Privacy Policy
Last Updated: September 25, 2026
Introduction and Scope
Design Aesthetics (“Design Aesthetics”, “we”, “us” or “our”) is a design and marketing studio with an office at Suite 5700, 100 King Street West, Toronto, Ontario, that builds websites, web applications and social media content for healthcare practices, clinics, health brands and related organizations. This Privacy Policy (the “Policy”) describes how we collect, use, disclose, retain, transfer and protect personal information in the course of operating our website at design.aes-studio.com and our related subdomains (the “Site”), responding to enquiries, marketing our services, and delivering our services (the “Services”).
This Policy applies to personal information about identifiable individuals, including prospective, current and former clients, their personnel, individuals who contact us, and individuals whose business contact information we obtain for the purpose of offering our Services. It does not apply to (a) information that we process on behalf of a client under a written agreement, in respect of which we act as a service provider, or (b) personal information about our own employees, contractors and applicants, which is governed by separate internal policies.
We are accountable for personal information under our control in accordance with the Personal Information Protection and Electronic Documents Act (Canada) (“PIPEDA”) and applicable provincial privacy legislation, including the Personal Health Information Protection Act, 2004 (Ontario) (“PHIPA”), the Act respecting the protection of personal information in the private sector (Quebec) (“Quebec Law 25”) where it applies, and Canada’s Anti-Spam Legislation (“CASL”).
By using the Site, submitting an enquiry, subscribing to our communications or engaging us for Services, you acknowledge that you have read and understood this Policy. Where we require consent for a particular use of personal information, we will request it separately. If you do not agree with this Policy, please do not use the Site or provide personal information to us.
This Policy is incorporated by reference into, and forms part of, our Terms of Service. In the event of a conflict between this Policy and a written agreement between us, that agreement prevails to the extent of the conflict.
Definitions
- “Aggregated Information” means information in respect of which individual identifiers have been removed and which has been combined with other information such that it cannot reasonably be used to identify an individual.
- “Business Contact Information” means information about an individual in a professional capacity, including name, professional title, practice or employer name, business address, business telephone number, business email address, and professional registration or licence details.
- “Client Data” means personal information and other data that a client or its personnel provides to us, or that we receive, store, host, transmit, publish or otherwise process on a client’s behalf, in connection with the Services.
- “Commercial Electronic Message” or “CEM” has the meaning given to it in CASL, and includes promotional email, text messages and messages sent through direct-messaging platforms.
- “De-identified Information” means personal information from which identifiers have been removed such that it no longer reasonably identifies an individual, and in respect of which we do not attempt re-identification.
- “Personal Information” means information about an identifiable individual as defined under applicable Canadian privacy law, and includes “personal data”, “personally identifiable information” and any substantially similar term used in other jurisdictions.
- “Privacy Officer” means the individual designated by Design Aesthetics with responsibility for compliance with this Policy and with applicable privacy legislation, who may be contacted at [email protected].
- “Processing” means any operation performed on personal information, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, transfer, retention and destruction.
- “Service Provider” means a third party that processes personal information on our behalf under written terms that restrict its use to the services it provides to us.
Our Roles: Organization and Service Provider
(a) In respect of the Site, our marketing, business development and vendor management activities, and personal information we collect for our own purposes, we act as the organization with control of the information and are accountable for it under applicable privacy legislation. (b) In respect of Client Data, we act as a service provider and, where the client is a health information custodian within the meaning of PHIPA, as the client’s agent, and we process Client Data only on the client’s documented instructions and for the purposes of the Services.
Where we act as a service provider, we do not determine the purposes for which Client Data is collected or the manner in which it is used; those determinations belong to the client. The client is responsible for the lawfulness of its collection of Client Data, for obtaining any consent or authority required by law, for providing any required notices, and for responding to requests made by individuals whose information it holds.
If you are a patient, client, customer or employee of one of our clients and you wish to access, correct, restrict or delete information held by that organization, please direct your request to that organization. We will assist our clients in responding to such requests where required, but we do not act on them unilaterally.
We are not a health information custodian, we do not provide health care or clinical advice, and we do not make decisions about the collection, use or disclosure of health information.
