Privacy Policy

Colib Technology Inc. - Protection of Personal Information Policy

Last updated: 2026-09-11

This policy explains, in simple and clear terms, how Colib Technology Inc. ("Colib", "we") collects, uses, discloses, retains and destroys personal information, including personal health information, on the colib platform. It applies to our two sites: the clinic and practitioner portal (www.colib.io) and the patient portal (portal.colib.io).

Colib complies with the applicable Canadian federal and provincial privacy laws, including:

  • Law 25 (Québec)
  • LPRPSP (Québec)
  • PIPEDA (Canada)
  • PHIPA (Ontario)
  • PIPA (British Columbia)
  • HIA (Alberta)

OUR ROLE AND YOUR CLINIC'S ROLE

colib is an electronic health record (EHR) and online booking platform used by clinics and health professionals across Canada.

When your clinic uses colib to manage your file, the clinic or the health professional remains responsible for your record: it determines which information is collected and for which purposes. Colib acts as the clinic's service provider: we host and process this information on the clinic's behalf, under strict confidentiality and security obligations.

For the information you provide directly to Colib (for example when a clinic subscribes to the platform, or when you create your patient portal account), Colib is responsible for its protection.

PERSONAL INFORMATION WE COLLECT

The information processed by the platform falls into the following categories:

  • Identity and contact information: name, date of birth, email, phone, address, emergency contact, preferred language.
  • Health insurance number: optional; your clinic enters it only where it is needed for direct billing or for the receipts required by your insurer or public plan. It is stored encrypted.
  • Health record information: clinical notes, responses to forms and questionnaires, documents and files, assessment scores - entered by your practitioner or provided by you.
  • Custom fields and forms: your clinic may define its own fields and questionnaires; colib treats the answers as potentially sensitive health information.
  • Appointments and communications: bookings, waiting lists, secure messaging, SMS and email notifications.
  • Telehealth: video consultations and, where enabled by your practitioner, audio transcription and AI-assisted note generation (see the Artificial intelligence section below).
  • In-person sessions: where enabled by your practitioner, an audio recording of the session, made after the practitioner has attested that you agreed to be recorded, its transcript and the resulting AI-assisted note draft.
  • Billing and insurance information: invoices, payments and insurance coverage. Card numbers are sent to our payment processor, which returns a token; colib stores only the token, the last four digits, the expiry date and the card's country. No user of the platform, whether at the clinic or at colib, can display a full card number, and colib does not place preauthorizations or holds on cards.
  • Account and technical information: login identifiers, hashed passwords, two-factor authentication codes, sessions, IP address, access audit logs, the record of your acceptance of our terms (version, date, encrypted IP address and browser), the devices used to sign in, and security events such as failed sign-ins and lockouts.
  • The consents you give (online booking terms and cancellation policy, text-message reminders, parent or guardian of a minor, form attestations), with the exact text you were shown, its version, the date and your encrypted IP address.
  • Website visitors and users: device information collected through cookies and similar technologies (see the Cookies and analytics section below).

HOW DO WE USE YOUR PERSONAL INFORMATION?

We use personal information only to provide, secure, maintain and improve the platform:

  • delivering the services to your clinic: records, scheduling, billing, communications and telehealth;
  • authenticating users and securing access to the platform;
  • providing support to clinics and patients;
  • meeting our legal and contractual obligations.

Health information is never used for advertising purposes and is never sold to third parties.

