Legal
Privacy Policy
How we collect, use, store, and protect your personal health information.
Last updated: May 24, 2026
1.Introduction
Gift of Gab Tech Inc. ("GGHealth," "we," "us," or "our") is committed to protecting the privacy and confidentiality of all personal information and personal health information ("PHI") entrusted to us through the GGHealth platform.
This Privacy Policy explains how we collect, use, disclose, store, and protect information in compliance with Ontario's Personal Health Information Protection Act, 2004 (PHIPA) and the federal Personal Information Protection and Electronic Documents Act (PIPEDA).
GGHealth is a healthcare intelligence platform designed for licensed healthcare professionals in Ontario, Canada — including physicians, midwives, pharmacists, nurses, and allied health professionals.
2.Information We Collect
2.1 Personal Health Information (PHI)
In the course of providing our services, we may process the following PHI on behalf of healthcare providers:
- Patient names, dates of birth, contact information, and health card numbers
- Clinical notes, diagnoses, treatment plans, and referral information
- Call recordings and transcriptions of provider-patient communications
- AI-generated call summaries and extracted action items
- Medication records, prescription history, and allergy information
- Lab results and diagnostic imaging reports
- Consent records and lockbox restriction preferences
2.2 Provider Information
We collect information about healthcare providers who use our platform:
- Name, professional designation, and licence number
- Practice name, address, and contact information
- Account credentials and multi-factor authentication details
- Usage data, login history, and session information
- Professional role and access permissions
2.3 Technical Information
We automatically collect technical information necessary for platform operation:
- IP address, browser type, and device information
- Access logs and audit trail records
- Performance metrics and error reports
- Cookie and session data (see our Cookie Policy)
3.How We Use Information
We use the information we collect solely for the following purposes:
- Providing healthcare services: Enabling providers to manage patient information, generate call summaries, and maintain clinical records
- AI-powered documentation: Transcribing and summarizing healthcare communications to reduce administrative burden
- Security and compliance: Maintaining audit trails, detecting breaches, and ensuring PHIPA/PIPEDA compliance
- Platform improvement: Analysing anonymised, aggregated usage data to improve platform performance and features
- Communication: Sending service-related notifications, security alerts, and system updates
- Legal obligations: Complying with applicable laws, regulations, and lawful requests from authorities
We do not sell, rent, or trade personal health information. We do not use PHI for advertising, marketing, or any purpose unrelated to healthcare service delivery.
4.Data Storage and Encryption
All personal health information is protected using industry-leading security measures:
- Encryption at rest: All PHI is encrypted using AES-256-GCM field-level encryption before storage in our database. Encryption keys are managed through Azure Key Vault with automatic rotation.
- Encryption in transit: All data transmitted between your device and our servers is protected using TLS 1.3 encryption.
- Canadian data residency: All data is stored within Microsoft Azure Canada Central data centres located in Ontario, Canada. When configured with Azure OpenAI Service (Canada Central), audio transcription processing also remains within Canadian borders. See Section 9 for details on third-party AI processors.
- Key management: Encryption keys are stored separately from encrypted data in Azure Key Vault, with hardware security module (HSM) protection.
- Database security: PostgreSQL databases are configured with encryption at rest, network isolation, and regular automated backups.
5.Who Can Access Data
Access to personal health information is strictly controlled through multiple mechanisms:
5.1 Role-Based Access Control (RBAC)
Every user is assigned a specific role — Physician, Midwife, Nurse, Pharmacist, Allied Health, or Administrator — with granular permissions appropriate to their professional responsibilities. Administrators manage system settings but cannot access patient clinical data.
5.2 Circle of Care
PHI is only accessible to healthcare providers who are within the patient's circle of care, as defined under PHIPA. Access is verified before every data retrieval.
5.3 Lockbox Controls
Patients may designate certain information as "lockbox" restricted. Lockbox-protected information is withheld even from providers within the circle of care, unless the patient provides explicit consent or a break-glass emergency access protocol is invoked. All break-glass access is logged, audited, and reported.
5.4 Multi-Factor Authentication
All accounts accessing patient data require multi-factor authentication. Passwords must meet strict complexity requirements (minimum 12 characters with mixed case, numbers, and special characters).
5.5 GGHealth Personnel
GGHealth staff do not have routine access to patient data. In rare cases where technical support requires access (e.g., troubleshooting a data issue), access is logged, time-limited, and supervised. All staff undergo privacy training and sign confidentiality agreements.
6.Patient Rights
Under PHIPA and PIPEDA, patients have the following rights regarding their personal health information:
- Right of access: You may request a copy of your personal health information held by your healthcare provider through the GGHealth platform.
