---
title: "Website Privacy Policy | GICMD"
brand_name: "GICMD"
brand_id: "gicmd"
locale: "en"
source: "node"
archetype: "legal"
html_route: "/privacy-policy/"
markdown_route: "/privacy-policy.md"
canonical_url: "https://gicmd.com/privacy-policy/"
markdown_url: "https://gicmd.com/privacy-policy.md"
robots: "index, nofollow"
updated_at: "2026-09-08T03:24:06.673Z"
---

# Website Privacy Policy | GICMD

GICMD privacy policy for quote requests, forms, website analytics, cookies, service inquiries, and privacy rights.

## Page Context

- Brand: GICMD
- Locale: en
- Canonical HTML: https://gicmd.com/privacy-policy/
- Markdown URL: https://gicmd.com/privacy-policy.md

Effective date: June 16, 2026

## Who we are
gicmd.com is operated for GIC Medical Disposal by Greenflow Environmental Services Inc., doing business as Greenflow, GIC Medical Disposal, and GIC-GREEN for Canadian operations, and by GIC-GREEN Inc. for U.S. operations. In this Privacy Policy, "we", "us", and "our" refer to those operating entities and the applicable brand site you are using.
You can contact us at info@gic-green.com, 1-877-244-8828, or 250 University Ave, 2nd Floor, Toronto, ON M5H 3E5.

## What this policy covers
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit gicmd.com, request a quote, submit a form, use visitor analytics or contact tools, communicate with us by email or phone, interact with our marketing, or otherwise provide information related to medical, biomedical, sharps, pharmaceutical, and healthcare waste services.
This policy applies to website and inquiry activity. Our Cookie Policy at /cookie-policy gives more detail about cookies, pixels, browser storage, visitor capture, analytics, advertising tools, and similar technologies. Separate customer portals, payment processors, third-party websites, and signed service agreements may have their own terms or privacy notices.

## Scope and legal limits
This Privacy Policy is intended to satisfy notice requirements that may apply in Canada, Ontario, Quebec, California, Florida, and other U.S. jurisdictions where we operate or receive inquiries. It applies only to personal information, personal data, personal health information, or similar information as those terms are defined by applicable law.
Nothing in this policy limits rights that cannot be waived under applicable law. To the fullest extent permitted by law, this policy does not create contractual rights, fiduciary duties, warranties, or obligations beyond those required by applicable law and our signed agreements.
If a signed customer, vendor, business associate, data processing, or service agreement applies to a specific relationship or data set, that agreement controls to the extent it is more specific or legally required.

## Personal information we collect
We collect only the information reasonably needed for the purposes described in this policy.
- Contact details, such as name, email address, phone number, mailing address, company name, job title, and preferred contact method.
- Service request details, such as waste stream, facility type, location, pickup timing, container needs, site count, documents requested, and notes you choose to provide.
- Account, billing, and transaction details when needed to quote, coordinate, invoice, process payment, or support a customer relationship.
- Communications, including emails, form submissions, call notes, chat messages, support requests, and feedback.
- Website, device, and visitor analytics information, such as IP address, browser type, device type, operating system, pages viewed, route changes, links or buttons clicked, referral source, landing page, campaign parameters, advertising click identifiers, session duration, time on page, scroll depth, approximate location, language preferences, browser privacy signals, performance data, and cookie or tracking identifiers.
- Form interaction information, such as form start and submit events, field names, touched fields, submitted form fields, page history before submission, and related visitor or session identifiers.
- Marketing preference information, including consent records, unsubscribe requests, campaign engagement, and lead source.
- Applicant or recruiting information if you contact us about a role or submit career-related information.

## Sensitive information and health information
Do not submit patient names, patient files, diagnosis information, medical record numbers, health insurance information, government identifiers, payment card numbers, account credentials, passwords, security codes, or other sensitive personal information through public website forms unless we specifically request it through an approved channel.
Public website forms are not approved channels for protected health information, personal health information, payment card data, or regulated medical records. If you submit this type of information anyway, you represent that you have all rights, authority, consents, and notices required to provide it to us, and we may delete, quarantine, restrict, or process it only as needed to protect the company, route the request, comply with law, or preserve legal rights.
When we receive regulated health or medical information under a signed customer agreement, business associate agreement, data processing agreement, or other approved channel, that agreement and applicable health privacy law control.

## How we collect information
We collect information directly from you when you submit forms, request a quote, call, email, use contact tools, subscribe, interact with social media integrations, use a client portal link, or otherwise communicate with us.
We also collect some information automatically through cookies, browser storage, first-party visitor and form capture scripts, analytics tools, advertising tools, security tools, server logs, and similar technologies when you use the site.