ARTIFICIAL INTELLIGENCE

Some features of the platform use an artificial intelligence component: the transcription of telehealth sessions, the generation of clinical note drafts, the rewriting assistant for notes, the extraction of a form's structure from an existing document, and voice dictation. These features are enabled and triggered by your clinic and your practitioner, and the resulting note is marked as AI-generated in the record. The transcription of telehealth sessions is performed first within colib's own infrastructure in Canada. If that transcription fails, and for voice dictation, the audio is transcribed by the Amazon Transcribe service in the AWS Canada (Montreal) region; the audio file is deleted from our storage as soon as the transcription is returned, and it is not used to train AI models. Note drafts, rewriting suggestions and form extractions are generated by a generative language model through the Amazon Bedrock managed service: your information is stored at rest in Canada only, and the model processes it in memory, for the few seconds a request lasts, over Amazon's private encrypted network. For clinics located in Quebec, and for clinics whose province is not recorded, that processing takes place in Canada, on a Mistral model hosted in the AWS Canada (Montreal) region. For other clinics, the Claude Sonnet 4.6 model (Anthropic) is called from Canada and the computation may run in Canada or in the United States; nothing is stored, logged or kept there, and no copy of your information remains once the draft has been produced. The AI service does not store the content submitted to it, does not use it to train AI models, and does not share it with the model provider. By default, the audio is deleted as soon as the transcription ends and the transcript once the note has been generated. Your clinic may choose, in its settings, to keep the recording as an encrypted document in your record and to keep the transcript as a clinical working document; both then remain for as long as the clinic keeps your record. Technical processing records, which contain no transcript, are deleted after 60 days. In Quebec, your consent is asked before a telehealth session that will produce an AI-assisted note, and you can withdraw it from the client portal (see our AI page). For an in-person session, a note draft can also be produced from an audio recording, after the practitioner has attested that you agreed to be recorded. For more details, see our artificial intelligence page.

SHARING YOUR PERSONAL INFORMATION

We do not sell or rent personal information. We share personal information only with the service providers required to operate the platform, under contractual safeguards:

  • Amazon Web Services (AWS), Canada (Montreal) region - hosting, storage, telehealth and AI processing;
  • Redis Cloud and MongoDB Atlas, hosted in the Canada (Montreal) region - cache and audit log;
  • Stripe - payment processing and card tokenization; card numbers are sent to Stripe, which returns a token; colib stores only the token, the last four digits, the expiry date and the card's country, and no colib employee can view a card number;
  • TELUS Health (eClaims), in Canada -- direct billing to insurers; integration currently under certification with TELUS: practitioner credentials are stored encrypted and no claim is transmitted for a client until the service is opened;
  • Telnyx, in the United States - fallback delivery of text message notifications (the recipient's phone number and the content of the message), used only if the Amazon SNS infrastructure fails, which has not happened to date; all text message notifications are delivered by Amazon SNS from the AWS Canada (Montreal) region;
  • Amazon SES and Amazon SNS, in the AWS Canada (Montreal) region - delivery of email notifications and of text message notifications;
  • Sentry - technical error and performance monitoring of the applications (see below);
  • Microsoft (Microsoft Graph) and Google (Google Calendar API) - optional synchronisation of a practitioner's own calendar, which they enable themselves: the event we create there carries only the appointment type, the location of the appointment, a link back to the appointment in Colib and, if the practitioner turns that option on, the client's initials -- no name, no contact details and no health information;
  • Google (Sign in with Google) - optional sign-in of a practitioner with their Google account, chosen by the practitioner; Colib receives the account's email address and name. Not available when two-factor authentication is active on the account;
  • Google (Maps and Places APIs), in the United States - address suggestions while you type your address in the online booking form, and the map of the clinic shown on its public page: while you type, the characters entered in the address field and your IP address are sent to Google; the map image is generated once from the clinic's own address and then stored by colib, so displaying it sends nothing to Google. Legal basis: the performance of the service requested by the clinic (contract);
  • Google reCAPTCHA, in the United States - protection of the practitioner sign-up form, of our contact forms and of the contact form on the clinics' public practice pages against automated abuse; the service receives your IP address, technical information about your browser and your interactions with the page, and places a cookie. Legal basis: our legitimate interest in preventing fraud and abuse;
  • Have I Been Pwned (Pwned Passwords), outside Canada - when you choose a password, the first five characters of its hashed fingerprint are sent to check it against known breaches; the password itself never leaves our servers. Legal basis: our legitimate interest in securing accounts;
  • Mailchimp (Intuit), in the United States - sending of our newsletter and of our product and service emails to clinics: the name, email address, language, province, clinic name and date of last sign-in of practitioners who hold an account, and the email address and language of visitors who subscribe to the newsletter. No information about a clinic's clients is ever sent to Mailchimp. Legal basis: your consent for the newsletter, which you can withdraw at any time from the link in every email, and our legitimate interest in informing clinics that hold an account about the service;
  • CookieScript - management of your cookie consent choices.
  • YouTube (Google) - playback of presentation videos on our public pages; the player is loaded only after you accept, and we use the cookie-free player domain.
  • Freshworks, in the United States - the support chat available on colib.io; when you are signed in, your email address is pre-filled in the chat form, where it can be changed or removed, and the conversation and the details provided in it are processed by Freshworks. The chat is not present in the client portal, nor on the public practice, booking and form pages. Legal basis: our legitimate interest in providing support.

