Privacy Policy
1. INTRODUCTION
Stery Inc. (the "Publisher" or "we") is committed to protecting the personal information of users of the Stery application (the "Application"), in accordance with the Act respecting the protection of personal information in the private sector (the "Private Sector Act", CQLR c. P-39.1) as amended by the Act to modernize legislative provisions as regards the protection of personal information (2021, c. 25, "Law 25").
This Privacy Policy (the "Policy") describes the personal information we collect, why we collect it, how we use and protect it, and the rights you have in relation to it.
This Policy is separate from the Application's Terms of Use and is a stand-alone document, as required by the Private Sector Act.
2. PRIVACY OFFICER
In accordance with section 3.1 of the Private Sector Act, the Publisher has appointed a person in charge of the protection of personal information:
Privacy Officer
Stery Inc.
512 Pine Avenue
Saint-Lambert, Quebec, Canada
Email: contact@stery.ca
Phone: 1 888 559-7719
The privacy officer oversees compliance with the Private Sector Act and with these governance policies and practices regarding personal information.
3. PERSONAL INFORMATION COLLECTED
3.1 Professional identification information
- –Operator's first and last name
- –Professional role (dentist, assistant, technician)
3.2 Sterilization data (professional information)
- –Sterilization cycle number and date
- –Autoclave identifier, name and serial number
- –Cycle type and physical parameters (temperature, pressure, duration)
- –Chemical and biological test results
- –Cycle status (pass, fail, reason for failure)
- –Name of the operator who ran the cycle
- –List of instruments included in the cycle
3.3 Photographs and visual evidence
- –Photos of the autoclave display
- –Photos of chemical indicators
- –Photos of biological test results
3.4 Technical data
- –Unique tablet identifier
- –Identifiers of the Stery System Peripherals
- –System operating logs (timestamps, connectivity status)
3.5 Voice data (if the voice assistant is enabled)
- –Voice recognition is performed entirely on the tablet
- –No voice recording is kept or transmitted to an external server
- –Processing is instantaneous and ephemeral
3.6 Information we do not collect
We do not collect:
- –Health data about the Clinic's patients
- –Biometric data about users
- –Geolocation data
- –Web browsing data
- –Data for advertising or commercial profiling purposes
4. PURPOSES OF COLLECTION AND PROCESSING
Personal information is collected and processed exclusively for the following purposes:
- Providing the sterilization traceability Service
- Draws on every category of information collected.
- Identifying operators for each cycle (accountability)
- Relies on professional identification information.
- Generating compliant traceability labels
- Relies on cycle sterilization data.
- Operating and synchronizing the Stery System
- Relies on the device's technical data.
- Sending regulatory compliance reminders
- Relies on technical data to schedule notifications.
- Producing audit and history reports
- Combines sterilization data and photographic evidence.
- Remote maintenance and technical support
- Relies on the technical data required for diagnostics.
- Meeting legal and regulatory obligations
- Draws on every category of information collected.
No personal information is used for commercial prospecting, targeted advertising or profiling.
5. LEGAL BASIS FOR PROCESSING
The processing of personal information rests on the following legal bases:
- –The User's express consent, obtained separately for each purpose
- –Performance of the sale and subscription agreement between the Clinic and the Publisher
- –Legal obligations regarding traceability of medical device sterilization
6. SENSITIVE PERSONAL INFORMATION
Some of the data collected may constitute sensitive personal information within the meaning of section 12 of the Private Sector Act — in particular data relating to the compliance of sterilization cycles and biological test results, insofar as it may affect the safety of the care provided to patients.
Consent to the collection and use of that data is obtained expressly, freely and on an informed basis, in accordance with the heightened requirements of the Private Sector Act for sensitive information.
7. RETENTION PERIODS
- Sterilization data (cycles, tests, labels)
- Kept for 10 years from the date of the cycle, in order to meet regulatory compliance and medical device traceability requirements.
- Photographs and visual evidence
- Kept for 10 years from the date of the cycle, as supporting evidence of the compliance of the process.
- Operator identification information
- Kept for the entire term of the contractual relationship, then for a further two years for account management and to meet statutory retention obligations.
