Home » Privacy Policy
Campus reception

Privacy Policy

Introduction

Welcome to the Ontario Institute of Health and Innovation (“OIHI”) privacy notice. Ontario Institute of Health and Innovation is part of The Global University Systems B.V. group of companies which is made up of different legal entities, details of which can be found at: www.globaluniversitysystems.com.

Ontario Institute of Health and Innovation respects your privacy and is committed to protecting your personal data. This privacy notice tells you how we look after your personal data when you visit our websites (regardless of where you visit from) and tells you about your privacy rights and how the law protects you.

This privacy notice is provided in a layered format so you can click through to the specific areas set out below.  Please also use the Glossary at section 12 for the meaning of some of the terms used in this privacy notice.

Purpose Of This Privacy Notice

This privacy notice aims to give you information on how Ontario Institute of Health and Innovation collects and processes your personal data including any data you may provide through this website when you:

  • arrive on our website from a social media site such as Facebook Twitter, Instagram, Snapchat, Pinterest, VKontakte or LinkedIn;
  • complete a call back / enquiry form;
  • you register on our site to apply for a course or programme, corporate/ executive education, professional training, (online, distance learning or campus based) and whether you are applying for yourself or for employees or other staff at your organisation which may be or become a customer of ours;
  • sign up for marketing materials; or
  • you provide us with your personal data by any other means.

This website is not intended for children and we do not knowingly collect data relating to children on this website.  However where Ontario Institute of Health and Innovation processes personal data of children in its business operations, we ensure that appropriate safeguards and consents are obtained from parents or caregivers as applicable. You may contact  compliance@guscanada.ca for further information about this.

It is important that you read this privacy notice together with any other privacy notice or fair processing notice we may provide on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your data.

This privacy notice supplements the other notices and does not replace them.

1. Important Information And Who We Are

Data Controller

Ontario Institute of Health and Innovation INC (‘OIHI’), a company registered in Canada with number 721513-4 with its registered office at 124 Eglinton Ave West, (4th floor), Toronto, ON, M4R 2G8, Canada is the data controller of your personal. OIHI is part of The Global University Systems B.V. group of companies which is made up of different legal entities, details of which can be found at: www.globaluniversitysystems.com.

We have appointed a data protection officer (DPO) who is responsible for overseeing questions in relation to this privacy notice. If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact the DPO using the details set out below.

Contact Details

Our Full Details Are:

Full name of data controller legal entity:  Ontario Institute of Health and Innovation
Name or title of DPO:  FAO Data Protection Officer (Jessie Atkins)
Email address: compliance@guscanada.ca

Postal address: 124 Eglinton Ave West, (4th floor), Toronto, ON, M4R 2G8, Canada
Telephone number: +14168002204

You have the right to make a complaint at any time to the Information and Privacy Commissioner of Ontario the supervisory authority for data protection issues in Ontario. (www.ipc.on.ca/)

We would always prefer that you come to us to help address any concerns of a privacy nature before you go to The Information and Privacy Commissioner, so please contact us in the first instance.

Changes To The Privacy Notice And Your Duty To Inform Us Of Changes

This version was last updated on 18 October 2021 and historic versions can be obtained by contacting us.

We may from time to time change the detail in this notice.  Any changes we may make in the future will be posted on this page.  Please check back frequently to see any such updates or changes.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us.

Third-Party Links

This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy notice of every website you visit.

2. The Data We Collect About You

Personal data, or personal information, means any information about an individual from which that person can be identified. Anonymous data is therefore not treated as personal data.

We have grouped together different kinds of personal data which we may collect, use, store and transfer as follows:

