Privacy Policy

Effective Date: June 2019

This Privacy Policy explains how 36Eight Technologies Inc. (“36Eight”) uses the personal information that it collects from the users of its products and services. Personal information is any information that can identify an individual. We take the protection of your personal information seriously. This Policy tells you how.  Our mandate for protecting your privacy is to ensure that our privacy standards meet or exceed the guiding principles established in federal and provincial privacy legislation.

1. Collection of Personal Information

We limit the collection of personal information to what is reasonably required to fulfil the purposes for which it was collected. We collect personal information, as defined below, in a variety of ways, including: directly from you, from third parties, through in-store technologies, and when you are interacting with us online or through our mobile applications. 

A.   What is Personal Information  

“Personal information” is any information that identifies you or could be reasonably associated with you. The personal information we collect may include:

Individuals who register as a user of our products and services

 

  • Contact information, such as name, email address, country of residence.

  • Year and month of birth to ensure you have reached the age of majority and management of therapy. 

  • Gender to provide you with relevant therapy results.

  • Location information, using only cellular tower proximity, for purposes of providing relevant content based on your physical location.

  • Your medical cannabis use as you have provided through the 36Eight App you downloaded, for us to assist you with managing your therapy

  • Personal health information, using healthcare services provided by pharmacists, pharmacy staff, physicians, nurse practitioners, or other healthcare providers which includes any information that identifies or can identify you and relates to the state of your health or the treatment you are receiving. More specifically, personal health information means both diagnostic, treatment and care information, and/or registration information with healthcare services.

  • Personal content that you choose to upload, such as text, pictures or video; and

  • Optional - relevant personal interests to provide you the products or services you are interested in.

Individuals who purchase or redeem for our products and services, including:

 

  • Complete name of the purchaser or purchaser’s agent/caregiver.

  • Shipping address to deliver the product, which ensures we send the product to the right person.

  • Billing address, email address and phone number to communicate with the purchaser; and

  • If relevant, any payment information.

  • User posts to our user forum, 36Eight Community, which become public information, with no restriction on reproducing, publishing, uploading, posting, contest entries;

  • Comments, such as suggestions, proposals, plans, or other materials, whether online, by email, by postal mail; and

  • Transmitting or in any way publicly displaying the above information by anyone else.

 

B.  How Personal Information is Collected

We collect personal information in the following ways:

Directly from You

You may provide personal information to us through retail stores (e.g., pharmacy), by mail, by email, over the telephone, through our websites or mobile applications or in any other direct manner.

 

For example:

When you voluntarily share information about yourself with us, we will collect that information in order to provide you with our programs, products or services, respond to your inquiry, or for any other purpose disclosed to you at that time.

 

From Other Sources

Occasionally, we may receive personal information from other sources (e.g., Your health care practitioner). In these cases, we receive your personal information from these other sources with your consent or if the law requires or permits us to do so. 

 

From Used Technologies at Store Locations

We may collect personal information through various types of technologies used in retail stores (e.g., pharmacy’s management software (e.g., Kroll)). These can include point-of-sale systems.

 

Through Our Websites and Mobile Applications

We may collect certain types of information electronically when you interact with our websites, email, mobile applications, social media accounts, online advertising, or using our or a third party’s technologies, which include cookiesweb beaconssingle pixel gifs and other technologies such as Data Management Platforms (DMPs). This information helps us understand what actions you take on our websites and mobile applications and allows our websites and mobile applications to work correctly. We may collect information such as your internet service provider, Internet Protocol (IP) address, location, internet browser type and version, and operating system in order to assist your navigation of our website, as well as to determine what products are available near you.

We may combine this information with other information collected in-store or online such as your online and in-store transaction history. We do this to support our customer understanding using website and mobile analytics and to provide you with more tailored advertising and marketing campaigns. This includes serving interest-based advertising to you, subject to your right to withdraw consent. 

For example:

  • We may use your location or language preference to auto-select features when you visit our websites and mobile applications.

