Privacy Policy
What personal information Adaptiwise AI collects, why it collects it, who else touches it, how long it is kept, and how to see or erase it.
1What this covers, and who is accountable for what
Adaptiwise AI runs bookings, customer records, messaging and payments for small businesses and clinics at app.adaptiwise.com. Personal information reaches it by two different routes, and different organisations are accountable for each. Which one you are decides which paragraphs below are about you.
- Your Adaptiwise AI account
- The operator of this deployment is accountable for it: your name, email address, the hash of your password, your sessions and which workspaces you belong to. That is a direct relationship between you and us.
- A business's customer records
- The business is accountable for the people in its own records. Adaptiwise AI handles them as that business’s service provider, on its instructions, to run the service it is paying for — and for nothing else.
- A clinic’s clinical records
- The clinic is the health-information custodian for its patients. Adaptiwise AI is its service provider. If you are a patient asking about your chart, the clinic is the organisation that answers, and section 10 says how we help them do it.
2What is collected, and why
PIPEDA requires the purpose to be stated before the collection, so here it is, category by category. Nothing below is collected for advertising, and none of it is sold.
- Account and sign-in
- Name, email address, a hash of your password (never the password), and for each session its expiry, the address it was created from and the browser that created it. Purpose: to let you in, to keep other people out, and to let you see and end your own sessions.
- The business itself
- Business name, locations, addresses, opening hours, services, prices, staff members and their working hours. Purpose: to draw the booking page and decide what can be booked when.
- Customers and bookings
- Name, email address, phone number, appointment times, the service booked, notes the business records, intake answers the business asks for, and which of the consents below were given. Purpose: to take the booking, to keep the business’s record of it, and to send the messages about it.
- Clinical information, where a clinic records it
- Visit notes and, where the clinic asks for it, a personal health number. Purpose: the clinic’s own record of care. It is visible only to people the clinic has given the clinical-notes permission, and it is never used for anything else. See section 11.
- Payments
- Amount, currency, status, the processor’s reference, and what kind of payment it was. Card numbers are never collected — see section 5.
- Messages
- What was sent, to which channel, when, and what the provider said happened to it. Purpose: so a business can prove what a customer was told, and so a failed reminder can be seen rather than assumed.
- Technical records
- Server logs with a request id, the route, the status and the timing; rate-limit counters keyed on the requesting address, and — for somebody signed in to a business console — on their account rather than their address, so that one person going too fast does not slow their colleagues down; and an audit trail of who changed what. Message bodies are not logged, and monitoring metrics deliberately carry no identifier for a person — not an email address, not a phone number, not a booking link.
3Consent
- Booking asks for the business's cancellation policy to be accepted. It is required, because it is the term the fee is charged under.
- Reminders about the appointment are a separate box. It is ticked by default because a reminder about an appointment you are in the middle of making is what most people expect; untick it and no reminder is sent.
- Marketing is its own box and is never ticked for you.
- Where the business asks a clinical question — a health question about you, rather than your name and number — booking asks for one more consent, beside those questions and readable before it is ticked. A business that asks none never shows it. Section 11 says what it covers.
- Consent can be withdrawn: reply STOP to any text message, tell the business, or ask them to change the record. Withdrawing consent for reminders does not cancel the appointment.
4Text messages and email
- Messages are sent by Adaptiwise AI on behalf of the business you booked with, and carry that business’s name.
- STOP stops them. It suppresses that channel for you immediately, cancels reminders already queued for you, and every later message on that channel is refused and recorded rather than sent. HELP is answered by the carrier.
- Text messages that are not about an appointment already made are held between 21:00 and 08:00 in the location’s own timezone and sent when that window closes.
- Standard message and data rates may apply.
5Payments and card details
No card number ever reaches Adaptiwise AI. The browser exchanges the card with the processor and hands us a token that stands for it; the token is what is charged. We keep the amount, the currency, the outcome and the processor’s reference, so a business can reconcile its takings and issue a refund.
When the deployment is in sandbox mode there is no processor, no card and no charge — the amounts on screen are simulated, and are labelled as simulated.
7Service providers
Adaptiwise AI uses a small, fixed set of providers, and no others. When the deployment runs in sandbox mode — the default — messages and charges are simulated inside the system and no personal information is sent to any of them.
- Twilio
- Text messages. Receives the recipient’s phone number and the message. Processes outside Canada.
- Postmark
- Email. Receives the recipient’s email address, the subject and the body. Processes outside Canada.
- Stripe
- Card payments. Receives the card details directly from the payer’s browser, plus the amount and a reference for the booking. Processes outside Canada.
- OVHcloud
- Hosting. The server and the database run on an OVHcloud virtual server in Canada. OVHcloud does not process the data; it hosts the machine it sits on.