  • Academic Data includes eligibility data including education and academic history, training records, qualifications, personal statements, CVs, personal achievements and references.
  • Identity Data includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth and gender, Unique Learner Number, nationality, residency status, disability declaration, criminal conviction declaration, third party student reference number where that third party shares your data with us, photographic images.
  • Contact Data includes billing address, term-time and permanent residential address, country of residence, email address and telephone numbers.
  • Emergency Contact Data about next of kin names and contact details for use when there is an emergency that has involved you.
  • Employment Data (if you are sponsored by your employer) includes employer details, start date, end dates, your job title, contact details at work (email address, telephone number and postal address).
  • Financial Data includes student loan information, bank account and payment card details.
  • Marketing And Communications Data includes your preferences in receiving marketing from us and your communication preferences.
  • Profile Data includes any of your usernames and passwords, enquiries made by you, purchases or orders made by you, your interests, preferences, feedback and survey responses.
  • Student Data includes your term time and home address, ID photo, subject of interest, chosen program your progress data and your results (coursework and exam, including mocks), other results from before final study years, exam scripts and transcripts, your attendance, lecturers’ and tutors’ feedback on you or your staff (if you are a corporate) (student references), communications with Ontario Institute of Health and Innovation  the extent of your use of any learning facilities / services by Ontario Institute of Health and Innovation information relating to your use of the Ontario Institute of Health and Innovation library resources (including materials checked out and overdue items), data about your membership of student groups, associations and any event attendances), information regarding mentor and mentee data, and your membership of any relevant alumni network, data around your taking part in events hosted by us or advertised by us, learner analytics and profiling data, any disciplinary data, student, course, or tutor- related complaints data and any claims involving you of any nature whatsoever, extenuating circumstances, appeals, additional information as required by professional/accreditation/awarding body.
  • Monitoring And Reporting Requirements Data includes destination of leavers of HE data and Student Data reported to third parties for regulatory purposes.
  • Transaction Data includes details about payments to and from you and other details of products and services you have purchased from us.
  • Technical Data includes your IP address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access this website.
  • Usage Data includes URL data, web analytics data in relation to how you arrived at our sites, from where, what search items you looked for, which pages you visited on our sites, the duration of your visits and such other information about how you use our websites and the information provided on them, and how you use our products and services so as to assist us to improve our website offering to you.
  • Visa Data for international students, including passport and previous visas data, bank statements or other financial information for satisfying ourselves that visa requirements are met.

We also collect, use and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data may be derived from your personal data but is not considered personal data in law as this data does not directly or indirectly reveal your identity. For example, we may aggregate your Usage Data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy notice.

Special Category Data

When you make an application on our website for a course or program we will ask whether you have any disabilities. You are not obliged to inform us but any information you do provide will assist us to assess how we will meet our statutory obligation in relation to your disability.

Criminal Offence Data

For the purposes of compliance with our Safeguarding Policy, we may ask for Background checks or seek criminal records information.  This type of data is regulated under The Privacy Act 1983 and we ensure that we limit the use of any such data both in time and in scope and that we meet appropriate lawful grounds for processing such data.

For further information please contact our DPO at compliance@guscanada.ca

If You fail To Provide Personal Data

Where we need to collect personal data by law, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have with us, but we will notify you if this is the case at the time.

3. How Is Your Personal Data Collected?

We use different methods to collect data from and about you including through:

  • Direct Interactions. You may give us your Identity, Contact and Financial Data by filling in forms or by communicating with us by post, phone, email or otherwise. This includes personal data you provide when you:
  • Apply for our products or services;
  • Create an account on our website;
  • Use our site;
  • Subscribe to our service or publications;
  • Request marketing to be sent to you;
  • Enter a promotion or survey; or
  • Give us some feedback.
  • Automated Technologies Or Interactions. As you interact with our website, we may automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. Please see our cookie policy for further details.
  • Third Parties Or Publicly Available Sources. We may receive personal data about you from various third parties and public sources as set out below:

Technical Data From The Following Parties:

  1. Analytics providers such as Google analytics, Google optimizer, Google Webmaster tools, Google tag manager, Facebook, Instagram and Conversant based out of Europe & Convertr Media based in UK and other similar services which we will be using in the future;
  2. Advertising networks such as Google Advertising Network, Facebook, Instagram, Bing and Linkedin based outside Ontario and similar network we will be partnering with; and
  3. Search information providers such as Google, Bing and other search engines based inside and outside Ontario, social media networks such as Facebook, Linkedin and Instagram, based inside the EU and others providing similar services.
  4. Contact, Financial and Transaction Data from providers of technical, payment and delivery services such as Conversant, Google Analytics, Facebook, Instagram, Bing, Linkedin and Stripe, based outside Ontario and Convertr Media based inside the UK including similar services we will partner with in future.
  5. Identity and Contact Data from data aggregators.
  6. Student Data from staff, administrative functions of other educational establishments, mentees or mentors, complainants.
  7. Academic, contact, identity, marketing and communications and technical data from (i) publishers, who are owners of private websites, and are based in and outside Europe and (ii) agents, referring organisations such as other universities.

