Skip to content
All legal documents

Privacy Policy

How HealthCoreSecurity AI collects, uses, stores and discloses personal information, under PIPEDA, Quebec Law 25 and the provincial health privacy statutes.

Draft — no effective date set

Draft — not yet in force

This document has not been finalised and does not create binding obligations. It still needs company details that only we can supply, and review by Canadian privacy counsel. Anything shown as [[LIKE THIS]] is a blank, not a value.

Outstanding: entityName, entityJurisdiction, registeredAddress, privacyOfficerEmail, securityEmail, supportEmail, generalEmail, governingProvince, effectiveDate.

1. Who this policy is from

This policy is issued by [[ENTITY NAME]] ("we", "us"), incorporated in [[ENTITY JURISDICTION]], which operates the HealthCoreSecurity AI service and the healthcoresecurity.ca website.

Registered office: [[REGISTERED ADDRESS]]

We are accountable for the personal information in our custody and control. The person responsible for that accountability is our Privacy Officer, who can be reached at [[PRIVACY OFFICER EMAIL]]. This designation and its publication are required by Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and by Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25.

2. The three kinds of people in this policy

We handle information about three different groups, and the rules are not the same for each. Read the section that applies to you.

Visitors. Anyone who browses the website or fills in a form on it.

Clinic customers. The clinic that subscribes, and the individuals at that clinic who hold accounts — usually the owner, a practice manager, and the practitioners whose devices we protect.

Patients. People treated by our customers' clinics. We do not want, ask for, or set out to collect patient health records. See section 5, which is the most important section in this document if you are a clinic evaluating us.

3. What we collect from website visitors

If you fill in the assessment or contact form, we collect exactly the fields on that form: your clinic name, your name, your email address, and optionally your phone number, clinic type, number of staff, the practice-management software you use, and whatever you write in the message box.

Alongside that submission we record marketing attribution: the UTM parameters on the link you arrived through, the referring page, and the path of the page you were on when you submitted. This tells us which channels actually reach clinics. It is never used to make a decision about you.

We do not run web analytics. There is no Google Analytics, no Meta pixel, no Plausible, no PostHog, no session recorder and no advertising tag on this site. We are not quietly building a profile of your visit.

We do not store your IP address. Your IP is read in memory to rate-limit form submissions — so that one source cannot flood us — and is discarded. It is not written to the database and is not retained.

If you browse without submitting anything, we do not collect personal information about you at all.

4. What we collect from clinic customers

Account information. The clinic's name and type, your name, work email address and phone number, the number of people at the clinic, the practice-management or EMR software you run, and the security software you had before us. You give us this during signup.

Authentication. Your email address and a password, which is salted and hashed by our authentication provider. We never see, store or transmit your password in a form we could read.

Billing. Your subscription status, plan, and the identifiers Stripe issues for your customer and subscription records. Card numbers never touch our systems. Payment is taken on Stripe-hosted checkout pages; we receive confirmation that a payment succeeded and nothing more. This is deliberate — it keeps card data entirely outside our environment.

Security telemetry. This is the service itself. Once your devices are protected, we receive the signals a security product produces: process and file activity, network connections, logins and login failures, device and operating-system identifiers, the name of the signed-in user on a device, and the alerts our detection raises from all of that. We use it to detect and stop attacks on your clinic, and for nothing else.

5. Patient information, and why we work hard not to have it

Our customers are health information custodians. We are not. Under Ontario's Personal Health Information Protection Act (PHIPA), and its counterparts in Alberta (HIA), British Columbia, Saskatchewan (HIPA), Manitoba (PHIA), New Brunswick, Nova Scotia and Newfoundland and Labrador, a clinic remains the custodian of its patients' records and we act as its service provider and agent, handling information only as the clinic directs.

The service is designed to watch how software and devices behave, not to read what is inside a patient chart. Our detection looks at process execution, file access patterns, network destinations and authentication events. It does not index, parse or exfiltrate the contents of your records.

Despite that design, some personal health information can incidentally appear in security telemetry — most often as a file name or a file path, since clinics name files after patients. Where that happens:

  • we treat it as personal health information subject to the clinic's instructions, not as our own data;
  • we do not use it for any purpose other than delivering and supporting the security service;
  • we do not use it to train machine-learning models;
  • it is covered by the confidentiality and breach-notification obligations in our Data Processing Addendum.

Where we operate as a health information network provider within the meaning of Ontario Regulation 329/04 under PHIPA, we accept the specific duties that status carries, including notifying the custodian at the first reasonable opportunity of any unauthorised use or disclosure, and making a plain-language description of our services and safeguards publicly available. The Security page and the Data Processing Addendum are that description.

6. Why we are allowed to have it

We collect, use and disclose personal information with your knowledge and consent, for purposes a reasonable person would consider appropriate in the circumstances — the PIPEDA standard.

In practice:

WhatWhyBasis
Assessment and contact formTo answer your enquiry and follow up about the serviceYour consent, given by submitting the form
Account and authentication dataTo create and secure your accountNecessary to perform the contract
Billing dataTo charge the subscription you boughtNecessary to perform the contract
Security telemetryTo detect and respond to threats against your clinicNecessary to perform the contract, on the clinic's instructions
Marketing emailTo tell you about the serviceYour express or implied consent under CASL

You can withdraw consent at any time — see section 10. Withdrawing consent to the processing that is the security service means ending the subscription, because there is no service without it.

