Last updated: September 22, 2026
This Privacy Policy explains how Physicare.ai collects, uses, discloses, transfers, retains, and protects personal information and personal data in connection with the Services.
This Privacy Policy applies to:
This Privacy Policy does not replace any separate Data Processing Agreement, master services agreement, order form, or customer-specific notice that may apply.
For Customer Data processed on behalf of a clinic, practice, employer, or regulated healthcare professional in connection with the provision of care or related operations, the relevant customer generally acts as the controller, custodian, trustee, or equivalent primary decision-maker under applicable law.
In relation to that Customer Data, Physicare.ai acts as a processor, service provider, agent, affiliate, information manager, or equivalent service role, depending on the applicable law and contractual arrangement.
Physicare.ai acts as an independent controller only with respect to Business Data it processes for its own legitimate business purposes, including account administration, billing, authentication, security, fraud prevention, legal compliance, support, and service communications.
If you are a patient whose healthcare provider uses Physicare.ai, your healthcare provider remains the primary point of contact for requests relating to your clinical record, except where applicable law requires or permits Physicare.ai to respond directly.
Physicare.ai may process the following categories of information:
limited billing and transaction information from payment processors
Physicare.ai does not store full payment card numbers.
information collected through cookies, analytics tools, and similar technologies, subject to applicable consent requirements
Physicare.ai collects information:
Physicare.ai processes information for the following purposes:
Where Physicare.ai acts as an independent controller and GDPR applies, Physicare.ai relies on one or more of the following legal bases:
Where special category data under GDPR is processed through the Services on behalf of a healthcare customer, the relevant customer remains responsible for establishing an appropriate Article 9 condition for processing. Physicare.ai processes such data only on documented instructions, except where otherwise required by law.
Where Canadian law applies, Physicare.ai processes personal information in accordance with applicable federal and provincial privacy laws. Where Physicare.ai acts on behalf of a healthcare customer, that customer remains responsible for ensuring that any required notices, consents, authorizations, or other lawful grounds are in place.
The Services may include AI-assisted features that generate transcriptions, summaries, draft notes, structured outputs, documentation suggestions, administrative suggestions, or other assistive content.
AI-generated outputs are assistive only. They may be incomplete, inaccurate, outdated, biased, or inappropriate for a given patient, context, or jurisdiction.
Physicare.ai does not make solely automated decisions that produce legal effects or similarly significant effects on individuals through the Services.
Unless expressly stated otherwise in a separate written agreement or lawful program, Physicare.ai does not use identifiable Customer Data to train generalized third-party AI models.
Where Physicare.ai uses de-identified or anonymized data for analytics, product improvement, or research, it does so only where permitted by applicable law and subject to appropriate safeguards.
If you connect a Google account to Physicare.ai through the Google Calendar integration, Physicare.ai accesses certain Google user data solely to provide that integration. This section applies to that data and prevails over any other section of this Privacy Policy that is inconsistent with it.
Google user data is used only to provide the calendar features you enable: preventing online booking and flagging manual booking during your busy times, and showing your appointments in the “Physicare” calendar.
Event titles and descriptions from your Google calendars are never shown to other users. Other members of your workspace may see your busy time slots, without any detail, unless you choose to keep them private.
By default, no patient information is sent to Google. Patient initials are added to exported events only if you turn that option on.
Physicare.ai does not sell Google user data and does not share, transfer, or disclose it to third parties, except to hosting and infrastructure providers strictly necessary to operate the integration and bound by confidentiality obligations, where required by applicable law, or as part of a merger, acquisition, or sale of assets with your prior consent. Google user data is not sent to AI providers and is not used by the AI-assisted features described in section 7.
Physicare.ai's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, Physicare.ai does not use Google user data to serve advertisements, including personalized, retargeted, or interest-based advertisements; does not sell it or transfer it to data brokers or information resellers; does not use it to determine credit-worthiness or for lending purposes; and does not use it to develop, improve, or train generalized or non-personalized AI and/or machine learning models. The analytics, product improvement, and research uses described in sections 5 and 7 do not apply to Google user data.
Physicare.ai personnel do not read Google user data unless you give your explicit consent, it is necessary for security purposes such as investigating abuse, or it is required to comply with applicable law.
