Policies

Our policies outline the standards and procedures governing the operation of our cosmetic clinic. These policies complement your consumer rights and ensure a professional experience.

Communication Policy

Last updated: August 31, 2026

Read our communication policy to find more about how we communicate with our clients, social media followers, website visitors, and email subscribers.

At IVONNE, Inc. ("IVONNE"), clear and secure communication is essential. This policy explains how we contact you, how you can reach us, how marketing consent works, and the rules that keep our communications safe. In short: we only message people who have asked to hear from us, you can opt out at any time, and we honour that promptly.

Application of this policy

This policy applies whenever you send or receive communication with IVONNE through any digital or electronic channel. This includes, but is not limited to:

  • Email
  • Text and instant messaging — including SMS/MMS and any instant-messaging or chat application (for example, but not limited to, WhatsApp, Facebook Messenger, iMessage, or similar services)
  • Social media — including direct messages, comments, and mentions on any platform
  • Voice — including telephone calls and voicemail
  • Our client portal and website — including our chatbot and any web form
  • Any other electronic or digital channel we may use now or in the future

Where a section of this policy refers to one channel, the same principles apply to the others unless we say otherwise.

1. How We Contact You

Genuine IVONNE email is sent only from these domains:

  • bounces.ivonne.ca
  • e.ivonne.ca
  • ivonne.ca
  • ivonneclinic.ca

We also use our scheduling system (8270934076aa212755f6a4 and 40509548436aa212755f6e3), prescription updates from alumiermd.com, our landline at (613) 695-6662, SMS, social media (@ivonneclinic), and our website chatbot.

We will never email you from a free account like Gmail or Outlook.com, and our staff won't use personal accounts to do business. If you get a message claiming to be from us from any other address, don't click anything — call us at (613) 695-6662.

This verification — and everything in this policy — applies across all our channels: email, SMS, portal, social media, voice, and chatbot.

2. How To Reach Us

For anything about your communications with us:

  • General: 30482650126aa212755f710 · (613) 695-6662
  • Legal notices: 17085726816aa212755f948 (and also by regular mail — see below)
  • Report a suspicious message: (613) 695-6662

Critical or legal communication should never rely on email alone — please also send it by regular mail to the address at the bottom of this policy.

3. Response Times

We aim to respond within 48 business hours, though busy periods can take longer. An automated "we received your message" reply only confirms delivery — it isn't an answer. For anything urgent, call (613) 695-6662.

Your Email Address and Your Account

Your email provider — the company that runs your mailbox, such as Google (Gmail), Microsoft (Outlook, Hotmail, Live), Yahoo, Apple (iCloud) or your internet company — decides how addresses at its domain are read. A few providers treat certain variations of an address as the same mailbox, and most do not.

Google is the clearest example. Gmail and Googlemail ignore dots before the @ and deliver anything after a + sign to the same inbox, so 22348732016aa212755f993, 30428696736aa212755f9c1 and 20591546436aa212755f9f1 are one mailbox belonging to one person.

Where a provider works this way, we follow its rule and treat those forms as one account: you receive one copy of a mailing rather than several, and unsubscribing with any version of your address opts you out for all of them. These are the providers we currently do this for:

  • fastmail.com — anything after a + sign goes to the same inbox
  • gmail.com — dots in the address are ignored; anything after a + sign goes to the same inbox
  • googlemail.com — dots in the address are ignored; anything after a + sign goes to the same inbox
  • pm.me — anything after a + sign goes to the same inbox
  • proton.me — anything after a + sign goes to the same inbox
  • protonmail.com — anything after a + sign goes to the same inbox
  • telus.net — anything after a + sign goes to the same inbox

Most providers do not work this way. Microsoft states that adding a dot makes it a completely different address, and Yahoo treats dots as meaningful too. At a workplace or custom domain, two addresses differing only by a dot can belong to two different people. For anything not in the list above, we treat each address as its own. If you are unsure how your provider handles dots or + addressing, check its help pages rather than assuming two forms of your address reach the same place.

