PIPEDA
The Personal Information Protection and Electronic Documents Act (PIPEDA) is Canada's federal privacy law covering personal information collected in the course of commercial activity. This page describes how AcuClient is designed to support PIPEDA and what Canadian practitioners should know before onboarding.
Accountability
Effect Wellness Inc. is accountable for the personal information under its control, including information transferred to our sub-processors. A privacy point of contact is reachable at privacy@effectwellness.com.
Consent, purpose, and limitation
We collect and use personal information only for the purposes set out in the Privacy Policy: providing and improving the service, billing, operational communications, support, and legal compliance. When you enter client information into AcuClient as a practitioner, you are responsible for obtaining the consent required under PIPEDA (or, where applicable, provincial health-information legislation) for that collection and use.
Consent-capture tooling inside the product is being finalized as part of the launch release so that practitioner consent records are kept alongside the clients to whom they relate.
Accuracy, access, and correction
You can review and update account information at any time from your account settings. Clients of a practice can view their own records through the client portal and request corrections through their practitioner. To exercise access or correction rights with respect to personal information Effect Wellness Inc. holds directly about you, email privacy@effectwellness.com. We will respond within 30 days or explain any delay permitted by PIPEDA.
Safeguards
Technical and organizational safeguards are summarized on the Security page, including AES-256 encryption at rest, TLS 1.2+ in transit, role-based access, and monitoring of infrastructure.
Cross-border data transfer — honest disclosure
AcuClient is currently hosted on Supabase infrastructure in the United States (Oregon). As a result, personal information entered into the service is transferred to and stored in the United States, where it may be subject to US legal process. Canadian-region hosting is planned for a future platform upgrade; we will publish migration details here and in the Privacy Policy when that work is scheduled.
If your professional regulatory body or your own privacy policy requires Canadian data residency today, please contact us before onboarding clinical data so we can help you make an informed decision.
Breach notification
Effect Wellness Inc. maintains an incident-response procedure. If a breach of security safeguards is discovered that creates a real risk of significant harm, we will notify affected practitioners without unreasonable delay so that they can in turn notify the Office of the Privacy Commissioner of Canada and affected individuals as required by PIPEDA's mandatory breach-notification regime.
Retention and withdrawal of consent
Account and practice data are retained for the life of your subscription and then, after cancellation, for a 90-day export window before permanent deletion, except where longer retention is required by law or by the professional standards that apply to you. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice; withdrawal may affect our ability to continue providing the service.
Related pages
See the Privacy Policy, PHIPA page (Ontario health information), and Compliance overview.
AcuClient is operated by Effect Wellness Inc. For data-protection, privacy, or legal requests, email privacy@effectwellness.com. For general or product questions, use the contact details on our contact page.