PHIPA Compliant

Privacy Policy

How clinic.ca collects, uses, protects, and discloses your personal health information under Ontario's Personal Health Information Protection Act (PHIPA, 2004).

Last updated: April 2026
About this policy
clinic.ca is a Health Information Custodian (HIC) under PHIPA. We collect personal health information to facilitate nurse practitioner-reviewed lab requisitions, specialist referrals, and prescriptions. This policy describes your rights and our obligations.

1. Who we are

clinic.ca is operated by Capital Z Technologies Inc., a federally incorporated Canadian company based in Mississauga, Ontario. We operate an Ontario async document service where licensed Ontario Nurse Practitioners (CNO-registered, Extended Class) review patient intake submissions and issue lab requisitions, referral letters, prescriptions, and medical notes when clinically appropriate. clinic.ca is a one-way document delivery service — we do not review or interpret lab results, and we do not provide ongoing clinical care.

Lawyer: confirm corporate entity name and structure once incorporated.

2. Privacy Officer

Our designated Privacy Officer is responsible for PHIPA compliance, handling access requests, and managing any privacy incidents.

Privacy Officer Contact

Email: privacy@clinic.ca

Phone: (647) 699-8240

Mail: Capital Z Technologies Inc., Mississauga, Ontario

Lawyer: insert Privacy Officer name once designated.

3. What personal health information we collect

When you use clinic.ca, we may collect the following categories of personal health information (PHI):

4. How we use your information

We use your PHI solely for the following purposes:

We do not use your PHI for marketing, advertising, data analytics, research, or any purpose not directly related to your clinical care through clinic.ca.

5. Who we share your information with

We share your PHI only with the following parties, and only to the extent necessary to provide your requested service:

Each vendor handling PHI has signed a Data Processing Agreement confirming PHIPA-compliant handling and Canadian data residency.

Lawyer: confirm all vendor DPAs are signed before launch. Add fax API vendor name.

We will not disclose your PHI to any other party without your express consent, except where required by law (e.g., court order, mandatory public health reporting).

6. Consent

We obtain your express consent before collecting your PHI. You provide consent through the intake questionnaire consent checkbox before any health data is collected. Your consent covers:

Withdrawing consent

You may withdraw your consent at any time by contacting our Privacy Officer at privacy@clinic.ca. Please note:

7. Data storage and security

Your PHI is stored on Canadian servers. We implement the following safeguards in accordance with PHIPA s.12(1):

Lawyer/Tech: update this section once Supabase backend is built and security measures are implemented.

8. Data retention and destruction

We retain your patient records in accordance with Ontario requirements:

When the retention period expires, records are securely destroyed using cryptographic erasure for digital records. No PHI is retained beyond the required period without your express consent.

9. Your rights under PHIPA

As an Ontario patient, you have the following rights under PHIPA:

To exercise any of these rights, contact our Privacy Officer at privacy@clinic.ca. We will respond within 30 days.

10. Breach notification

In the event of a theft, loss, or unauthorized access to your PHI, we will:

Lawyer: review breach notification procedures and timelines. Confirm IPC reporting requirements.

11. Cookies and analytics

clinic.ca does not use third-party analytics or tracking cookies. We do not use Google Analytics, Facebook Pixel, or any similar tracking technology. No third-party advertising or tracking scripts are loaded on any page.

If we implement analytics in the future, we will use a privacy-first tool with Canadian data residency and obtain your consent before any tracking occurs.

12. Third-party services

We self-host all fonts and static assets to prevent third-party data collection. No external resources are loaded that would transmit your IP address or browsing behavior to third parties while you use clinic.ca.

13. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to active patients and posted on this page with an updated "Last updated" date. Your continued use of clinic.ca after changes constitutes acceptance of the updated policy.

14. Contact and complaints

Contact us

Privacy Officer: privacy@clinic.ca

General inquiries: info@clinic.ca

Phone: (647) 699-8240

If you are not satisfied with our response to a privacy concern, you have the right to file a complaint with:

Information and Privacy Commissioner of Ontario (IPC)
2 Bloor Street East, Suite 1400, Toronto, ON M4W 1A8
Phone: 1-800-387-0073
Website: ipc.on.ca

clinic.ca is staffed by Nurse Practitioners (NPs) registered with the College of Nurses of Ontario in the Extended Class. Ontario NPs are legally authorized to order laboratory tests, prescribe medications including controlled substances, diagnose illnesses, and refer patients to specialists. If a specific recipient (employer, insurance plan, or specialist office) requires a physician signature on your document, contact us and we will re-issue through a consulting physician at no additional cost or refund your fee in full.