Contact Details You Alone Control

The email address and mobile number you give us are not only how we reach you. They identify you in our records and are used to verify your identity when you sign in to your client portal, and when you access any account you hold with us or with a third party we work with on your behalf, including product accounts such as AlumierMD. A one-time code sent to your email address or mobile number is sufficient to obtain access.

You must therefore give us contact details that you alone control. By providing an email address or mobile number, you confirm that you are the only person with access to it, and that it is not shared with a spouse, partner, family member, employer or anyone else. This applies when you communicate with us, when you book or attend an appointment, when you sign in to your portal or a linked third-party account, and when you receive results, records, invoices or product information.

We rely on this confirmation. Where you supply contact details that others can access, personal health information may be disclosed to those persons, and they may be able to obtain access to your account. Disclosure arising in these circumstances occurs with your knowledge and consent. Under Ontario’s Personal Health Information Protection Act, 2004 (PHIPA) we take reasonable steps to protect your information against unauthorized access; we cannot control who else can open a mailbox or read messages on a device that is not exclusively yours.

If your contact details stop being exclusively yours, or you lose access to them, please tell us promptly so we can update your record and re-secure your account. You may update your details at any time through your client portal or by contacting 30482650126aa212755f710. If you are unable to provide contact details that only you can access, tell us and we will discuss alternatives, including communicating with you by mail or in person.

If you would like us to send appointment notices or other information to another person, such as a caregiver, family member or assistant, we will record that person separately as a notification contact with your express consent. That consent is limited to the information you specify, may be withdrawn at any time, and does not give that person access to your portal, your record or your account.

Nothing in this section limits your rights under PHIPA or the Personal Information Protection and Electronic Documents Act (PIPEDA), or our obligations under them.

Why this matters to you: your visit history, rewards, gift cards and account credits are attached to your client profile. If a visit or purchase is made under an address we cannot connect to that profile, the activity can land somewhere else and may not appear where you expect. Using the same address every time keeps it together.

Please use your own address, not one shared with someone else. If a couple or a family shares one email, our records cannot reliably tell who is who, and appointments, reminders, rewards and health information may be attributed to the wrong person. Each person should have their own address. If you would like someone else to receive appointment notices for you, tell us and we will add them as a notification contact instead.

If the address on your file looks wrong, or you think your visits are split across two profiles, email 30482650126aa212755f710 and we will correct it.

We follow Canada's Anti-Spam Legislation (CASL). We only send marketing to people who have given consent or are active clients, every marketing message has a clear opt-out, and we honour opt-out requests promptly.

Marketing may reach you by email, SMS, or phone/voicemail. To opt out of any or all of it, use the unsubscribe link in any marketing message or email 30482650126aa212755f710. Opting out applies across the relevant channels — email, SMS, and voice — not just the one you contacted us through. We keep your contact details on file only as needed to honour your request. We refresh marketing lists every 30–90 days on a best-effort basis, so on rare occasions you may need to opt out again.

One tip: when you fill out a form or get a confirmation email, please click the "confirm your email" link — that's what ensures our messages reach you, and to keep them out of spam you can whitelist our domain. We may also adjust or pause a subscription where needed for compliance or technical reasons.

5. Acceptable Use

Our phone, voicemail, text, email, chatbot, and messaging channels are for our clients, prospective clients, and approved suppliers. Please don't:

  • contact us using details from a purchased or third-party list;
  • send phishing, malware, fraudulent, or other unlawful messages;
  • send AI-generated messages without checking them for accuracy — we may disregard communications that are spammy or inauthentic;
  • contact us from disposable or temporary email services (throwaway addresses designed to expire);
  • contact us from email masking or relay services that hide your real address (for example Apple Private Relay, DuckDuckGo Email, or Firefox Relay). We need a stable address that reliably reaches you — relayed addresses are automatically declined;
  • contact us from a temporary student or institutional email address (for example, Canadian college, university, or other school-issued addresses). These accounts expire when you leave the institution and can't reach you over the long term — please use a permanent personal address instead. (If you're already a client using one of these, we'll keep your address on file.)

