Privacy Policy — My La Vie (HealthPass)

Last updated: 2026/07/18

What this app is. My La Vie (HealthPass) is an identity & access management (single sign-on) client. You use it to sign in, verify your identity (multi-factor authentication), and authorize access to applications provided by your organization. Despite the "HealthPass" name, this app does not collect, store, or process any health, medical, fitness, or clinical data.

This Privacy Policy explains how La Vie Health ("La Vie", "we", "us", "our") collects, uses, and protects information when you use the My La Vie (HealthPass) mobile application (the "App", package com.mylavie.sso). In many cases we act as a data processor on behalf of the organization that provided you with an account (the "data controller"); where we determine the purposes of processing ourselves, we act as the controller.

1. Information we collect

1.1 Account & identity information

To create and authenticate your session we process the credentials and identifiers you or your organization provide: email address, username, password, display name, and your user identifier. If you sign in with Google, we receive your Google account's email address and basic profile (requested scopes: email, profile) in the form of a Google ID token, which we send to our backend to establish your session.

1.2 Authentication & security data

We process session tokens (access and refresh tokens) needed to keep you signed in; these are held in the device's secure storage. If you enable multi-factor authentication, we process time-based one-time-passcode (TOTP) setup data and/or passkey (FIDO2/WebAuthn) public-key credentials. Biometric data (fingerprint/face) never leaves your device — it is handled entirely by your device's operating system; we only receive a cryptographic assertion, not your biometrics.

1.3 Device & connection information

When you sign in, the App resolves your device's public IP address (via the third-party echo service api.ipify.org) and sends it to our backend so that your sign-in is recorded accurately in our security logs. If push notifications are enabled, we process a device push token (Firebase Cloud Messaging) to deliver notifications to your device.

1.4 Diagnostics & usage data

In production builds we may collect crash reports, error diagnostics, and basic app usage events (for example, which screens were viewed, the app version, a session identifier, and your user identifier) through Microsoft Azure Application Insights, to keep the App reliable and secure. We do not use this data for advertising.

We do not collect your contacts, photos, precise GPS location, SMS, call logs, or any health/medical data. We do not sell your personal data, and we do not use it for third-party advertising or cross-app tracking.

2. How we use your information

3. Legal bases for processing

Where applicable law (such as Canada's PIPEDA, or the EU/UK GDPR) requires a legal basis, we rely on: performance of a contract (providing the sign-in service you requested), legitimate interests (securing accounts and the service), consent (for example, optional notifications), and compliance with legal obligations.

4. How we share information

We share personal data only as needed to operate the service:

RecipientPurposeData involved
Your organization (the account provider)Identity & access management on whose behalf we process your dataAccount, authentication, and sign-in activity
Google (Google Sign-In)Optional federated loginGoogle email & profile / ID token
Microsoft Azure (hosting & Application Insights)Backend hosting and diagnosticsRequests, crash/usage diagnostics
Google Firebase Cloud MessagingPush notification deliveryDevice push token
ipify (api.ipify.org)Resolving your public IP for sign-in logsYour public IP address

We may also disclose data where required by law, to protect our rights, or in connection with a corporate transaction. We do not sell your personal data.

5. International data transfers

Your data may be processed in countries other than your own. Where we transfer data internationally, we use appropriate safeguards as required by applicable law.

6. Data retention

We retain personal data for as long as your account is active and as needed to provide the service, then for the period required to meet legal, security, and audit obligations, after which it is deleted or anonymized. Retention of account data is primarily governed by your organization's policies.

7. Security

We use technical and organizational measures to protect your data, including encryption in transit (HTTPS), secure on-device storage of session tokens, and multi-factor authentication. No method of transmission or storage is completely secure, but we work to protect your information and continually improve our safeguards.

8. Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict the processing of your personal data, to object to processing, and to data portability. Many of these requests are handled by your organization as the account provider. To exercise your rights or ask questions, contact us at devapps@laviehealth.com (or your organization's administrator). You may also have the right to lodge a complaint with your local data protection authority.

9. Children's privacy

The App is an enterprise identity tool and is not directed to children. We do not knowingly collect personal data from children.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, through the App or by your organization.

11. Contact us

La Vie Health
100 Queen St., Suite 940 Ottawa, Ontario K1P 1J9
Email: devapps@laviehealth.com
Governing jurisdiction: the Province of Ontario, Canada