Google user data is transmitted over encrypted connections and stored encrypted at rest, with the safeguards described in section 11. Access to Google tokens is restricted to the systems that perform synchronization.
Physicare.ai keeps Google user data until you disconnect Google Calendar in Physicare.ai. Only busy time slots for the next 90 days are stored; they are replaced at each synchronization, so past time slots are not kept.
When you disconnect Google Calendar in Physicare.ai, the “Physicare” calendar and the events exported to it are deleted from your Google account, Physicare.ai's access is revoked, and the Google user data stored by Physicare.ai is deleted, unless retention is required by law.
If you remove Physicare.ai's access from your Google Account permissions page (myaccount.google.com/permissions), synchronization stops and busy time slots are deleted. Your Google account email address and your settings are kept so you can reconnect, until you disconnect Google Calendar in Physicare.ai or request their deletion by writing to privacy@physicare.ai.
Physicare.ai may disclose information:
Physicare.ai does not sell personal information.
Physicare.ai may use third-party subprocessors and service providers to support the delivery of the Services.
Physicare.ai primarily hosts production data in Canada. Certain service providers may process limited categories of information outside Quebec or outside Canada, including in the United States.
Where required, Physicare.ai implements appropriate safeguards for such transfers, which may include:
Information processed in another jurisdiction may be subject to lawful access requests by courts, regulators, law enforcement, or national security authorities in that jurisdiction.
A current list of material subprocessors should be maintained separately by Physicare.ai and made available as required.
Physicare.ai maintains administrative, technical, and physical safeguards designed to protect information appropriate to its sensitivity and the nature of the Services.
These safeguards may include:
No system or method of transmission can be guaranteed to be completely secure.
Physicare.ai retains information only for as long as necessary for the purposes described in this Privacy Policy, as required by contract, and as required or permitted by applicable law.
Customer Data is retained in accordance with the applicable customer agreement, customer instructions, legal obligations, and backup or deletion schedules.
Account, billing, audit, security, and legal records may be retained for longer periods where reasonably necessary for tax, accounting, dispute resolution, enforcement, fraud prevention, security investigation, or legal compliance purposes.
Where Physicare.ai acts only as a processor or service provider in relation to Customer Data, the return, export, retention, deletion, and destruction of that data are governed primarily by the applicable customer agreement and lawful customer instructions.
Depending on the applicable law, individuals may have rights relating to their personal information, including:
Where Physicare.ai processes information on behalf of a clinic, practice, employer, or other customer, Physicare.ai may direct the request to that customer or require that the request be submitted to that customer first.
Physicare.ai will assist its customers in responding to lawful requests to the extent required by law or contract.
To submit a request relating to information for which Physicare.ai acts as controller, contact privacy@physicare.ai. Physicare.ai may require reasonable verification of identity before responding.
Physicare.ai maintains processes to identify, investigate, document, and respond to security and confidentiality incidents.
Where Physicare.ai acts on behalf of a customer and becomes aware of a breach affecting Customer Data, Physicare.ai will notify the customer without undue delay and provide information reasonably necessary to support the customer's legal and regulatory obligations.
Where Physicare.ai is independently required by applicable law to notify individuals, regulators, or authorities, it will do so in accordance with that law.
Physicare.ai uses strictly necessary cookies required for the operation and security of the website and Services.
Physicare.ai may also use optional analytics cookies or similar technologies where permitted by law and, where required, only with prior consent.
Users may manage cookie preferences through the website's consent tools where available.
The Services are not directed to children as independent users, except where a healthcare customer uses the Services in connection with the care of minors.
In such cases, the relevant healthcare customer remains responsible for obtaining any required authority, notice, or consent under applicable law.
Where GDPR or UK GDPR applies:
Physicare.ai may update this Privacy Policy from time to time.
If a change materially affects rights or obligations, Physicare.ai will provide reasonable notice by email, through the Services, or by other appropriate means.
The "Last updated" date at the top of this Privacy Policy indicates when it was last revised.
Privacy contact : privacy@physicare.ai
Support contact : support@physicare.ai
Mailing address : #300 - 204 Rue du St.-Sacrement, Montréal, QC H2Y 1W8
Individuals may also lodge a complaint with the competent privacy or data protection authority in their jurisdiction.