Commercial electronic messages

Canada's Anti-Spam Legislation applies to us. We send commercial email only where we have your express consent or a business relationship that gives us implied consent, we identify ourselves in every message, and every message carries a working unsubscribe link that we action promptly. If you ask us to stop, we stop.

7. Automated processing

Our detection uses machine learning and, for triage and summarisation, large language models. Two things follow, and we would rather state them than have you discover them.

Alerts are assessed by software before a human sees them. That is the product. What it does is decide whether activity on a device looks malicious and whether to isolate that device. It is a decision about a machine, and a human analyst reviews containment actions.

We do not make automated decisions about individuals that produce legal or similarly significant effects. We do not score, rank or profile your staff or your patients, and nothing about you is decided solely by a machine. If that ever changes, this section changes first, and Quebec residents will receive the notice and the right to submit observations that Law 25 requires.

We do not train models on your data. Your telemetry, your records and your patients' information are not used to train or fine-tune any model, ours or a third party's.

8. Who else touches it

We use service providers to run the service. Each one gets only what it needs, under contract, and none of them may use your information for their own purposes. The current list — who they are, what they do, and which country they are in — is published and kept current at Sub-processors.

Beyond those providers, we disclose personal information only:

  • to you, or to someone you authorise in writing;
  • where a law, warrant, subpoena or court order with jurisdiction over us compels it;
  • to our professional advisers under a duty of confidentiality;
  • to an acquirer, if the business is sold — in which case the information remains subject to this policy or to one no less protective, and you will be told.

We do not sell personal information. We do not rent it, trade it, or share it with advertisers or data brokers. There is no circumstance in which we would.

9. Where it lives, and when it leaves Canada

The primary database is hosted in Canada, in the Montreal region of our database provider. Your account records, the clinic profile, and the enquiries submitted through this website are stored there.

Some of our providers are located in, or route traffic through, the United States and other countries. That matters, and PIPEDA and Alberta's Personal Information Protection Act both require us to tell you plainly rather than bury it:

Personal information stored or processed outside Canada is subject to the laws of that country, and may be accessible to its courts, law enforcement and national-security authorities under those laws.

The Sub-processors page names each provider and the country it operates in, so you can see exactly which parts of the service cross the border. We use contractual protections with each of them, but we will not pretend a contract overrides a foreign court.

If your clinic's regulator or professional college requires Canadian-only processing, tell us before you subscribe. We would rather have that conversation early than discover the constraint afterwards.

10. Your rights

You have the right to:

  • Know whether we hold personal information about you, and to get a copy of it.
  • Correct it if it is inaccurate or incomplete.
  • Withdraw consent, subject to legal and contractual restrictions and reasonable notice.
  • Have it deleted, where we have no lawful reason to keep it.
  • Receive it in a portable form — a structured, commonly used technological format. Quebec residents have this right under Law 25; we extend it to everyone rather than operate two standards.
  • Complain, to us and then to a regulator.

Write to [[PRIVACY OFFICER EMAIL]]. We will respond within 30 days, which is the PIPEDA limit. If we need longer we will tell you why within those 30 days, as the Act requires. We will ask you to verify your identity first — the alternative is handing your records to whoever asks for them.

There is no charge for a reasonable request.

If we refuse, we will tell you in writing why, and what you can do about it.

Complaining to a regulator

You do not have to go through us first, although it usually resolves faster if you do.

  • Federal: Office of the Privacy Commissioner of Canada — priv.gc.ca
  • Quebec: Commission d'accès à l'information du Québec — cai.gouv.qc.ca
  • Alberta / British Columbia: the Office of the Information and Privacy Commissioner for your province
  • Ontario health information: Information and Privacy Commissioner of Ontario — ipc.on.ca

11. How long we keep it

InformationKept for
Enquiries that never become customers24 months from last contact
Security telemetry and alerts12 months
Account and billing records after cancellation7 years after the end of the subscription, for tax and audit
Encrypted backups35 days

Deletion requests are honoured in the live systems immediately and work through backups on the cycle above. We keep account and billing records longer than anything else because tax and corporate law requires us to; that retention is limited to what those obligations need.

12. How we protect it

The full description is on the Security page. In summary: access to customer data is restricted to staff who need it for their role and is logged; the database enforces access rules at the row level in the database itself rather than trusting application code; data is encrypted in transit and at rest; administrative access requires multi-factor authentication; and we run a published vulnerability disclosure programme.

No safeguard is perfect, and we will not claim ours is.

13. If something goes wrong

If a breach of security safeguards creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, and keep a record of the breach as PIPEDA requires. Where Quebec's Law 25 applies we will also notify the Commission d'accès à l'information and maintain the confidentiality incident register it requires.

Where the information belongs to a clinic's patients, we will notify the clinic as the custodian at the first reasonable opportunity, so that it can meet its own obligations to its patients and its regulator. We will not sit on it.

14. Children

The service is sold to clinics, not to individuals, and the website is not directed at children. We do not knowingly collect personal information directly from children through this website. Patient records held by our customers may of course concern children; those are handled under section 5 and the clinic's own obligations.

15. Cookies

Covered separately, in the Cookie Policy.

16. Changes

If we change this policy we will change the date at the top of the page. If a change is material — if it widens what we collect, what we do with it, or who we give it to — we will tell account holders directly and give notice before it takes effect. We will not make a material change retroactively.

17. Contact

Privacy Officer [[ENTITY NAME]] [[REGISTERED ADDRESS]] [[PRIVACY OFFICER EMAIL]]