Testerup to 1 year freeJoin

Privacy Policy — Physicare.ai

Last updated: March 2, 2026

1. Introduction

Physicare.ai ("we", "our", "us") is a Canadian platform that provides intelligent tools to rehabilitation professionals to assist them with clinical documentation, treatment planning, and patient monitoring.

We are committed to protecting the privacy and personal information of all our users. This privacy policy ("Policy") describes how we collect, use, retain, protect, and disclose your personal information, in accordance with An Act to modernize legislative provisions as regards the protection of personal information (commonly known as "Law 25", Quebec) and the Personal Information Protection and Electronic Documents Act (PIPEDA, Canada).

2. Person Responsible for the Protection of Personal Information

In accordance with Law 25, we have designated a person responsible for the protection of personal information (PRPPI) whose contact details are as follows:

Name : William Prud'homme

Email : privacy@physicare.ai

Mailing address : #300 – 204 Saint-Sacrement Street, Montreal, Quebec H2Y 1W8

The PRPPI is the point of contact for any question, request, or complaint regarding the protection of your personal information. You may contact them at any time.

3. Scope of the Policy

This Policy applies to all users of the Physicare.ai platform, including healthcare professionals (physiotherapists, occupational therapists, kinesiologists, and other rehabilitation professionals) and patients.

4. Personal Information Collected

We limit the collection of personal information to what is necessary for the purposes identified in Section 5 of this Policy. We collect the following categories of personal information:

4.1 Identification Information

Last name, first name, email address, and password (encrypted).

4.2 Health Information (Sensitive Information)

Clinical observations, treatment plans, diagnoses, prescribed exercises, follow-up notes, and audio recordings of clinical sessions.

4.3 Technical and Usage Information

Usage logs, preferences, connection information (date, time, IP address), device type, operating system, and browser version.

4.4 Payment Information

Payment transactions are processed by Stripe. Physicare.ai does not store your credit card numbers. Only transaction identifiers and billing history are retained.

4.5 Data Collected Through Tracking Technologies

We use Google Analytics and Microsoft Clarity to analyze platform usage. These tools collect aggregated browsing data, such as pages viewed, session duration, and interactions on the platform. This data is used solely for service improvement purposes. You can manage your cookie and tracking preferences through our consent banner during your first visit. By default, only cookies strictly necessary for the operation of the platform are enabled.

5. Purposes of Collection and Processing

Your personal information is collected and processed for the following specific purposes:

5.1 Clinical Service Delivery

Provide clinical documentation, treatment planning, and patient monitoring features.

5.2 Platform Operation and Improvement

Ensure the proper technical operation of the platform, personalize the user experience, and improve our services.

5.3 Administrative Communications and Technical Support

Send account-related communications (registration confirmation, billing, service change notifications) and provide technical support.

5.4 Artificial Intelligence Improvement (Separate Purpose — Separate Consent Required)

Subject to your explicit and separate consent, health data may be irreversibly anonymized (through PHI masking) and then used to train and improve our artificial intelligence models. This anonymized data cannot in any way identify a user. You may refuse this use without any consequence on your access to the platform's services.

6. Consent

6.1 General Principle

Consent is required for the collection, use, and disclosure of your personal information. Given the sensitive nature of the health information processed by Physicare.ai, we obtain manifest, free, informed consent given for specific purposes, in accordance with Law 25.

6.2 Separate Consents

When creating your account and using the platform, you will be asked to consent separately to the following purposes:

  • Clinical service delivery (sections 5.1 and 5.2) — required for platform use.
  • Administrative communications (section 5.3) — required for platform use.
  • Use of anonymized data for AI improvement (section 5.4) — optional.
  • Use of third-party analytical cookies, Google Analytics and Microsoft Clarity (section 4.5) — optional.

6.3 Right to Withdraw Consent

You may withdraw your consent at any time by changing your preferences in your account settings or by contacting our PRPPI at privacy@physicare.ai. Withdrawing consent for essential purposes (sections 5.1 to 5.3) may limit or prevent the use of certain platform features. Withdrawal of consent takes effect upon receipt and is not retroactive.