- Right to correction: You may request corrections to your personal health information if you believe it is inaccurate or incomplete.
- Right to data export: You may request your data in a portable, machine-readable format.
- Right to withdrawal of consent: You may withdraw consent for the collection, use, or disclosure of your personal health information, subject to legal and regulatory requirements. Withdrawal does not affect the lawfulness of processing performed before withdrawal.
- Right to lockbox restrictions: You may apply lockbox restrictions to prevent specific information from being shared, even within your circle of care.
- Right to an audit: You may request a record of who has accessed your personal health information and when.
- Right to complain: You may file a complaint with the Information and Privacy Commissioner of Ontario (IPC) if you believe your privacy rights have been violated.
To exercise any of these rights, contact your healthcare provider directly or reach out to our Privacy Officer at privacy@giftofgab.ai.
7.Breach Notification
In the event of a privacy breach involving personal health information, GGHealth follows the mandatory breach notification requirements under PHIPA:
- Detection: Our platform includes real-time anomaly detection and automated breach alerts to identify potential breaches as quickly as possible.
- Containment: Upon detection, we immediately take steps to contain the breach and prevent further unauthorised access.
- Assessment: We assess the scope and severity of the breach, including what information was affected and who may be impacted.
- Notification to the IPC: We report the breach to the Information and Privacy Commissioner of Ontario as required by PHIPA.
- Notification to affected individuals: We notify affected patients and healthcare providers at the first reasonable opportunity, including a description of the breach, the information involved, and steps being taken.
- Remediation: We take corrective action to prevent future breaches and document the incident thoroughly.
8.Data Retention and Destruction
We retain personal health information in accordance with applicable legal requirements:
- Clinical records: Retained for a minimum of 10 years from the last entry, or 10 years after the patient reaches age 18 (for minors), in accordance with Ontario regulatory requirements.
- Audit logs: Retained for a minimum of 6 years to support compliance verification and incident investigation.
- Call recordings and transcriptions: Retained as part of the clinical record for the applicable retention period, unless the patient requests earlier deletion (subject to legal requirements).
- Account data: Provider account information is retained for the duration of the service relationship plus 2 years, then securely destroyed.
- Technical logs: Retained for 12 months for security monitoring purposes.
When data reaches the end of its retention period, it is securely destroyed using cryptographic erasure (destruction of encryption keys) and verified deletion procedures.
9.Third-Party Services
GGHealth uses select third-party services to operate the platform. All third-party processors are contractually bound to comply with applicable privacy requirements:
- Microsoft Azure (Canada Central): Cloud infrastructure, database hosting, key management, and compute services — all within Canadian data centres.
- Microsoft Azure OpenAI Service (Canada Central): When configured, speech-to-text transcription (Whisper model) is processed through Azure OpenAI deployed in Canada Central, keeping audio data within Canadian borders.
We do not share personal health information with any third party for their own use. All third-party data processing agreements are available for review upon request.
9.1 Third-Party AI Processors
GGHealth uses the following AI services for transcription and summarisation of healthcare communications. We are transparent about what data each processor receives and where it is processed:
- OpenAI (Whisper) — Speech-to-Text Transcription: Call recordings are sent to OpenAI's Whisper API for transcription. When Azure OpenAI Service is configured (Canada Central region), this processing occurs entirely within Canada. When using OpenAI's direct API, audio data is processed on US-based servers. OpenAI's data usage policy states that data sent through the API is not used to train models. Data received: audio recordings of healthcare calls.
- Anthropic (Claude) — Call Summarisation: Transcribed text (not audio) is sent to Anthropic's Claude API for generating structured clinical summaries, including SOAP notes and action items. Anthropic's API is currently US-based. The transcript text sent for summarisation does not include patient identifying information (names, health card numbers, contact details) which are handled separately in our encrypted storage. Anthropic's data policy states that API inputs are not used to train models. Data received: de-identified transcript text of healthcare calls.
We are actively evaluating Canadian-hosted alternatives for all AI processing to achieve full data residency within Canadian borders for the entire pipeline.
11.Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you through the platform and update the "Last updated" date at the top of this page.
We encourage you to review this policy periodically. Continued use of the platform after changes are posted constitutes acceptance of the updated policy.
12.Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy Officer:
You may also contact the Information and Privacy Commissioner of Ontario (IPC) if you have concerns about how your personal health information is being handled:
Information and Privacy Commissioner of Ontario
2 Bloor Street East, Suite 1400
Toronto, Ontario M4W 1A8
Telephone: 1-800-387-0073
Website: www.ipc.on.ca