- Technical data (tokens, device identifiers)
- Kept for the duration of the active session or until revoked, to ensure the Service works properly.
- Voice data
- Not kept. Processing is instantaneous and entirely local; no data is recorded or transmitted.
Once the retention period expires, personal information is destroyed or irreversibly anonymized, in accordance with the Publisher's destruction policy.
The Publisher maintains a retention schedule and carries out periodic destruction to ensure the stated periods are respected.
8. DISCLOSURE TO THIRD PARTIES
8.1 Service providers
The Publisher may disclose personal information to selected service providers, strictly to the extent necessary for the purposes described. Those providers operate in the following areas:
- –Cloud hosting and storage: sterilization data, photographs and technical identifiers, hosted on servers located in Canada;
- –Communication between System components: technical data required for the Peripherals to operate in real time.
Contractual agreements meeting the requirements of the Private Sector Act are entered into with each provider, setting out the protection measures applicable to the information disclosed. The list of providers is available on request from the privacy officer.
8.2 Autoclave manufacturer integration (optional)
If the Clinic enables integration with an autoclave manufacturer's cloud platform, cycle data may be exchanged with that manufacturer. This feature is optional and requires the Clinic's express consent.
8.3 Our commitments
- –No personal information is sold, rented or traded for commercial or advertising purposes.
- –No information is disclosed to third parties other than those identified above, except where required by law (a court order or a request from a competent authority).
9. HOSTING AND DATA LOCATION
9.1 Location
- Local storage (tablet)
- Stays in Canada, on the device installed on the Clinic's premises.
- Database and cloud storage
- Hosted in Canada, on servers located on Canadian soil.
- Communication infrastructure
- Runs on secure servers providing an adequate level of protection.
9.2 Data residency commitment
The Publisher undertakes to host sterilization data and personal information on servers located in Canada, so that personal information remains under the jurisdiction of Canadian and Quebec privacy laws.
9.3 Transfers outside Québec
Should a transfer of personal information outside Québec become necessary (for example, to operate certain infrastructure services), the Publisher undertakes to:
- –Carry out a privacy impact assessment in accordance with section 17.1 of the Private Sector Act before any transfer;
- –Ensure the information receives adequate protection in the destination jurisdiction;
- –Enter into appropriate contractual agreements with the recipients;
- –Inform the individuals concerned of the nature of the information transferred and of the destination jurisdiction.
10. DATA SECURITY
10.1 Technical measures
The Publisher implements security measures that are reasonable and proportionate to the sensitivity of the personal information processed:
- –Encryption in transit: All communications between System components and the servers are encrypted to industry standards.
- –Encryption at rest: Data stored on the tablet and in the cloud is encrypted at rest.
- –Secure credential storage: Sensitive credentials are protected by hardware-backed secure storage.
- –Controlled environment: The tablet runs in a locked, remotely administered environment that prevents unauthorized use.
- –Secure communications: Exchanges between Stery System components use secure protocols.
10.2 Organizational measures
- –A confidentiality incident management policy;
- –Regular privacy impact assessments;
- –Restricted data access based on the principle of least privilege;
- –Logging of access to personal information;
- –Training of the Publisher's staff on the obligations of the Private Sector Act.
10.3 Limits
No security measure can guarantee absolute protection against intrusion or unauthorized access. The Publisher nevertheless undertakes to implement security measures that follow industry best practices and are proportionate to the sensitivity of the information processed.
11. YOUR RIGHTS
Under the Private Sector Act, you have the following rights in relation to your personal information:
11.1 Right of access
You have the right, on request, to be told whether personal information about you exists and to be given access to it (s. 27 of the Private Sector Act). We respond to any request within 30 days.
11.2 Right of rectification
You have the right to have any inaccurate, incomplete or equivocal personal information about you corrected (s. 28 of the Private Sector Act).
11.3 Right of erasure
You may request the deletion of your personal information where its collection or processing does not comply with the law.
