information in a structured, commonly used and machine-readable format. This right also allows them to request the direct transfer of this information to another organization, where technically possible.
This right applies in particular to personal information collected with the consent of the person concerned or as part of the performance of a contract. Clinique Omicron undertakes to respond to such requests within the time limits laid down by law.
How to exercise your rights
To exercise any of these rights, the person concerned must submit a written request, accompanied by proof of identity, to the Privacy Officer of Clinique Omicron :
Privacy Officer
E-mail : protectionrenseignements@cliniqueomicron.ca
The Clinic will respond to requests within 30 days of receipt of a complete request. In the event of refusal, the person concerned will be informed of the reasons for the refusal, as well as possible recourse, including the possibility of lodging a complaint with the Commission d'accès à l'information du Québec.
Clinique Omicron Inc. takes the management of privacy incidents very seriously in order to protect the personal information it holds. A rigorous framework is in place to detect, report, assess and promptly deal with any incident so as to limit its impact and comply with legal obligations.
12.1. Definition of a confidentiality incident
A confidentiality incident is any event involving :
- Unauthorized access to personal information, whether intentional or accidental.
- Unauthorized use of personal information for unintended or unconsented purposes.
- Unauthorized disclosure of personal information to third parties without the required consent or in violation of applicable laws.
- Loss of personal information, including accidental deletion, theft, or temporary or permanent inaccessibility.
Examples of confidentiality incidents :
- Sending medical information to the wrong recipient.
- Hacking into computer systems containing sensitive data.
- Loss of an unsecured laptop containing confidential files.
- Unauthorized access to files by an unauthorized employee.
12.2. Incident reporting and management procedures
Clinique Omicron has implemented a confidentiality incident management procedure to ensure a rapid and effective response in the event of an incident. This procedure includes the following steps:
- Incident detection and reporting
- Any employee, service provider or partner of the Clinic must immediately report any suspected or confirmed incident of confidentiality.
- You can report directly to the Privacy Officer (RPRP) by e-mail at : protectionrenseignements@cliniqueomicron.ca
- The incident report must contain a detailed description of the event, including the date, time, nature of the information involved, and the circumstances of the incident.
- Incident assessment
- The RPRP carries out an in-depth analysis to determine the nature of the incident, the causes, the extent of the impact, and the potential risk to those involved.
- Risk assessment takes into account the sensitivity of the compromised information, the likelihood of malicious use, and the possible consequences for individual privacy.
- Immediate corrective measures
- Take measures to contain the incident (e.g. suspend unauthorized access, restore data, secure compromised systems).
- Implement solutions to correct identified vulnerabilities and prevent recurrence of the incident.
- Complete documentation of the incident, the measures taken and the results of the risk assessment.
12.3 Obligation to notify data subjects and authorities
When a confidentiality incident presents a serious risk of harm to the persons concerned, Clinique Omicron is obliged to inform them and the competent authorities.
- Notification to the persons concerned
- Notification is sent as soon as possible after the incident is discovered.
- It includes :
- A description of the incident and the personal information involved.
- Possible risks for the person concerned.
- Measures taken to mitigate the effects of the incident.
- Measures the data subject can take to protect himself (e.g. credit monitoring, changing passwords).
- Contact information for the Privacy Officer should you have any questions.
- Notification to the competent authorities
- The Commission d'accès à l'information du Québec (CAI) must be informed when the incident presents a serious risk of harm.
- The notification includes details of the nature of the incident, the type of information affected, the action taken, and the number of people involved.
- Keeping an incident register
- Clinique Omicron maintains a confidentiality incident register, documenting each reported incident, whether or not it required formal notification.
- This register may be required during an audit or investigation by the CAI.
The rigorous management of confidentiality incidents reflects Clinique Omicron's commitment to protecting the privacy of those concerned and to reacting proactively in the event of a security breach.