7. Use of Artificial Intelligence

7.1 Nature of AI

Physicare.ai integrates artificial intelligence tools that generate suggestions for clinical documentation, treatment plans, diagnoses, and exercises. These tools serve exclusively as decision-support aids for rehabilitation professionals.

7.2 No Fully Automated Decisions

No decision affecting users is made in a fully automated manner by our platform. The healthcare professional retains full control and responsibility at all times to validate, modify, or reject any AI-generated suggestion before its application.

7.3 Transparency

Content generated by artificial intelligence is clearly identified as such on the platform. AI suggestions do not in any way replace professional clinical judgment.

8. Data Retention and Deletion

8.1 Retention Periods

Personal information is retained for the following periods:

  • Account data (identification, preferences): retained for the duration of account use, then anonymized within 90 days following permanent account closure.
  • Clinical and health data: retained for the duration of account use. Upon account closure, data is anonymized and retained only in non-identifiable form. Healthcare professionals are responsible for complying with minimum retention periods required by professional orders and applicable laws (for example, a minimum of five years for certain clinical records) and must retain their own copies in accordance with these obligations before closing their account.
  • Audio recordings: retained for a maximum of 90 days after creation, then permanently deleted.
  • Technical data and usage logs: retained for a maximum of 12 months.
  • Billing data: retained in accordance with applicable tax and accounting requirements (generally six years).

8.2 Data Deletion

You may request the complete deletion of your account and personal information by contacting privacy@physicare.ai. We will process your request within 30 days. Certain data may be retained beyond this period if required by law (tax obligations, professional obligations, ongoing litigation).

9. Hosting, Subcontractors, and Data Transfers

9.1 Hosting

Data is securely hosted in data centers located in Canada, primarily through Google Cloud Platform (Montreal region) and Amazon Web Services (Canada region).

9.2 Subcontractors

We use the following service providers in the operation of the platform:

ProviderFunctionData Location
Google Cloud PlatformPrimary hostingMontreal, Canada
Amazon Web Services (AWS)Service infrastructureCanada
StripePayment processingUnited States and Canada
Google AnalyticsPlatform usage analyticsUnited States
Microsoft ClarityPlatform usage analyticsUnited States
OpenAIAI inference (clinical suggestion generation)United States
Google GeminiAI inference (clinical suggestion generation)United States
AnthropicAI inference (clinical suggestion generation)United States

Each subcontractor is contractually required to protect your personal information in accordance with standards at least equivalent to those set out in this Policy and by applicable laws. All data transmitted to AI providers (OpenAI, Google Gemini, Anthropic) for inference undergoes protected health information masking (PHI masking) before transmission, so that no data that could directly identify an individual is sent to these providers. This data is not used by these providers to train their models.

9.3 Transfers Outside Quebec

Certain subcontractors (Stripe, Google Analytics, Microsoft Clarity, OpenAI, Google Gemini, Anthropic) may process data outside Quebec or Canada. In accordance with Law 25, a privacy impact assessment (PIA) is conducted before any transfer of personal information outside Quebec to ensure that the data receives adequate protection. Physicare.ai commits to transferring personal information only to jurisdictions offering a level of protection equivalent to that of Quebec, or to implementing appropriate contractual measures to ensure such protection.

9.4 No Sale of Data

No personal information is sold, rented, or exchanged to third parties for commercial or advertising purposes.

10. Data Security

We implement reasonable technical and organizational security measures to protect your personal information against unauthorized access, loss, alteration, or disclosure. These measures include encryption of data in transit and at rest, secure user authentication, role-based access management and the principle of least privilege, logging and monitoring of data access, and staff training in security best practices.

11. Data Accuracy

In accordance with the sixth principle of PIPEDA and the requirements of Law 25, Physicare.ai is committed to ensuring that personal information held is as accurate, complete, and up-to-date as necessary to fulfill the purposes for which it is used. Professionals are encouraged to keep their patients' clinical information up to date and to report any inaccuracies. Users may at any time request the rectification of their personal information by contacting our Person Responsible for the Protection of Personal Information at privacy@physicare.ai.