## Website visitor capture and lead attribution
We use first-party visitor and form capture tools to understand site activity, improve pages, attribute inquiries, reduce spam, troubleshoot forms, and connect a submitted quote or contact request with the pages and events that led to it.
These tools may create a persistent visitor identifier in local browser storage and a session identifier in session storage. They may collect page views, route changes, referrers, landing pages, campaign parameters, advertising click identifiers, click interactions, form start and submit metadata, field names, touched fields, page history, scroll depth, active time, browser and device signals, performance signals, and browser privacy preference signals.
When you submit a form, we may add visitor, session, landing page, referrer, and attribution fields to the submission so our team can understand the inquiry context and route the request appropriately. Our public website capture tools are configured not to intentionally collect password, payment card, SSN/SIN, captcha, token, or similar sensitive security fields.
If Microsoft Clarity or a similar session analytics tool is active on the site, we may send visitor, session, page, and event identifiers to that tool to correlate website activity and improve site performance and conversion paths.
We do not use website visitor capture to make decisions that produce legal or similarly significant effects about a person. If that changes, we will provide any notice, consent, or opt-out rights required by applicable law.

## How we use personal information
We use personal information for business and operational purposes, including to:
- respond to quote requests, service inquiries, support questions, and account communications;
- assess service fit, plan pickups, coordinate documentation, and support regulated waste service workflows;
- create, manage, and maintain customer, lead, billing, service, and communication records;
- process payments, invoices, account requests, and related administrative activity;
- send service, transactional, operational, and permitted marketing communications;
- personalize and improve website content, user experience, routing, and conversion paths;
- measure website performance, advertising effectiveness, search visibility, and campaign performance;
- attribute leads, detect duplicate or suspicious submissions, prevent spam, and maintain CRM, sales, and support context;
- protect our websites, systems, customers, employees, rights, and property;
- comply with legal, regulatory, accounting, tax, contractual, and audit obligations;
- establish, exercise, investigate, or defend legal rights, claims, disputes, audits, or enforcement matters;
- evaluate or complete a merger, sale, financing, restructuring, or similar business transaction.

## Marketing communications
Where required, we send commercial electronic messages only with consent or another lawful basis. Marketing emails or texts that we control will identify the sender and include an unsubscribe mechanism or other opt-out instructions.
You can also ask us to stop using your information for marketing by contacting info@gic-green.com. We may keep suppression records to honor opt-outs and may still send transactional, service, safety, legal, or account-related messages where permitted.

## Cookies and similar technologies
We use cookies, local storage, session storage, and similar technologies to operate the site, remember preferences, maintain visitor and session identifiers, understand traffic and performance, improve content, support security, and measure marketing activity.
The site may use functional cookies, analytics cookies, performance cookies, security cookies, advertising or targeting cookies, customization cookies, session cookies, persistent cookies, third-party cookies, and browser storage. You can control cookies through your browser settings, but blocking cookies or storage may affect site functionality and attribution.
Some browsers offer privacy preference signals such as Do Not Track or Global Privacy Control. Where legally required and technically feasible, we use valid opt-out preference signals to limit or opt you out of applicable sale, sharing, targeted advertising, soft identity, or enrichment uses. Operational first-party analytics, security, service, and request-handling activity may still be processed where permitted by law. Third-party tools may also provide their own privacy controls.
For more detail, see our Cookie Policy at /cookie-policy.

## Privacy choices and opt-outs
You may use our Privacy Choices page at /privacy-choices, email smicanovic@gic-green.com, or email info@gic-green.com to request marketing opt-out, cookie or tracking preference assistance, or an opt-out from sale, sharing, targeted advertising, soft identity, or enrichment uses where those rights apply.
If your browser sends a valid Global Privacy Control signal, we treat it as an opt-out of sale or sharing where required by law. Browser-based opt-outs may apply only to the browser, device, and site where the signal is received. If we cannot reasonably connect an opt-out request to your browser, visitor identifier, email address, or other record, we may ask for the information reasonably needed to process the request.
Opt-outs do not prevent all processing. We may continue processing personal information for security, fraud prevention, debugging, request handling, service delivery, legal compliance, internal operations, signed agreements, and other purposes permitted by law.

## When we disclose information
We do not sell personal information in exchange for money. Some privacy laws define "sale", "sharing", or "targeted advertising" broadly enough to include certain advertising, analytics, or cross-context tracking activities. If we use tools in a way that is considered a sale, sharing, or targeted advertising under applicable law, we will provide required opt-out rights and honor required opt-out preference signals.
We may disclose personal information when reasonably necessary for the purposes described in this policy, including to:
- employees, contractors, affiliates, and service teams that need the information to do their work;
- payment processors, banks, billing providers, and accounting providers;
- CRM, cloud hosting, email, communications, chat, analytics, advertising, security, enrichment, and customer support providers;
- operations, logistics, disposal, documentation, compliance, and service partners where needed to evaluate or deliver requested services;
- professional advisers, insurers, auditors, regulators, courts, law enforcement, or other parties where required or permitted by law;
- buyers, investors, lenders, or advisers in connection with a proposed or completed business transaction.
Service providers, processors, contractors, and partners are expected to access personal information only as needed for their role and to protect it appropriately. We may require contractual limits where required by law, but we are not responsible for independent third-party services that you choose to use or access outside our control.

