Last updated: 2026/07/18
This Privacy Policy explains how La Vie Health
("La Vie", "we", "us", "our") collects, uses, and
protects information when you use the My La Vie (HealthPass) mobile application (the
"App", package com.mylavie.sso). In many cases we act as a
data processor on behalf of the organization that provided you with an
account (the "data controller"); where we determine the purposes of processing ourselves,
we act as the controller.
To create and authenticate your session we process the credentials and identifiers you or
your organization provide: email address, username, password, display name, and your
user identifier. If you sign in with Google, we receive your Google account's
email address and basic profile (requested scopes: email,
profile) in the form of a Google ID token, which we send to our backend to
establish your session.
We process session tokens (access and refresh tokens) needed to keep you signed in; these are held in the device's secure storage. If you enable multi-factor authentication, we process time-based one-time-passcode (TOTP) setup data and/or passkey (FIDO2/WebAuthn) public-key credentials. Biometric data (fingerprint/face) never leaves your device — it is handled entirely by your device's operating system; we only receive a cryptographic assertion, not your biometrics.
When you sign in, the App resolves your device's public IP address (via the
third-party echo service api.ipify.org) and sends it to our backend so that your
sign-in is recorded accurately in our security logs. If push notifications are enabled, we
process a device push token (Firebase Cloud Messaging) to deliver
notifications to your device.
In production builds we may collect crash reports, error diagnostics, and basic app usage events (for example, which screens were viewed, the app version, a session identifier, and your user identifier) through Microsoft Azure Application Insights, to keep the App reliable and secure. We do not use this data for advertising.
Where applicable law (such as Canada's PIPEDA, or the EU/UK GDPR) requires a legal basis, we rely on: performance of a contract (providing the sign-in service you requested), legitimate interests (securing accounts and the service), consent (for example, optional notifications), and compliance with legal obligations.
We share personal data only as needed to operate the service:
| Recipient | Purpose | Data involved |
|---|---|---|
| Your organization (the account provider) | Identity & access management on whose behalf we process your data | Account, authentication, and sign-in activity |
| Google (Google Sign-In) | Optional federated login | Google email & profile / ID token |
| Microsoft Azure (hosting & Application Insights) | Backend hosting and diagnostics | Requests, crash/usage diagnostics |
| Google Firebase Cloud Messaging | Push notification delivery | Device push token |
ipify (api.ipify.org) | Resolving your public IP for sign-in logs | Your public IP address |
We may also disclose data where required by law, to protect our rights, or in connection with a corporate transaction. We do not sell your personal data.
Your data may be processed in countries other than your own. Where we transfer data internationally, we use appropriate safeguards as required by applicable law.
We retain personal data for as long as your account is active and as needed to provide the service, then for the period required to meet legal, security, and audit obligations, after which it is deleted or anonymized. Retention of account data is primarily governed by your organization's policies.
We use technical and organizational measures to protect your data, including encryption in transit (HTTPS), secure on-device storage of session tokens, and multi-factor authentication. No method of transmission or storage is completely secure, but we work to protect your information and continually improve our safeguards.
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict the processing of your personal data, to object to processing, and to data portability. Many of these requests are handled by your organization as the account provider. To exercise your rights or ask questions, contact us at devapps@laviehealth.com (or your organization's administrator). You may also have the right to lodge a complaint with your local data protection authority.
The App is an enterprise identity tool and is not directed to children. We do not knowingly collect personal data from children.
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, through the App or by your organization.
La Vie Health
100 Queen St., Suite 940 Ottawa, Ontario K1P 1J9
Email: devapps@laviehealth.com
Governing jurisdiction: the Province of Ontario, Canada