Privacy Policy

Colib Technology Inc. - Protection of Personal Information Policy

Last updated: 2026-08-31

This policy explains, in simple and clear terms, how Colib Technology Inc. ("Colib", "we") collects, uses, discloses, retains and destroys personal information, including personal health information, on the colib platform. It applies to our two sites: the clinic and practitioner portal (www.colib.io) and the patient portal (portal.colib.io).

Colib complies with the applicable Canadian federal and provincial privacy laws, including:

  • Law 25 (Québec)
  • LPRPSP (Québec)
  • PIPEDA (Canada)
  • PHIPA (Ontario)
  • PIPA (British Columbia)
  • HIA (Alberta)

OUR ROLE AND YOUR CLINIC'S ROLE

colib is an electronic health record (EHR) and online booking platform used by clinics and health professionals across Canada.

When your clinic uses colib to manage your file, the clinic or the health professional remains responsible for your record: it determines which information is collected and for which purposes. Colib acts as the clinic's service provider: we host and process this information on the clinic's behalf, under strict confidentiality and security obligations.

For the information you provide directly to Colib (for example when a clinic subscribes to the platform, or when you create your patient portal account), Colib is responsible for its protection.

PERSONAL INFORMATION WE COLLECT

The information processed by the platform falls into the following categories:

  • Identity and contact information: name, date of birth, email, phone, address, emergency contact, preferred language.
  • Health record information: clinical notes, responses to forms and questionnaires, documents and files, assessment scores - entered by your practitioner or provided by you.
  • Custom fields and forms: your clinic may define its own fields and questionnaires; colib treats the answers as potentially sensitive health information.
  • Appointments and communications: bookings, waiting lists, secure messaging, SMS and email notifications.
  • Telehealth: video consultations and, where enabled by your practitioner, audio transcription and AI-assisted note generation (see the Artificial intelligence section below).
  • Billing and insurance information: invoices, payments and insurance coverage. Card numbers are exchanged with our payment processor for a token at the moment of entry and are never stored by colib: we retain only the token, the last four digits, the expiry date and the card's country. No user of the platform, whether at the clinic or at colib, can display a full card number, and colib does not place preauthorizations or holds on cards.
  • Account and technical information: login identifiers, hashed passwords, two-factor authentication codes, sessions, IP address and access audit logs.
  • Website visitors and users: device information collected through cookies and similar technologies (see the Cookies and analytics section below).

HOW DO WE USE YOUR PERSONAL INFORMATION?

We use personal information only to provide, secure, maintain and improve the platform:

  • delivering the services to your clinic: records, scheduling, billing, communications and telehealth;
  • authenticating users and securing access to the platform;
  • providing support to clinics and patients;
  • meeting our legal and contractual obligations.

Health information is never used for advertising purposes and is never sold to third parties.

ARTIFICIAL INTELLIGENCE

Some features of the platform use an artificial intelligence component, for example the transcription of telehealth sessions and the generation of clinical note drafts. These features are enabled and triggered by your clinic and your practitioner, and the resulting note is marked as AI-generated in the record. Audio transcription is performed within colib's own infrastructure in Canada; the audio is not sent to any third-party service. Note drafts are generated by the Claude model (Anthropic) through the Amazon Bedrock managed service: your information remains stored at rest in Canada, and the AI processing itself runs in memory only, on AWS infrastructure located in Canada or the United States, over encrypted connections. The AI service does not store the content submitted to it, does not use it to train AI models, and does not share it with the model provider. By default, the audio recording and the transcript are deleted within minutes of the session, as soon as the note has been generated, unless your practitioner chooses to keep them in your record as an encrypted private document. For more details, see our artificial intelligence page.

SHARING YOUR PERSONAL INFORMATION

We do not sell or rent personal information. We share personal information only with the service providers required to operate the platform, under contractual safeguards:

  • Amazon Web Services (AWS), Canada (Montreal) region - hosting, storage, telehealth and AI processing;
  • Redis Cloud and MongoDB Atlas, hosted in the Canada (Montreal) region - cache and audit log;
  • Stripe - payment processing and card tokenization; the card number is exchanged for a token at the moment of entry and is never stored by colib, and no colib employee can view a card number;
  • Telnyx and Twilio - delivery of text message notifications (the recipient's phone number and the content of the message); Telnyx is the provider used, Twilio serving only as a fallback;
  • Amazon SES and Amazon SNS, in the AWS Canada (Montreal) region - delivery of email notifications and of certain text message notifications;
  • Sentry - technical error and performance monitoring of the applications (see below);
  • Microsoft (Microsoft Graph) and Google (Google Calendar API) - calendar synchronisation, where a practitioner enables it;
  • Google (Places API) - address suggestions while an address is being typed;
  • CookieScript - management of your cookie consent choices.
  • YouTube (Google) - playback of presentation videos on our public pages; the player is loaded only after you accept, and we use the cookie-free player domain.
  • Freshworks - the support chat available to clinic staff on colib.io; the signed-in user's email address is pre-filled in the chat form, where it can be changed or removed, and the conversation and the details provided in it are processed by Freshworks. The chat is not present in the client portal.