Important note: Sterilization data forms a regulatory audit trail. A deletion request may be refused where it would conflict with the retention obligations imposed by the applicable medical device traceability regulations. In that case, you will be informed in writing along with the reasons for the refusal.
11.4 Right to portability
In accordance with section 27 of the Private Sector Act, you may request that your personal information be released in a structured, commonly used technological format (PDF, CSV). The Application includes a built-in PDF export feature for cycle reports.
11.5 Withdrawal of consent
You may withdraw your consent at any time by sending a request to the privacy officer. Withdrawing consent:
- –Does not affect the lawfulness of processing carried out before the withdrawal;
- –May make certain features of the Service unusable;
- –Does not apply to processing based on a statutory retention obligation.
11.6 Exercising your rights
To exercise any of these rights, send a written request to the privacy officer at the contact details given in article 2. We may ask you for additional information to verify your identity before acting on your request.
12. CONSENT
12.1 How consent works
In accordance with sections 14 and following of the Private Sector Act:
- –Consent is requested separately for each processing purpose;
- –Consent is free, informed and given for specific purposes;
- –Consent for sensitive information is express;
- –Consent is not bundled into the Terms of Use but collected separately through dedicated mechanisms in the Application;
- –Consent cannot be a condition of access to the Service, unless the collection is necessary in order to provide it.
12.2 Consent of minors
As the Application is intended for professional use, it is not designed to be used by minors. No personal information about minors is collected.
13. MANAGING CONFIDENTIALITY INCIDENTS
13.1 Definition
A confidentiality incident means any access to, use, communication or loss of personal information, or any other breach of its protection (s. 3.6 of the Private Sector Act).
13.2 Notice to the Commission d'accès à l'information
In accordance with section 3.5 of the Private Sector Act, where a confidentiality incident presents a risk of serious injury, the Publisher will promptly notify the Commission d'accès à l'information du Québec (CAI).
13.3 Notice to the individuals concerned
The Publisher will promptly notify the individuals whose personal information is affected by the incident, telling them:
- –The nature of the personal information concerned;
- –The circumstances of the incident;
- –The date or period during which the incident occurred or is likely to have occurred;
- –The measures taken or planned to reduce the risk of injury;
- –The steps the individual can take to mitigate the risk;
- –The contact details of a resource person.
13.4 Incident register
The Publisher maintains a register of confidentiality incidents, in accordance with section 3.8 of the Private Sector Act. That register is kept for at least five (5) years and is available on request from the CAI.
13.5 Corrective measures
Following any incident, the Publisher takes reasonable measures to reduce the risk of injury and to prevent incidents of the same kind from recurring.
14. CHANGES TO THIS POLICY
The Publisher reserves the right to amend this Policy at any time. Amendments take effect thirty (30) days after they are notified to the individuals concerned by any appropriate means (in-app notification, communication to the Clinic).
The Publisher undertakes to clearly inform Users of any substantial change to the Policy, in particular regarding the categories of information collected, the processing purposes or the service providers involved.
15. CONTACT AND COMPLAINTS
15.1 Contact
For any question about this Policy or the protection of your personal information, or to exercise your rights:
Privacy Officer
Stery Inc.
512 Pine Avenue
Saint-Lambert, Quebec, Canada
Email: contact@stery.ca
Phone: 1 888 559-7719
15.2 Complaints
If you believe your personal information has not been handled in accordance with the Private Sector Act, you may:
1. Contact us directly using the details above. We will handle your complaint promptly.
2. File a complaint with the Commission d'accès à l'information du Québec (CAI):
Commission d'accès à l'information du Québec
525, boulevard René-Lévesque Est, bureau 2.36
Québec (Québec) G1R 5S9
Phone: 1-888-528-7741
Website: www.cai.gouv.qc.ca
LEGISLATIVE REFERENCES
This Policy is drafted in accordance with the following laws and regulations:
- –Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), as amended by Law 25 (2021, c. 25)
- –Personal Information Protection and Electronic Documents Act (PIPEDA) (S.C. 2000, c. 5)
- –Civil Code of Québec (CQLR, c. CCQ-1991)
- –Charter of Human Rights and Freedoms (CQLR, c. C-12)