4. How We Use Your Personal Data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

  • Where we need to perform the contract, we are about to enter into or have entered into with you.
  • Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
  • Where we need to comply with a legal or regulatory obligation.

Please see the table below to find out about the types of lawful basis that we will rely on to process your personal data.

Generally, we do not rely on consent as a legal basis for processing your personal data other than in relation to sending direct marketing communications to you via email or SMS. You have the right to withdraw consent to marketing at any time by contacting our DPO at compliance@guscanada.ca or by clicking the unsubscribe link in the relevant emails.

5. Purposes For Which We Will Use Your Personal Data

We have set out below a description of all the ways we plan to use your personal data, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.

We may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data.

Students Or Prospective Students

Purpose/Activity: Type Of Data:Lawful Basis
To respond to your request for a call (or email) back, course enquiries, applications(a) Contact DataPerformance of a contract with you (in our anticipation of entering into such contract with you)
Purpose/Activity: Type Of Data:Lawful Basis
To enrol / register you as a new candidate and provide student number / identity card(a) Identity Data

(b) Contact Data

(c) Academic Data
Performance of a contract with you
Purpose/Activity: Type Of Data:Lawful Basis
Direct marketing of or about student benefits and opportunities, University activities and events, services or career opportunities and professional and industrial bodies wishing to communicate with students about career opportunities.

Direct marketing may include cookie based remarketing services intended to deliver targeted marketing to you based on your internet searches
(a) Contact DataConsent

Legitimate interest
Purpose/Activity: Type Of Data:Lawful Basis
To process your application including for the provision of services including:(a) Identity Data(a) Performance of a contract with you
(a) Manage payments, fees and charges(b) Contact Data(b) Necessary for our legitimate interests (to recover debts due to us)
(b) Collect and recover money owed to us(c) Financial Data(c) Consent
(c) accounting for  GST  purposes(d) Transaction Data

(e) Marketing and Communications Data

(f) Academic Data
Purpose/Activity: Type Of Data:Lawful Basis
To manage our relationship with you which will include:(a) Identity Data(a) Performance of a contract with you
(a) Notifying you about changes to our terms or privacy policy(b) Contact Data(b) Necessary to comply with a legal obligation
(b) Provision of learning material(c) Profile Data(c) Necessary for our legitimate interests (to keep our records updated and to study how students use our products/services)
(c) Asking you to leave a review or take a survey

(d) Monitor attendance or any change in student status.

(e) Administration of appeals, complaints, and matters relating to health and conduct and to cheating and plagiarism (unfair means)

(f) Granting of awards

(g) Administration of alumni membership
(d) Marketing and Communications Data(d) Necessary for the candidate’s legitimate interests (to receive the benefit of the award)
Purpose/Activity: Type Of Data:Lawful Basis
Equal opportunities monitoringGender ethnicity religion and nationalityLegal Obligation
Purpose/Activity: Type Of Data:Lawful Basis
Enrolment(a) Identity Data

(b) Student Data
Performance of a contract with you
Purpose/Activity: Type Of Data:Lawful Basis
Make adjustments to meet disability requirements / medical conditionsHealth DataConsent
Purpose/Activity: Type Of Data:Lawful Basis
Provide health and safety first aid assistance emergency evacuation, hazard risk assessment, accident monitoringHealth DataVital interests; Consent
Purpose/Activity: Type Of Data:Lawful Basis
Emergency accident / health managementemergency contact / next of kin detailsVital interests; Consent

Customers (Or Prospective Customers) Of Online Courses And Published Media

Purpose/Activity: Type Of Data:Lawful Basis
Register new customer of online materials(a) Identity Data

