Qlynic Legal
Privacy Policy
Effective: August 14, 2026
Version 2.2
Data hosted in Canada (Azure Canada Central)
This policy explains how
Arxeon Inc. (operating
Qlynic) handles personal
information and health information. Purple boxes are plain-language summaries for convenience only; the full
text governs. For health information held for clinics, the
Subscriber Agreement (including its
Information Manager Agreement) prevails over this policy if they differ.
1.Overview & scope
This policy covers qlynic.com, the Qlynic applications, the patient portal, and related services (the
“Platform”), operated by Arxeon Inc., 2705 225 11 Ave SE, Calgary, Alberta T2G 0G3.
It addresses three audiences:
- Clinics and their staff — account holders and authorized users of a clinic subscription;
- Patients — individuals whose information a clinic manages through Qlynic, or who use the patient portal in connection with their clinic;
- Visitors — people browsing our website or contacting us.
2.The laws that apply
- Health Information Act (Alberta) — “HIA”
- Governs health information. Clinics and their physicians are the custodians; Arxeon acts as their information manager (Section 3).
- Personal Information Protection Act (Alberta) — “PIPA”
- Governs personal information Arxeon holds for its own purposes in Alberta — for example clinic staff account details and billing contacts.
- PIPEDA (Canada)
- Applies to personal information in the course of commercial activity, including where information crosses provincial or national borders.
- CASL (Canada)
- Governs commercial electronic messages (Section 15).
3.Health information: our role
Plain-language summaryYour medical records belong with your clinic. Qlynic is the system your clinic uses — we process health information only on the clinic’s instructions, and requests about your records go to your clinic.
- For health information in the Platform, the clinic remains the custodian under the HIA. Arxeon is the clinic’s information manager under section 66 of the HIA and, where the clinic uses electronic claims submission, an affiliate of the custodian as an accredited Alberta Health H-Link submitter.
- Arxeon collects, uses, and discloses health information only to provide the services the clinic has subscribed to, on the clinic’s instructions, or as required by law — never for sale, advertising, or training artificial-intelligence models. The full commitments (safeguards, subprocessors, breach notification, retention, destruction) are in the Information Manager Agreement, Schedule A of the Subscriber Agreement.
- Patients: to access or correct your health records, contact your clinic — the custodian responds under the HIA. If we receive your request directly, we refer it to your clinic within 5 business days (Section 13).
4.Information we collect
| Category | Examples | Source |
| Account & contact | Name, role, work email, phone number, login credentials (passwords stored only as salted hashes) | You / your clinic |
| Billing | Billing contact and address, tax registration numbers where provided, subscription and invoice records. Card details are collected and stored by Stripe — Arxeon never sees full card numbers. | You / Stripe |
| Clinical (Customer Data) | Patient demographics and identifiers (including ULI), appointments, clinical records and documents, messages, telehealth session records, claims and assessments | Your clinic, on its instructions |
| Ambient scribe (only when used, with consent) | Microphone audio processed in real time into text — the audio itself is never recorded or stored; a transient transcript used only to draft the visit note; and session records: the consent attestation (who confirmed it, and when), duration, and character/token counts | Your clinic, during a consented visit |
| Communications | SMS and email content sent through the Platform, delivery status, opt-out records; support correspondence | Platform activity |
| Technical & security | IP addresses, device and browser information, sign-in and security events, audit logs, coarse IP-based location used for security checks (looked up locally — no data is sent to the geolocation provider) | Automatic |
| Usage | First-party analytics about how the Platform is used (pages, features, timing) | Automatic |
5.How we use information
- To provide the Platform — operating accounts, records, scheduling, communications, telehealth, document processing, claims submission, and support.
- To keep it safe — authentication, fraud and abuse prevention, rate limiting, IP-based security controls, audit trails, and incident investigation.
- To bill — subscriptions, invoices, and taxes (through Stripe).
- To communicate — transactional and service messages (such as verification codes, security alerts, and billing notices); marketing only in accordance with Section 15.
- To improve — using aggregated or de-identified information that does not identify any individual or clinic.
- To comply with law — including lawful requests we are required to answer (Section 8).
What we never do. We do not sell personal or health information. We do not use it for third-party advertising. We do not use it to train AI models — ours or anyone else’s.
6.AI features
Plain-language summaryAI features run only when your clinic chooses to use them. The content is processed by our AI provider solely to produce the result, can’t be used to train models, and isn’t kept beyond what the arrangement allows.
- Some features use artificial intelligence to draft, summarize, or extract information. Content is sent for AI processing only when a user actively uses such a feature; clinics can avoid AI processing entirely by not using those features.