La Clinique Omicron utilise diverses technologies numériques pour améliorer l’expérience des utilisateurs, optimiser ses services en ligne et assurer la sécurité des communications électroniques. L’utilisation de ces technologies est encadrée afin de respecter la vie privée des utilisateurs et de protéger leurs renseignements personnels conformément aux lois applicables en matière de protection des données.
13.1. Cookies and similar technologies
Les témoins de connexion (ou cookies) sont de petits fichiers texte enregistrés sur l’appareil de l’utilisateur lorsqu’il visite notre site web. Ils sont utilisés pour diverses finalités, notamment pour faciliter la navigation, améliorer l’expérience utilisateur et collecter des données statistiques sur l’utilisation du site.
Types of cookies used :
- Essential cookies: necessary for the proper operation of the website (e.g. session management, security).
– Témoins de performance : permettent d’analyser la fréquentation et l’utilisation du site afin d’en améliorer la performance.
– Témoins de fonctionnalité : facilitent la personnalisation de l’expérience utilisateur (ex. : mémorisation des préférences linguistiques).
– Témoins publicitaires : utilisés pour afficher des publicités ciblées en fonction des intérêts de l’utilisateur.
Cookie management :
– L’utilisateur peut gérer ou désactiver les témoins à tout moment via les paramètres de son navigateur.
– Le refus de certains témoins peut limiter l’accès à certaines fonctionnalités du site.
– Lors de la première visite sur le site, une bannière de consentement est affichée pour informer l’utilisateur de l’utilisation des témoins et recueillir son consentement.
13.2. Analysis of browsing data (Google Analytics, etc.)
La Clinique Omicron utilise des outils d’analyse, tels que Google Analytics, pour recueillir des informations sur l’utilisation du site web. Ces outils nous aident à comprendre comment les utilisateurs interagissent avec le site afin d’en améliorer la performance et le contenu.
Data collected :
- Anonymized IP address
– Type de navigateur et système d’exploitation
- Pages visited, duration of visits and browsing paths
- Approximate geographical location
- Source of traffic (search engines, social networks, etc.)
Finalités de l’analyse :
- Evaluate website performance
– Identifier les tendances de navigation et les points d’amélioration
- Optimize content and services
Data protection :
– L’anonymisation des adresses IP est activée pour limiter l’identification des utilisateurs.
- The data collected is used for statistical purposes and is not shared for commercial purposes without explicit consent.
Les utilisateurs peuvent désactiver la collecte de données par Google Analytics en installant le module complémentaire de désactivation disponible ici.
13.3. Electronic communications security
La Clinique Omicron met en œuvre des mesures de sécurité robustes pour protéger la confidentialité et l’intégrité des communications électroniques, notamment lors de l’échange de renseignements personnels par courriel, via des formulaires en ligne ou par d’autres canaux numériques.
Safety measures :
- Data encryption during transmission, including for e-mails containing sensitive information.
– Authentification sécurisée pour l’accès aux plateformes électroniques (authentification à deux facteurs, mots de passe robustes).
– Surveillance des activités suspectes sur les systèmes d’information pour détecter rapidement les tentatives d’intrusion ou les cyberattaques.
- Staff training on best practices in electronic communications security.
Recommendations to users :
- Do not share sensitive personal information via unsecured e-mail.
- Use strong passwords and do not share them with third parties.
– Signaler immédiatement toute activité suspecte à la Clinique Omicron via : protectionrenseignements@cliniqueomicron.ca.
These practices are designed to ensure a secure digital environment that complies with the highest standards of cybersecurity and privacy protection.
13.4. Protection contre les soumissions automatisées (Cloudflare Turnstile)
La Clinique Omicron utilise le service Cloudflare Turnstile sur ses formulaires en ligne afin de prévenir les soumissions automatisées par des robots et de protéger l’intégrité des renseignements transmis. Ce service fonctionne de manière invisible, sans interaction visible pour l’utilisateur et sans recours à des CAPTCHA traditionnels.
