.png)
Health Ascendance
PRIVACY POLICY FOR HEALTH ASCENDANCE
Effective Date: September 08, 2026
Welcome to Health Ascendance ("we," "us," or "our"). We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about this privacy notice, or our practices regarding your personal information, please contact us.
This privacy policy describes how Health Ascendance collects, uses, discloses, and retains your personal information when you visit our website or use our coaching services (collectively, the "Services"), in compliance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.
1. The 10 Fair Information Principles of PIPEDA
Our privacy practices are based on the 10 fair information principles set out in PIPEDA, including:
-
Accountability: We are responsible for personal information under our control and have designated a Privacy Officer.
-
Identifying Purposes: We identify the purposes for which we collect personal information before or at the time of collection.
-
Consent: We obtain your knowledge and consent for the collection, use, or disclosure of your personal information.
-
Limiting Collection: We collect only the personal information that is necessary for the identified purposes.
-
Limiting Use, Disclosure, and Retention: We do not use or disclose personal information for purposes other than those for which it was collected, except with your consent or as required by law.
-
Accuracy: We keep personal information accurate, complete, and up-to-date as necessary.
-
Safeguards: We protect personal information with security safeguards appropriate to the sensitivity of the information.
-
Openness: We make readily available to you specific information about our policies and practices relating to the management of personal information.
-
Individual Access: Upon request, you will be informed of the existence, use, and disclosure of your personal information and will be given access to that information.
-
Challenging Compliance: You may address a challenge concerning compliance with the above principles to our Privacy Officer.
2. What Personal Information Do We Collect?
We may collect the following categories of personal information when you interact with our Services:
Client Registration:
-
Type of Data:
-
Identity
-
Contact
-
-
Legal Basis:
-
Performance of a contract with you
-
Service Processing and Delivery:
-
Type of Data:
-
Identity
-
Contact
-
Financial
-
Transaction
-
-
Legal Basis:
-
Performance of a contract with you
-
Necessary for our legitimate interests (to recover debts due to us)
-
-
Includes:
-
Manage payments, fees, and charges
-
Collect and recover money owed to us
-
Relationship Management:
-
Type of Data:
-
Identity
-
Contact
-
Profile
-
-
Legal Basis:
-
Performance of a contract with you
-
Necessary to comply with a legal obligation
-
Necessary for our legitimate interests (to keep our records updated)
-
-
Includes:
-
Notifying you about changes to our terms or privacy policy
-
Dealing with your requests, complaints, and queries
-
Business Administration and Security:
-
Type of Data:
-
Identity
-
Contact
-
Technical
-
-
Legal Basis:
-
Necessary for our legitimate interests (for running our business, IT services, network security)
-
Necessary to comply with a legal obligation
-
-
Includes:
-
Troubleshooting
-
Data analysis
-
Testing
-
System maintenance
-
Support
-
Reporting
-
Hosting of data
-
Marketing and Analytics:
-
Type of Data:
-
Identity
-
Contact
-
Profile
-
Usage
-
Marketing and Communications
-
Technical
-
-
Legal Basis:
-
Necessary for our legitimate interests (to study how clients use our services and to develop them)
-
Consent (having obtained your prior consent to receiving direct marketing communications)
-
3. How Do We Collect Your Personal Information?
We use different methods to collect data from and about you, including through:
-
Direct Interactions: You may give us your personal information by filling in online forms, corresponding with us by post, phone, email, or otherwise (e.g., when you apply for our services, subscribe to our publications, request marketing, or provide feedback).
-
Automated Technologies: As you interact with our Site, we automatically collect Technical Data about your equipment, browsing actions, and patterns through cookies, server logs, and other similar technologies.
-
Third Parties: We receive personal data about you from various third parties and public sources, including:
-
Analytics providers (e.g., Google, Meta)
-
Advertising networks (e.g., Hyros)
-
Payment and delivery service providers (e.g., Stripe, Payfunnels)
-
4. How Do We Use Your Personal Information?
PIPEDA requires us to have a legal basis for collecting and using your personal information. We rely on one or more of the following legal bases:
-
Performance of a Contract: To deliver our coaching services and process payments.
-
Legitimate Interests: To conduct our business, prevent fraud, improve our services, and communicate with you about service-related matters.
-
Legal Obligation: For compliance with legal obligations (e.g., tax and record-keeping requirements).
-
Consent: We obtain your explicit consent for collecting sensitive health information and for sending marketing communications.
5. Direct Marketing and CASL Compliance
Under Canada's Anti-Spam Legislation (CASL), we are required to obtain your prior express consent before sending you any commercial electronic messages (CEMs) , such as marketing emails or newsletters.
We will only send you marketing communications if you have provided your express consent or if an implied consent exception applies (e.g., you have an existing business relationship with us). All CEMs we send will include our contact information, a clear unsubscribe mechanism, and a statement that you can withdraw your consent at any time. You may unsubscribe from receiving marketing communications at any time by clicking the "unsubscribe" link in any email we send you or by contacting us directly.
6. Disclosure of Your Personal Information
We may share your personal information where necessary with the following parties for the purposes set out in this policy:
-
Third-Party Service Providers: Such as payment processors (Stripe, Payfunnels), analytics providers (Google, Meta), advertising networks (Hyros), email marketing platforms (ActiveCampaign), communication platforms (Slack, Zapier, DocuSign), community platforms (Skool.com), and scheduling providers (Calendly).
-
Business Transfers: If we sell, transfer, or merge parts of our business, your personal data may be transferred to the new owners, who will use it in the same way as set out in this policy.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes.
7. International Transfers of Personal Information
Some of our third-party service providers are located outside of Canada (e.g., in the United States). When we transfer your personal information outside of Canada, we remain accountable for it and ensure that an adequate level of protection is in place. By providing us with your personal information, you consent to the transfer, storage, and processing of your information outside of Canada.
8. Data Security
We have implemented appropriate security safeguards to protect your personal information against loss, theft, unauthorized access, disclosure, copying, use, or modification. These safeguards include physical measures (e.g., locked cabinets), technological measures (e.g., encryption, passwords, firewalls), and organizational measures (e.g., limiting access on a "need-to-know" basis, employee training on confidentiality). While we take reasonable steps to secure your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure.
9. Data Retention
We will retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. When information is no longer required, it will be securely destroyed, erased, or made anonymous. We conduct regular reviews to determine whether information is still required and securely dispose of information that is no longer needed. By law, we may be required to keep basic information about our clients (including Contact, Identity, Financial, and Transaction Data) for a minimum period of seven (7) years for tax and record-keeping purposes.
10. Your Legal Rights
Under PIPEDA and other applicable privacy laws, you have the right to:
-
Request access to your personal information that we hold about you and receive a copy of it (commonly known as a "subject access request").
-
Request correction of your personal information that is inaccurate or incomplete.
-
Withdraw your consent at any time where we are relying on consent to process your personal information. Withdrawal of consent will not affect the lawfulness of any processing carried out before you withdraw your consent.
-
Request the transfer of your personal information to you or to a third party, where technically feasible.
To exercise any of these rights, please contact our Privacy Officer using the contact details set out in Section 14. We will respond to all legitimate requests within 30 days. Occasionally, it may take us longer than 30 days if your request is particularly complex or you have made multiple requests. In this case, we will notify you and keep you updated.