EyeFACE Institute
Your Privacy Matters at EyeFACE Institute
We handle personal and health information with the same discretion, precision, and care we bring to every eye and face treatment.
This policy explains how EyeFACE collects, uses, protects, and shares information for website inquiries, secure intake, cookies, analytics, payments, EyeFACE Circle, and patient care.
We do not sell or rent personal information or personal health information.
Effective date: May 4, 2026
Last updated: May 4, 2026
Our commitment to you.
EyeFACE Institute is an Ontario health care practice. Depending on the service and the information involved, we handle information under Ontario's Personal Health Information Protection Act (PHIPA), federal privacy laws including PIPEDA where applicable, professional obligations, and our own privacy and records policies.
This website is educational and administrative. It is not a substitute for medical advice, diagnosis, or treatment. Do not use website forms, ordinary email, or social media for urgent medical concerns.
Privacy at a glance.
- We collect only what is needed to respond, coordinate care, provide services, and meet legal and professional obligations.
- We do not sell or rent personal information or personal health information.
- Clinical details and medical photographs belong in secure intake pathways, not ordinary email or social media.
- Optional analytics and future marketing tools load only after consent and are not intended to receive health information.
- Photos, testimonials, case examples, and clinical details are not used publicly without separate consent or authorization.
- You can ask privacy questions, request access or correction, withdraw consent where permitted, or contact the Ontario privacy commissioner.
1. Scope and definitions
This policy applies to eyeface.ca, EyeFACE Institute website requests, consultation and booking pathways, EyeFACE Circle links, and administrative communication connected to EyeFACE care. “Personal information” means information that can identify you. “Personal health information” includes identifying information about your health, health history, care, photographs, referrals, test results, treatment plans, and payment for health care.
2. Information we collect
Website and contact information
- Name, email address, phone number, preferred service, preferred timing, and message content you choose to submit.
- Basic technical information such as browser type, device type, referring page, consent preferences, and approximate usage data.
- Information collected through essential cookies or local storage required for site function and privacy preferences.
Consultation and intake information
- Goals, health history, medications, prior treatments, photographs, documents, referral details, and appointment preferences when you choose to submit them.
- Administrative records needed to respond to inquiries, coordinate scheduling, send secure pre-visit forms, provide quotes, and support follow-up.
- Clinical records created during care, consultation, treatment planning, procedures, or medically necessary follow-up.
Payment and booking information
- Appointment and payment status, fee-confirmation details, and payment links when applicable.
- Payment card details are handled by approved payment processors. EyeFACE does not store payment card numbers on this website.
3. Why we use information
EyeFACE uses information to respond to inquiries, suggest the appropriate pathway, coordinate consultation or referral steps, confirm appointments, open secure intake, support clinical assessment, provide quotes or payment links, document consent, deliver care, follow up, improve website function, and meet legal, professional, quality, safety, billing, and record-keeping obligations.
Patient photographs are part of the clinical record when they are submitted or created for care. Photos, testimonials, case examples, and clinical details are not used for the public website, marketing, social media, teaching, publication, or similar public-facing purposes unless separate consent or authorization is obtained. EyeFACE may use de-identified or aggregate information for quality improvement, safety, education, or operational review only where permitted by law and with safeguards appropriate to the information.
4. EyeFACE Circle (secure patient portal)
EyeFACE Circle is our secure patient portal and intake pathway. It is used for selected patient intake, secure messaging, document exchange, treatment proposals, payments, recovery education, and follow-up. Information you submit through EyeFACE Circle may become part of your administrative or clinical record.
Please do not send medical photographs, detailed medical history, or urgent clinical concerns through ordinary email unless EyeFACE staff specifically direct you to do so. When sensitive information is needed, our team will direct you to an appropriate secure link.
Learn About EyeFACE Circle™5. Disclosures and third-party providers
EyeFACE does not sell or rent personal information or personal health information. We share information only when needed for care, administration, payment, referral coordination, legal compliance, quality/safety work, or when you consent or the law permits or requires it. Providers may process information in Canada or other jurisdictions depending on the service.
