Privacy policy

Privacy of personal information is an important principle of Magic Needle. We are committed to collecting, using, and disclosing personal information responsibly and only to the extent necessary for the services we provide. We also try to be open and transparent as to how we handle personal information. We use a number of consultants and agencies that may, in the course of their duties, have limited access to the personal information we hold. These include consultants, contractors, office security and maintenance, bookkeepers, and accountants, temporary workers, credit card/merchant terminal services provider companies, cleaners, and lawyers. We restrict their access to any personal information we hold as much as is reasonably possible. We also have their assurance that they follow appropriate privacy principles.
This document describes our privacy policies.

What is personal information?

Personal information is information about an identifiable individual. Personal information includes information that relates to their personal characteristics (e.g., gender, age, income, home address, email, name, phone number, ethnic background, family status), their health (e.g., health history, health conditions, health services received by them) or their activities and views (e.g., religion, politics, opinions expressed by an individual, etc.) Personal information is to be contrasted with business information (e.g., an individual’s address, email address, and telephone number), which is not protected by privacy legislation.

What is the personal health information?

In Ontario, personal health information is covered under the Personal Health Information Protection Act (PHIPA). Personal Health Information is very broadly defined in PHIPA and includes the following components:
  • It must relate to an identifiable individual, including information that can be combined with other data (e.g., a code or a key to then identify the individual)
  • It can be in an oral or recorded format (thus simply asking a question even if the answer is not recorded can constitute collecting personal health information), and it relates to the individual’s:
1. Physical or mental condition, including his or her family health history,
2. Health care (including maintenance, preventative, or palliative measures,
3. Health services provider),
4. Payment for health services including health card number,
5. Substitute decision maker, or
6. Non-healthcare information (e.g. contact information) mixed in with other personal health information
Magic Needle collects, retains, destroys when appropriate, and discloses all personal health information in accordance with PHIPA.

Primary purposes for collecting personal information

About Clients:

We collect, use, and disclose personal information in order to provide services for our clients in the best possible way.
For example, we collect information about a client’s health history, including their family history, physical condition and function, and social situation in order to help us assess what their health conditions and needs are, to advise them of their options, and then to provide the health care they choose to have. A second primary purpose is to obtain a baseline of health and social information so that in providing ongoing health services we can identify changes that are occurring over time. We rarely collect such information without the client’s express consent, but this might occur in an emergency or where we believe the client would consent if asked and it is impractical to obtain consent (e.g., a family member passing a message from our client and we have no reason to think that the message is not genuine).

About website visitors:

Third-Party Links and Sources of Information
This website may include links to other websites. This privacy policy applies only to this website and does not apply to websites linking to or from this site. You should carefully examine the privacy policies of sites appearing on, or linking to or from this website, which do not display this privacy policy. Personal information that you choose to provide to other websites will be subject to the privacy policies of those sites. Information collected on this site is used to improve the site and ensure the best possible visitor’s and client’s experience.

Cookies
This website uses standard technology known as “cookies” including session cookies and persistent cookies.
  • Session cookies temporarily keep your settings. This information is stored until your browser is closed.
  • Persistent cookies remain after the browser is closed and are stored locally on your system. We do not use these cookies to store personal information. You may choose to delete persistent cookies after visiting the website.

Tracking
This website uses analytical tools such as Google Analytics - a tracking tool provided by Google, for audience activity measurement, demographics reporting, and remarketing. You can opt out of Google Analytics by installing a browser plug-in available on Google’s website.
This website collects information about how our website is used. Each time a visitor comes to the website our web server collects the visitor’s domain name and/or IP address. We cannot determine an individual’s identity from an IP address.

Advertising and marketing
This website may require third-party advertisers to place cookies in your browser. When you visit this website, advertising cookies will be placed on your computer so that we can understand what you’re interested in on this website. The techniques used do not collect personal information at all, such as your name, email address, or telephone number, unless it is supplied to us voluntarily by you, like by completing a form. Any information you supply is kept confidential, and it is never sold or transferred to any third-party companies. If you want to opt out of advertising and marketing, contact us via email with according request.

