1. Our commitment and scope
Structura Health Inc. (“Structura”, “we”) builds software that helps healthcare clinics manage privacy, security and regulatory-readiness. This policy explains how we handle personal information for which Structura is responsible as an organization — primarily the personal information of our website visitors, prospects, customer contacts and Authorized Users (collectively, our “business contacts”).
Two different roles — please read carefully.
Structura as controller of its own data. For business-contact and website data, Structura decides the purposes and means, and this policy governs.
Structura as processor / PHIPA agent / electronic service provider. When our customers (clinics) load patient or staff data — including Personal Health Information (PHI) — into the Service, the clinic is the health information custodian and Structura processes that data only on the clinic’s instructions under our customer agreement and Data Processing Agreement (DPA). We do not use customer-loaded PHI for our own purposes. Individuals with questions about how a clinic handles their PHI should contact that clinic; we will support the custodian in responding.
2. Privacy Officer (Accountability)
Structura is accountable for personal information under its control and has appointed a Privacy Officer responsible for compliance with this policy and applicable privacy laws. Under Quebec’s Law 25, the person with the highest authority is the Privacy Officer by default unless the role is delegated in writing.
Contact the Privacy Officer at [email protected].
3. What personal information we collect
We collect only what we need for the purposes below:
- Account & contact data: name, business email, phone, employer, role, credentials provided at signup.
- Usage & technical data: log data, IP address, device/browser, feature usage, audit-trail events.
- Communications: support requests, demo requests, sales correspondence.
- Billing data: billing contact, addresses, tax/registration numbers (payment card data is handled by our payment processor, not stored by us).
- Website data: cookies/analytics as described in Section 9.
We do not seek to collect PHI through our marketing channels. PHI enters the Service only via customer use and is governed by the DPA.
4. Why we use it and our legal basis (Consent)
We use personal information to provide and secure the Service; authenticate users; communicate about accounts, support and service changes; bill and collect; meet legal and tax obligations; and improve and market the Service to business contacts.
We rely on consent (express or implied as appropriate to sensitivity and context) and other lawful bases. For sensitive information and for purposes under Quebec’s Law 25, we seek clear, specific, informed consent, and you may withdraw consent subject to legal/contractual limits.
5. Disclosure, subprocessors and service providers
We do not sell personal information. We disclose it only to subprocessors that help us run the Service (cloud hosting, email, analytics, support tooling), bound by contract to comparable protection; to professional advisors, auditors and authorities where required by law or to protect rights; and to successors in a corporate transaction, subject to this policy. We maintain and update a subprocessor list and will notify affected customers of material changes per the DPA.
6. Data residency and cross-border transfers
Canadian data-residency infrastructure is on our roadmap and is not yet our current infrastructure; we will update this section and notify customers before onboarding any production customer data, and no production customer data is hosted under this policy until that update is made. In the interim, and for any data currently processed outside Canada, we use contractual and technical safeguards to ensure comparable protection. Where Quebec residents’ personal information is transferred outside Quebec, we conduct a Privacy Impact Assessment and apply Law 25 transfer safeguards. PHIPA does not prohibit out-of-province processing, but the custodian remains accountable; our DPA documents the controls.
7. Safeguards
We protect personal information with administrative, technical and physical safeguards proportionate to sensitivity, including encryption in transit and at rest, role-based access control, audit logging, least-privilege access, secure development practices, vulnerability management, vendor due diligence, and staff confidentiality and training. Our security program is aligned to CCCS guidance and is pursuing a SOC 2 readiness program — a roadmap milestone, not a current certification.
8. Breach response and notification
We maintain a breach-response runbook. If a breach of security safeguards creates a real risk of significant harm, we will, as soon as feasible: notify affected individuals and the Office of the Privacy Commissioner of Canada as required by PIPEDA; where the data is customer PHI, notify the affected customer (custodian) at the first reasonable opportunity so the custodian can meet its PHIPA obligations; and notify the Commission d’accès à l’information du Québec and affected individuals where Law 25 applies. We keep records of breaches of security safeguards for at least 24 months as required by PIPEDA.
9. Cookies and analytics
Our website uses cookies and analytics to operate the site and understand usage. Where required — including for Quebec visitors and certain tracking technologies under Law 25 — we obtain opt-in consent via a cookie banner and provide controls to manage preferences.
10. Retention and accuracy
We retain personal information only as long as needed for the purposes collected or as required by law, then delete or de-identify it. We take reasonable steps to keep information accurate and up to date and will correct it on request.
11. Your rights
Subject to law, you may access the personal information we hold about you; request correction; withdraw consent; and, where Law 25 applies, request portability, de-indexation, and information about automated decision-making. To exercise rights or raise a concern, contact the Privacy Officer. We will respond within legally required timeframes. If you are unsatisfied, you may complain to the OPC (federal), the Office of the Information and Privacy Commissioner of Alberta, the Ontario IPC (PHIPA matters), or the CAI Québec (Law 25), as applicable.
12. Children
The Service is a B2B tool not directed to children; we do not knowingly collect children’s personal information through our business channels.
13. Changes
We may update this policy; material changes will be posted with a new effective date and, where required, communicated directly.
Privacy questions? Contact our Privacy Officer at [email protected] or read our Terms of Service.