Skip to content
All legal documents

Data Processing Addendum

The binding terms on which HealthCoreSecurity AI processes personal information and personal health information on behalf of a clinic, under PIPEDA, Quebec Law 25 and the provincial health privacy statutes.

Draft — no effective date set

Draft — not yet in force

This document has not been finalised and does not create binding obligations. It still needs company details that only we can supply, and review by Canadian privacy counsel. Anything shown as [[LIKE THIS]] is a blank, not a value.

Outstanding: entityName, entityJurisdiction, registeredAddress, privacyOfficerEmail, securityEmail, supportEmail, generalEmail, governingProvince, effectiveDate.

This Addendum forms part of the Terms of Service and applies automatically to every clinic that subscribes. You do not need to sign a separate copy for it to bind us. If your regulator, insurer or counsel needs it executed as a standalone agreement, write to [[PRIVACY OFFICER EMAIL]] and we will sign one.

1. Who is who

You are the custodian. Your clinic is the health information custodian under PHIPA and its provincial equivalents, and the organisation accountable under PIPEDA for the personal information you collect from patients and staff. You decide the purposes.

We are your service provider and agent. [[ENTITY NAME]] processes that information only to deliver the security service, and only on your instructions. We do not decide the purposes, and we do not become a custodian by handling it.

Your instructions are: the Terms of Service, your order form, the configuration you set, and anything else you tell us in writing. If we think an instruction would breach privacy law, we will tell you rather than silently carry it out.

2. What we process, and why

Subject matterDelivery of the managed cybersecurity service
DurationThe term of your subscription, plus the deletion window in section 10
Nature and purposeDetecting, investigating, containing and reporting on security threats to your clinic's devices and systems
Types of informationSecurity telemetry: process, file and network activity; authentication events; device and account identifiers; the name of the signed-in user on a device. Account and billing records. Incidentally, personal health information appearing in file names or paths.
Categories of individualYour staff and contractors whose devices are in scope; incidentally, your patients

We do not receive a copy of your patient database and we do not set out to process records of health care. Where personal health information reaches us incidentally, it is covered in full by this Addendum.

3. Our duties as a health information network provider

Where we operate as a health information network provider within the meaning of Ontario Regulation 329/04 under PHIPA, or its equivalent in another province, we accept the duties that status carries. Specifically, we will:

  1. Notify you at the first reasonable opportunity of any unauthorised use or disclosure of personal health information in our custody. Not "without undue delay" — at the first reasonable opportunity, which is the standard the regulation sets.
  2. Not use personal health information except as necessary to provide the service, and not disclose it except as this Addendum permits.
  3. Not permit access by our personnel except where necessary to provide the service.
  4. Make available to you, in writing, a plain-language description of the service including the safeguards protecting confidentiality and security. The Security page and this Addendum are that description.
  5. Perform and make available an assessment of the services' threats, vulnerabilities and risks to privacy and security, on request.
  6. Keep and make available an electronic record of accesses to and transfers of personal health information in our systems, to the extent our systems create such records.

These duties are cumulative with everything else in this Addendum, not a substitute for it.

4. Confidentiality

Everyone at [[ENTITY NAME]] who can reach your information is bound by written confidentiality obligations that survive their employment, is trained on their privacy and security responsibilities, and is granted access on a need-to-know basis for their role. Access is logged.

5. Security

We maintain administrative, physical and technical safeguards appropriate to the sensitivity of the information. Those are described on the Security page, which is incorporated here by reference and which we keep current.

We will not materially reduce the protections described there during your subscription.

6. Breach notification

If we become aware of a breach of security safeguards affecting your information we will:

  • tell you at the first reasonable opportunity, and in any event without undue delay;
  • tell you what we know — what happened, when, what categories of information and roughly how many individuals are affected, what we are doing about it, and what we recommend you do;
  • keep telling you as we learn more, rather than waiting until we have a complete picture;
  • support you in meeting your own notification obligations to patients, to the Office of the Privacy Commissioner of Canada, to your provincial commissioner and to your professional college;
  • keep the records of the breach that PIPEDA requires, and where Law 25 applies, maintain the confidentiality incident register.

The decision to notify patients is yours, as custodian. We will not make it for you, and we will not delay your ability to make it.

Report a suspected incident to us at [[SECURITY EMAIL]].

7. Sub-processors

You authorise us to use the sub-processors listed at Sub-processors. Each is bound by written terms no less protective than this Addendum, and we remain responsible to you for what they do.

We will update that page before a new sub-processor starts handling your information. Subscribe to notifications there, or check it — either way, if you object to a new sub-processor on reasonable privacy or security grounds, tell us within 30 days and we will either find an alternative or let you terminate the affected service without penalty and refund the unused portion of your term.

8. Where information is processed

The primary database is in Canada. Some sub-processors operate in the United States and elsewhere; the Sub-processors page names each one and its location.

Information processed outside Canada is subject to the laws of that jurisdiction, including lawful access by its authorities. We use contractual protections, but we will not tell you a contract defeats a foreign court order.

If your regulator requires Canadian-only processing, raise it with us before subscribing.

9. Helping you meet your obligations

We will give you reasonable assistance, at no charge for ordinary requests, with:

  • Access and correction requests from your patients or staff. If a request comes to us, we will not answer it ourselves — we will route it to you, because you are the custodian.
  • Privacy impact assessments and the threat-risk assessments your regulator or insurer asks for.
  • Regulator enquiries relating to information we process for you.

10. Return and deletion

On termination, or on your written request at any time:

  • we stop processing, except as needed to complete the deletion;
  • for 30 days you may ask for an export, which we will provide in a structured, machine-readable format;
  • we then delete or irreversibly de-identify the information in live systems;
  • backups age out within 35 days, after which the information is gone from those too;
  • we certify the deletion in writing if you ask.

The exception is information we are legally required to retain — billing records for tax purposes, and records of a breach that PIPEDA requires us to keep. Those remain subject to this Addendum's confidentiality and security terms for as long as we hold them.

11. Audit

On reasonable notice, no more than once a year unless a breach or a regulator says otherwise, you may:

  • ask for the written information reasonably needed to confirm we are meeting this Addendum, including our current security documentation and any third-party audit reports or evidence packages we hold;
  • have a mutually agreed independent auditor, bound by confidentiality, examine the parts of our environment relevant to your information.

We will not give an auditor access to another customer's data, and we may charge reasonable costs for an on-site audit beyond the annual one.

12. Conflicts

If this Addendum conflicts with the Terms of Service or the Privacy Policy on how we handle information processed for you, this Addendum governs.

13. Contact

Privacy Officer [[ENTITY NAME]] [[REGISTERED ADDRESS]] [[PRIVACY OFFICER EMAIL]]