Draft pending legal review. This page describes how the platform is built today; the binding version will be published before general availability.
What applies to us
PIPEDA, the federal Personal Information Protection and Electronic Documents Act, governs how private companies in Canada handle personal information. Ontario's Personal Health Information Protection Act (PHIPA) applies to health information custodians and the agents and providers who work with them. Imedica holds staff training data, not patient records, but we design to PHIPA's stricter standard because the services we work with are bound by it.
The ten principles, in practice
- 01
Accountability
Imedica HealthTech Inc. is responsible for the personal information it holds. Questions go to our privacy contact below, and every administrative action is written to an audit log.
- 02
Identifying purposes
We collect what's needed to run training: your name, email, role and organization to sign you in and manage seats, and your decisions in scenarios to score and explain them. Nothing else.
- 03
Consent
Your organization invites you; you create your own account and accept the terms. Training data is used for your training and your service's de-identified reporting, never sold or used for advertising.
- 04
Limiting collection
No health information about patients is collected: scenarios are fictional. We don't collect location, contacts or device identifiers beyond what sign-in needs.
- 05
Limiting use, disclosure and retention
Training data stays with the service that owns it. AI explanations are generated without your name, email or organization. Records are kept while your service's agreement is active and deleted or returned when it ends.
- 06
Accuracy
You can correct your profile at any time. Your training lead can update roles and deactivate accounts when people leave.
- 07
Safeguards
Identity, content and analytics are separate Postgres schemas with no relations between them; a keyed one-way hash (HMAC-SHA256) is the only link. Passwords are hashed with bcrypt, sessions are server-side and revocable.
- 08
Openness
This page, our privacy policy and the security page describe how the platform works in plain language.
- 09
Individual access
You can ask for a copy of the personal information we hold about you, and we'll answer in writing within 30 days.
- 10
Challenging compliance
If you're not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada or, in Ontario, the Information and Privacy Commissioner.
Reporting without singling anyone out
Training leads see their own organization only, and only figures built from five or more people. The check runs inside the reporting query, so a small group can't be filtered into view.
Where the data lives
The platform is designed to run entirely in Canadian data centres. We confirm the exact hosting arrangement in writing during procurement, and we'll tell customers before it changes.
Contact
Privacy questions, access requests and procurement questionnaires: hi@imedica.tech. For the technical detail, see Privacy & security and the privacy policy.