Skip to content
iMedica
Schemas · identity / content / analytics

Privacy lives in the data model.

Built for PIPEDA and Ontario's PHIPA from the first table. Who you are and what you did are stored apart, and only a keyed hash connects them.

What a privacy officer will ask.

The answers below describe the code as it runs, not a policy we intend to follow.

  1. 01 / 04

    Three schemas that never join

    Imedica's database is split into three Postgres schemas. Identity holds names, emails, organizations and logins. Content holds scenarios and training runs. Analytics holds the de-identified copies used for reporting.

    No table in one schema references another. The only way to connect a person to their training is a keyed one-way hash (HMAC-SHA256) computed by the application with a secret that never enters the database. A copy of the training data alone can't be tied back to anyone.

  2. 02 / 04

    Reporting that can't single anyone out

    Analytics records carry no name, no email, no free text and no exact time: completion is stored to the week, and experience as a range. Training directors see figures for their own organization only.

    Any figure that would describe fewer than five distinct people is withheld. The check runs inside the reporting query itself.

  3. 03 / 04

    Access and accountability

    Roles are explicit: paramedic, instructor, physician, and Imedica administrator. Instructors only reach their own organization. Sessions are server-side and revocable, passwords are hashed with bcrypt, and resetting a password signs out every device.

    Logins, invitations, role changes and every edit to clinical content are written to an audit log.

  4. 04 / 04

    Where it runs

    The platform is designed to run entirely in Canadian data centres, with the application and database in the same Canadian region. We'll confirm the exact hosting arrangement in writing during procurement.

Names live in one place.

Scores live in another.

Only a hash connects them.

What reaches the AI model.

When a run ends, Anthropic's Claude writes the debrief. It gets the clinical picture and nothing about the person. It can't change a score, its writing is checked for anything that looks like personal information before it's stored, and physicians can flag any explanation from the review queue.

Sent

  • The scenario and its moments
  • Each decision and when it was made
  • The rule engine's verdict for each one

Never sent

  • Name, email or employee number
  • Organization or service
  • Any identifier that could be joined back

Questions from your privacy officer?

Send them to hi@imedica.tech. We answer procurement and privacy questionnaires in writing, and we'll walk your team through the data model on a call.

Write to us