Legal

Privacy Policy

This policy explains how Physicare.ai handles personal information when you visit our website, use our services or interact with us.

Last updated April 13, 2026

How this policy applies

This policy does not replace a data processing agreement, master services agreement, order form or notice provided by your clinic. Those documents may include additional terms.

Questions about a clinical record?

Your clinic or healthcare provider is usually responsible for your clinical record. Contact them first to access, correct or discuss that information.

1. Scope

This policy applies to website visitors, clinic owners and administrators, healthcare professionals, authorized staff, patients using features enabled by their clinic, and business contacts or prospects.

2. Our privacy roles

For clinical and operational data entered into Physicare, the clinic, practice, employer or regulated professional is generally the organization that decides why and how the information is used. Depending on the law, that organization may be called a controller, custodian or trustee.

Physicare generally handles that customer data as a processor, service provider or agent under the customer’s instructions and agreement. Physicare is separately responsible for business data used to administer accounts, billing, authentication, security, fraud prevention, compliance, support and service communications.

3. Information we handle

  • Account and business details, such as name, work contact information, organization, role, credentials, subscription, billing and support history.
  • Clinical and workflow data provided by customers, such as patient identifiers, appointments, notes, transcripts, assessments, programs, questionnaires and communications.
  • Technical data, such as IP address, browser, device, operating system, session, authentication, audit, crash and performance logs.
  • Limited billing and transaction details from payment processors. Physicare does not store full payment card numbers.
  • Cookie and analytics data where permitted and, when required, after consent.

4. Where information comes from

  • Directly from users, customers and business contacts.
  • From customers that add information about patients, staff or other authorized users.
  • Automatically from browsers, devices and systems when the website or service is used.
  • From service providers and other business contacts where permitted.

5. How we use information

  • Provide, host, operate, maintain and support the service.
  • Create accounts, authenticate users and manage permissions.
  • Support transcription, documentation, workflows and AI features under customer instructions.
  • Manage subscriptions, billing, invoicing and collections.
  • Protect the service, prevent misuse and respond to security incidents.
  • Maintain logs, backups, reliability and product performance.
  • Send service, support, product and legally required communications.
  • Meet contractual, legal, regulatory and governance obligations.
  • Perform limited analytics and improvements, or other optional uses with consent where required.

7. AI-assisted features

Physicare can help prepare transcripts, summaries, draft notes, structured content, documentation suggestions and administrative support. These outputs assist the clinician. They may be incomplete, inaccurate, outdated, biased or inappropriate and must be reviewed before use.

Physicare does not use AI to make solely automated decisions with legal or similarly significant effects. Identifiable customer data is not used to train generalized third-party AI models unless covered by a separate written agreement or lawful program. De-identified or anonymized data may be used for analytics, research or product improvement where permitted and protected by appropriate safeguards.

8. When information is disclosed

Physicare does not sell personal information.

  • Service providers and subprocessors that help operate the service.
  • The customer organization and its authorized users.
  • Authorities or other parties when required by law, legal process, safety or security needs.
  • A successor or relevant party during a merger, financing, reorganization or sale, subject to appropriate safeguards.

9. Hosting and international transfers

Physicare primarily hosts production data in Canada. Some providers may process limited information outside Quebec or Canada, including in the United States. Information processed in another country may be subject to lawful access there.

Where required, safeguards may include contracts, transfer impact assessments, standard contractual clauses and technical or organizational measures. A material subprocessor list is maintained and made available when required.

10. Security

Physicare uses administrative, technical and physical safeguards appropriate to the sensitivity of the information. Measures may include encryption in transit and at rest, role-based access, least privilege, authentication, monitoring, logging, secure hosting, backups, recovery procedures, confidentiality requirements and incident response. No system can be guaranteed completely secure.

11. Retention and deletion

Information is kept only as long as needed for the service, the customer agreement and applicable law. Customer data follows customer instructions and contractual, legal, backup and deletion schedules. Account, billing, audit, security and legal records may be retained longer when there is a legitimate need.

When Physicare acts for a customer, return, export, retention, deletion and destruction are governed mainly by that customer’s agreement and instructions.

12. Your privacy rights

Depending on the law, you may be able to request access, correction, deletion, restriction or portability, object to certain processing, withdraw consent, or complain to a privacy authority.

Requests involving data controlled by a clinic may be sent to that clinic, with Physicare assisting as required. For information Physicare controls, email privacy@physicare.ai. We may need to verify your identity before completing a request.

13. Privacy and security incidents

Physicare maintains processes to identify, investigate, document and respond to incidents. If a breach affects customer data, the customer is notified without undue delay. Physicare also provides notices to individuals or regulators when legally required.

14. Cookies and analytics

The website and service use strictly necessary cookies. Optional analytics cookies may be used where permitted and, when required, only after consent. Available consent tools can be used to manage cookie preferences.

15. Minors

Physicare is not directed to children as independent users. A clinic may use the service while caring for a minor. In that case, the customer is responsible for the authority, notices and consents required by law.

16. EEA and United Kingdom

Where the GDPR or UK GDPR applies, customers remain responsible for the required legal basis, health-data condition and transparency when Physicare processes information for them. Applicable transfer safeguards may include standard contractual clauses, the UK International Data Transfer Addendum or Agreement, and supplementary measures. Physicare will appoint an EU representative where Article 27 requires one.

17. Changes to this policy

This policy may be updated as the service, laws or practices change. Material changes will receive reasonable notice by email, through the service or by another appropriate method. The date at the top shows the latest revision.

18. Contact and complaints

Contact Physicare with privacy questions or requests using the details below. You may also complain to the privacy authority that has jurisdiction where you live or work.

Legal

Contact Physicare

For privacy questions, requests or concerns, contact our privacy team.

Mailing address
Physicare Inc.
#300 - 204 Rue du St.-Sacrement
Montréal, QC H2Y 1W8
View the current policy on Physicare.ai