EyeFACE Circle / secure patient portal
Used for selected patient intake, secure messaging, document exchange, treatment proposals, payments, recovery education, and follow-up.
Microsoft Bookings / Microsoft 365
Used for selected scheduling, calendar coordination, email, and administrative communication.
Square or approved payment providers
Used when consultation or treatment payments are completed by secure payment link.
Supabase or approved data stores
May be used to store contact or booking request records when EyeFACE enables the website request backend.
Google Analytics 4
Loaded only after analytics consent. IP anonymization is enabled. Analytics tools are not intended to receive clinical or personal health information.
Website hosting and security providers
Used to deliver the website, maintain uptime, protect traffic, and troubleshoot technical issues.
6. Cookies, analytics, and marketing tools
This website uses strictly necessary cookies and local storage for core functionality, privacy preferences, security, page function, and basic navigation. Optional analytics and future marketing tools are activated only after you give consent through the cookie consent banner. You can reopen the banner using the Privacy button on the site.
Google Analytics 4 is loaded only after analytics consent. IP anonymization is enabled in the site configuration. Analytics and marketing tools are not intended to receive clinical information, medical photographs, referral notes, or personal health information.
Marketing consent is separate from consent for care. If EyeFACE offers email, SMS, retargeting, or other marketing communications, you can decline or withdraw marketing consent without affecting your access to clinical care. Personal health information is not used to build advertising audiences.
7. Security safeguards
EyeFACE uses administrative, technical, and physical safeguards appropriate to the sensitivity of the information and the purpose for which it is handled.
- HTTPS encryption for website traffic and secure links for sensitive intake when clinical information is required.
- Role-based staff access so information is available only where it is needed for administrative or clinical work.
- Vendor configuration designed to keep clinical information and medical photographs out of ordinary website analytics.
- Staff confidentiality expectations, privacy-aware workflows, and secure handling of patient photographs, documents, and records.
- Secure disposal or deletion workflows when information no longer needs to be retained and the law permits disposal.
8. Retention
Patient records are retained according to PHIPA, CPSO guidance, applicable professional rules, and EyeFACE record-retention policies. Adult patient medical records are typically retained for at least 10 years from the date of the last entry, and records for children are typically retained for at least 10 years after the day the patient reached or would have reached 18 years of age. Records may be retained longer where required or appropriate for legal, clinical, quality, or operational reasons.
9. Your privacy rights
Under PHIPA and other applicable laws, patients and prospective patients may have rights related to their personal information and personal health information.
- Ask why personal information or personal health information is collected, used, or disclosed.
- Request access to records of personal health information, subject to limited legal exceptions.
- Request correction of records that you believe are inaccurate or incomplete.
- Withdraw consent where the law allows, with the understanding that this may affect what services can be provided.
- Ask EyeFACE not to use or disclose certain personal health information for health care purposes where PHIPA permits that instruction.
- Ask a privacy question or make a complaint to EyeFACE, the Information and Privacy Commissioner of Ontario, or another applicable regulator.
PHIPA access requests are generally answered within 30 calendar days unless an extension or exception applies. Identity verification may be required before records are released or corrected.
10. Privacy incidents and complaints
If EyeFACE becomes aware of a privacy incident involving your information, we will assess it and notify affected individuals and regulators where required by law. You may raise a privacy concern with EyeFACE first, or contact the Information and Privacy Commissioner of Ontario if your concern relates to personal health information under PHIPA.
11. Contact the EyeFACE Privacy Officer
EyeFACE Institute Privacy Officer
Email: info@eyeface.ca
Phone: (647) 351-6501
Address: 4789 Yonge Street, Toronto, ON M2N 0G3
Please include “Privacy Officer” in the subject line. Do not include urgent clinical details in ordinary email.
12. Changes to this policy
EyeFACE may update this policy as our services, technology, vendors, or legal obligations change. The latest version will be posted on this page with the updated date above.
Secure, confidential next step
When clinical details, photographs, documents, or sensitive questions are needed, our team will direct you to the appropriate secure EyeFACE Circle pathway.