  • We may use your online and/or in-store purchase history to provide you with interest-based advertisements on products that you purchase frequently.

  • We may collect, combine and categorize your personal information on an aggregated basis to identify online and offline purchasing patterns to help us analyze our businesses to better serve customers.

The technologies we use include:

  • Cookies, which are small text files that are saved on your computer when you visit a website so that information can be saved between visits, such as your login credentials or language preferences. For example, cookies allow you to log in quickly when you visit our sites.

  • Web beacons, and single pixel gifs, which are small image files that have information about you, such as your IP address, that can be downloaded when you visit a website or open an email. This allows us to understand your online behaviour, monitor our email delivery, and provide you with interest-based advertising. These tools also allow our third-party tracking tools to gather information, such as your IP address, and provide this back to us in an anonymized, aggregate form (i.e. in a manner that prevents us from identifying you personally). Aggregate information refers to personal information compiled and expressed in a summary form where no personal identifiers are included.

  • Other technologies, such as DMP services and analytics engines, which pull usage data from multiple sources and help manage and collect this data to use for personalization, interest-based advertising, customizing content and other methods to gain insights into our customers’ needs and preferences.

 

We may use Google Analytics, a web analysis service of Google Inc. ("Google"). Google Analytics uses cookies to analyze your use of our websites, to create reports about visitor activities for us and to provide further services associated with the use of the websites and the Internet. Although this information is collected through your Google ad settings, it is not provided to us in a personally identifiable format.

You may delete or disable certain of these technologies at any time via your browser. However, if you do so, you may not be able to use some of the features on our websites or mobile applications.  

2. Purpose for Collection Personal Information

 

A.   Providing Programs, Products and Services

We use your personal information in order to provide you with our programs, products and services, which include:

  • When applicable, providing you with a quote for a program, product or service.

  • Verifying your identity, including the age of majority.

  • Determining your eligibility for a program, product or service;

  • Creating, administering, and maintaining your account/profile with us.

  • Processing your transaction(s). 

  • Fulfilling your product and service requests, inquiries, and purchases.

  • Providing you with healthcare services (e.g., pharmacy)

  • Providing your Health Care Practitioner(s) with information to manage your Health

 

B.   Managing Our Businesses

We use your personal information for many business reasons, which include:

  • Deploying and managing our information technology applications and systems, including managing our websites.

  • Managing and facilitating the use of our websites and mobile applications, which may include using cookies and other similar technologies.

  • Enabling your participation in contests, promotions, surveys, chats, seminars or workshops when or if available. 

  • Protecting parties from errors and fraud.

  • Monitoring and investigating incidents as applicable by law.

  • Meeting our legal and regulatory obligations.

  • Maintaining our programs, products and services

 

C.   Communicating with You

We use your personal information to communicate with you in a variety of ways:

  • Providing you with information and updates about our programs, products, services, promotions, contests and events when or if available.

  • Responding to your inquiries.

  • Taking or verifying instructions from you.

  • Subject to your consent, informing you in a variety of ways (e.g., email, telephone, SMS, direct mail) about programs, products, services, special offers, promotions, contests or events that may be of interest to you and when or if available. 

  • Delivering interest-based advertisements relating to our products and services or third-party products and services that may be of interest to you. 

  • Subject to your right to withdraw consent, providing you with offers or services based on the approximate location provided by your mobile device (also called “location-based advertising”)

 

If you no longer wish to receive commercial electronic messages, please let us know by following the unsubscribe directions provided in every commercial electronic message. 

 

D.   Conducting Market Research

We may use your personal information in order to conduct market research by tracking and analyzing current or previously collected information to improve or to develop new products, services, programs, promotions, contests or events, and to better understand our customer base. When doing so, we will use your information in an aggregated format or with direct personal identifiers removed.

 

The information we use for market research may include:

  • Purchase history (e.g., the number and amount of transactions by type, location/store of purchase, product code information, brand, quantity purchased, date, time, payment method used, promotional offers used in connection with the transaction, etc.).