Some technical files needed to display our pages (script libraries, icons) are served by the public content delivery networks jsDelivr and Cloudflare, which receive the IP address of the browser requesting them. Our text fonts are hosted on our own servers: displaying our pages sends no request, and therefore no IP address, to Google Fonts.

Sentry receives technical information used to detect and correct malfunctions: the address of the page, the error and its technical context, the browser and the IP address. A page address may contain a technical reference to a record; it never contains a name, an email address or any content of a health record, and colib removes those references before transmission. Error monitoring operates on all pages, including pages where you are signed in, so that malfunctions affecting your clinic can be detected and corrected. Performance monitoring, which sends navigation timings even when nothing goes wrong, is disabled on those pages.

We may also disclose personal information where required by law, or to respond to a lawful request from an authority.

Colib's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

DATA RESIDENCY

All personal information and health information managed by the platform is stored at rest in Canada: the AWS Canada (Montreal) region and managed services located in Canada. Backups are retained in Canada.

The following processing or access takes place outside Canada, and nothing else does:

  • the transient AI inference described in the Artificial intelligence section, which runs in memory for the few seconds of the request, with no storage and no logging: in Canada only for clinics located in Quebec, and in Canada or the United States for other clinics;
  • payment processing by Stripe; no health record information is ever sent to Stripe, and the client's identity is replaced by an internal reference before transmission -- a pseudonymisation, not an anonymisation, since colib can re-associate that reference with the client;
  • audience measurement and advertising, processed by our providers outside Canada, as described in the Cookies and analytics section;
  • technical error monitoring by Sentry, hosted in the United States, which receives the information described in the Sharing section;
  • a fallback delivery of text message notifications by Telnyx, in the United States, which would occur only if the Amazon SNS infrastructure failed and has not happened to date -- text messages are delivered from Canada by Amazon SNS; our email notifications, by contrast, are sent from the AWS Canada (Montreal) region;
  • the newsletter and service emails sent to clinics through Mailchimp, the reCAPTCHA protection of our forms, the address suggestions of Google Places and the support chat provided by Freshworks, all processed in the United States, with only the information described in the Sharing section;
  • remote access to our Canadian systems by a small number of authorized colib personnel connecting from outside Canada, under named individual accounts, with multi-factor authentication, through a controlled VPN, and with every access logged; such access stores no personal information outside Canada.

Information processed outside Canada may be subject to the laws of the country where it is processed, including lawful requests from the courts or public authorities of that country. Communications of personal information outside Quebec also occur; every person and service provider concerned is bound by confidentiality and security obligations towards colib.

A small, fixed list of named colib administrators may attach their own account to a clinic for support and maintenance; that list is defined in the application's source code and cannot be extended without a code change. Their identity is never substituted for a user's: every action they take is written to the clinic's own audit log under their own name, where the clinic can see it.

SECURITY

colib applies a defence-in-depth security architecture:

  • encryption in transit (TLS 1.2 or 1.3 only) and at rest, plus application-level AES-256 encryption of sensitive information;
  • administrative access to production systems only through a controlled VPN, from named individual accounts and with multi-factor authentication; per-clinic isolation and explicit sharing to the patient;
  • strong password policy and two-factor authentication;
  • audit logging of every consultation, creation, modification and deletion;
  • daily backups in Canada;
  • regular independent penetration tests.

For more details, see our security page.

RETENTION AND DESTRUCTION

We retain personal information only as long as necessary for the purposes described above and to meet our legal obligations.