Données techniques traitées :
– Adresse IP du visiteur
– En-têtes du navigateur (type de navigateur, langue, système d’exploitation)
– Signaux comportementaux non personnalisés (mouvements de souris, rythme de saisie, caractéristiques de l’appareil) utilisés exclusivement pour distinguer un humain d’un robot
– Jeton de validation temporaire émis par Cloudflare
Finalités du traitement :
– Détecter et bloquer les tentatives de soumission automatisée
– Protéger les formulaires de prise de rendez-vous, de demande de dossier, de dépôt de document et de consentement contre les abus
– Garantir la disponibilité et la fiabilité des services en ligne
Data protection :
– Aucun renseignement permettant d’identifier directement la personne concernée n’est utilisé à d’autres fins que la vérification anti-robot.
– Les données techniques traitées par Cloudflare ne sont pas utilisées à des fins publicitaires ni de profilage commercial.
– Cloudflare agit en qualité de sous-traitant pour le compte de la Clinique Omicron, conformément à la Loi sur la protection des renseignements personnels dans le secteur privé du Québec (Loi 25).
Encadrement contractuel :
Le traitement est encadré par les politiques de Cloudflare, Inc. :
– Addendum de confidentialité Turnstile : https://www.cloudflare.com/application-services/products/turnstile-privacy/
– Politique de confidentialité de Cloudflare : https://www.cloudflare.com/privacypolicy/
L’utilisateur qui souhaite exercer ses droits relativement à ce traitement (accès, rectification, retrait du consentement dans la mesure permise par la finalité de sécurité) peut communiquer avec le responsable de la protection des renseignements personnels de la Clinique Omicron aux coordonnées indiquées à la section 15 de la présente politique.
Clinique Omicron Inc. recognizes that the protection of personal information depends largely on the vigilance and good practices of its staff. This is why training and accountability measures are in place to ensure secure data management throughout its life cycle.
14.1 Making employees aware of the need to protect personal information
Staff awareness is essential to prevent confidentiality incidents. Clinique Omicron is committed to providing ongoing training tailored to each individual's roles and responsibilities.
Continuing education program :
- Initial training :
- Introduction to the basic principles of privacy protection.
- Presentation of internal information security policies.
- Raising awareness of data management risks (cybersecurity, human error, etc.).
- Periodic training :
- Workshops to update on new safety practices and legislative changes (e.g. Quebec's Bill 25).
- Security incident simulations to reinforce employees' ability to react.
- Awareness sessions on managing confidentiality incidents and preventing data leaks.
- Specialized modules :
- Targeted training for employees with privileged access to sensitive data (e.g. medical staff, human resources, IT).
- IT security, including best practices for the use of e-mail, passwords, mobile devices, etc.
Monitoring and evaluation :
- Knowledge tests to assess understanding of data protection issues.
- Mandatory participation reports for all employees, with reminders in the event of non-compliance.
14.2. Confidentiality agreements for employees and subcontractors
To further protect personal information, Clinique Omicron requires all employees, suppliers and subcontractors to sign confidentiality agreements.
Content of confidentiality agreements :
- Commitment to confidentiality: Obligation to protect the confidentiality of personal information and to limit its use to authorized business purposes.
- Restricted access to data: Commitment to access only the information required to perform assigned duties.
- Responsibilities in the event of an incident: Obligation to promptly report any confidentiality incident or data security breach.
- Penalties for non-compliance: Specification of the disciplinary measures that can be taken in the event of non-compliance (warning, suspension or even termination of employment or service contract).
Application to subcontractors :
- Any subcontractor with access to personal information must also sign a confidentiality agreement before commencing operations.
- Service contracts include specific clauses on data protection, including security, confidentiality and incident management requirements.
Compliance audit :
– La Clinique effectue des audits internes réguliers pour s’assurer que les employés et les sous-traitants respectent leurs engagements en matière de confidentialité.
- In the event of non-compliance, corrective measures are rapidly implemented.
These initiatives aim to create a strong organizational culture focused on the protection of personal information, and to empower every team member in the secure management of data.
