Klinifai, Inc. – Privacy Policy
Last updated: September, 20, 2025
1. Who We Are
Klinifai, Inc. (“Klinifai,” “we,” “our,” “us”) provides software that records voice interactions between patients and healthcare providers, converts them into transcripts, and fills clinical templates to support healthcare delivery.
We operate as a service provider / agent to healthcare organizations (“Health Information Custodians” or “HICs”) under Ontario’s Personal Health Information Protection Act (PHIPA).
2. What Information We Collect
We process two categories of information:
A. Personal Health Information (PHI) (on behalf of healthcare providers):
- Audio recordings of patient and provider interactions.
- Transcripts and structured clinical notes generated from recordings.
- Limited technical metadata (timestamps, session IDs, user access logs).
B. Anonymized Metadata (for quality improvement and model training):
- Aggregated, de-identified information about what procedures were performed.
- Tools and techniques used during procedures (e.g., orthodontic appliances, filling material, anesthetic method).
- All identifiers (such as patient names, dates of birth, or addresses) are removed before use.
- This metadata is used to improve Klinifai’s services and train models without exposing personally identifiable information (PII) or PHI.
We do not use PHI itself for model training.
3. How We Use Information
- PHI: used strictly to provide transcription and documentation services to the healthcare organization that collected the information.
- Anonymized metadata: used internally to enhance accuracy and performance of our products, algorithms, and services.
We do not sell PHI or anonymized metadata to third parties.
4. Cross-Border Data Flows
Our infrastructure uses Amazon Web Services (AWS) and may use third-party AI services such as OpenAI for transcription or natural language processing.
- Primary storage and processing may occur in the United States.
- As a result, PHI and anonymized metadata may be transferred outside Ontario/Canada.
- While outside Canada, information may be subject to the laws of the foreign jurisdiction (e.g., lawful access by U.S. authorities).
To reduce risk, Klinifai:
- Maintains vendor contracts requiring comparable protections under Canadian law.
- Uses encryption at rest and in transit for all PHI.
- Restricts access to authorized personnel.
- Applies de-identification before using metadata for model training.
If we expand processing to Canadian data centers (e.g., AWS ca-central-1), we will update this notice.
5. Safeguards
- We maintain administrative, technical, and physical safeguards appropriate for sensitive health information, including:
- Encryption (TLS, AES-256).
- Role-based access with multi-factor authentication.
- Continuous audit logging and monitoring.
- Secure deletion and retention policies.
6. Breach Notification
- Under PHIPA, if PHI is lost, stolen, or accessed without authorization, Klinifai will notify the healthcare organization (HIC) at the first reasonable opportunity.
- The HIC is responsible for notifying patients and the Information and Privacy Commissioner of Ontario where required.
- For cross-border incidents that create a real
risk of significant harm, Klinifai will also comply with federal
PIPEDA requirements to support notification to the Office of the Privacy Commissioner of Canada (OPC) and affected individuals.
7. Retention & Trashing
- PHI is retained only as long as necessary to provide services or as directed by the HIC.
- After this period, PHI is securely deleted or returned.
- Anonymized metadata may be retained for research and product development, as it cannot be linked back to individual patients.
8. Individual Rights
Patients seeking access to or correction of their health information should contact their healthcare provider directly. Klinifai supports providers in fulfilling such requests under PHIPA.
9. Contact Information
Questions or complaints about this Privacy Policy may be directed to our Privacy Officer:
Privacy Officer
Klinifai, Inc.
Box 57002 STN Brittany Glen, Mississauga, Ontario, L5M 0M5, Canada
hello@klinifai.com