Information We Collect
We collect personal information that you provide to us, information collected automatically when you use the Site, and business contact information we obtain from public and professional sources in the course of marketing our Services.
Information you provide to us
- Contact and identification information, such as your name, professional title, practice or organization name, email address, telephone number and location, provided when you submit an enquiry, book a call, message us through WhatsApp, Instagram, LinkedIn or another platform, or otherwise correspond with us.
- Project and business information, such as details about your practice, services, treatments, brand, objectives, competitors, personnel, locations, budgets, timelines and decisions, together with any materials you provide for the purpose of a proposal or an engagement.
- Content and media, including footage, photographs, audio recordings, testimonials, reviews, imagery of identifiable individuals, logos, copy and other content provided to us for use in deliverables, together with any consents, releases or permissions relating to them.
- Access and configuration information, including administrative credentials, keys, and hosting, domain, analytics, advertising and platform access, and configuration details for systems we administer on your behalf.
- Billing and payment information, including invoicing contacts, billing address, purchase order references and payment confirmations. Card and bank details are processed directly by our payment processors, and we do not store complete payment card numbers.
- Communications and records, including the content of emails, messages, call notes and meeting records, and our notes of our dealings with you.
Information collected automatically
- Technical information, such as your IP address, device type, browser type and version, operating system, language settings, referring URL and approximate location derived from IP address.
- Usage information, such as the pages you view, the time you spend on them, your navigation and click paths, session duration, form interactions and error events, collected using cookies and similar technologies where they are deployed on the Site.
- Security and fraud-prevention information, such as records generated by our security controls, including bot-detection and reCAPTCHA signals, rate-limiting events and access logs.
Business contact information we obtain from other sources
- Public and professional sources, including professional and regulatory registers and listings (for example, registers of licensed dentists and physicians), publicly available practice websites, and publicly available professional and social media profiles, from which we obtain business contact information and practice details in order to identify organizations that may have an interest in our Services.
- Referrals and introductions, including information provided by a mutual contact, partner, association or existing client.
- Advertising and lead platforms, including information submitted through forms hosted on advertising platforms we use, together with campaign and creative identifiers associated with the submission, and information generated by measurement and retargeting technologies used to assess our own campaigns.
Information we do not seek
We do not purchase personal information from data brokers or list vendors, we do not seek sensitive categories of personal information (as that term is defined under Quebec Law 25 or other applicable law), and we do not request health information through the Site. Do not send us patient, health or other sensitive information through web forms, unencrypted email, or consumer messaging applications. Where we need to receive such information, we will first confirm an appropriate method in writing.
How We Use Personal Information
We use personal information for the purposes set out below, and for purposes that are reasonably related to them and that a reasonable person would consider appropriate in the circumstances:
- To respond to enquiries, schedule and conduct calls, and assess whether our Services are a fit.
- To prepare proposals, statements of work, estimates and agreements.
- To provide, administer, deliver and support the Services, including the planning, capture, writing, design, editing, approval, scheduling and publication of content, and the design, development, hosting and maintenance of websites and applications.
- To administer accounts, access and environments on systems that we manage on a client’s behalf.
- To invoice, process payments, maintain accounting and tax records, and collect amounts owing.
- To communicate with you about your engagement, our Services, changes to our policies and other administrative matters.
- To market our Services, including through direct outreach to business contacts, advertising, retargeting and the measurement of our campaigns.
- To maintain, secure and improve the Site, our Services and the quality of our delivery, including through analytics and de-identified or aggregated reporting.
- To detect, prevent, investigate and respond to fraud, abuse, security incidents and unauthorized access.
- To comply with our legal, tax, accounting, insurance and regulatory obligations, and to establish, exercise or defend legal claims.
We do not sell, rent or trade personal information. We do not provide personal information to third parties so that they may market their own products or services to you, and we do not use personal information to build advertising profiles of visitors to the Site. Where a Service Provider uses automated or artificial-intelligence-assisted tooling in the course of providing services to us, that processing is governed by written terms that restrict the use of personal information to the provision of those services.
