Privacy Policy and Privacy Statement
1. Policy statement
Good Care Technologies Inc is committed to protecting personal information and personal health information entrusted to it by patients, customers, healthcare providers, enterprise partners, and service providers. Good Care collects, uses, discloses, retains, and disposes of personal information only for authorized purposes, with appropriate safeguards, accountability, transparency, and respect for individual rights.
2. Information we may process
- Identity and contact information, such as name, email address, telephone number, address, date of birth, account identifiers, and authentication identifiers.
- Healthcare and clinical information, such as diagnostic, clinical, pharmacy, prescription, care pathway, laboratory, health program, and patient support information, where authorized.
- Integration information, such as partner identifiers, API metadata, MFA or authentication-passed status, device/session information, audit logs, and access events required to support secure platform integration.
- Operational information, such as service requests, consent records, preferences, communications, support tickets, billing or eligibility information where applicable, and security logs.
- Limited employment or contractor information for workforce management, access provisioning, training, compliance, and security administration.
3. Purposes for processing
- To provide, operate, support, secure, and improve the Good Care clinical and diagnostic patient data platform.
- To enable authorized customer integrations, including controlled API-based access and identity-aware user experiences.
- To provide care-related, diagnostic, pharmacy, patient support, or platform services as authorized by patients, customers, healthcare providers, custodians, contracts, and applicable law.
- To maintain security, auditability, access control, fraud prevention, incident response, quality assurance, compliance, and business continuity.
- To meet legal, regulatory, professional, contractual, accounting, audit, and reporting obligations.
- To respond to access, correction, deletion, consent, privacy, and support requests, subject to lawful limits and retention obligations.
4. Limits on use and disclosure
Good Care does not sell PHI. Good Care will not use customer data for unrelated purposes, marketing, profiling, AI model training, or secondary use unless expressly authorized in writing and permitted by applicable law. Good Care will limit use and disclosure of PI and PHI to authorized purposes and personnel with a business need-to-know.
6. Safeguards
- Administrative safeguards: privacy officer oversight, policies, procedures, training, confidentiality obligations, incident response, vendor oversight, and access approvals.
- Technical safeguards: encryption, identity-aware access controls, least privilege, audit logging, monitoring, backup controls, secure configuration, vulnerability management, and network/security controls.
- Physical safeguards: facility access controls, secure work practices, device protections, and secure disposal practices appropriate to the environment.
- Governance safeguards: data classification, retention schedules, data minimization, privacy risk reviews, and periodic access reviews.
7. Data residency, cross-border processing, and service providers
Good Care will store and process customer data in Canada or other contractually approved jurisdictions only. Backup locations will be limited to approved Canadian or contractually authorized regions. Good Care will use service providers only where appropriate contractual, privacy, security, confidentiality, audit, and incident notification protections are in place.
8. Retention and disposal
Good Care retains PI and PHI only as long as required for authorized legal, regulatory, contractual, operational, care-related, security, audit, and dispute-resolution purposes. When no longer required, data is securely deleted, de-identified, destroyed, returned, or archived according to approved retention and disposal procedures and customer instructions.
9. Individual access, correction, and deletion requests
Good Care will support access, correction, deletion, portability, consent, and privacy requests where required by law and contract. Where Good Care acts on behalf of a customer or health information custodian, Good Care will coordinate with the customer/custodian responsible for responding to the individual and will not independently disclose customer-controlled records unless authorized or required by law.
10. Privacy inquiries and complaints
Privacy inquiries, requests, and complaints may be directed to: Grisha Pasternak, Privacy Officer, Good Care Technologies Inc, gp@goodcare.net. Good Care will document and investigate privacy inquiries and complaints and will respond within applicable legal or contractual timelines.
11. Policy review and change management
This Privacy Policy and Privacy Statement will be reviewed periodically and updated as legal, operational, technology, contractual, or service changes require. Material changes involving enterprise customer data will be assessed for customer notice and contractual approval requirements.