(b) Contact Data
Performance of a contract with you
Purpose/Activity: Type Of Data:Lawful Basis
Process / fulfil / deliver customer order(a) Identity Data(a) Performance of a contract with you
Manage payments, fees and charges(b) Contact Data(b) Necessary for our legitimate interests (to recover debts due to us or defend legal claims)
Collect/ recover monies owed

Accounting records

Defence of legal claims brought against us
(c) Financial Data

(d) Transaction Data

(e) Marketing and Communications Data
(c) Necessary to comply with a legal obligation

Clients Of Ontario Institute Of Health And Innovation (Including Employer Clients)

Purpose/Activity: Type Of Data:Lawful Basis
To register you as a client of Ontario Institute of Health and Innovation(a) Identity Data

(b) Contact Data
Performance of a contract with you
Purpose/Activity: Type Of Data:Lawful Basis
Process / fulfil / deliver customer order(a) Identity Data(a) Performance of a contract with you
Manage payments, fees and charges(b) Contact Data(b) Necessary for our legitimate interests (to recover debts due to us or defend legal claims)
Collect/ recover monies owed

Accounting records

Defence of legal claims brought against us
(c) Financial Data

(d) Transaction Data

(e) Marketing and Communications Data
(c) Necessary to comply with a legal obligation

For All:

Purpose/Activity: Type Of Data:Lawful Basis
Recruitment (Academic job applications performed via webform)(a) Identity Data

(b) Contact Data
Performance of a contract
Purpose/Activity: Type Of Data:Lawful Basis
Relationship management(a) Identity Data(a) Performance of a contract with you
Updating privacy policy and notify you of the same(b) Contact Data(b) Necessary to comply with a legal obligation
Updating terms and conditions and notify you of the same

Seeking your feedback
(c) Profile Data

(d) Marketing and Communications Data
(c) Necessary for our legitimate interests (continuous improvement / updating records/ analyse customer behaviour patterns)

Processing Complaints

Purpose/Activity: Type Of Data:Lawful Basis
To administer and protect our business and our Website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)(a) Identity Data

(b) Contact Data

(c) Technical Data
(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)

(b) Necessary to comply with a legal obligation
Purpose/Activity: Type Of Data:Lawful Basis
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you(a) Identity Data

(b) Contact Data

(c) Profile Data

(d) Usage Data

(e) Marketing and Communications Data

(f) Technical Data
Legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)
Purpose/Activity: Type Of Data:Lawful Basis
To use data analytics to improve our website, products/services, marketing, student and partner relationships and experiences(a) Technical Data

(b) Usage Data
Legitimate interests (to define customer types for our products /services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)
To make suggestions and recommendations to you about goods or services that may be of interest to you(a) Identity Data

(b) Contact Data

(c) Technical Data

(d) Usage Data

(e) Profile Data
Necessary for our legitimate interests (to develop our products/services and grow our business)

Alumni

Purpose/Activity:Type Of Data:Lawful Basis:
To respond to your request for a call or email backContact DataConsent
Direct marketing of or about alumni benefits, events and opportunities (e.g. alumni discounts, networking sessions, workshops, mentorship programs)Contact DataConsent
To manage our relationship with you which will include:

(a) Notifying you about changes to our terms or privacy policy

(b) Asking you to provide a testimonial

(c) Administration of alumni membership
Contact Data

Identity Data

Marketing and Communications Data
Performance of a contract with you

Necessary to comply with a legal obligation

Consent
To administer and protect our business and our Website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)Identity Data

Contact Data

Technical Data
Necessary for our legitimate interests

Necessary to comply with a legal obligation
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to youIdentity Data

Contact Data

Profile Data

Usage Data

Marketing and Communications Data

Technical Data
Legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)
To use data analytics to improve our website, products/services, marketing, student and partner relationships and experiencesTechnical DataLegitimate interests (to define customer types for our products /services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)
To make suggestions and recommendations to you about goods or services that may be of interest to youIdentity Data

Contact Data

Technical Data

Usage Data

Profile Data
Necessary for our legitimate interests (to develop our products/services and grow our business)

