GladstoneMD Ltd. (“GladstoneMD”, “we”, “us”, “our”) provides software that supports clinical documentation and practice workflow (the “Services”). This Privacy Policy describes how we collect, use, disclose, retain, and protect information in connection with the Services.
This Privacy Policy applies to our website and business communications, and to the GladstoneMD application used by clinics and their authorized users. If you do not agree with this Privacy Policy, do not use the Services.
Our role
When the Services are used in a healthcare setting, the Customer is generally responsible for decisions about patient information, including notices and consents, and for meeting legal obligations that apply to its practice and records. In that context, GladstoneMD processes Customer Content, which may include personal information and personal health information, on behalf of the Customer to provide the Services, subject to the Customer’s instructions and applicable law.
Where the Customer is a Health Information Custodian under applicable privacy legislation, GladstoneMD acts as the Customer’s agent in accordance with that legislation and processes personal health information solely on the Customer’s behalf and in accordance with the Customer’s instructions.
Patients with questions about a clinic’s use of the Services, including requests for access or correction, should contact the clinic or provider directly. Where appropriate and lawful, we will assist the Customer.
Customers are responsible for patient facing notices and consents that may be required for use of the Services. If a patient has questions or wishes to withdraw consent, the patient should contact the Customer or their clinician.
Information we collect
We collect information that is reasonably necessary to operate the Services.
Website and communications
We collect information you choose to provide when you contact us or request information, such as your name, contact details, organization, role, and the content of your communications.
We also collect basic website usage information, which may include IP address, device and browser information, and pages visited. We use cookies and similar technologies to operate the website and understand usage. You can manage cookies through your browser settings and, where available, on site controls.
Application use
When Customers use the application, we process information provided by or on behalf of the Customer and its authorized users. This may include:
- Account information such as name, email address, role, and authentication information
- Subscription and billing information as needed to administer the Customer relationship
- Customer Content submitted through the Services for clinical documentation and workflow purposes, which may include personal information and personal health information
- Non-clinical service data such as logs, product usage telemetry, and performance metrics used to operate, maintain, secure, and improve the Services
The Services are intended for use by regulated healthcare professionals and personnel acting under clinician direction. The Services are not intended for patient self use.
How we use information
We use information for the following purposes:
- To provide and operate the Services, including generating drafts and outputs requested through the Services
- To administer accounts, subscriptions, and billing
- To provide support and respond to requests
- To maintain security, prevent misuse, and enforce our terms
- To improve the Services and user experience
Product improvement
We may use de-identified and aggregated information derived solely from non-clinical service data for product quality improvement, system performance, safety testing, and internal benchmarking. We do not use personal health information, including de-identified information derived from personal health information, to train or fine-tune machine learning or AI models, or for analytics, benchmarking, research, or product development. We may use non-clinical service data, including product usage telemetry, system performance metrics, and support metadata, to improve the Services and user experience, including to develop and improve Service features. We do not sell personal information or Customer Content and we do not attempt to re-identify de-identified information.
Disclosures
We disclose information only in the following circumstances:
- Service providers: We use third parties to help us deliver the Services, such as hosting, infrastructure, AI processing, payment processing, customer support tooling, and communications providers. These providers are engaged to perform services for us and are subject to contractual requirements appropriate to the sensitivity of the information, including confidentiality, security safeguards, restrictions on use, and limitations on disclosure. Personal health information is stored in Canada. However, in order to provide, operate, secure, and support the Services, GladstoneMD and its service providers may access or process personal health information from locations outside Canada. Where this occurs, we implement administrative, technical, and contractual safeguards designed to provide a level of protection appropriate to the sensitivity of the information and consistent with applicable privacy laws. Where a service provider is located outside Canada, personal health information may be subject to the laws of the jurisdiction in which it is accessed or processed, including lawful access by courts, law enforcement, or national security authorities in accordance with those laws.
- Customer instructions: We disclose information where a Customer directs us to do so, including through integrations enabled by the Customer.
- Legal requirements: We disclose information where required by law or lawful process, or where necessary to protect the rights, security, or safety of GladstoneMD, our Customers, users, or others.
- Business transactions: We may disclose information in connection with a financing, merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.
Transfers
Personal health information that we process on behalf of Customers is primarily stored in Canada. In order to provide, operate, secure, and support the Services, GladstoneMD and its authorized service providers may access or process personal health information from locations outside Canada, including for system operations, technical support, monitoring, and AI-enabled processing.
Where personal health information is accessed or processed outside Canada, we implement administrative, technical, and contractual safeguards designed to protect the information and to limit its use to authorized purposes.
Where information is processed outside the jurisdiction where it was collected, it may be subject to the laws of that jurisdiction and may be accessible to courts, law enforcement, or national security authorities in accordance with those laws.
Customers remain responsible for providing any notices or obtaining any consents that may be required under applicable laws or professional obligations in connection with their use of the Services.
Retention
We retain Customer Content for the duration of the Customer relationship, subject to Customer-directed deletion and applicable law. Temporary processing data, such as source audio and AI interaction context, is retained only for the limited periods needed to deliver the requested functionality. After termination of a Customer account, we generally provide a thirty (30) day export period as described in the Terms of Service, after which access is disabled and Customer Content is deleted from active systems. Customer Content may persist in backups for a limited period until overwritten through normal backup rotation.
Customers are responsible for maintaining their official records in their systems of record and for meeting documentation and retention obligations that apply to them.
Security
We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, alteration, and disclosure. Safeguards include access controls, multi factor authentication, encryption, logging, and monitoring, aligned to the sensitivity of the information and the Services provided. No method of transmission or storage is fully secure.
Customers are responsible for managing user access and maintaining credential security. Access to Customer Content is restricted to authorized personnel who need it to operate the Services, provide support requested by the Customer, or meet legal obligations. We use access controls and logging to support accountability.
In the event of a security incident involving personal information or personal health information, we will notify the affected Customer at the first reasonable opportunity and cooperate with the Customer in meeting any applicable legal obligations.
Requests and choices
You may opt out of marketing communications by using the unsubscribe mechanism in the message or by contacting us. We may still send service related communications where appropriate.
Authorized users and business contacts may request access to, or correction of, personal information we hold about them, subject to applicable law and identity verification. Patients should direct requests to their clinic or provider.
Updates
We may update this Privacy Policy from time to time by posting an updated version and updating the effective date. Where changes are material, we may provide additional notice through the Services or by email.
Contact
If you have a privacy concern, you may contact our Privacy Officer. If your concern relates to a clinic’s handling of your health record, please contact the clinic directly.
If you are not satisfied with our response, you may contact the Information and Privacy Commissioner of Ontario at www.ipc.on.ca or the Office of the Privacy Commissioner of Canada at www.priv.gc.ca, as applicable.
Privacy Officer
GladstoneMD Ltd.
Email: privacy@gladstonemd.com