La Clinique Omicron Inc. et l’ensemble des entités du Groupe Omicron (Gestion Omegis Inc., UVO Soins à domicile) désignent un Responsable de la protection des renseignements personnels (RPP) chargé de veiller à la conformité des pratiques de l’organisation en matière de gestion des renseignements personnels, conformément à l’article 3.1 de la Loi sur la protection des renseignements personnels dans le secteur privé (LPRPSP) telle que modifiée par la Loi 25.
15.1. Governance Structure — Principal RPP and Delegated RPP
The Omicron Group has established a two-tier structure to ensure comprehensive coverage of its obligations:
Le RPP principal détient l’autorité décisionnelle en matière de protection des renseignements personnels. Il est responsable de l’orientation stratégique, de l’approbation des politiques, de la déclaration des incidents graves à la Commission d’accès à l’information (CAI) et de la supervision de l’ensemble des obligations Loi 25 pour toutes les entités, succursales et secteurs d’activité du Groupe.
Le RPP délégué assure le traitement opérationnel quotidien des demandes d’accès, de rectification et de portabilité, la réception des signalements d’incidents, ainsi que la coordination des réponses aux plaintes. Il constitue le point de contact accessible pour les patients, employés et partenaires.
15.2. Role and Responsibilities
The RPP and its delegate are jointly responsible for:
- Ensure Group compliance with Law 25, the PDPA, and applicable sectoral laws (LSSSS, Code of Ethics of Physicians, OIIQ standards)
- Développer, mettre à jour et superviser l’application des politiques de confidentialité et des protocoles de sécurité des données
- Conduct Privacy Impact Assessments (PIAs) for any new project, system, or data transfer outside of Quebec
- Coordonner la réponse aux incidents de confidentialité, incluant l’évaluation des risques, la notification des personnes concernées et la déclaration à la CAI dans les délais légaux
- Maintain the privacy incident log and the information asset register
- Organize the mandatory annual staff training on personal information protection
- Répondre aux demandes d’accès, de rectification, de portabilité et de désindexation dans le délai légal de 30 jours
- Receiving and processing personal information protection complaints
15.3. Official Coordinates
Patients, employees, and partners wishing to exercise their rights, report an incident, or lodge a complaint can contact the Omicron Group's RPP at the following details:
RPP principal — Decision-making responsible Operations Department — Omicron Group Email: rprp@cliniqueomicron.ca Phone: 514-606-3350
RPP Delegate — Operational Contact Point Administration and Accounting — Clinique Omicron Inc. Email: rprp@cliniqueomicron.ca Phone: 514-606-3350
Le RPP et son délégué s’engagent à répondre à toute demande dans un délai de 30 jours calendriers à compter de la réception de la demande complète. En cas de nécessité, ce délai peut être prorogé de 10 jours supplémentaires avec avis écrit au demandeur.
En cas de refus de donner suite à une demande, une explication motivée sera fournie, accompagnée des recours disponibles, notamment le droit de déposer une plainte auprès de la Commission d’accès à l’information du Québec — www.cai.gouv.qc.ca
La Clinique Omicron Inc. s’engage à traiter de manière rigoureuse et confidentielle toute plainte relative à la protection des renseignements personnels. Ce processus vise à garantir la transparence, le respect des droits des personnes concernées, ainsi que la conformité aux obligations légales prévues par la Loi sur la protection des renseignements personnels dans le secteur privé.
16.1 How to file a complaint
Any person concerned may lodge a complaint if he or she believes that Clinique Omicron :
- Mismanaged personal information;
– N’a pas respecté ses obligations légales en matière de confidentialité ;
– N’a pas répondu de manière satisfaisante à une demande liée à l’accès, la rectification, la suppression ou la portabilité de ses données.
How to file a complaint :
- The complaint must be submitted in writing (e-mail or letter) to Chief Privacy Officer (CPO).
- The complaint must contain the following information:
- Complainant's full name ;
- Contact details (address, telephone number, e-mail) ;
- Precise description of the alleged facts;
- Relevant documents in support of the complaint (if applicable).