8Where the data is held
The application and its database run on a single OVHcloud virtual server in Canada. Every connection to it is over TLS. Each workspace’s rows are separated in the database itself by row-level security, so a request scoped to one business cannot read another’s even if the application asks it to.
The providers in section 7 are outside Canada, so information handed to them for a message or a payment is processed outside Canada and is subject to the law where they operate.
9How long it is kept
- Business records — customers, bookings, notes, messages, payments — are kept until the business deletes them or asks for them to be erased. There is no automatic deletion schedule over them, and this policy will not pretend there is one. A clinic has its own retention obligations, and deciding them is the clinic’s.
- Sessions expire after thirty days, and expired sessions are removed.
- Short-lived operational records — a held booking slot, the key that stops a retried payment charging twice — expire on their own within hours.
- The audit trail of who changed what, and the record of what was sent to whom, are retained: they are the evidence a business needs about its own actions.
10Seeing, correcting and erasing your information
Ask the business you booked with. They hold the record and they are the organisation accountable for it, so a request to see, correct or erase it starts with them — and there is no separate Adaptiwise AI portal to sign into instead.
- The business can produce everything held about one person — visits, messages, notes, intake answers and consents — as a single export, from the console.
- The business can correct any of it in place.
- The business can act on an erasure request, which redacts the identifying fields rather than merely hiding the record.
- If you cannot reach the business, or you are asking about your own Adaptiwise AI account rather than a booking, write to the operator’s privacy mailbox — to be completed and we will answer within thirty days.
Some things cannot be erased on request, and we would rather say so here than in a reply: an opt-out record (erasing it would erase your instruction not to be contacted), and records a business is required by law to keep, such as payment and clinical records within their retention period.
11Health information
Where a clinic uses Adaptiwise AI, the clinic is the health-information custodian and Adaptiwise AI is its service provider. We handle visit notes and personal health numbers only to provide the service to that clinic. We do not use them for anything else, and we do not disclose them to anyone outside the clinic’s own workspace.
- Clinical fields are separated per business by row-level security, and reading them requires a clinical-notes permission the clinic grants explicitly, person by person.
- They are not encrypted in a column of their own today, over and above the protections that apply to the rest of the record.
- Reading a chart is written to the audit trail, and so is every change to one: who opened it, whose record it was, when, and through which screen. A clinic can ask who has been in a patient’s record and be answered.
- Where a clinic records a personal health number or asks a clinical question when somebody books, it has to be agreed to first: a separate consent, in plain words, readable before it is accepted, and kept with the record of when it was given.
12How it is protected
- TLS on every connection, in the browser and to the database.
- Passwords are stored as hashes and are never recoverable, by us or by anybody else.
- Each workspace is separated in the database by row-level security rather than by application code remembering to filter.
- Every screen and every route is behind a permission the business grants, and a request for another workspace’s data is answered as though the data did not exist.
- The product pages load nothing from another origin — no fonts, no scripts, no analytics — which removes the most common way a page leaks who is reading it.
- Secrets live in the deployment’s environment, never in the code and never in a page.
No system is perfectly secure, and this one is young. Section 14 says what happens when something goes wrong.
13Children
Adaptiwise AI is sold to businesses and is not directed at children. A business may hold a record about a minor — a clinic treating one, for instance — on the basis its own professional obligations require, including a parent’s or guardian’s consent. That is the business’s decision and its responsibility, not something the software collects on its own.
14If something goes wrong
- We contain it first, and find out what was reachable.
- We tell the affected businesses without undue delay, with what we know and what we do not.
- Where a breach creates a real risk of significant harm, PIPEDA requires a report to the Office of the Privacy Commissioner of Canada and notice to the people affected. We support the accountable business in doing that, and where the account is directly ours we do it.
- A record of the breach is kept — of every breach of security safeguards, including one judged not to create that risk, for twenty-four months, which is what PIPEDA requires whether or not anything is reported.
The full procedure is on the Security page: who decides that something is reportable, the clocks we work to, which duty is ours and which belongs to the clinic that holds the record, and where a copy of your information can still be after the original is gone. That page is also how to report a security problem to us.
15Changes to this policy
When the product changes what it collects, who touches it or how long it is kept, this page changes and the date at the top moves with it. A change that materially affects an account holder is notified to the account holder rather than left to be found here.
16Questions and complaints
Privacy questions about your own Adaptiwise AI account go to the operator’s privacy mailbox — to be completed. Questions about a booking or a clinical record go to the business you booked with, which holds it. This page names no privacy officer, because appointing one is the operator’s to do and inventing a name here would be worse than the gap.
A security problem is different and has its own address: a way into data that should not be open, or a reason to think somebody has already been in it, goes to security@adaptiwise.com — see the Security page. Do not put anybody’s personal or health information in that email; a description is enough.
If a Canadian organisation has not answered you properly, you can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca. The terms of the service itself are in the Terms of Service.