Legal Bases, Consent and Commercial Communications
We collect, use and disclose personal information with the knowledge and consent of the individual, except where consent is not required or is expressly permitted by applicable law, including section 7 of PIPEDA. Consent may be express, or implied by the circumstances and the individual’s conduct.
Withdrawing consent. You may withdraw your consent at any time, subject to legal and contractual restrictions and to reasonable notice. Withdrawal is not retroactive and does not affect the lawfulness of processing carried out before withdrawal. Withdrawing consent may prevent us from continuing to provide some or all of the Services, or from communicating with you about them.
Business outreach and CASL. We may send Commercial Electronic Messages to business contacts where we have consent, where consent may be implied because the recipient is engaged in a commercial activity, the message is relevant to that person’s business role and the address was conspicuously published or disclosed without a statement that the person does not wish to receive such messages, or where another exception under CASL applies. Every such message identifies us, includes our contact information and includes a functioning unsubscribe mechanism. Unsubscribe and do-not-contact requests are actioned without delay and in any event within the period required by law. We maintain an internal do-not-contact list, and a request to stop receiving commercial messages does not prevent us from sending messages required to administer an existing engagement.
Telephone contact. Our telephone outreach is directed at business contacts and business lines in connection with their professional role. We comply with Canada’s Unsolicited Telecommunications Rules and maintain internal do-not-call records where applicable. You may ask us at any time to stop calling you, and we will do so.
Information about other people. Where you provide us with personal information about another individual, you represent that you have the authority to do so and that any consent required for us to process that information for the purposes described in this Policy has been obtained.
Other jurisdictions. Where the law of a jurisdiction requires us to identify a legal basis for processing (including, if and to the extent applicable, the European Economic Area, the United Kingdom and Switzerland), we rely on your consent, the performance of a contract with you, our legitimate interests in operating, securing and growing our business, and compliance with our legal obligations. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.
How We Disclose Personal Information
We disclose personal information only as described in this Policy, as authorized by you, or as required or permitted by law:
- Service Providers that perform functions on our behalf, including hosting, infrastructure and content delivery, email delivery and communications, customer relationship management, scheduling and booking, analytics, payment processing, cloud storage and backup, project management, transcription, design and editing tooling, security and bot detection, and professional services. Service Providers are bound by written agreements that require confidentiality and restrict their use of personal information to the services they provide to us.
- Advertising and analytics platforms, in connection with the measurement and targeting of our own marketing, subject to the choices you have made on those platforms and to this Policy.
- Professional advisers, insurers, auditors and financiers, where reasonably necessary for the operation of our business.
- At your direction, or where disclosure is necessary to deliver a Service you have requested, including where a client instructs us to publish content or to transmit information to a third-party platform.
- Where required by law, regulation, subpoena, court order, warrant or other lawful request, or where disclosure is necessary to establish, exercise or defend legal claims, to protect the rights, property or safety of any person, or to investigate suspected unlawful activity. Where lawful and practicable, we will notify the individual concerned before disclosing, unless we are prohibited from doing so.
- In connection with a financing, reorganization, merger, acquisition, sale of assets or similar corporate transaction, subject to confidentiality protections consistent with this Policy.
Aggregated and de-identified information
We may create, use, disclose and commercialize Aggregated Information and De-identified Information for research, benchmarking, service improvement, industry reporting and other business purposes. Aggregated Information and De-identified Information are not personal information under applicable law. We will not attempt to re-identify De-identified Information, and we require recipients not to attempt to do so.
We do not sell personal information, and we do not provide personal information to data brokers or list vendors.
Cross-Border Processing and Storage
We are based in Canada. Our Service Providers may store, process and support personal information on servers located in Canada, the United States and other jurisdictions, and our personnel and contractors may access information from outside your jurisdiction.
As a result, personal information may be subject to the laws of those jurisdictions and may be accessible to courts, law enforcement, regulatory and national security authorities in those jurisdictions under a lawful order or demand. Where personal information is transferred outside Canada, we use contractual and other measures to provide a comparable level of protection while the information is under our control.