Some technical files needed to display our pages (script libraries, icons) are served by the public content delivery networks jsDelivr and Cloudflare, which receive the IP address of the browser requesting them. Our text fonts are hosted on our own servers: displaying our pages sends no request, and therefore no IP address, to Google Fonts.

Sentry receives technical information used to detect and correct malfunctions: the address of the page, the error and its technical context, the browser and the IP address. A page address may contain a technical reference to a record; it never contains a name, an email address or any content of a health record, and colib removes those references before transmission. Error monitoring operates on all pages, including pages where you are signed in, so that malfunctions affecting your clinic can be detected and corrected. Performance monitoring, which sends navigation timings even when nothing goes wrong, is disabled on those pages.

We may also disclose personal information where required by law, or to respond to a lawful request from an authority.

Colib's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

DATA RESIDENCY

All personal information and health information managed by the platform is stored at rest in Canada: the AWS Canada (Montreal) region and managed services located in Canada. Backups are retained in Canada.

The following processing or access takes place outside Canada, and nothing else does:

  • the transient AI inference described in the Artificial intelligence section, which runs in memory only, in Canada or the United States, and is not retained by the provider;
  • payment processing by Stripe; no health record information is ever sent to Stripe, and the client's identity is replaced by an internal reference before transmission -- a pseudonymisation, not an anonymisation, since colib can re-associate that reference with the client;
  • audience measurement and advertising, processed by our providers outside Canada, as described in the Cookies and analytics section;
  • technical error monitoring by Sentry, hosted in the United States, which receives the information described in the Sharing section;
  • delivery of text message notifications by Telnyx and, as a fallback, Twilio, both in the United States, and the support chat provided by Freshworks; our email notifications, by contrast, are sent from the AWS Canada (Montreal) region;
  • remote access to our Canadian systems by a small number of authorized colib personnel connecting from outside Canada, under named individual accounts, with multi-factor authentication, through a controlled VPN, and with every access logged; such access stores no personal information outside Canada.

Information processed outside Canada may be subject to the laws of the country where it is processed, including lawful requests from the courts or public authorities of that country. Communications of personal information outside Quebec also occur; every person and service provider concerned is bound by confidentiality and security obligations towards colib.

A small, fixed list of named colib administrators may attach their own account to a clinic for support and maintenance; that list is defined in the application's source code and cannot be extended without a code change. Their identity is never substituted for a user's: every action they take is written to the clinic's own audit log under their own name, where the clinic can see it.

SECURITY

colib applies a defence-in-depth security architecture:

  • encryption in transit (HTTPS/TLS) and at rest, plus application-level AES-256 encryption of sensitive information;
  • administrative access to production systems only through a controlled VPN, from named individual accounts and with multi-factor authentication; per-clinic isolation and explicit sharing to the patient;
  • strong password policy and two-factor authentication;
  • audit logging of every consultation, creation, modification and deletion;
  • daily backups in Canada;
  • regular independent penetration tests.

For more details, see our security page.

RETENTION AND DESTRUCTION

We retain personal information only as long as necessary for the purposes described above and to meet our legal obligations.

  • Health records are retained on behalf of your clinic for as long as the clinic maintains them, in accordance with the professional retention rules that apply to the clinic.
  • When a record or an appointment is deleted by the clinic, it is physically and irreversibly purged 45 days after its deletion, together with all related data.
  • When a clinic stops using the platform, all of its data - including the patient records attached to it - is automatically and permanently deleted after 18 months.
  • Temporary data (import files, drafts, abandoned online bookings) is purged automatically on a documented schedule.
  • Certain operational data is deleted automatically after a fixed period, whether or not the clinic asks for it: the history of SMS messages and the log of emails sent after 365 days; cancelled appointments after 12 months (other calendar entries after 32 days); the history of appointment status changes and draft notes after 35 days; incomplete client records after 6 days; and absences 600 days after they end.
  • Clinical notes, invoices, documents and completed forms are never purged automatically: they remain in the record for as long as the clinic keeps it.
  • Access audit logs are retained for 18 months.