  • Health records are retained on behalf of your clinic for as long as the clinic maintains them, in accordance with the professional retention rules that apply to the clinic.
  • When a record or an appointment is deleted by the clinic, it is physically and irreversibly purged 45 days after its deletion, together with all related data. A record for which a card payment was made in the last 15 days cannot be deleted until that period has elapsed.
  • When a patient closes their portal account or a clinic deletes a record, the account is anonymised, the payment objects held by Stripe and the client's completed forms are deleted, the sign-in devices and password history are erased, and the access log entries are anonymised but kept until the 18-month retention expires, so that the record of who did what cannot be erased by closing an account.
  • A clinic that has never subscribed to a paid plan and in which nobody has signed in for 18 months receives a warning email; its account and all of its data -- including the client records attached to it -- are then permanently deleted. A clinic that has held a paid subscription and stops using the platform keeps its data until it asks us to delete its account, at which point the account and all of its data are permanently deleted.
  • Temporary data (import files, drafts, abandoned online bookings) is purged automatically on a documented schedule.
  • Certain operational data is deleted automatically after a fixed period, whether or not the clinic asks for it: the history of SMS messages and the log of emails sent after 365 days; cancelled appointments after 12 months (other calendar entries after 32 days); the history of appointment status changes and draft notes after 35 days; incomplete client records after 6 days; and absences 600 days after they end.
  • Clinical notes, invoices, documents and completed forms are never purged automatically: they remain in the record for as long as the clinic keeps it. A telehealth transcript that a clinic chooses to keep stays in the record as a clinical working document, for as long as the clinic keeps the record. The devices and IP addresses used to sign in to your account are kept for 12 months after their last use, so that we can warn you of a sign-in from an unknown device; they are deleted with the account.
  • The clinic audit log (who viewed or changed a record) is retained for 3 years and the client portal access log for 18 months; closing an account anonymises its entries but does not shorten that retention. Security events are kept for 18 months, the AI usage log (which holds no content) for 36 months, the log of our own administrators' actions for 18 months, and technical error logs for 35 days.

YOUR RIGHTS

You may access the personal information we hold about you, request that it be rectified, and withdraw your consent where applicable. You may also obtain a copy of the computerized personal information you have provided, in a structured and commonly used technological format (right to portability under Law 25). Patients can download all of their data at any time from the My access log tab of the client portal, as a ZIP archive (profile, access log and, for each clinic, appointments, invoices, documents, forms, shared notes, messages, consents, waiting-list requests, programs, gift certificates and payment methods -- last four digits only).

  • For your health record, address your request first to your clinic, which remains responsible for it; colib assists the clinic in responding.
  • For information held directly by Colib (such as your patient portal account), contact our Privacy Officer using the details below.

Requests are addressed to our Privacy Officer (see the contact details below) and are answered within 30 days, as provided by law. If you are not satisfied with the way your information is handled, see the Complaints section below.

COMPLAINTS

If you believe that your personal information has not been handled in accordance with this policy or with the law, you may file a complaint with our Privacy Officer. Here is how it works:

  1. Write to thibault@colib.io, or by post to the address given in the Privacy Officer section below, describing the situation and, where possible, the clinic concerned and the dates.
  2. We acknowledge receipt of your complaint within 5 business days.
  3. Before disclosing any information or acting on a complaint, we verify the identity of the person making it, for example by contacting them at the email address or telephone number recorded in the account, or by asking for a piece of identification; a complaint made on behalf of someone else requires proof of the authority to act for that person.
  4. We investigate and give you a written answer within 30 days of receiving the complaint, stating the measures taken or the reasons for our decision. Where the complaint concerns a health record held by your clinic, we involve the clinic, which remains responsible for that record.

If you are not satisfied with our answer, or if you do not receive one within that time, you may lodge a complaint with the Commission d'acces a l'information du Quebec (www.cai.gouv.qc.ca), with the Office of the Privacy Commissioner of Canada, or with the privacy regulator of your province.