PIPEDA requires that we inform you that personal information may be processed outside Canada and that foreign authorities may be able to access it. By providing personal information to us, you acknowledge this. If you require that particular personal information remain in Canada, please contact the Privacy Officer and we will determine whether we can accommodate the request without compromising the Services.
Retention and Destruction
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, to comply with our legal, tax, accounting and insurance obligations, to resolve disputes and to enforce our agreements. Retention periods are determined by the nature and sensitivity of the information, the purpose of collection, the applicable limitation periods (including under the Limitations Act, 2002 (Ontario)), and any legal hold.
Unless a shorter or longer period is required by law, by contract or by the circumstances, we generally retain: enquiry records that do not result in an engagement, for up to twenty-four (24) months; business contact and marketing records, for as long as the contact remains relevant to our business development activities and for a reasonable period afterwards, subject to any do-not-contact instruction; client, project, content and billing records, for up to seven (7) years after the end of the engagement or the last activity, whichever is later; and website analytics data, for no longer than twenty-six (26) months.
When personal information is no longer required, we delete, destroy or irreversibly anonymize it using secure methods, and we require our Service Providers to do the same. Where deletion is not immediately possible (for example, where information is contained in a backup or archive), we isolate and restrict access to the information and retain it only until deletion becomes possible, after which it is destroyed in accordance with this Policy.
Where we process Client Data on behalf of a client, retention, deletion and return are governed by our agreement with that client, by that client’s instructions, and by any legal retention requirement applicable to the client.
Security Safeguards and Breach Notification
We maintain administrative, technical, physical and contractual safeguards that are appropriate to the sensitivity of the personal information we hold. These include least-privilege access controls, authentication requirements, encryption of data in transit, encryption of stored data where appropriate, logging and monitoring, prompt patching, segregation of client environments, confidentiality obligations for personnel and contractors, onboarding and offboarding procedures, and review of the security practices of our Service Providers.
No method of transmission over the internet and no method of electronic storage is completely secure. We do not guarantee, represent or warrant that personal information in our control will never be accessed, disclosed, altered, lost or destroyed by an unauthorized act, and, to the maximum extent permitted by applicable law, we are not liable for unauthorized acts of third parties that are beyond our reasonable control. The limitations, exclusions and allocation of risk set out in our Terms of Service apply to the Site, this Policy and the Services.
Where we become aware of a breach of security safeguards involving personal information under our control in respect of which there is a real risk of significant harm to an individual, we will, without unreasonable delay: (a) report the breach to the Office of the Privacy Commissioner of Canada and to any other regulator as required; (b) notify affected individuals and organizations as required by law; and (c) maintain a record of the breach as required by law. Where the breach involves Client Data, we will notify the affected client without undue delay so that the client can meet its own notification obligations.
You are responsible for maintaining the security of your own credentials, devices, systems and accounts, and for maintaining your own backups of content and data where the Services do not include backup.
Your Rights and How to Exercise Them
Subject to applicable law and to certain exceptions, you may have the following rights in respect of personal information about you:
- Access, meaning the right to request confirmation of whether we hold personal information about you and to request access to that information, together with information about how it has been used and to whom it has been disclosed.
- Correction, meaning the right to request correction of personal information that is inaccurate, incomplete or out of date. Where we do not make a requested correction, we will annotate the record with the request and, where appropriate, disclose the unresolved request to recipients of the information.
- Withdrawal of consent and objection, meaning the right to withdraw consent to, or object to, processing that is based on consent, subject to legal and contractual restrictions and to reasonable notice.
- Deletion, meaning the right to request deletion of personal information, subject to our legal, tax, accounting, insurance and dispute-resolution obligations and to the rights of others.
- De-indexing, cessation of dissemination and portability, where required by the law of your jurisdiction (including Quebec Law 25 and, where applicable, the General Data Protection Regulation), meaning the right to request de-indexing, cessation of dissemination, or the transfer of computerized personal information in a structured and commonly used format.
- Non-discrimination, meaning the right not to be denied services or charged a different price for exercising your rights.
- Complaint, meaning the right to lodge a complaint with the appropriate supervisory authority.