Contact details for filing a complaint :
E-mail : protectionrenseignements@cliniqueomicron.ca
Phone : 514-606-3350
16.2. Processing times
Clinique Omicron treats each complaint confidentially and impartially, according to the following steps:
1. Acknowledgement of receipt of complaint :
- The clinic will acknowledge receipt of the complaint within 5 working days of its receipt.
- A written acknowledgement of receipt is sent to the complainant, confirming receipt of the complaint and specifying the estimated processing time.
2. Complaint assessment :
- The RPRP analyzes the complaint, assesses the facts, gathers additional information if necessary and consults the parties concerned.
- This assessment includes an analysis of the compliance of the clinic's practices with applicable laws.
3. Response to the complainant :
- Clinique Omicron will provide a reasoned written response within 30 days of receipt of the complete complaint.
- The response specifies the conclusions of the assessment, any corrective measures taken, or the reasons for any refusal to act on the complaint.
4. Time extension (if necessary) :
- If exceptional circumstances prevent a response within 30 days, the Clinic will inform the complainant of the reasons for the delay and the additional time required.
16.3. Recourse to the Commission d'accès à l'information du Québec (CAI)
Si le plaignant n’est pas satisfait de la réponse fournie par la Clinique Omicron ou s’il estime que ses droits n’ont pas été respectés, il peut déposer une plainte auprès de la Commission d’accès à l’information du Québec (CAI).
Contact information for the Commission d'accès à l'information du Québec :
- Website : www.cai.gouv.qc.ca
- Phone : 1-888-528-7741
- Complaint form : Available online on the CAI website
The complaint to CAI must be accompanied by all relevant documentation, including a copy of the complaint originally submitted to Clinique Omicron and the response received, if any.
Clinique Omicron Inc. is committed to keeping its privacy policy up-to-date to reflect changes in legislation, technological developments and organizational practices. This process ensures that the management of personal information remains compliant with current legal requirements and data protection best practices.
17.1. Frequency of revisions
The privacy policy is reviewed regularly to ensure its relevance and effectiveness.
Frequency of revisions :
- Annual review: The policy is reviewed at least once a year by the Chief Privacy Officer (CPO), in collaboration with the relevant stakeholders.
- Ad hoc revision: The policy may also be updated at any time in the event of :
- Legislative or regulatory changes, particularly with regard to personal data protection (e.g. changes to the Act respecting the protection of personal information in the private sector).
- Introduction of new technologies or services likely to affect the management of personal information.
- Major organizational changes (mergers, acquisitions, reorganization of departments).
- Results of internal audits or confidentiality incidents requiring adjustments.
17.2. Notification of changes to users
Clinique Omicron ensures that all persons concerned are informed in a transparent manner of any changes made to its privacy policy.
Notification procedure :
- Publication on website: The most recent version of the policy is always available on Clinique Omicron's official website at the following address cliniqueomicron.ca
- Notification of Changes: In the event of significant changes affecting the way personal information is collected, used, disclosed or retained, the Clinic will notify users:
- A visible notice on the home page of the website;
- By e-mail to the persons concerned, where applicable.
- Date of last update: Each version of the policy specifies the date of the last update to enable users to identify recent changes.
Effective date of changes :
- Changes take effect on the date indicated in the updated policy.
- By continuing to use the Clinic's services after the changes come into effect, users are deemed to have read the revised policy.
Responsible for updates :
The Privacy Officer is responsible for coordinating policy revisions and ensuring that all changes are properly documented and communicated.