COOKIES AND ANALYTICS

colib uses cookies and similar technologies (log files, pixels) to measure audience and improve our services. Not every part of the platform carries the same technologies:

  • Google Analytics is used for audience measurement on colib.io and in the client portal, including on pages where you are signed in.
  • Google Ads is used on our public pages: our marketing and information pages, and the public practice and booking pages of the clinics that use colib, to measure the performance of our own advertising campaigns. The Facebook pixel is used on our marketing and information pages only. Neither is present in the client portal, nor in the practitioner application, nor when the booking module is embedded as a widget in a clinic's own website. An OpenAI advertising pixel is also used on our marketing and information pages and on the public practice and booking pages, to measure the performance of our own campaigns on OpenAI's services; it is not present in the client portal nor in the practitioner application.
  • When the booking module is embedded as a widget in a clinic's own website, no colib measurement or advertising tag is loaded at all.

The information transmitted to these tools is limited to: the address and the title of the page visited, the referring page, the IP address, the browser, the operating system and the device type, and a randomly generated cookie identifier. A page address may contain a technical reference to a record or to an appointment; it never contains a name, an email address, a diagnosis or any content of a health record. colib sends these tools no appointment event, no account name and no answer to a form or a questionnaire.

colib does not use the information of platform users for advertising. We do not upload client lists to Google or to Meta, we do not use advanced or audience matching, and we do not build remarketing or targeted advertising audiences from the users of the platform. The content of health records is never used for advertising purposes, and no information held by the platform is ever sold.

A clinic may also configure its own Google Analytics, Google Tag Manager or Google Ads identifiers on its public practice page and booking page. Those tags belong to the clinic, which is responsible for them; where they are enabled, a booking confirmation sends the clinic's own tags a booking reference, the name of the appointment type and the name of the clinic. They are loaded only after you accept the corresponding cookies in the banner.

A clinic's public practice and booking pages are listed by search engines and promoted on colib.io only if the clinic allows it in its settings (Allow Colib to list and promote my practice, on by default); it can turn this off at any time, after which those pages ask search engines not to index them. Pages meant for patients (forms, client portal) are never indexed.

A consent banner lets you accept or refuse each category of cookie, and you can change your choice at any time. Audience measurement (Google Analytics) is active by default and places a measurement cookie on your device. It is strictly limited to measuring how our pages are used: Google signals and advertising personalisation are switched off, so this data is never reused to target you with advertising, and it is never combined with the content of a health record. You can refuse audience measurement at any time from the banner; it stops immediately and the cookie is deleted. Advertising technologies -- Google Ads and the Facebook pixel -- are not active until you accept them, and our embedded video player is not loaded at all until then. Unlike Google Ads and the Facebook pixel, the OpenAI pixel is loaded by default and is not controlled by the consent banner; it receives the address of the page visited and technical information about the browser, and no content of a health record. Refusing has no effect on your ability to use the platform.

Cookies are grouped into four categories, which you can accept or refuse separately. Strictly necessary cookies keep you signed in, protect the forms you submit, remember your language and your time zone, and hold a booking or a shopping cart in progress; they cannot be refused, because without them the service cannot be delivered. Functionality cookies remember minor display preferences. Performance cookies are the Google Analytics measurement cookies. Targeting cookies are the advertising cookies and those set by the embedded video player. The full list of the cookies we use, with their purpose and their lifetime, is available from the banner at any time.

You can disable cookies in your browser and opt out of these services here:

  • FACEBOOK - https://www.facebook.com/settings/?tab=ads
  • GOOGLE - https://www.google.com/settings/ads/anonymous
  • Digital Advertising Alliance - http://optout.aboutads.info/
  • Google Analytics - https://tools.google.com/dlpage/gaoptout

CONFIDENTIALITY INCIDENTS

Any incident involving personal information (unauthorized access, use, disclosure or loss) is handled under a documented procedure: containment, assessment of the risk of injury, recording in our incident register, correction and notification. Where an incident presents a risk of serious injury, we notify the affected clinics and persons as well as the Commission d'acces a l'information, as required by law.

PRIVACY OFFICER

The person in charge of the protection of personal information at Colib is:

Thibault Bréboin
Privacy Officer, Colib Technology Inc.
thibault@colib.io
Colib Technology Inc., P.O. Box 2056, Squamish, BC V8B 0B4, Canada

CHANGES

We may update this policy from time to time to reflect changes to our practices or for legal or regulatory reasons. The current version is always available on this page, with its effective date shown at the top.

CONTACT US

For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by e-mail at support@colib.io Complaints are handled as described in the Complaints section above.