6. How We Use Sensitive Personal Information (Special Category Data)

The law requires us to meet additional conditions for collecting, storing and using personal data that is considered ‘special category’ data. We have in place an appropriate policy document and safeguards which we are required by law to maintain when processing such data. We may process special categories of personal information in the following circumstances:

Students Or Prospective Students

Purpose/Activity: Type Of Data:Lawful Basis
To enroll you as a student we need to determine your immigration status with Ontario Institute of Health and InnovationNationality data

Immigration status (information from visas and passports)
(a) Performance of a contract with you

(b) Legal obligation e.g. to comply with Government of  Ontario  and other authorities
Purpose/Activity: Type Of Data:Lawful Basis
To make required adjustments and necessary support for applicable learning needsDisability data

Special learning needs
(a) Performance of a contract with you

(b) Complying with our legal obligations (The Accessibility for Ontarians with Disabilities Act, 2005)

(c) Explicit consent (information is voluntary)
Purpose/Activity: Type Of Data:Lawful Basis
(a) Monitor student absences*Medical / health data(a) Performance of a contract with you
(b) Deal with applications for mitigating circumstancesDoctors’ notes(b) Explicit consent (this information is voluntary)
(c) Deal with applications for interruptions of studies or deferrals

(d) Confirm any dietary requirements
Medical Records (potentially)(c) *sometimes a visa will stipulate that a student must keep a minimum attendance level; in this case we will ask for medical evidence to support absence and thus to avoid breaching our obligations to the Ontario government.
Purpose/Activity: Type Of Data:Lawful Basis
To monitor and report on equal opportunitiesData relating to race and ethnic(a)Compliance with a legal obligation

The above information may also need to be used using the lawful basis of pursuant to a legal claim or to protect your interests (or someone else’s interests) (where you are not capable of giving your consent (for example if you suffer a medical problem preventing your ability to communicate).

Consent

It is not a condition of becoming a student with us that you give us consent for any particular type of processing. However, should you choose not to give consent, then you may not benefit from certain support services for example.

We do not need your consent in circumstances where we use special categories of your data in accordance with our legal obligations (and we set this out in our written policies).

On rare occasions we may ask for your explicit (written) consent to use certain special categories of data. If we do this, we will make sure you have a detailed explanation of the data we need and why. This will enable you to make an informed decision whether you wish to consent.

Marketing

We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. We will always give you options to determine how we use your personal data in this regard.

Promotional Offers From Us

You will receive marketing communications from us if you have requested information from us or purchased products or services from us or if you provided us with your details when you filled out a survey or feedback form and, in each case, you have not opted out of receiving that marketing.

Opting Out

You can ask us to stop sending you marketing messages at any time by following the opt-out / unsubscribe links on any marketing message sent to you at any time or by contacting our Privacy team at: compliance@guscanada.ca

Where you opt out of receiving these marketing messages, this will not stop us storing your data provided to us as a result of a applying for a course or programme or buying some other service or materials from us.

Cookies

You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly. For more information about the cookies we use, please read below.

We Use “Cookies” On This Site.

A cookie is a piece of data stored on a site visitor’s hard drive to help us improve your access to our site and identify repeat visitors to our site. For instance, when we use a cookie to identify you, you would not have to log in a password more than once, thereby saving time while on our site. Cookies can also enable us to track and target the interests of our users to enhance the experience on our site. Usage of a cookie is in no way linked to any personally identifiable information on our site.

Third party vendors, including Google may use cookies to serve ads based on a user’s prior visits to Ontario Institute of Health and Innovation website. Users may opt out of Google’s use of cookies by visiting the Google advertising opt-out page.

Change Of Purpose

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact our DPO.

If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

7. Disclosures Of Your Personal Data

We may have to share your personal data with the parties set out below for the purposes set out in the table in paragraph 4 above.

  • Internal Third Parties as set out in the Glossary.
  • External Third Parties as set out in the Glossary.
  • Third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this privacy notice.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

8. International Transfers

We share your personal data within the GUS Group of which Ontario Institute of Health and Innovation is a part of. This will involve transferring your data outside Canada.

Some of our external third parties are based outside Canada so their processing of your personal data will involve a transfer of data outside Canada.