For security, we may limit or decline communication from business or organizational domains whose ownership we cannot publicly verify — for example, a corporate domain with private/redacted WHOIS registration. We rely on public registration details to confirm who you are; if a business hides them, we have no reliable way to establish that, so we may decline until ownership is verified. (This does not apply to ordinary personal freemail accounts.) We can lift any such restriction on a case-by-case basis once ownership is confirmed.

If you're not yet in our systems. Our email systems accept messages only from recognized senders — active clients, prospective clients, and approved suppliers — to keep client information secure and our inboxes free of spam. If you're trying to reach us and you're not one of those, here's how:

  • Existing clients: the best way to reach us is through your private client portal at clinic.ivonne.ca, created just for you — your messages reach us securely and are tied to your record.
  • To become a client, please apply at ivonne.ca/apply. Once you're enrolled, your address is recognized automatically.
  • Vendors, suppliers, and partners should pre-register through our Sell to IVONNE page rather than emailing us directly.
  • For legal, privacy, or regulatory matters, messages from recognized legal, government, and regulatory senders are accepted. If a message doesn't reach us, you can also write to us at our mailing address (below).

Messages from unrecognized senders may be automatically declined and returned undelivered. This isn't personal — it's how we protect our clients' information.

6. Attachments

Keep attachments and total message size under 20 MB. For security we automatically block executable and archive files (e.g. .exe, .bat, .cmd, .zip) and encrypted Office documents. If a file is blocked, call us and we'll arrange another way to receive it.

7. Security & Suspicious Messages

We protect our communications with measures such as two-factor authentication, encryption, and SPF, DKIM, DMARC and DNSSEC on our domain. Even so, bad actors can spoof or imitate us, and we can't take responsibility for messages we didn't actually send.

If something looks suspicious — or if a message to us bounces — don't click any links; call us at (613) 695-6662 or report it using the contact details below.

An email arriving from our domain isn't automatically an official message; personal correspondence should be sent from a personal account. When you write from a government, NGO, or business address, we'll treat it as official unless you say otherwise — so please tell us the nature of your message.

8. Disclaimer & Changes

Email and digital communication are provided on a best-effort, as-is basis with no guarantee of delivery or availability. We can't take responsibility for lost, misdelivered, corrupted, spoofed, or malicious communication, and an email from our domain isn't necessarily an official message. All communication is also subject to our Terms and Conditions and Privacy Policy at www.ivonne.ca.

By contacting us — by email, form, booking, phone, paper, or in person — you agree to these policies; if you don't, please don't send us your personal information. We may update this policy at any time without notice, so please check back periodically.

Contact Information About This Policy

For any questions or complaints in relation to this agreement or any product or treatment you purchase, you may contact IVONNE at the following:

By Regular Mail:
IVONNE, Inc.
0116-320 Queen Street, Ottawa ON K1R 5A3

By Email:
17085726816aa212755f948

By Phone:
(613) 695-6662

By Social Media:
@ivonneclinic

Updates

  • June 27, 2025 Added notice requiring clients and suppliers to notify us in advance of email or domain name changes.
  • August 7, 2025 Updated section "Email Communication Limitations with Specific Domains" to incluce all student webmail domains.
  • June 5, 2026 Major plain-language rewrite (24 sections to 9). Added an up-front "Application of this policy" scope section covering all channels. Sender-domain list is now generated automatically from live DNS. Consolidated intake guidance for people not yet in our systems (client portal, apply page, supplier pre-registration, legal/regulatory senders). Acceptable-use rules now explicitly decline disposable/temporary addresses, email masking/relay services, and temporary student/institutional addresses, and clarify that we decline business domains with private/redacted WHOIS we cannot verify. Removed dated, rotting operational detail (verbatim bounce text, named-vendor block list, hardcoded blocked-domain list) and duplicative/promotional sections. No client rights or CASL protections reduced.
  • August 30, 2026: Added an explanation of how your email address is matched to your account, including which providers treat different forms of an address as one mailbox, and why using your own address keeps your visits and rewards together.
  • August 30, 2026: Added a section explaining that the email address and mobile number on your file are used to verify your identity, and asking that you give us contact details only you can access.

Notice an error, inconsistency, or legal concern with this policy? Active clients can report it via their client portal.

Back to Policies