12. Confidentiality Incident Management

Physicare.ai maintains a register of all confidentiality incidents, whether they involve unauthorized access, use, or disclosure of personal information, or the loss of personal information. This register is retained for a minimum period of 24 months from the date the incident was identified. In the event of an incident, we conduct a serious harm risk assessment. When an incident presents a real risk of significant harm, we notify the relevant authorities and affected individuals as soon as possible, in accordance with both applicable regimes: for users residing in Quebec, the Commission d'accès à l'information du Québec (CAI) is notified in accordance with Law 25; for users residing elsewhere in Canada, the Office of the Privacy Commissioner of Canada (OPC) is notified in accordance with PIPEDA. The register contains sufficient detail to allow the relevant authorities to verify Physicare.ai's compliance with its breach notification obligations.

13. Privacy Impact Assessment (PIA)

In accordance with Law 25, Physicare.ai conducts privacy impact assessments before any project involving the collection, use, or disclosure of personal information, including before implementing new features, before any transfer of personal information outside Quebec, and before acquiring or developing new data processing systems.

14. Privacy by Default

In accordance with Law 25, the privacy settings of the Physicare.ai platform are configured by default to the highest level of privacy. Analytical cookies and non-essential tracking technologies are disabled by default. Any feature involving broader data sharing or visibility requires voluntary activation by the user.

15. Your Rights

In accordance with Law 25 and PIPEDA, you have the following rights:

  • Right of access: You may request access to all personal information we hold about you.
  • Right of rectification: You may request the correction of inaccurate, incomplete, or ambiguous personal information.
  • Right to withdraw consent: You may withdraw your consent to the collection, use, or disclosure of your personal information, subject to legal or contractual restrictions.
  • Right to deletion (right to erasure): You may request the deletion of your personal information when collection or processing is no longer necessary for the purposes for which it was collected.
  • Right to portability: You may request to receive your personal information in a structured, commonly used technological format, and request that it be transmitted to another organization, to the extent technically feasible.
  • Right to challenge compliance and file a complaint: You may challenge Physicare.ai's compliance with personal information protection principles by addressing your challenge to our Person Responsible for the Protection of Personal Information (PRPPI) at privacy@physicare.ai. We will acknowledge receipt of your complaint, conduct an investigation, and communicate the outcome to you within a reasonable timeframe. If you are not satisfied with our response, you may file a complaint with the relevant authority: the Commission d'accès à l'information du Québec (CAI) for users residing in Quebec, or the Office of the Privacy Commissioner of Canada (OPC) for users residing elsewhere in Canada.

To exercise any of these rights, contact our PRPPI at privacy@physicare.ai. We will process your request within 30 days of receipt.

16. Information Concerning Minors

Physicare.ai does not knowingly collect personal information from minors (under 14 years of age in Quebec) without the consent of a parent or legal guardian. If a minor is a patient of a professional using the platform, parental or guardian consent is required in accordance with applicable laws.

17. Changes to This Policy

We may update this Policy to reflect changes in our practices, services, or applicable legislation. In the event of a substantial change, we will notify you by email or by a prominently visible notice on the platform at least 30 days before the changes take effect. If the changes affect the purposes of collection or use of your personal information, new consent may be requested. Your continued use of the platform after the changes take effect constitutes acceptance of the updated Policy. If you do not accept the changes, you may stop using the platform and request the deletion of your account.

18. Contact Us

For any question, access request, rectification, deletion, portability, or any other request relating to your personal information, you may contact us:

Person Responsible for the Protection of Personal Information

William Prud'homme

Email : privacy@physicare.ai

Address : #300 – 204 Saint-Sacrement Street, Montreal, Quebec H2Y 1W8

For general technical support: support@physicare.ai

Physicare.ai is committed to upholding the highest standards in personal information protection in a digital health context.

Physicare.ai - Healthcare Consultation Platform