Whenever we transfer your personal data out of Canada, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  • We will only transfer your personal data to countries by following the guidelines set by the Privacy Commissioner of Canada (OPC) on the Personal Information Protection and Electronic Documents Act (PIPEDA) that have been deemed to provide an adequate level of protection for personal data by the European Commission. For further details, see Guidelines for Processing personal data across borders available at: https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/
  • You have explicitly consented to the proposed transfer, after having been informed of the possible risks of such transfers for you due to the absence of an adequacy decision and appropriate safeguards.
  • The transfer is necessary for the performance of a contract between you and us as the data controller or for the implementation of pre-contractual measures taken at your request.
  • The transfer is necessary for the conclusion or performance of a contract concluded in your interests between us as the data controller and another natural or legal person.
  • The transfer is necessary for important reasons of public interest.
  • The transfer is necessary for the establishment, exercise or defence of legal claims.
  • The transfer is necessary in order to protect your vital interests or the vital interests of other persons, where you are physically or legally incapable of giving consent.

Please contact our DPO if you want further information on the specific mechanism used by us when transferring your personal data

9. Data Security

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

10. Data Retention

How long will you use my personal data for?

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

In some circumstances you can ask us to delete your data: Email our DPO at compliance@guscanada.ca for more information.

In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.

11. Your Legal Rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data. Please click on the links below to find out more about these rights:

  • Request Access To Your Personal Data.
    • You have the right to access your personal data (known as an “access request”). This enables you to receive a copy of the personal data we hold about you and check that we are lawfully processing it.
    • To Make A Request: If you wish to make a request for access to your information, please contact us at 124 Eglinton Ave West, (4th floor), Toronto, ON, M4R 2G8, Canada or by email at compliance@guscanada.ca
    • What We May Need From You: We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response to provide you with your information promptly.
  • Request Correction Of Your Personal Data

This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

  • Request Erasure Of Your Personal Data

This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.

  • Object To Processing Of Your Personal Data

You may raise an objection to the processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.

  • Request Restriction Of Processing Your Personal Data

You may request to restrict our processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data’s accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

  • Request The Transfer Of Your Personal Data

You may exercise your right to transfer your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

  • Right To Withdraw Consent

This applies only where we rely on your consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain services to you. We will advise you if this is the case at the time you withdraw your consent.

In certain circumstances, you can exercise your right to prevent such processing by checking certain boxes on the forms we use to collect your data. You can also contact us at compliance@guscanada.ca  if you wish to exercise your rights.

If You Wish To Exercise Any Of The Rights Set Out Above, Please Contact Our Dpo.

Many of the online site(s) and service(s) we provide allow you to manage your personal information. Should you need further assistance, please contact Ontario Institute of Health and Innovation’s Privacy Officer, Jessie Atkins, at compliance@guscanada.ca 

12. Glossary

Lawful Basis

Legitimate Interest means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting our DPO.

Performance of Contract means processing your data where it is necessary for the performance of a contract to which you are a party or to take preliminary pre-contractual steps at your request before entering into such a contract.

Comply with a legal or regulatory obligation means processing your personal data where it is necessary for compliance with a legal or regulatory obligation that we are subject to.

Third Parties

Internal Third Parties

Other companies in the GUS Group acting as joint controllers or processors and who are based throughout the world and provide shared services such as IT, legal services, system administration services and leadership reporting.

External Third Parties
  • Service providers acting as processors based outside Canada that provides, i provide IT, marketing and system administration services.
  • Professional advisers acting as processors or joint controllers including lawyers, bankers, auditors and insurers based throughout the world who provide consultancy, banking, legal, insurance and accounting services.
  •  Canada Revenue Agency, The Government of Ontario, regulators and other authorities acting as processors or joint controllers based in the United Kingdom and other countries who require reporting of processing activities in certain circumstances.
  • Employers who request a reference from Ontario Institute of Health and Innovation
  • External Examiners for examination, assessment and moderation purposes
  • Awarding body partners – in order to process the administration of student enrolment onto programmes
  • Professional/Funding bodies, Student Loans company
  • Marketing service providers
  • Other universities, employers, prospective employers, providers of supervised trainings contracts or pupillages