Privacy Policy

Colib Technology Inc. - Protection of Personal Information Policy

Last updated: 2026-07-21

This policy explains, in simple and clear terms, how Colib Technology Inc. ("Colib", "we") collects, uses, discloses, retains and destroys personal information, including personal health information, on the colib platform. It applies to our two sites: the clinic and practitioner portal (www.colib.io) and the patient portal (portal.colib.io).

Colib complies with the applicable Canadian federal and provincial privacy laws, including:

  • Law 25 (Québec)
  • LPRPSP (Québec)
  • PIPEDA (Canada)
  • PHIPA (Ontario)
  • PIPA (British Columbia)
  • HIA (Alberta)

OUR ROLE AND YOUR CLINIC'S ROLE

colib is an electronic health record (EHR) and online booking platform used by clinics and health professionals across Canada.

When your clinic uses colib to manage your file, the clinic or the health professional remains responsible for your record: it determines which information is collected and for which purposes. Colib acts as the clinic's service provider: we host and process this information on the clinic's behalf, under strict confidentiality and security obligations.

For the information you provide directly to Colib (for example when a clinic subscribes to the platform, or when you create your patient portal account), Colib is responsible for its protection.

PERSONAL INFORMATION WE COLLECT

The information processed by the platform falls into the following categories:

  • Identity and contact information: name, date of birth, email, phone, address, emergency contact, preferred language.
  • Health record information: clinical notes, responses to forms and questionnaires, documents and files, assessment scores - entered by your practitioner or provided by you.
  • Custom fields and forms: your clinic may define its own fields and questionnaires; colib treats the answers as potentially sensitive health information.
  • Appointments and communications: bookings, waiting lists, secure messaging, SMS and email notifications.
  • Telehealth: video consultations and, where enabled by your practitioner, audio transcription and AI-assisted note generation (see the Artificial intelligence section below).
  • Billing and insurance information: invoices, payments and insurance coverage; card numbers are tokenized by our payment provider and are never stored by colib.
  • Account and technical information: login identifiers, hashed passwords, two-factor authentication codes, sessions, IP address and access audit logs.
  • Website visitors and users: device information collected through cookies and similar technologies (see the Cookies and analytics section below).

HOW DO WE USE YOUR PERSONAL INFORMATION?

We use personal information only to provide, secure, maintain and improve the platform:

  • delivering the services to your clinic: records, scheduling, billing, communications and telehealth;
  • authenticating users and securing access to the platform;
  • providing support to clinics and patients;
  • meeting our legal and contractual obligations.

Health information is never used for advertising purposes and is never sold to third parties.

ARTIFICIAL INTELLIGENCE

Some features of the platform use an artificial intelligence component, for example the transcription of telehealth sessions and the generation of clinical note drafts. These features are enabled and triggered by your clinic and your practitioner, and the resulting note is marked as AI-generated in the record. Audio transcription is performed within colib's own infrastructure in Canada; the audio is not sent to any third-party service. Note drafts are generated by the Claude model (Anthropic) through the Amazon Bedrock managed service: your information remains stored at rest in Canada, and the AI processing itself runs in memory only, on AWS infrastructure located in Canada or the United States, over encrypted connections. The AI service does not store the content submitted to it, does not use it to train AI models, and does not share it with the model provider. By default, the audio recording and the transcript are deleted a few hours after the note is generated, unless your practitioner chooses to keep them in your record as an encrypted private document. For more details, see our artificial intelligence page.

SHARING YOUR PERSONAL INFORMATION

We do not sell or rent personal information. We share personal information only with the service providers required to operate the platform, under contractual safeguards:

  • Amazon Web Services (AWS), Canada (Montreal) region - hosting, storage, telehealth and AI processing;
  • Redis Cloud and MongoDB Atlas, hosted in the Canada (Montreal) region - cache and audit log;
  • Stripe - payment processing and card tokenization;
  • communication providers used to deliver SMS and email notifications.

We may also disclose personal information where required by law, or to respond to a lawful request from an authority.

Colib's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

DATA RESIDENCY

All personal information and health information managed by the platform is stored at rest in Canada: AWS Canada (Montreal) region and managed services located in Canada. Two limited exceptions involve processing outside Canada: the transient AI inference described in the Artificial intelligence section (in memory only), and payment processing by Stripe; audience-measurement data from our sites is also processed by its providers outside Canada. No health record information is ever sent to Stripe; the client's first name, last name and email are anonymized before transmission, and only the payment information itself is transmitted as-is.

SECURITY

colib applies a defence-in-depth security architecture:

  • encryption in transit (HTTPS/TLS) and at rest, plus application-level AES-256 encryption of sensitive information;
  • strict access controls, per-clinic isolation and explicit sharing to the patient;
  • strong password policy and two-factor authentication;
  • audit logging of every consultation, creation, modification and deletion;
  • daily backups in Canada;
  • regular independent penetration tests.

For more details, see our security page.

RETENTION AND DESTRUCTION

We retain personal information only as long as necessary for the purposes described above and to meet our legal obligations.

  • Health records are retained on behalf of your clinic for as long as the clinic maintains them, in accordance with the professional retention rules that apply to the clinic.
  • When a record or an appointment is deleted by the clinic, it is physically and irreversibly purged 45 days after its deletion, together with all related data.
  • When a clinic stops using the platform, all of its data - including the patient records attached to it - is automatically and permanently deleted after 18 months.
  • Temporary data (import files, drafts, abandoned online bookings) is purged automatically on a documented schedule.
  • Access audit logs are retained for 18 months.

YOUR RIGHTS

You may access the personal information we hold about you, request that it be rectified, and withdraw your consent where applicable. You may also obtain a copy of the computerized personal information you have provided, in a structured and commonly used technological format (right to portability under Law 25).

  • For your health record, address your request first to your clinic, which remains responsible for it; colib assists the clinic in responding.
  • For information held directly by Colib (such as your patient portal account), contact our Privacy Officer using the details below.

Requests are addressed to our Privacy Officer (see the contact details below) and are answered within 30 days, as provided by law. You may also file a complaint with the Commission d'acces a l'information du Quebec or the privacy regulator of your province.

COOKIES AND ANALYTICS

Our sites use cookies and similar technologies (log files, pixels) to measure audience, improve our services and support our marketing, including Google Analytics, Google Ads and the Facebook pixel. These tools measure page views and interactions with the sites; the content of health records (notes, forms, messages, documents) is never transmitted to them.

You can disable cookies in your browser and opt out of these services here:

  • FACEBOOK - https://www.facebook.com/settings/?tab=ads
  • GOOGLE - https://www.google.com/settings/ads/anonymous
  • Digital Advertising Alliance - http://optout.aboutads.info/
  • Google Analytics - https://tools.google.com/dlpage/gaoptout

CONFIDENTIALITY INCIDENTS

Any incident involving personal information (unauthorized access, use, disclosure or loss) is handled under a documented procedure: containment, assessment of the risk of injury, recording in our incident register, correction and notification. Where an incident presents a risk of serious injury, we notify the affected clinics and persons as well as the Commission d'acces a l'information, as required by law.

PRIVACY OFFICER

The person in charge of the protection of personal information at Colib is:

Thibault Bréboin
Privacy Officer, Colib Technology Inc.
thibault@colib.io

CHANGES

We may update this policy from time to time to reflect changes to our practices or for legal or regulatory reasons. The current version is always available on this page, with its effective date shown at the top.

CONTACT US

For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at support@colib.io