Your Privacy isn’t just important, it’s the Law.
Acuity Medical Law Inc. Privacy Policy
1 . Purpose and Scope
This Privacy Policy explains how Acuity Medical Law (“Acuity,” “we,” “our,” or “us”) collects, uses, stores, and discloses personal information obtained through:
-
acuitymedicallaw.ca and any sub-domains (the “Site”);
-
our secure Client Portal, where clients may upload case-related documents; and
-
marketing tools provided by Meta Platforms, Inc. (“Meta”) and Google LLC (“Google”) that track conversions and measure advertising effectiveness.
This policy is drafted to meet the requirements of Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA). If you reside in another jurisdiction (e.g., the EU/EEA under the GDPR or U.S. states with privacy statutes), we honour any additional rights that apply.
2 . Information We Collect
| Category | Examples | How Collected |
|---|---|---|
| Contact Information | Name, email address, phone number, mailing address | Web forms, phone calls, email, in-person |
| Case Information | Matter details, opposing parties, medical records | Direct client uploads or communications |
| Uploaded Documents | PDFs, images, audio/video, spreadsheets, etc. | Via the Client Portal |
| Technical Data | IP address, browser type, device IDs, cookies, page views, ad interactions | Site cookies, Meta Pixel, Google Analytics, Google Ads Conversion Tracking |
| Usage Data | Time on page, link clicks, navigation paths | Same tracking tools |
3 . How We Use Your Information
| Purpose | Legal Basis* |
|---|---|
| Provide legal advice and related services | Contractual necessity |
| Operate, secure, and troubleshoot the Client Portal | Legitimate interests |
| Track ad performance (Meta Pixel & Google Ads) | Consent (cookie banner) |
| Improve Site content and user experience | Legitimate interests |
| Comply with legal and regulatory obligations | Legal obligation |
*“Legal basis” terminology is provided for jurisdictions that require it (e.g., GDPR). Under PIPEDA, we rely on your informed consent and limit collection to what is reasonable in the circumstances.
4 . Cookies & Conversion Tracking
Meta Pixel and Google Analytics / Google Ads set first- and third-party cookies to learn whether an ad view or click leads to actions on our Site (e.g., submitting a form). These cookies may share hashed identifiers with Meta or Google. You may:
-
reject non-essential cookies via our banner;
-
adjust ad-personalization settings in your Facebook or Google account; or
-
use browser add-ons such as the Google Analytics Opt-out Browser Add-on.
5 . Document Uploads & Retention Protocol
-
Upload Destination – Documents you upload through the Client Portal are encrypted in transit (TLS 1.2 or higher) and stored temporarily on servers hosted by GoDaddy Canada in its Canadian data centre.
-
Internal Transfer – Once our staff download your files, they are moved to Acuity’s secure offline archives (air-gapped storage maintained at our Halifax office).
-
Deletion Schedule – The server copy is automatically deleted within 24 hours of successful transfer to the offline archive, or within seven (7) days if transfer is delayed for technical reasons.
-
Access Controls – Only your assigned legal team members have file permissions before deletion. After transfer, physical access to offline archives is limited to senior partners and our IT security officer.
6 . How We Share Information
We do not sell personal information. We share only as necessary with:
-
Service Providers – IT hosting (GoDaddy), email relay, secure cloud backup, analytics providers (Meta, Google). All are bound by contractual confidentiality.
-
Regulatory or Law-Enforcement Authorities – Where required by subpoena, court order, or applicable law.
-
Professional Advisors – Auditors, insurers, and legal counsel under confidentiality obligations.
7 . Data Retention
| Data Type | Retention Period |
|---|---|
| Uploaded documents on GoDaddy server | Up to 7 days (see § 5) |
| Offline archive of case files | Minimum 7 years after matter closure (Nova Scotia Barristers’ Society guidance) |
| Marketing and analytics data | 26 months (Google Analytics default) unless you opt-out sooner |
| Email correspondence | 7 years or as required by legal duty |
8 . Security Measures
-
AES-256 encryption at rest (offline archives)
-
Multi-factor authentication for all staff accounts
-
Quarterly penetration testing and annual privacy impact assessments
-
Internal Role-Based Access Control (RBAC) policies
-
Incident-response plan in line with PIPEDA breach-notification requirements
9 . Your Rights
Depending on your location, you may have the right to:
-
Access the personal information we hold about you;
-
Correct inaccuracies;
-
Withdraw consent (e.g., for marketing cookies) at any time;
-
Delete certain data, subject to legal retention duties;
-
Complain to the Office of the Privacy Commissioner of Canada or your local regulator.
To exercise these rights, contact us using the details below.
10 . International Data Transfers
Meta and Google may process data outside Canada (e.g., the U.S. or EU). We rely on their standard contractual clauses and other safeguards to protect your information when it traverses borders.
11 . Third-Party Links
Our Site may link to external websites (e.g., legal resources, partner organizations). We are not responsible for their privacy practices. Review those policies before providing information.
12 . Changes to This Policy
We may update this Privacy Policy to reflect changes in law or our practices. We will post the revised version with a new “last updated” date and, where required, seek your renewed consent.
13 . Contact Us
Acuity Medical Law Inc.
15 Condor Rd.
Halifax, NS B4A 3K9, Canada
Email: aris@acuitymedicallaw.ca
Phone: +1 902-404-2673
By using our Site, Client Portal, or services, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.