Skip to content
iMedica
Compliance · Canada

PIPEDA & PHIPA

Canada's private-sector privacy law has ten principles. Here is each one, and what Imedica actually does about it.

Draft pending legal review. This page describes how the platform is built today; the binding version will be published before general availability.

What applies to us

PIPEDA, the federal Personal Information Protection and Electronic Documents Act, governs how private companies in Canada handle personal information. Ontario's Personal Health Information Protection Act (PHIPA) applies to health information custodians and the agents and providers who work with them. Imedica holds staff training data, not patient records, but we design to PHIPA's stricter standard because the services we work with are bound by it.

The ten principles, in practice

  1. 01

    Accountability

    Imedica HealthTech Inc. is responsible for the personal information it holds. Questions go to our privacy contact below, and every administrative action is written to an audit log.

  2. 02

    Identifying purposes

    We collect what's needed to run training: your name, email, role and organization to sign you in and manage seats, and your decisions in scenarios to score and explain them. Nothing else.

  3. 03

    Consent

    Your organization invites you; you create your own account and accept the terms. Training data is used for your training and your service's de-identified reporting, never sold or used for advertising.

  4. 04

    Limiting collection

    No health information about patients is collected: scenarios are fictional. We don't collect location, contacts or device identifiers beyond what sign-in needs.

  5. 05

    Limiting use, disclosure and retention

    Training data stays with the service that owns it. AI explanations are generated without your name, email or organization. Records are kept while your service's agreement is active and deleted or returned when it ends.

  6. 06

    Accuracy

    You can correct your profile at any time. Your training lead can update roles and deactivate accounts when people leave.

  7. 07

    Safeguards

    Identity, content and analytics are separate Postgres schemas with no relations between them; a keyed one-way hash (HMAC-SHA256) is the only link. Passwords are hashed with bcrypt, sessions are server-side and revocable.

  8. 08

    Openness

    This page, our privacy policy and the security page describe how the platform works in plain language.

  9. 09

    Individual access

    You can ask for a copy of the personal information we hold about you, and we'll answer in writing within 30 days.

  10. 10

    Challenging compliance

    If you're not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada or, in Ontario, the Information and Privacy Commissioner.

Reporting without singling anyone out

Training leads see their own organization only, and only figures built from five or more people. The check runs inside the reporting query, so a small group can't be filtered into view.

Where the data lives

The platform is designed to run entirely in Canadian data centres. We confirm the exact hosting arrangement in writing during procurement, and we'll tell customers before it changes.

Contact

Privacy questions, access requests and procurement questionnaires: hi@imedica.tech. For the technical detail, see Privacy & security and the privacy policy.