Privacy Policy

    Version: 2026-08-22 · Effective: August 22, 2026

    How TherapyCRM handles account, technical, and client information for Canadian therapy practices.

    • Practices control their clients’ health information; TherapyCRM processes it for the practice.
    • Client information is not sold, used for advertising, or used to train AI models.
    • Some contracted providers may process information outside Canada, where foreign laws can apply.
    • Practice owners can disable AI-assisted features, and qualified users must review AI output.

    Initial production version: role separation, Canadian scope, AI handling, cross-border processing, safeguards, incidents, retention, and privacy rights.

    1. Scope and our role

    This Privacy Policy explains how DataInn ("TherapyCRM", "we", "us") handles personal information in connection with the TherapyCRM web application, parent portal, attendance app, AI assistant, and related support (the "Services"). It applies to the practices that subscribe to the Services ("Customers"), their staff, and — through the parent portal — the families the practice serves.

    We act in two different roles. For account, billing, and usage information about our Customers and their staff, we decide how the information is used and are accountable for it. For the client and family information a practice records in the Services ("Client Information"), the practice is the custodian or accountable organisation; we process that information only on the practice's instructions as its service provider or agent. If you are a client or parent, your practice is your first point of contact for access, correction, and consent questions, and this Policy describes what we do on the practice's behalf.

    2. Where the Services are offered

    The Services are offered to practices located in Canada, outside the Province of Quebec. We have not designed the Services for Quebec's specific privacy and language requirements and make no representation that they are suitable for use there, or in any other country. Practices are responsible for confirming suitability for their jurisdiction before placing personal information in the Services.

    3. Information we handle

    Account and practice information (we are accountable):

    • names, email addresses, phone numbers, roles, and credentials of practice owners and staff;
    • practice name, address, province, time zone, and billing details (payment card details are collected and stored by our payment processor, not by us);
    • records of acceptance of our Terms and this Policy, including the version, the person accepting, the time, and the network address used.

    Client Information (the practice is accountable; we process on its instructions):

    • client and family demographic and contact details, guardian and custody information, and consents;
    • appointments, attendance, schedules, and waitlists;
    • treatment plans, goals, session data, progress notes, assessments, and uploaded documents;
    • insurance, funding, and invoicing details;
    • messages sent to families through the Services and portal activity.

    Technical information (we are accountable):

    • device, browser, and network details; sign-in events; security and audit logs; and usage and performance measurements needed to operate and secure the Services.

    4. Why we use information

    • to provide, secure, support, and improve the Services;
    • to carry out a practice's instructions, including sending appointment reminders and other communications the practice configures;
    • to manage subscriptions, billing, and account security;
    • to produce audit trails and security records required of a health-information service provider;
    • to meet legal obligations and respond to lawful requests.

    We do not sell personal information, use Client Information for marketing, or use it to train artificial-intelligence models. Improvement work uses aggregated or de-identified measurements wherever possible.

    5. Consent

    Customers consent to our handling of account and technical information by accepting our Terms. Each practice is responsible for obtaining every consent needed for the Client Information it places in the Services — including consent from a parent or legal guardian for minors and consent for communications sent on its behalf — and for confirming a guardian's authority before granting portal access. Where the Services ask for a consent to be recorded, the recording is a convenience for the practice, not a substitute for the practice's own consent practices.

    6. AI-assisted features

    Some features use third-party artificial-intelligence models to draft, summarise, extract, or answer questions. Before any text is sent to a model provider, names, contact details, dates of birth, addresses, and similar identifiers are removed or replaced with placeholders, and the original values are restored only inside the Services. Only model providers hosted in North America are used, under terms that prohibit them from using content to train their models and that limit any retention to the short period needed to operate and secure their service. AI output is assistive only and must be reviewed by a qualified person. A practice owner can disable AI features for the whole practice in Practice Settings.

