Your Privacy isn’t just important, it’s the Law. 

Acuity Medical Law Inc. Privacy Policy

1 . Purpose and Scope

This Privacy Policy explains how Acuity Medical Law (“Acuity,” “we,” “our,” or “us”) collects, uses, stores, and discloses personal information obtained through:

  • acuitymedicallaw.ca and any sub-domains (the “Site”);

  • our secure Client Portal, where clients may upload case-related documents; and

  • marketing tools provided by Meta Platforms, Inc. (“Meta”) and Google LLC (“Google”) that track conversions and measure advertising effectiveness.

This policy is drafted to meet the requirements of Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA). If you reside in another jurisdiction (e.g., the EU/EEA under the GDPR or U.S. states with privacy statutes), we honour any additional rights that apply.


2 . Information We Collect

Category Examples How Collected
Contact Information Name, email address, phone number, mailing address Web forms, phone calls, email, in-person
Case Information Matter details, opposing parties, medical records Direct client uploads or communications
Uploaded Documents PDFs, images, audio/video, spreadsheets, etc. Via the Client Portal
Technical Data IP address, browser type, device IDs, cookies, page views, ad interactions Site cookies, Meta Pixel, Google Analytics, Google Ads Conversion Tracking
Usage Data Time on page, link clicks, navigation paths Same tracking tools

3 . How We Use Your Information

Purpose Legal Basis*
Provide legal advice and related services Contractual necessity
Operate, secure, and troubleshoot the Client Portal Legitimate interests
Track ad performance (Meta Pixel & Google Ads) Consent (cookie banner)
Improve Site content and user experience Legitimate interests
Comply with legal and regulatory obligations Legal obligation

*“Legal basis” terminology is provided for jurisdictions that require it (e.g., GDPR). Under PIPEDA, we rely on your informed consent and limit collection to what is reasonable in the circumstances.


4 . Cookies & Conversion Tracking

Meta Pixel and Google Analytics / Google Ads set first- and third-party cookies to learn whether an ad view or click leads to actions on our Site (e.g., submitting a form). These cookies may share hashed identifiers with Meta or Google. You may:

  • reject non-essential cookies via our banner;

  • adjust ad-personalization settings in your Facebook or Google account; or

  • use browser add-ons such as the Google Analytics Opt-out Browser Add-on.


5 . Document Uploads & Retention Protocol

  1. Upload Destination – Documents you upload through the Client Portal are encrypted in transit (TLS 1.2 or higher) and stored temporarily on servers hosted by GoDaddy Canada in its Canadian data centre.

  2. Internal Transfer – Once our staff download your files, they are moved to Acuity’s secure offline archives (air-gapped storage maintained at our Halifax office).

  3. Deletion Schedule – The server copy is automatically deleted within 24 hours of successful transfer to the offline archive, or within seven (7) days if transfer is delayed for technical reasons.

  4. Access Controls – Only your assigned legal team members have file permissions before deletion. After transfer, physical access to offline archives is limited to senior partners and our IT security officer.


6 . How We Share Information

We do not sell personal information. We share only as necessary with:

  • Service Providers – IT hosting (GoDaddy), email relay, secure cloud backup, analytics providers (Meta, Google). All are bound by contractual confidentiality.

  • Regulatory or Law-Enforcement Authorities – Where required by subpoena, court order, or applicable law.

  • Professional Advisors – Auditors, insurers, and legal counsel under confidentiality obligations.


7 . Data Retention

Data Type Retention Period
Uploaded documents on GoDaddy server Up to 7 days (see § 5)
Offline archive of case files Minimum 7 years after matter closure (Nova Scotia Barristers’ Society guidance)
Marketing and analytics data 26 months (Google Analytics default) unless you opt-out sooner
Email correspondence 7 years or as required by legal duty

8 . Security Measures

  • AES-256 encryption at rest (offline archives)

  • Multi-factor authentication for all staff accounts

  • Quarterly penetration testing and annual privacy impact assessments

  • Internal Role-Based Access Control (RBAC) policies

  • Incident-response plan in line with PIPEDA breach-notification requirements


9 . Your Rights

Depending on your location, you may have the right to:

  • Access the personal information we hold about you;

  • Correct inaccuracies;

  • Withdraw consent (e.g., for marketing cookies) at any time;

  • Delete certain data, subject to legal retention duties;

  • Complain to the Office of the Privacy Commissioner of Canada or your local regulator.

To exercise these rights, contact us using the details below.


10 . International Data Transfers

Meta and Google may process data outside Canada (e.g., the U.S. or EU). We rely on their standard contractual clauses and other safeguards to protect your information when it traverses borders.


11 . Third-Party Links

Our Site may link to external websites (e.g., legal resources, partner organizations). We are not responsible for their privacy practices. Review those policies before providing information.


12 . Changes to This Policy

We may update this Privacy Policy to reflect changes in law or our practices. We will post the revised version with a new “last updated” date and, where required, seek your renewed consent.


13 . Contact Us

Acuity Medical Law Inc.
15 Condor Rd.
Halifax, NS B4A 3K9, Canada
Email: aris@acuitymedicallaw.ca
Phone: +1 902-404-2673


By using our Site, Client Portal, or services, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.