Your data is protected.
We have implemented security measures to ensure your personal information is used responsibly and ethically. Through strict access controls, we guarantee the confidentiality and integrity of your data.
Security Measures & Data Management.
Biotonix is committed to strict cybersecurity and data privacy, fully complying with Quebec’s Law 25 under VP of Technology Sébastien Lacoste. In partnership with Solulan, a SOC 2 certified expert, we leverage advanced DLP, backup, and Microsoft security solutions to protect your data.
Secure Canadian Hosting
Sensitive data from Biotonix applications is stored securely in Microsoft Azure on servers located entirely in Canada, benefiting from the platform’s advanced enterprise protections.
Strict Access Controls
We apply a strict “principle of least privilege,” ensuring our employees only have access to the data necessary for their specific tasks. Multi-factor authentication (MFA) is mandatory across our systems to prevent unauthorized access.
User Ownership & Control
You own your data. Users can permanently delete their personal information at any time directly through the mobile app, or by submitting a written request to our Data Protection Officer.
Responsible Data Retention
- Active Users: Data is kept as long as your account remains active.
- Inactive Users: Data is securely deleted after 24 months of inactivity (unless retention is legally required).
- Transactional Data: Invoices and payment histories are kept for a minimum of 7 years for regulatory and audit compliance.
- Anonymized Data: Certain data may be retained in a fully anonymized format for statistical analysis and service improvement, ensuring user identification is impossible.
Guided by Transparency and Ethics.
Our approach to data security relies on a strong, proactive commitment to our users. We build our protocols on these core pillars.
our rights are at the center of our concerns. We maintain a transparent and honest relationship with data owners, ensuring confidentiality at all times.
Continuous Staff Training
We continuously train and support our team to guarantee a consistent, secure, and informed management of all personal data.
Proactive Accountability
In the unlikely event of a security breach, we are committed to transparency, including voluntary notification to the Commission d’accès à l’information (CAI) and prompt communication with affected users.