Last updated: March 25, 2019
Canada Med Dispensary and Xeraflop Technologies Inc. dba Xera One (“us”, “we”, or “our”) operate CanadaMedDispensary.ca (the “Site”).
2. Data Controller
3. What are the information we collect?
We collect information, including personal information, in various ways when you use our site. “Personal information” means any information which, either alone or in combination with other information, identifies you as an individual, such as your name, post address and email address.
We collect personal information that you provide us voluntarily. For example, when you create an account with us, you provide us with your first name, your last name, your email address, postal address, phone number, company name and other information.
We recognize our customers’ right to control the type of personal information that is collected about them. Our customers can access, make rectification and delete their personal information at any time. We retain your personal information while you are a customer and will delete your personal information upon request.
For more information, feel free to email us at [email protected]
4. Legal basis for processing
We need to process your information in order to provide you with the products you have requested from us. When the processing is not strictly necessary, such as when we process your personal data in order to improve our services, we base our processing on us having a legitimate interested.
You have the right to object to processing of your personal data based upon a legitimate interest as legal basis. If you object to such processing, we will continue with the processing only if there is a compelling legitimate basis for the processing that outweighs your interest, fundamental rights or freedoms. Please see below if you want to read more about your rights.
5. How do we use the information we collect?
In general, we use the information we collect primarily to provide, maintain, protect, and improve our current products and services and to develop new ones. This may include:
To ease the creation and the security of your account on our service. To administer your account if you have a subscription plan with our site, including billing and payment. To identify you as a customer in our services. To improve our services, products, site and how we operate our business. To understand and improve your experience using our services. To provide and deliver products that you may have requested. For our customer service team to answer your questions. To communicate with you about products updates, news or security alerts. To administer and carry out our obligations towards you as a customer, and safeguard our legal interests. To develop and improve our products and services. To uphold a high security for our services and prevent misuse and unauthorised usage of our services. To comply with our legal obligations.
6. Automated Decision Making
We do not use any automated decision-making which has significantly effects on you.
7. For how long do we keep your personal data?
We may be required to keep your personal data for other reasons, such as to comply with legal obligations or to safeguard our legal interest, or for any other important public interest.
8. With whom do we share your personal data with?
We may share your personal data with third parties such as our cloud provider which we cooperate with to provide our services. These IT services providers may only process your personal data in accordance with our instructions. We will share your data in a manner necessary to provide the products you have ordered on our site with Licensed Producer(s) and medical practitioners via email, text message, fax and other electronic messaging including between the Licensed Producer(s) and their respective subsidiaries, affiliates, technology providers, medical practitioners, and business brands. We may also in certain cases be required to share your personal data with public authorities or other third parties in connection with court proceedings, corporate acquisitions or similar reasons.
Although we do not sell your personal data to any third party, third parties may set third party cookies when you visit our website.
9. Where do we process your personal data?
We aim at only processing your personal data within Canada and host our server infrastructure in Canada. In some cases, we may transfer your personal data to a country outside of Canada. If personal data is transferred to any such country, we will ensure that your personal data is protected and that the transfer is carried out in accordance with applicable law.
10. Your rights / our responsibility for your rights
We are responsible for answering your request to exercise your rights within one month from our receipt of your request. If your request is complicated, or if we have received a large extent of requests, we are entitled to prolong our response period with two additional months. If we assess that we cannot perform the actions you have requested, we will within one month explain why and inform you about your right to lodge a complaint with the data protection authority.
All information and communication, and all actions we carry out, is at no cost for you. If the action you request is manifestly unfounded or excessive, we are entitled to charge you an administrative fee to provide you with the requested information or carry out the requested action or refuse to meet your request.
Your right to access, rectification and erasure of personal data and restriction of processing.
You have the right to request:
Access to your personal data
This means that you have the right to request an abstract from our data record regarding our use of your personal data. You also have the right to request a copy of the personal information being processed at no cost. However, we may charge you a reasonable administrative fee to provide you with additional copies of the personal data. If you make your access request by electronic means such as email, we will provide you with the information in a commonly used electronic format.
Rectification of your personal data
We will at your request, or at our own initiative, rectify, anonymise, erase or complement personal data that you or we discover is inaccurate, incomplete or misleading. You also have the right to complement the personal data with additional data if relevant information is missing.
Erasure of your personal data
You have the right to request that we erase your personal data if we do no longer have an acceptable reason for processing the data. Given this, erasure shall be made by us if: the personal data is no longer necessary for the purposes for which it was collected, you object to the processing of your personal data based on our legitimate interest and there is no overriding legitimate ground for the processing, the personal data has not been lawfully processed, we are required to erase the personal data due to a legal obligation, or you are a child and we have collected the personal data in relation to the offer of information society services. However, there might be requirements under applicable law, or other weighty reasons, that entail in that we cannot immediately erase your personal data. In such case, we will stop using your personal data for any other reasons than to comply with the applicable law, or the relevant weighty reason.
Right to restrict processing
This means that we temporarily restrict the processing of your personal data. You have the right to request restriction of the processing when: you have requested rectification of your personal data in accordance with the section above during the time period we are verifying the accuracy of the data the processing is unlawful and you do not want the personal data to be erased, We, in our capacity as data controller, do no longer need the personal data for the purposes for which it was processed, but you require us to retain the information for the establishment, exercise or defence of legal claims, or you have objected to our legitimate interest for the processing in accordance with the section “Your right to object to the processing” during the time period we determine whether the legitimate interest overrides your privacy rights.
We will take all reasonable and possible actions to notify any recipients of your personal data as set out in the section “With whom do we share your personal data with” above regarding any rectification, erasure or restrictions carried out by us. At your request, we will also inform you of which third parties we have shared your personal data with.
Your right to object to the processing
You have the right to object to such processing of your personal data based upon our legitimate interest. If you object to such processing, we will only continue with the processing if we have a compelling legitimate reason for the processing that outweighs your interest, rights or freedoms, or unless continued processing is necessary for the establishment, exercise or defence of a legal claim.
Your right to portability
You have the right to portability. This means that you have the right to receive certain of your personal data in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller. You only have this right when your personal data is processed by automated means and our legal basis for the processing is performance of a contract between you and us. This means e.g. that you have the right to receive and transfer all of the personal data that you have provided us with to create a user account at our site.
Your right to lodge a complaint with the data protection authority You have the right to lodge any complaints regarding our processing of your personal data with the data protection authority.
We protect your personal data
You shall always feel safe when providing us with your personal data. Therefore, we have implemented appropriate security measures to protect your personal data against unauthorised access, alteration and erasure. In the case of a security breach that may significantly affect you or your personal data, e.g. when there is a risk of fraud or identity theft, we will contact you and inform you of what you can do to reduce this risk.
Email: [email protected]