This approach is intended to ensure the transparency of Clinique Omicron's practices and to strengthen user confidence in the management of their personal information.
|
TYPE OF CONTACT WITH OMICRON CLINIC
|
TYPES OF RP AND SENSITIVE RP COLLECTED
|
PURPOSES FOR WHICH PPR AND SENSITIVE PPR ARE COLLECTED AND USED
|
COLLECTION RESOURCES
|
|---|---|---|---|
|
Service providers and consultants (in general) |
- Name |
- Identification |
- By e-mail sent by the consultant |
|
Patients |
- Name |
- Identification |
- By phone |
|
Job applicants and Employees |
- Name |
- Payroll processing and payment |
- By e-mail sent by the candidate or employee |
|
Service providers and consultants (care providers only) |
- Various permit and license numbers |
- Prescription management |
- By e-mail sent by the consultant |
Clinique Omicron Inc. uses automated data collection technologies to optimize the user experience on its digital platforms, improve the quality of its services and ensure the security of the information processed. This appendix describes the types of data collected automatically, their purposes, and the options available to users to manage their privacy preferences.
B.1. Details of automated data collection
Automated data collection is based on various technologies that enable us to track user activity as they interact with our websites and applications.
1. Cookies
Cookies are small text files placed on the user's device (computer, phone, tablet) when visiting a website. They are essential for the proper operation of the site and offer several functionalities:
- Essential cookies: necessary for site navigation and access to secure functions (e.g. user session management).
- Performance and analysis cookies: used to collect information on site use (visitor numbers, length of visits, pages consulted) for the purposes of continuous improvement.
- Personalization indicators: to store user preferences (language, display settings).
- Advertising cookies: facilitate the delivery of advertising content targeted to the user's interests (with explicit consent).
2. Spy pixels (web beacons or invisible pixels)
Web beacons are tiny invisible images embedded in web pages or e-mails. They are used to :
- Check whether an e-mail has been opened by the recipient ;
- Track interactions on online ads;
- Analyze user behavior on the site.
3. Log Files
Log files automatically record certain information when you visit the site, such as :
- The user's IP address (often partially anonymized) ;
- Browser type and operating system;
- Pages consulted, duration of sessions and interactions carried out.
4. Traffic analysis tools (e.g. Google Analytics)
Clinique Omicron uses tools like Google Analytics to understand user behavior and optimize the digital experience. These tools collect data such as:
- Pages visited, time spent on each page ;
- Source of traffic (search engines, social networks, etc.) ;
- Click-through rates and conversions.
B.2 Purposes of automated data collection
The data collected automatically is used with respect for the confidentiality of users, and is used for the following purposes:
- Optimizing the user experience: improving navigation, personalizing content and settings.
- Site performance analysis: monitoring of traffic statistics to identify user needs and optimize services.
- Security and fraud prevention: detection of suspicious activity, protection against cyber-attacks and management of security incidents.
– Marketing ciblé (avec consentement) : affichage de publicités adaptées aux intérêts des utilisateurs et mesure de l’efficacité des campagnes marketing.
B.3 Managing user preferences
Users of Clinique Omicron have several ways to manage the collection of their automated data.
1. Managing cookies via the website
- On the first visit, a consent banner is displayed to inform the user of the use of cookies.
- Users can accept, refuse or personalize their cookie preferences at any time via the cookie management center available on the site.
– Le refus des témoins peut limiter certaines fonctionnalités du site, notamment l’accès à des contenus personnalisés.
2. Browser settings
Users can configure their browser to :
- Block all cookies;
- Delete cookies already saved ;
- Receive notifications before a cookie is installed.
Instructions vary depending on the browser used (Google Chrome, Mozilla Firefox, Safari, etc.).
3. Deactivation of analysis tools (Google Analytics, etc.)
Users can disable the collection of data by tools such as Google Analytics by installing an available browser add-on. here.
B.4 Security of automatically collected data
Clinique Omicron applies rigorous security measures to protect automatically collected data:
- Data encryption for transfers of sensitive information ;
- Access control restricted to authorized persons ;
- Monitoring suspicious activity and security vulnerabilities ;
- Regular system updates to prevent security breaches.
B.5 Contact for automated data management
For any questions or concerns relating to the management of automated data, users may contact :
Chief Privacy Officer (CPO)
E-mail : protectionrenseignements@cliniqueomicron.ca
Phone : 514-606-3350
Clinique Omicron undertakes to respond to any request relating to data confidentiality within a reasonable period of time, in accordance with the legal obligations in force.