  • Website or mobile application activities (e.g., offers viewed, opt-out preferences, email bounce backs, click-throughs, content on social media, and IP addresses).

  • Account activity, balances and payment history.

  • Use of mobile devices interacting with our websites or mobile applications (e.g., use of features, and duration, frequency, type and location of calls and text messages); and

  • The methods used to apply for or to access or use our programs, products, services, promotions, contests or events.

E.   Conducting Data Analytics

We may use your personal information in order to conduct data analytics for business purposes, such as:

  • Managing and developing our business and operations.

  • Improving our programs, products, and services (e.g., improving our websites and mobile applications).

  • Understanding customer needs and preferences and customizing how we tailor and market products and services to our customers based on their interests; and

  • Measuring the effectiveness of our marketing.

 

When doing so, we will use your information in an aggregated format or with direct personal identifiers removed. 

3. Disclosure/Sharing of Your Personal Information

We may share your personal information with our service providers (companies operating on our behalf) and other third parties (companies with which we provide programs, products or services) for the purposes described in this policy and in accordance with applicable law. We do not sell your personal information to any organization or person; the only exception to this would be if we sell or transfer any part of our business. We will not share your personal information except as indicated below.

 

A.   Service Providers

While providing our programs, products, services, promotions, contests and events we may share personal information with our service providers. These service providers help us operate our business, technology systems and applications, internal procedures, infrastructure and advertising and marketing. They provide services to us such as data hosting, contest administration, email deployment, call centre, marketing, sales and processing or analysis of personal information. We require these service providers to limit their access to and/or use of personal information to what is required to provide their services and to comply with our privacy requirements.

 

B.   Third Parties

While providing some or all of our programs, products and services, we may do so through arrangements with third parties. As a result, your personal information may be collected, used and shared by us and the applicable third party. These third parties may have their own privacy policies and terms and conditions, which will govern their use of your personal information. We recommend that you review the third party’s privacy policy and its terms and conditions.  We may need to share information about you and your transaction with other companies for the purpose of processing your transaction, including vendor direct shipping, credit card authorization and fraud prevention. This may involve transmissions over various networks and changes to conform to and adapt to the technical requirements of connecting networks or devices. Credit card information is always encrypted during transfer over networks. 

 

C. Sale or Transfer of Business or Other Transaction

We may decide to sell or transfer all or part of our business to a related company or to a third party, to merge with another entity, to insure or securitize our assets, or to engage in another form of corporate or financing transaction (including the proceedings of insolvency or bankruptcy), corporate reorganization, share sale, or other change in corporate control. If your personal information is required in connection with any such transactions, we will comply with the legal requirements for the disclosure of personal information.  Were 36Eight to engage in a merger, acquisition or sale, the licence regarding Tracked Data may be among the assets transferred.

 

D. Other Permitted Reasons

Canadian law permits or requires the use, sharing, or disclosure of personal information without consent in specific circumstances (e.g., when investigating and preventing suspected or actual illegal activities, including fraud, or to assist government and law enforcement agencies). These circumstances include situations when permitted or required by law or when necessary to protect our group of companies, our employees, our customers, or others. If this happens, we will not share more personal information than is reasonably required to fulfil that particular purpose.

 

E. With Your Consent

Other than the purposes listed above, we may, with your implied or express consent, share or disclose your personal information outside of our group of companies, in accordance with applicable law (e.g., share your information with your health care practitioner).

By subscribing to our programs, products and services and/or submitting information to us in connection with using our programs, products and services, you are providing your consent to the collection, use and disclosure of personal information as set out in this policy. In some cases, your consent may be “implied” i.e., your permission is assumed based on your action or inaction at the point of collection, use or sharing of your personal information.

4. How Long Do We Keep Personal Information

We will store your personal information for as long as necessary to fulfill the purposes for which it was collected, except where otherwise required or permitted by law (e.g., healthcare providers must retain patient records in accordance with their statutory retention obligations which varies depending on jurisdictions). Once no longer required, your personal information will be securely destroyed or anonymized (so the information no longer identifies you).