- AI processing is performed by our contracted AI provider, Anthropic (Section 8), under a data processing agreement that prohibits using the content to train models and minimizes retention. Where a zero-data-retention arrangement is in effect, prompts and outputs are not stored at rest by the provider after the response is returned, apart from narrow legal and safety exceptions.
- AI outputs are assistive drafts. Clinicians review and remain responsible for all clinical content (Terms, Section 5). No decision about an individual is made by AI without human review.
- The Ambient Scribe. When a clinic uses the scribe during a visit — and only after the clinic records the patient’s consent for that visit — microphone audio streams from the provider’s device to Microsoft Azure AI Speech in Canada (Canada Central), where it is converted to text in real time. The service is configured so that audio is not retained, and Arxeon never receives or stores audio. The transcript exists transiently to draft the visit note (drafted via our AI provider under the safeguards above) and is not stored by Arxeon; what we keep is the consent attestation, session duration, and character/token counts.
- Declining the scribe. A patient may decline AI transcription at any visit, and may ask their clinic to set a permanent do-not-record preference on their record. While that preference is set, scribe sessions cannot be started for that patient anywhere on the Platform.
7.Where your data lives
- Storage: Platform data, including health information and backups, is hosted in Microsoft Azure’s Canadian regions (Canada Central).
- Limited cross-border processing: encrypted traffic may transit international network points (content delivery and security); SMS and email are delivered through providers that may process message content and contact details outside Canada; AI processing (Section 6) may occur in the United States; payment processing involves Stripe in Canada and the United States; and live telehealth call media is carried by Daily.co over a global media edge, encrypted in transit and not recorded.
- Information processed outside Canada may be subject to lawful access by authorities in that jurisdiction under its laws. We limit cross-border processing to the purposes above and bind providers contractually as described in Section 8.
8.Sharing & service providers
We share personal information only: with the service providers below, acting on our instructions; with Alberta
Health, when a clinic approves a claim for submission; where required by law (we disclose only what is legally
required and, unless prohibited, notify the affected clinic first); or as part of a business transaction such as
a merger or asset sale, in which case these commitments continue to apply to the transferred information.
| Provider | Role | Processing location | Data touched |
| Microsoft Azure | Cloud hosting, storage, backups (all Qlynic portals) | Canada (Canada Central region) | All Customer Data, including health information (encrypted at rest) |
| Microsoft Azure AI Speech | Real-time speech-to-text for the Ambient Scribe | Canada (Canada Central region) | Encounter audio, streamed and not retained. Arxeon never receives or stores the audio. |
| Daily.co | Live video and audio transport for telehealth visits | United States / global media edge | Real-time call media between patient and clinician, encrypted in transit. No chart, claim or record content. Calls are not recorded. |
| Cloudflare | Network security, DDoS protection, content delivery | Global network (encrypted transit) | Traffic metadata; encrypted content in transit |
| Stripe | Payment processing and tax calculation | Canada / United States | Billing contact, address, payment details. No health information. |
| Twilio | SMS delivery and phone-number verification | United States / carrier networks | Phone numbers and SMS content sent through the Platform |
| Twilio SendGrid | Email delivery | United States | Email addresses and message content |
| Anthropic | AI processing for AI-assisted features | United States | Content submitted to AI features, only when used; no model training; minimized retention under a data processing agreement |
| MaxMind | IP geolocation for security features | Local database lookup (no data sent) | IP addresses only. No health information. |
Providers handling health information are bound to obligations materially as protective as our Information Manager
Agreement. Changes to this list follow the notice-and-objection process in Schedule A of the Subscriber Agreement.
9.Cookies & analytics
- Essential cookies keep you signed in, protect against request forgery, and remember security state. The Platform does not work without them.
- Preference cookies remember settings such as interface choices.
- First-party analytics measure how the Platform is used so we can improve it. We do not use third-party advertising networks, ad pixels, or cross-site tracking, and we do not share analytics with advertisers.
- You can control cookies in your browser; blocking essential cookies will prevent sign-in.
10.Security
We protect information with layered safeguards: encryption in transit (TLS) and at rest; role-based access control
and unique named accounts; two-factor authentication where offered; audit logging of security-relevant events;
rate limiting and network protections against abuse; segregated environments and vulnerability management;
confidentiality obligations and training for personnel, with access limited to those who need it; and the physical
security of Microsoft Azure’s certified Canadian data centres. No system is perfectly secure — which is why
Section 11 exists — but security is engineered into the Platform, not added on.
11.Breach notification
- If a privacy or security breach affects a clinic’s health information, we notify the clinic without unreasonable delay — and in any event within 72 hours of confirming it — with what we know, what we’ve contained, and what we recommend, and we support the clinic’s own duties under section 60.1 of the HIA (notifying the Commissioner, the Minister, and affected individuals where there is a risk of harm).