    7. Where information is stored and processed

    Client Information and account information are stored in North America. The application is operated from servers in Europe, which handle information in transit to deliver the Services. Service providers that support the Services may therefore process information outside Canada. While information is outside Canada it is subject to the laws of that jurisdiction, including lawful access by authorities there. We require every service provider to protect information to a standard comparable to our own and to use it only to provide their service to us.

    We may change or replace the providers and facilities we use, and move information between them, at any time without notice, provided the safeguards in this Policy are maintained and Client Information continues to be stored in North America. We will update this Policy and give practices at least 30 days' notice before storing Client Information outside North America.

    Practices that require all processing to remain in Canada should not place information in the Services.

    8. Who we share information with

    We share information only with:

    • service providers that host infrastructure, store files, deliver email and text messages, process payments, and supply artificial-intelligence models — each bound by contract to safeguard information and use it only for the service they provide to us;
    • the practice that is accountable for the information, and the people it authorises;
    • professional advisers and successors in connection with a financing, merger, or sale of the business, subject to this Policy;
    • authorities where required by law, a court order, or to protect the safety of a person.

    A list of the categories of service providers we use, and the countries where they process information, is available from our Privacy Officer on request.

    9. Safeguards

    We apply safeguards appropriate to health information, including multi-factor authentication, role-based access control, tenant isolation between practices, automatic session time-outs, audit logging of access to and changes in client records, encryption in transit, encryption at rest provided by our hosting providers, private storage for clinical documents, rate limiting, and security monitoring. Staff access to Client Information is limited to what operating and supporting the Services requires.

    Practices are responsible for their own devices, networks, staff training, the access rights they grant, and the credentials their users keep. No safeguard is perfect, and we do not guarantee that information can never be accessed without authorisation.

    10. Privacy incidents

    If we confirm that Client Information has been accessed, used, or disclosed without authorisation, or lost, we will notify the affected practice's designated contact without undue delay and within any period the law requires of us, tell the practice what we know, and cooperate with the practice's own obligations to notify individuals, regulators, or colleges. We keep a record of privacy incidents.

    11. Retention and deletion

    • Client Information is kept for as long as the practice's subscription is active and for a read-only export window of 30 days afterwards. It is then scheduled for deletion from active systems and removed from backups as they cycle out in the normal course.
    • Practices are responsible for exporting any records they must keep under their own retention obligations before the export window closes.
    • Account, billing, acceptance, and audit records are kept for as long as needed to meet legal, accounting, and security obligations, and then deleted or de-identified.

    12. Your rights

    Customers and their staff may ask us to access or correct the account information we hold about them. Clients and parents should direct requests to access, correct, or withdraw consent for Client Information to their practice, which is accountable for it; we will assist the practice in responding. Anyone may ask the Privacy Officer how their information has been handled, and may complain to the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner if not satisfied with our response.

    13. Children and minors

    The Services are used by practices that serve children and youth. Information about minors is collected by the practice under the consent of a parent or legal guardian, or of the minor where the practice determines the minor is capable of consenting, in accordance with the practice's professional obligations. We do not knowingly collect information from minors directly except through a portal account a practice has set up under a guardian's consent.

    14. Compliance posture

    The Services are designed to support practices subject to Canada's federal private-sector privacy law and provincial health-privacy statutes, including where TherapyCRM acts as an agent or service provider of a health-information custodian. We do not hold a privacy or security certification and do not claim one; we are pursuing an independent security attestation and will state it here only once it has been issued.

    15. Changes to this Policy

    We may update this Policy. Material changes are published with a new version date, and practice owners are asked to accept the new version in the application. Earlier versions are available from the Privacy Officer on request.

    16. Privacy Officer and contact

    Our Privacy Officer is accountable for our compliance with this Policy and can be reached at privacy@therapycrm.io. We acknowledge privacy inquiries within two business days and respond as required by law. Postal: DataInn, Privacy Officer, Ontario, Canada.

    Version history

    Published versions remain available for review.