How to make a request. Contact the Privacy Officer at [email protected] or by mail at Suite 5700, 100 King Street West, Toronto, ON M5X 1A9, Canada. Please describe the right you are exercising and the information to which it relates. We may require information sufficient to verify your identity and, where you are acting for another person, your authority to act. Information provided for verification is used only for that purpose and is destroyed when it is no longer required.
We will respond to a request for access or correction within thirty (30) days after receipt of a complete request, or within any longer period permitted by applicable law. Where we extend the response period or refuse a request in whole or in part, we will advise you in writing of our reasons and of your right to make a complaint, and of the steps available to you.
There is no fee for a reasonable request. Where cost recovery is permitted by applicable law, we will provide an estimate before proceeding. Where a request relates to Client Data, we will forward the request to the relevant client and assist as required.
Where we hold business contact information about you for the purpose of marketing our Services, you may ask us to stop contacting you or to remove your information from our marketing records at any time, and we will do so without requiring you to give a reason.
Children
The Site and the Services are directed at businesses and adults. We do not knowingly collect personal information from individuals under sixteen (16) years of age, or under the applicable age of consent in their jurisdiction, and we do not solicit it.
Where imagery of a minor is to be included in content created for a client, the client is responsible for obtaining all required consents and permissions, including from a parent or legal guardian.
If we learn that we have collected personal information from a child in circumstances where consent was required and was not obtained, we will delete or destroy that information without unreasonable delay. If you believe we hold such information, please contact the Privacy Officer.
Automated Processing
We do not use personal information to make decisions by automated means that produce legal effects, or similarly significant effects, concerning individuals.
Where automation is used in the course of our business (for example, to route an enquiry, to score a business lead, to schedule a call, to measure campaign performance, or to analyse publicly available content), the output informs activities that are carried out and reviewed by people and does not by itself determine an individual’s access to the Services or the terms on which they are provided.
Third-Party Services and Links
The Site contains links to, integrations with, and embeds from third-party websites, platforms and services, including social media platforms, scheduling tools, mapping services, hosting and content-delivery providers and advertising platforms. This Policy does not apply to those third parties. We are not responsible for their content, security, availability or privacy practices, and we encourage you to review their terms and privacy policies.
Where a client engages us in relation to a third-party platform, that platform’s own terms and data practices apply to the client and to content published through it, and are outside our control.
Deletion of information collected through our WhatsApp Business channel is described at /data-deletion. Requests relating to personal information more generally are handled as described under “Your Rights and How to Exercise Them”.
Changes to This Policy
We may amend, restate or replace this Policy at any time to reflect changes in our practices, our Services, our technology or applicable law. The version posted on this page bearing the most recent “Last Updated” date is the current version, supersedes all previous versions, and is effective on posting.
Where a change is material, we will provide reasonable notice before it takes effect, including by notice on the Site and, where we hold a business contact address for you, by email, or as otherwise required by applicable law. Your continued use of the Site or the Services after the effective date constitutes acceptance of the amended Policy. If you do not agree with an amendment, you must stop using the Site and, where applicable, terminate your engagement in accordance with our Terms of Service.
Interpretation and governing law. Headings are for convenience only and do not affect interpretation. A reference to a statute includes its regulations and any amendment or replacement. The singular includes the plural. “Including” means “including without limitation”. If any provision of this Policy is determined to be invalid or unenforceable, that provision will be severed and the remainder of the Policy will continue in full force. This Policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable in Ontario.
Contact and Complaints
Privacy Officer, Design Aesthetics, Suite 5700, 100 King Street West, Toronto, ON M5X 1A9, Canada. Email: [email protected]. Telephone: +1 888 546 3470.
We will respond to questions and concerns about this Policy and about our handling of personal information. We ask that you raise any concern with the Privacy Officer first so that we have an opportunity to resolve it.
If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada (1-800-282-1376, priv.gc.ca) or the Information and Privacy Commissioner of Ontario (1-800-387-0073, ipc.on.ca), as applicable.
Where we process information as a service provider or agent, complaints about that information should also be directed to the client organization responsible for it, which has the primary relationship with the individual concerned.