YOUR RIGHTS

You may access the personal information we hold about you, request that it be rectified, and withdraw your consent where applicable. You may also obtain a copy of the computerized personal information you have provided, in a structured and commonly used technological format (right to portability under Law 25).

  • For your health record, address your request first to your clinic, which remains responsible for it; colib assists the clinic in responding.
  • For information held directly by Colib (such as your patient portal account), contact our Privacy Officer using the details below.

Requests are addressed to our Privacy Officer (see the contact details below) and are answered within 30 days, as provided by law. You may also file a complaint with the Commission d'acces a l'information du Quebec or the privacy regulator of your province.

COOKIES AND ANALYTICS

colib uses cookies and similar technologies (log files, pixels) to measure audience and improve our services. Not every part of the platform carries the same technologies:

  • Google Analytics is used for audience measurement on colib.io and in the client portal, including on pages where you are signed in.
  • Google Ads is used on our public pages: our marketing and information pages, and the public practice and booking pages of the clinics that use colib, to measure the performance of our own advertising campaigns. The Facebook pixel is used on our marketing and information pages only. Neither is present in the client portal, nor in the practitioner application, nor when the booking module is embedded as a widget in a clinic's own website.
  • When the booking module is embedded as a widget in a clinic's own website, no colib measurement or advertising tag is loaded at all.

The information transmitted to these tools is limited to: the address and the title of the page visited, the referring page, the IP address, the browser, the operating system and the device type, and a randomly generated cookie identifier. A page address may contain a technical reference to a record or to an appointment; it never contains a name, an email address, a diagnosis or any content of a health record. colib sends these tools no appointment event, no account name and no answer to a form or a questionnaire.

colib does not use the information of platform users for advertising. We do not upload client lists to Google or to Meta, we do not use advanced or audience matching, and we do not build remarketing or targeted advertising audiences from the users of the platform. The content of health records is never used for advertising purposes, and no information held by the platform is ever sold.

A clinic may also configure its own Google Analytics, Google Tag Manager or Google Ads identifiers on its public practice page and booking page. Those tags belong to the clinic, which is responsible for them; where they are enabled, a booking confirmation sends the clinic's own tags a booking reference, the name of the appointment type and the name of the clinic.

A consent banner is presented before any cookie or measurement technology that is not strictly necessary is placed on your device. Until you accept, and if you refuse, no measurement or advertising cookie is placed and no identifier is created: the Google tags operate in a restricted mode in which they store nothing on your device and receive only limited technical information -- the address of the page, the IP address and the browser -- with no identifier attached to you. The Facebook pixel and our embedded video player are not loaded at all until you accept. You can accept or refuse by category and change your choice at any time from the banner; refusing has no effect on your ability to use the platform.

Cookies are grouped into four categories, which you can accept or refuse separately. Strictly necessary cookies keep you signed in, protect the forms you submit, remember your language and your time zone, and hold a booking or a shopping cart in progress; they cannot be refused, because without them the service cannot be delivered. Functionality cookies remember minor display preferences. Performance cookies are the Google Analytics measurement cookies. Targeting cookies are the advertising cookies and those set by the embedded video player. The full list of the cookies we use, with their purpose and their lifetime, is available from the banner at any time.

You can disable cookies in your browser and opt out of these services here:

  • FACEBOOK - https://www.facebook.com/settings/?tab=ads
  • GOOGLE - https://www.google.com/settings/ads/anonymous
  • Digital Advertising Alliance - http://optout.aboutads.info/
  • Google Analytics - https://tools.google.com/dlpage/gaoptout

CONFIDENTIALITY INCIDENTS

Any incident involving personal information (unauthorized access, use, disclosure or loss) is handled under a documented procedure: containment, assessment of the risk of injury, recording in our incident register, correction and notification. Where an incident presents a risk of serious injury, we notify the affected clinics and persons as well as the Commission d'acces a l'information, as required by law.

PRIVACY OFFICER

The person in charge of the protection of personal information at Colib is:

Thibault Bréboin
Privacy Officer, Colib Technology Inc.
thibault@colib.io

CHANGES

We may update this policy from time to time to reflect changes to our practices or for legal or regulatory reasons. The current version is always available on this page, with its effective date shown at the top.

CONTACT US

For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at support@colib.io