- Where Arxeon is itself the organization accountable for affected personal information (for example clinic staff account data), we notify affected individuals and the Office of the Information and Privacy Commissioner of Alberta where the breach creates a real risk of significant harm, as PIPA requires, and any other regulator required by law.
- We investigate, contain, remediate, and document every incident, and preserve evidence.
12.Retention
Plain-language summaryWhile your clinic subscribes, its data stays. When the relationship ends: 60 days to export, deletion from live systems within 90 days, backups overwritten within a further 35 days. Billing records live longer because tax law says so.
| Data | Retention |
| Customer Data (including health information) | For the duration of the clinic’s subscription; after it ends, exportable for 60 days, deleted from active systems within 90 days, with encrypted backups overwritten in the ordinary cycle (not exceeding a further 35 days) — except under a legal hold or statutory requirement |
| Account & billing records | As required for legal, accounting, and tax purposes (generally 6–7 years under Canadian tax law) |
| Security & audit logs | Up to 24 months, or longer where needed for an active investigation or legal obligation |
| Support correspondence | Up to 24 months after resolution |
| Marketing consents & opt-outs | Opt-out records are kept indefinitely so they keep working |
Clinics’ own records-retention obligations as custodians (including college requirements) remain theirs; the
export window exists so they can be met.
13.Your rights
Patients
- Rights to access and correct your health records are exercised with your clinic, the custodian under the HIA. If you contact us directly about your health records, we refer your request to your clinic within 5 business days and assist the clinic in responding.
- You may decline AI-assisted transcription (the Ambient Scribe) at any visit, and may ask your clinic to set a permanent do-not-record preference, which the Platform enforces (Section 6).
Clinic users & visitors
- You may request access to, or correction of, the personal information Arxeon holds about you (such as your account details), subject to the exceptions in PIPA and PIPEDA.
- You may withdraw consent to marketing at any time (Section 15). Withdrawal of consent needed to operate your account may limit our ability to provide the Platform to you.
- You may request deletion of your personal information; we will delete what we are not legally required to keep (Section 12).
To exercise rights, contact the Privacy Officer (Section 17). We respond within the time limits set by applicable
law. If you are unsatisfied, you may contact the Office of the Information and Privacy Commissioner of
Alberta (oipc.ab.ca) or the Office of the Privacy Commissioner of Canada (priv.gc.ca).
14.Children
The Platform is a professional tool for clinics and is not directed at children. Health information about minors is
managed by clinics as custodians under the HIA, and patient-portal access involving minors is governed by the
clinic’s own policies and applicable law regarding guardians and mature minors.
15.Marketing & CASL
- Transactional and service messages (verification codes, security alerts, billing and service notices) are part of operating the Platform and are not marketing.
- We send commercial electronic messages only with consent as CASL requires, and every such message includes a working unsubscribe. Unsubscribing does not affect service messages.
- Messages a clinic sends to its patients through the Platform are the clinic’s messages; the clinic is responsible for its consents, and the Platform’s opt-out handling (such as SMS “STOP”) is honoured automatically.
16.Changes to this policy
We update this policy when our practices change. Material changes affecting subscribed clinics are announced with
at least 30 days’ notice by email or in-app. Each revision updates the version and effective date above and is
recorded in the Version history — the date changes only when the document does.
17.Contact & privacy officer
Privacy Officer — Farhad Norouzi
Arxeon Inc. (operating Qlynic)
2705 225 11 Ave SE, Calgary, Alberta T2G 0G3, Canada
privacy@qlynic.com
Related documents
§Version history
| Version | Date | Summary |
| 2.2 | August 14, 2026 | Subprocessor completeness: Microsoft Azure AI Speech (already described in Section 6) and Daily.co (live telehealth media transport) added as explicit rows in the Section 8 table; cross-border processing in Section 7 updated to name telehealth call media. |
| 2.1 | August 11, 2026 | Ambient Scribe disclosures: real-time speech-to-text in Canada with no audio retention; transient transcripts; session metadata retained (consent attestation, duration, metrics); patient right to decline and the enforced do-not-record preference; AI-features section expanded accordingly. |
| 2.0 | July 12, 2026 | Complete rewrite: Arxeon Inc. named; HIA information-manager role and patient request routing; full data-collection inventory; AI processing disclosure with no-training and retention commitments; Canadian residency (Azure Canada Central) with disclosed cross-border processing; complete subprocessor table; breach-notification commitments (72-hour clinic notice; PIPA individual/OIPC notice); concrete retention schedule aligned with the Terms and the Information Manager Agreement; CASL practices; privacy-officer contact; fixed the effective-date display so it changes only with the document. |
| 1.x | 2025 | Superseded. Prior general policy without entity, HIA role, subprocessor, AI, residency, breach, or retention specifics. |