Statement of Information Practices

Renew by Design is committed to protecting the privacy and confidentiality of our clients’ personal information. This statement describes how we collect, use, and disclose your information, and how you can exercise your rights.

1. Our Commitment to Privacy

We manage personal information in accordance with the Personal Health Information Protection Act, 2004 (PHIPA) and the Personal Information Protection and Electronic Documents Act (PIPEDA). Although coaching is a professional service, we treat your information with the same rigor as regulated health records.

2. Collection of Personal Information

We collect information directly from you or from a person authorized to act on your behalf. This may include:

  • Contact Information: Name, address, phone number, and email.

  • Service Records: Clinical notes, coaching goals, and progress tracking.

  • Financial Information: Billing details and payment history.

We only collect what is reasonably necessary to provide coaching services and manage our business operations.

3. Use and Disclosure of Information

We use your information to provide services, process payments, and conduct internal quality reviews. We do not disclose your information to third parties without your express consent, except in the following limited circumstances required or permitted by Ontario law:

  • To eliminate or reduce a significant risk of serious bodily harm to yourself or others.

  • To report suspected child abuse or neglect as required by the Child, Youth and Family Services Act.

  • To comply with a court order, subpoena, or warrant.

4. Communication via SMS (Text Messaging)

If you opt-in to receive SMS communications from Renew by Design for appointment reminders or brief service updates, the following privacy protocols apply:

4.1 Service Architecture

We utilize Microsoft 365 Business services to facilitate SMS. While messages are secured within our Microsoft tenant at rest, they are transmitted via third-party telecommunications carriers over the Public Switched Telephone Network (PSTN).

4.2 Encryption Limitations

Messages are encrypted while in transit between our devices and Microsoft’s infrastructure. However, standard SMS messages are not encrypted once they leave the Microsoft environment for delivery via cellular networks. We advise against sharing sensitive health or legal information via SMS.

4.3 Data Handling and Residency

SMS logs and message history are stored within our Microsoft 365 environment on Canadian-based servers.

4.4 No Commercial Sale of Data

We do not sell, rent, or lease your phone number or the contents of your SMS communications. Your mobile "opt-in" information is used exclusively for service delivery and is never shared with third parties for their own marketing or promotional purposes.

4.5 Opt-Out

You may withdraw your consent for SMS communications at any time by replying "STOP" or by contacting our Privacy Officer directly.

5. Our Data Secondary Custodian (Jane App)

We use Jane App, a secure practice management platform, to store your records and facilitate scheduling.

5.1 Data Residency

All personal information is stored on encrypted servers located in Canada.

5.2 Access Controls

Jane App acts as a service provider (agent) and has no independent right to access or use your data. Your records are protected by bank-level encryption (SSL/TLS) and strict internal access controls.

6. Your Rights: Access and Correction

You have the right to access the personal information we hold about you. You may also request a correction of your record if you believe it is inaccurate or incomplete.

6.1 How to Request

Please submit a written request to our Privacy Officer (details below).

6.2 Timelines

We will respond to your request within 30 days.

7. Safeguards and Retention

We maintain administrative, technical, and physical safeguards to protect against unauthorized access, loss, or theft. We retain your records for 10 years following your last appointment, or as required by professional liability standards.

8. Questions and Complaints

If you have questions about our privacy practices or wish to make a complaint, please contact us first so we can address your concerns:

Privacy Officer: Sonia Migneault Email: info@renewbydesign.ca

If we are unable to resolve your concern, you have the right to contact the Information and Privacy Commissioner of Ontario (IPC): 2 Bloor Street East, Suite 1400, Toronto, ON M4W 1A8 Phone: 416-326-3333 | www.ipc.on.ca.