## Retention
We keep personal information only as long as reasonably necessary for the purposes described in this policy, including to manage inquiries, provide services, maintain customer and business records, satisfy legal and accounting obligations, resolve disputes, enforce agreements, and support security or audit requirements.
Retention periods vary depending on the type of information, the nature of the relationship, operational needs, and legal or regulatory requirements. For first-party visitor analytics, raw event records are generally retained for a shorter period than lead or customer records, page and session summaries may be retained for analytics and attribution, and linked lead history may be retained with the related inquiry or customer record.
We may retain information for longer where reasonably necessary to comply with law, preserve evidence, prevent fraud or abuse, resolve disputes, enforce agreements, maintain suppression lists, complete audits, support business continuity, or protect our legal rights.

## Security
We use administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, disclosure, or destruction. These safeguards may include secure transmission, access controls, account controls, vendor controls, monitoring, backup practices, and internal confidentiality requirements.
No website, network, or storage system is completely secure. We cannot guarantee absolute security, but we work to protect information using safeguards appropriate to the sensitivity and context of the information.
If we determine that a security or confidentiality incident requires notice under applicable law, we will provide notice as required. Not every security event is a legally reportable breach.

## Your choices and rights
Depending on where you live and the laws that apply, you may have rights to request access to or confirmation of personal information, correction of inaccurate information, deletion, portability, withdrawal of consent, restriction or objection to certain processing, information about disclosures, or opt-out of marketing, sale, sharing, targeted advertising, profiling, sensitive information processing, or certain automated uses.
Canadian residents may have rights under PIPEDA, Quebec private-sector privacy law, Ontario health privacy law where applicable, and other provincial privacy laws. Quebec residents may also have rights to information about collection, use, disclosure, retention, access, rectification, complaint handling, and the person responsible for personal information.
California residents may have rights under the CCPA as amended, including rights to know, access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, use an authorized agent, and be free from unlawful discrimination. This policy is intended to serve as a notice at collection where applicable.
Florida residents and residents of other U.S. states may have rights where state privacy laws apply, including rights to access, correct, delete, obtain a copy, opt out of sale, targeted advertising, or profiling that produces legal or similarly significant effects, and appeal certain decisions.
To make a privacy request, contact our Privacy Officer at smicanovic@gic-green.com or info@gic-green.com. We may need to verify your identity, authority, jurisdiction, relationship with us, or the record involved before responding. We will respond within the time required by applicable law.
We may deny, limit, or delay a request where permitted by law, including where we cannot verify the request, the request is excessive or abusive, the information is privileged or confidential to another person, the information is needed for legal compliance or claims, deletion would impair security or fraud prevention, retention is required by law or contract, the information is deidentified or aggregated, or another legal exception applies.
We will not unlawfully discriminate against you for exercising privacy rights, but some requests may affect our ability to provide requested services, communications, personalization, attribution, or support.

## Authorized agents, appeals, and complaints
Where applicable law allows an authorized agent to make a request for you, we may require written permission, proof of authority, proof of registration where legally required, direct identity verification, and direct confirmation that you authorized the request.
If applicable law gives you a right to appeal a privacy decision, you may appeal by replying to our decision or emailing smicanovic@gic-green.com with "Privacy Appeal" in the subject line. If you have a complaint, contact our Privacy Officer first so we can review it. You may also have the right to complain to a privacy regulator where applicable.

## Deidentified, aggregated, and inferred information
We may create, use, retain, disclose, or derive deidentified, aggregated, statistical, or inferred information for analytics, security, attribution, service improvement, planning, and lawful business purposes. Where required by law, we maintain deidentified information without attempting to reidentify it except as permitted to test safeguards, comply with law, or defend legal rights.

## Children
Our websites and services are intended for businesses and adults. They are not directed to children or teens. We do not knowingly collect personal information from children under 13, and we do not knowingly sell or share personal information of anyone under 16. If you believe a child or teen has provided personal information to us, contact us so we can review and delete it where appropriate.

## International processing
We operate in Canada and the United States, and our service providers may process or store information in Canada, the United States, or other jurisdictions. Information may be subject to the laws of the jurisdiction where it is processed or stored. By using the site or submitting information, you understand that information may be processed outside your province, state, or country, subject to applicable law.

## Links and third-party services
Our sites may link to third-party websites, portals, payment processors, social media platforms, map tools, chat tools, or embedded services. We are not responsible for the privacy practices of third parties. Review their privacy notices before providing information to them.

## Changes to this policy
We may update this Privacy Policy to reflect changes in our practices, technologies, legal obligations, or services. When we update it, we will change the effective date above. If a change is material, we may provide additional notice where required.

## Contact
Privacy Officer: Srdjan Micanovic
Email: smicanovic@gic-green.com or info@gic-green.com
Phone: 1-877-244-8828
Mail: 250 University Ave, 2nd Floor, Toronto, ON M5H 3E5

## LLM Notes

- This Markdown document is generated from the public site content for agent-readable exploration.