 

Please note that if your personal information is collected by a third party, it will be retained in accordance with the privacy policies and records retention requirements of that third party.  

5. How to Request Access to Your Personal Information 

Under Canadian privacy law, you have the right to access the personal information we hold about you, subject to any legal restrictions. Upon request, we will provide you with access to your personal information within a reasonable timeframe, in compliance with applicable laws. Our contact information is: contactus@36eighttechnologies.com. To inquire or to express concerns about the protection of your personal information at 36Eight Technologies, please contact us at privacy@36eighttechnologies.com or call +1 604 900 5368‬.

 

It is your responsibility to provide accurate, correct and complete information. If you notice any errors in your personal information or need to update it, please let us know through the steps outlined below.

Most of the personal information we hold about you is accessible to you through your retail store account (e.g., Pharmacy). You can access and update or correct your personal information by contacting your retail store (e.g., pharmacy). To access your personal health information, please contact your healthcare provider directly.

For personal information that is not available through your retail store, you can request access by contacting the applicable Privacy Office, by email or postal address. 

If you are unsatisfied with our response to your access and/or correction request, or how we handle your personal information, please contact the appropriate Privacy Office. If the Privacy Office is unable to address your concern to your satisfaction, you may bring the matter to the attention of the appropriate Privacy Commissioner. Some of our activities are subject to the jurisdiction of the Office of the Privacy Commissioner of Canada; other activities are subject to the jurisdiction of the Privacy Commissioner of your province or territory of residence.

6. How We Protect Your Personal Information

We use advanced technology for Internet security that corresponds to the high sensitivity of the information you entrust to us. This includes secure areas with entry/exit control, third-party encryption of payment forms, password protected file systems, decentralized database design and confidentiality rules for our employees.  If we ever learn of a security breach, we will notify affected users without delay.

 We take the security of your personal information very seriously and are committed to protecting your privacy by using a combination of administrative and technical safeguards. These measures include multi-factor authentication (MFA), masking, encryption, logging and monitoring, described below. We store your personal information for as long as it is necessary to provide you with our programs, products, and services and for a reasonable time thereafter, or as permitted or required by law. By having these safeguards, we aim to avoid the loss, misuse, unauthorized access, disclosure, or modification of your personal information that we hold. These safeguards also apply when we dispose of or destroy your personal information.

For example, where appropriate, we use the following safeguards:

  • Multi-Factor Authentication, which is a method of confirming administrative access to our platform.

  • Masking, which is the process of obscuring your information so that the structure remains the same, but the content is no longer identifiable.

  • Anonymization, which is the process of altering your data so that it can no longer be used to identify you personally.

  • Encryption, which is the process of obscuring your information in order to make it unreadable without the use of a code or a key; and

  • Logging and monitoring, which is the process of tracking, recording and monitoring activity related to the access and/or use of your accounts or personal information.

 

We use all reasonable safeguards, including contractual requirements with our service providers, to protect your personal information wherever it is used or stored. In general, we store, access and use personal information in Canada. Some of our service providers may access, process or store your personal information outside of your province, territory or Canada in the course of providing their services to us. When we engage a service provider that operates outside of Canada, personal information may be stored, processed, accessed or used in another country. In that case, the personal information is subject to the law of the jurisdiction in which it is used or stored, including any law permitting or requiring disclosure of the information to the government, government agencies, courts and law enforcement in that jurisdiction. 

7. Changes to Policy

We may make changes to this policy from time to time. Any changes we make will become effective when we post a modified version of the policy on this webpage. If we make any significant changes to the policy, we will post a notice on our websites. By continuing to participate in our programs, and/or use our services or purchase our products after the modified version of the policy has been posted, you are accepting changes to the policy, subject to any additional requirements which may apply. If you do not agree to the changes in our policy, it is your responsibility to stop participating in our programs, and/or using our services. It is your obligation to ensure that you read, understand and agree to the latest version of the policy. The “Effective Date” at the top of the policy indicates when it was last updated.