How this policy applies
This policy does not replace a data processing agreement, master services agreement, order form or notice provided by your clinic. Those documents may include additional terms.
Legal
This policy explains how Physicare.ai handles personal information when you visit our website, use our services or interact with us.
Last updated April 13, 2026
This policy does not replace a data processing agreement, master services agreement, order form or notice provided by your clinic. Those documents may include additional terms.
Your clinic or healthcare provider is usually responsible for your clinical record. Contact them first to access, correct or discuss that information.
This policy applies to website visitors, clinic owners and administrators, healthcare professionals, authorized staff, patients using features enabled by their clinic, and business contacts or prospects.
For clinical and operational data entered into Physicare, the clinic, practice, employer or regulated professional is generally the organization that decides why and how the information is used. Depending on the law, that organization may be called a controller, custodian or trustee.
Physicare generally handles that customer data as a processor, service provider or agent under the customer’s instructions and agreement. Physicare is separately responsible for business data used to administer accounts, billing, authentication, security, fraud prevention, compliance, support and service communications.
Where European privacy law applies and Physicare is the controller, processing may rely on a contract, legal obligation, legitimate interest or consent. Customers are responsible for the legal basis and any required condition for special-category health information they control.
In Canada, personal information is handled under applicable federal and provincial privacy laws. Customers remain responsible for the notices, consents and authorizations required for the information they place in Physicare.
Physicare can help prepare transcripts, summaries, draft notes, structured content, documentation suggestions and administrative support. These outputs assist the clinician. They may be incomplete, inaccurate, outdated, biased or inappropriate and must be reviewed before use.
Physicare does not use AI to make solely automated decisions with legal or similarly significant effects. Identifiable customer data is not used to train generalized third-party AI models unless covered by a separate written agreement or lawful program. De-identified or anonymized data may be used for analytics, research or product improvement where permitted and protected by appropriate safeguards.
Physicare primarily hosts production data in Canada. Some providers may process limited information outside Quebec or Canada, including in the United States. Information processed in another country may be subject to lawful access there.
Where required, safeguards may include contracts, transfer impact assessments, standard contractual clauses and technical or organizational measures. A material subprocessor list is maintained and made available when required.
Physicare uses administrative, technical and physical safeguards appropriate to the sensitivity of the information. Measures may include encryption in transit and at rest, role-based access, least privilege, authentication, monitoring, logging, secure hosting, backups, recovery procedures, confidentiality requirements and incident response. No system can be guaranteed completely secure.
Information is kept only as long as needed for the service, the customer agreement and applicable law. Customer data follows customer instructions and contractual, legal, backup and deletion schedules. Account, billing, audit, security and legal records may be retained longer when there is a legitimate need.
When Physicare acts for a customer, return, export, retention, deletion and destruction are governed mainly by that customer’s agreement and instructions.
Depending on the law, you may be able to request access, correction, deletion, restriction or portability, object to certain processing, withdraw consent, or complain to a privacy authority.
Requests involving data controlled by a clinic may be sent to that clinic, with Physicare assisting as required. For information Physicare controls, email privacy@physicare.ai. We may need to verify your identity before completing a request.
Physicare maintains processes to identify, investigate, document and respond to incidents. If a breach affects customer data, the customer is notified without undue delay. Physicare also provides notices to individuals or regulators when legally required.
Physicare is not directed to children as independent users. A clinic may use the service while caring for a minor. In that case, the customer is responsible for the authority, notices and consents required by law.
Where the GDPR or UK GDPR applies, customers remain responsible for the required legal basis, health-data condition and transparency when Physicare processes information for them. Applicable transfer safeguards may include standard contractual clauses, the UK International Data Transfer Addendum or Agreement, and supplementary measures. Physicare will appoint an EU representative where Article 27 requires one.
This policy may be updated as the service, laws or practices change. Material changes will receive reasonable notice by email, through the service or by another appropriate method. The date at the top shows the latest revision.
Contact Physicare with privacy questions or requests using the details below. You may also complain to the privacy authority that has jurisdiction where you live or work.
Legal
For privacy questions, requests or concerns, contact our privacy team.