Related and secondary purposes for collecting personal information

Like most organizations, we also collect, use, and disclose information for purposes related to or secondary to our primary purposes. The most common examples of our related and secondary purposes are as follows:
  • To invoice clients for goods or services that were not paid for, to process credit card payments or to collect unpaid accounts.
  • To advise clients and others of special events or opportunities (e.g., new service, arrival of a new product, change of location/contact information) that we have available.
  • Occasional communications from the Magic Needle (e.g. newsletter, holiday/birthday cards, information about our services, special offers).
  • Our clinic reviews client information for the purpose of ensuring that we provide high-quality services. In addition, external consultants (e.g., auditors, lawyers, practice consultants, voluntary accreditation programs) may on our behalf do audits and continuing quality improvement reviews of Magic Needle, including reviewing client information.
  • We may report misconduct, incompetence, or incapacity of other practitioners. Also, we believes that we should report information suggesting illegal behavior to the authorities. External regulators have their own strict privacy obligations. Sometimes these reports may include personal information about our clients, or other individuals, to support the concern (e.g., improper services).
  • The cost of some services provided by Magic Needle to clients is paid for by third parties (e.g. extended health/ insurers). These third-party payers often have your consent or legislative authority to direct us to collect and disclose to them certain information in order to demonstrate client entitlement to this funding.
  • Clients or other individuals we deal with may have questions about our or services after they have been received. We also provide ongoing services for many of our clients over a period of months or years for which previously collected information is helpful.
  • If Magic Needle or its assets were to be sold, the purchaser would want to conduct a “due diligence” review of the Clinic’s records to ensure that it is a viable business that has been honestly portrayed to the purchaser. This due diligence may involve a review of our accounting and service files. The purchaser would not be able to remove or record personal information. Before being provided access to the files, the purchaser must provide a written promise to keep all personal information confidential.

You can opt out of some of the related or secondary purposes (e.g., by declining to receive communications from the Magic Needle by contacting us via email with according request, by paying for your services in advance). However, we do not have a choice about some of these related or secondary purposes (e.g., external regulation).

Protecting personal information

We understand the importance of protecting personal information. For that reason, we have taken the following steps:
  • Paper information is either under supervision or secured in a locked or restricted area.
  • Electronic hardware is either under supervision or secured in a locked or restricted area at all times. In addition, passwords are used on all devices.
  • Paper information is transmitted through sealed, addressed envelopes or boxes by reputable companies.
  • Electronic information is transmitted either through a direct line or is anonymized or encrypted.
  • Staff is trained to collect, use, and disclose personal information only as necessary to fulfill their duties and in accordance with our privacy policy.
  • External consultants and agencies with access to personal information must enter into privacy agreements with us.

Retention and destruction of personal information

We need to retain information for some time to provide services for our clients and for our own accountability to external regulatory bodies. If you ask (send us a request via email), we will destroy/delete your information right away.
We destroy paper files containing personal information by shredding them. We destroy electronic information by deleting it from the software that has been used to contain such information and/or from the hardware.

You can access your information

With only a few exceptions, you have the right to see what personal information we hold about you. Often all you have to do is ask (send us a request via email). We can help you identify what records we might have about you. We will also try to help you understand any information you do not understand (e.g., short forms, technical language, etc.). We will need to confirm your identity, if we do not know you, before providing you with this access. We reserve the right to charge a nominal fee for such requests.
If there is a problem, we may ask you to put your request in writing. If we cannot give you access, we will tell you within 30 days if at all possible, and tell you the reason, as best we can, as to why we cannot give you access.
If you believe there is a mistake in the information, you have the right to ask for it to be corrected. This applies only to factual information. We may ask you to provide documentation that our files are wrong. If we agree that we made a mistake, we will make the correction and notify anyone to whom we sent this information. If we do not agree that we have made a mistake, we will still agree to include in our file a brief statement from you on the point and we will forward that statement to anyone else who received the earlier information.

Do you have questions or concerns?

If you have any questions, or concerns regarding your personal information our services, or our privacy practices, please email us at info@acupuncturemn.ca
Or contact us at the following address:
Magic Needle Acupuncture And Herbal Clinic (Sergey Fuchinde)
2 Bingham Street
Richmond Hill, ON (L4C 9R1)
Phone: 416-567-9859

For more general inquiries, the Privacy Commissioner of Canada oversees the administration of privacy legislation in the private sector. The Commissioner also acts as a kind of ombudsman for privacy disputes. The Privacy Commissioner can be reached at:
112 KENT STREET | OTTAWA, ONTARIO | K1A 1H3
PHONE (613) 995-8210 | TOLL-FREE 1-800-282-1376 | FAX (613) 947-6850 | TTY (613) 992-9190 www.privcom.gc.ca
Inquiries pertaining to personal health information in Ontario can be directed to:
Information and Privacy Commissioner/Ontario
2 Bloor Street East, Suite 1400
Toronto, ON, M4W 1A8
Phone: 416-326-3333 or 1-800-387-0073
Fax: 416-325-9195
WWW.IPC.ON.CA


This policy is made under the Personal Information Protection and Electronic Documents Act. Specific policies pertaining to personal health information are made under the Personal Health Information Protection Act.