Last updated: May 22, 2025
Gotcare Inc. (“Gotcare”, “we”, “our”, or “us”) is committed to protecting the privacy and security of the personal information and personal health information (“PHI”) that is entrusted to us. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you interact with Gotcare, including when you visit our websites, use the Gotcare platform, receive services from us, or otherwise engage with our team.
This Policy aligns with Gotcare’s internal Privacy Program Plan and reflects the requirements of privacy legislation across the provinces in which we operate, including Ontario’s Personal Health Information Protection Act, 2004 (PHIPA) and Freedom of Information and Protection of Privacy Act (FIPPA), British Columbia’s Personal Information Protection Act (PIPA), Alberta’s Health Information Act (HIA) and Personal Information Protection Act (PIPA), Nova Scotia’s Personal Health Information Act (PHIA), and other applicable provincial and federal laws.
Read more about Gotcare’s privacy program Plan
1. Scope & Application
This Policy applies to all personal information and PHI that Gotcare handles in the course of providing services across Canada. It governs our practices with respect to:
- Clients and care recipients
- Care workers and other service providers
- Visitors to our websites and digital properties
- Business partners, contractors, and third‑parties who access or process personal information on our behalf
2. Information You Provide
The information we collect directly from you (or your authorized representative) depends on your relationship with Gotcare and may include:
Category | Examples |
---|---|
Personal Health Information (PHI) | Medical history, care plans, treatment notes, assessment results, vital signs, and other data necessary to deliver or coordinate in-home and virtual care services. Employment & Credential Data (Care Workers) |
Personal Information | Name, contact details, demographic information, preferred language, emergency contacts, and billing details. |
Employment & Credential Data (Care Workers) | Resumes, professional credentials, background-check results, training records, and shift information. |
3. Information We Automatically Collect
When you interact with our websites or digital services, we automatically collect certain usage and device data, such as IP addresses, browser types, device identifiers, pages visited, and interaction timestamps. We use cookies or similar technologies to enable essential site functions, enhance user experience, and compile aggregate analytics. You can adjust your browser settings to refuse or remove cookies; however, some platform features may not function properly without them.
4. Purposes for Collection & Use
We limit collection to what is reasonably necessary and use information only for the following purposes:
- Care Delivery & Coordination – to assess needs, develop personalized care plans, match clients with suitable care workers, monitor outcomes, and provide virtual clinical support.
- Client & Worker Support – to respond to inquiries, schedule visits, and resolve service issues.
- Safety & Quality Improvement – to verify identity, ensure safety of clients and workers, prevent fraud, and improve the quality and security of our services.
- Program Administration & Billing – to manage contracts, process payments, and meet regulatory or funding‑partner reporting obligations.
- Research & Analytics – to generate de‑identified or aggregated insights that improve population health, program design, and system‑level planning.
- Legal & Regulatory Compliance – to comply with PHIPA, FIPPA, occupational health and safety laws, tax laws, and any court orders or lawful requests.
We do not use PHI for marketing or advertising without your explicit consent.
5. How We Share Information
- We disclose personal information only for the purposes identified in this Policy or as otherwise permitted or required by law.
- Third‑party service providers that support our operations (e.g., secure data‑hosting, telehealth platforms) may access information within Canada under agreements that require them to meet or exceed Gotcare’s privacy and security standards.
- We prohibit the storage of PHI outside Canada and restrict out‑of‑country access unless explicitly approved and strictly controlled.
- We retain personal information for as long as necessary to fulfill the identified purposes and to comply with legal requirements, after which it is securely de‑identified or destroyed.
6. Individual Access & Correction Rights
Subject to limited exceptions under PHIPA and other laws, you have the right to:
- Request access to your personal information and PHI under our custody.
- Obtain copies in a portable format or direct us to transfer records to another custodian.
- Request corrections to inaccurate or incomplete information.
Be informed of disclosures where required by law.
We will respond to written requests within the timelines set out in applicable legislation and may charge a reasonable fee as permitted.
7. Opting Out & Unsubscribing from Services
You may withdraw consent or opt out of non‑essential communications at any time:
- Marketing e‑mails and newsletters – click the “unsubscribe” link in the footer of any message.
- SMS notifications or in‑app alerts – adjust your preferences in your account settings or reply “STOP”.
- Other uses of your information – contact our support line at support@gotcare.ca or +1 (888) 819-1244 to request changes or to withdraw consent, subject to legal or contractual restrictions.
Opting out of communications that are integral to the delivery of care or the administration of your account may limit our ability to provide certain services.
8. How We Protect Information
Gotcare employs layered administrative, technical, and physical safeguards proportionate to the sensitivity of the information, including:
- Governance & Accountability – a dedicated Chief Privacy Officer, written policies, annual training, and Privacy Impact Assessments (PIAs) for new systems or significant changes.
- Encryption – TLS 1.3 encryption for data in transit and AES‑256 for data at rest.
- Role‑Based Access Controls & MFA – access granted on a need‑to‑know basis with mandatory multi‑factor authentication.
- Secure Hosting – data stored exclusively on Canadian AWS data centres holding ISO 27001, SOC 2/3, and HIPAA certifications.
- De‑Identification & Data Masking – identifiers removed or obscured when full detail is unnecessary.
- Monitoring & Auditing – continuous logging of user activities, regular third‑party security assessments, and a documented breach‑response protocol.
9. Contacting Us
Questions, concerns, or requests regarding privacy may be directed to our Chief Privacy Officer:
Chief Privacy Officer
Gotcare Inc.
1655 Dupont Street, Suite 105
Toronto, ON M6P 3T1
Email: support@gotcare.ca
Toll‑Free: +1 (888) 819‑1244
If your concerns remain unresolved, you have the right to contact the Information and Privacy Commissioner of Ontario or your local privacy regulator.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes to our practices, technology, or legal requirements. The “Last Updated” field at the top of this document indicates when it was last revised. We will provide advance notice of material changes and, where required, seek renewed consent.
Thank you for trusting Gotcare with your personal information and health data. We value that trust and remain committed to safeguarding your privacy while delivering compassionate, relationship‑driven care.