ClinikaPath App Privacy Policy
Effective Date: April 11, 2026
1. INTRODUCTION
This App Privacy Policy describes how ClinikaPath ("we", "us", or "our") collects, uses, stores, and protects information within the ClinikaPath software application (the "App").
Scope Limitation:
This Privacy Policy applies strictly and exclusively to the authenticated ClinikaPath software application used by registered healthcare professionals and clinic administrators. It does not cover data collected by our public marketing website.
2. THE "ZERO-PHI" MANDATE
ClinikaPath is explicitly designed as a de-identified clinical visualization and educational tool. The App is not an Electronic Medical Record (EMR) or Electronic Health Record (EHR) system.
- Strict Prohibition: Users are strictly prohibited from entering Protected Health Information (PHI) or Personally Identifiable Information (PII) regarding patients into the App. This includes names, dates of birth, contact information, and government health identifiers.
- Anonymization Requirement: All patient profiles and treatment care plans must be created using anonymous, internal reference identifiers (e.g., "Patient #402").
- Because the App enforces this Zero-PHI data model, ClinikaPath does not process, store, or transmit PHI subject to the Health Insurance Portability and Accountability Act (HIPAA), the Personal Information Protection and Electronic Documents Act (PIPEDA), or the Personal Health Information Protection Act (PHIPA).
3. INFORMATION WE COLLECT
We collect information exclusively related to the clinician or administrative user holding the account.
a) Account and Clinician Data
When you register for a subscription, we collect:
- First and last name
- Professional email address
- Clinic or business name
- Account credentials (passwords are securely hashed)
b) De-identified Clinical Parameters
To generate the "Wavy Path" visualizations, we store the clinical inputs provided by the user:
- De-identified Patient IDs
- Diagnosis and treatment goals
- Customized milestone text, timelines, and care plan adjustments
- Plan generation prompts utilized by the clinician
c) Payment Information
We use a secure third-party payment processor (Stripe) to manage subscriptions. ClinikaPath does not directly collect or store your full credit card number. We only receive payment confirmation, billing history, and a billing address.
d) Usage and Diagnostic Data
We automatically collect technical data regarding your interaction with the App to ensure functionality and security, including:
- IP addresses and device identifiers
- Login timestamps and session durations
- Error logs and performance metrics
4. HOW WE USE YOUR INFORMATION
We use the collected information to:
- Provide, maintain, and authenticate access to the App.
- Process automatically generated treatment plans based on your inputs.
- Process subscription payments and manage your account.
- Provide technical support and respond to user inquiries.
- Monitor App stability, prevent fraud, and improve software performance.
5. THIRD-PARTY SUB-PROCESSORS AND AI INTEGRATION
ClinikaPath relies on trusted third-party infrastructure to deliver the App. We do not sell your personal data or your clinical templates to third parties.
- Artificial Intelligence Providers: Clinical inputs (Diagnosis, Goals, Timelines) are processed through enterprise-grade Large Language Models (such as Google Cloud Vertex AI or OpenAI API) to generate the baseline recovery care plans. Data transmitted to these enterprise APIs is not used to train public consumer AI models.
- Infrastructure & Hosting: The App and its databases are hosted on secure, industry-standard cloud infrastructure.
- Payment Processors: Billing data is securely managed by Stripe.
All third-party sub-processors are legally bound to strict data security and confidentiality standards.
6. DATA SECURITY
We implement robust administrative, technical, and physical safeguards to protect your account data and clinical templates, including:
- Encryption of data at rest and in transit (TLS/SSL).
- Role-based access controls for ClinikaPath administrators.
- Regular security monitoring and infrastructure updates.
While we strive to use commercially acceptable means to protect your data, no method of transmission over the Internet or electronic storage is 100% secure.
7. DATA RETENTION AND ACCOUNT DELETION
- Active Accounts: We retain your account information and clinical templates for as long as your subscription remains active.
- Cancelled Accounts: Upon subscription cancellation or account termination, ClinikaPath reserves the right to permanently delete all associated account data and generated care plans after 30 days.
- User Deletion Requests: You may request the immediate deletion of your account and associated data at any time by contacting our support team.
8. YOUR PRIVACY RIGHTS
As the account holder, you maintain the right to:
- Access and review the personal information associated with your account profile.
- Correct or update inaccurate account information.
- Request the export of your account data.
- Request the permanent deletion of your account.
9. GOVERNING LAW
This Privacy Policy shall be governed by and construed in accordance with the laws of the Province of Ontario and the federal laws of Canada applicable therein, without regard to its conflict of law provisions.
10. CHANGES TO THIS APP PRIVACY POLICY
We may update this App Privacy Policy periodically to reflect changes in our software practices or legal requirements. We will notify active subscribers of any material changes via email or an in-app notification prior to the change becoming effective.
11. CONTACT INFORMATION
For any questions, concerns, or data requests regarding the App or this Privacy Policy, please contact us at:
ClinikaPath
Email: info@clinikapath.com