Skip to content

Qlynic Legal

Privacy Policy

Effective:  August 14, 2026 Version  2.2 Data hosted in  Canada (Azure Canada Central)
This policy explains how Arxeon Inc. (operating Qlynic) handles personal information and health information. Purple boxes are plain-language summaries for convenience only; the full text governs. For health information held for clinics, the Subscriber Agreement (including its Information Manager Agreement) prevails over this policy if they differ.

1.Overview & scope

This policy covers qlynic.com, the Qlynic applications, the patient portal, and related services (the “Platform”), operated by Arxeon Inc., 2705 225 11 Ave SE, Calgary, Alberta T2G 0G3. It addresses three audiences:

2.The laws that apply

Health Information Act (Alberta) — “HIA”
Governs health information. Clinics and their physicians are the custodians; Arxeon acts as their information manager (Section 3).
Personal Information Protection Act (Alberta) — “PIPA”
Governs personal information Arxeon holds for its own purposes in Alberta — for example clinic staff account details and billing contacts.
PIPEDA (Canada)
Applies to personal information in the course of commercial activity, including where information crosses provincial or national borders.
CASL (Canada)
Governs commercial electronic messages (Section 15).

3.Health information: our role

Plain-language summaryYour medical records belong with your clinic. Qlynic is the system your clinic uses — we process health information only on the clinic’s instructions, and requests about your records go to your clinic.

4.Information we collect

CategoryExamplesSource
Account & contactName, role, work email, phone number, login credentials (passwords stored only as salted hashes)You / your clinic
BillingBilling contact and address, tax registration numbers where provided, subscription and invoice records. Card details are collected and stored by Stripe — Arxeon never sees full card numbers.You / Stripe
Clinical (Customer Data)Patient demographics and identifiers (including ULI), appointments, clinical records and documents, messages, telehealth session records, claims and assessmentsYour clinic, on its instructions
Ambient scribe (only when used, with consent)Microphone audio processed in real time into text — the audio itself is never recorded or stored; a transient transcript used only to draft the visit note; and session records: the consent attestation (who confirmed it, and when), duration, and character/token countsYour clinic, during a consented visit
CommunicationsSMS and email content sent through the Platform, delivery status, opt-out records; support correspondencePlatform activity
Technical & securityIP addresses, device and browser information, sign-in and security events, audit logs, coarse IP-based location used for security checks (looked up locally — no data is sent to the geolocation provider)Automatic
UsageFirst-party analytics about how the Platform is used (pages, features, timing)Automatic

5.How we use information

What we never do. We do not sell personal or health information. We do not use it for third-party advertising. We do not use it to train AI models — ours or anyone else’s.

6.AI features

Plain-language summaryAI features run only when your clinic chooses to use them. The content is processed by our AI provider solely to produce the result, can’t be used to train models, and isn’t kept beyond what the arrangement allows.

7.Where your data lives

8.Sharing & service providers

We share personal information only: with the service providers below, acting on our instructions; with Alberta Health, when a clinic approves a claim for submission; where required by law (we disclose only what is legally required and, unless prohibited, notify the affected clinic first); or as part of a business transaction such as a merger or asset sale, in which case these commitments continue to apply to the transferred information.

ProviderRoleProcessing locationData touched
Microsoft AzureCloud hosting, storage, backups (all Qlynic portals)Canada (Canada Central region)All Customer Data, including health information (encrypted at rest)
Microsoft Azure AI SpeechReal-time speech-to-text for the Ambient ScribeCanada (Canada Central region)Encounter audio, streamed and not retained. Arxeon never receives or stores the audio.
Daily.coLive video and audio transport for telehealth visitsUnited States / global media edgeReal-time call media between patient and clinician, encrypted in transit. No chart, claim or record content. Calls are not recorded.
CloudflareNetwork security, DDoS protection, content deliveryGlobal network (encrypted transit)Traffic metadata; encrypted content in transit
StripePayment processing and tax calculationCanada / United StatesBilling contact, address, payment details. No health information.
TwilioSMS delivery and phone-number verificationUnited States / carrier networksPhone numbers and SMS content sent through the Platform
Twilio SendGridEmail deliveryUnited StatesEmail addresses and message content
AnthropicAI processing for AI-assisted featuresUnited StatesContent submitted to AI features, only when used; no model training; minimized retention under a data processing agreement
MaxMindIP geolocation for security featuresLocal database lookup (no data sent)IP addresses only. No health information.

Providers handling health information are bound to obligations materially as protective as our Information Manager Agreement. Changes to this list follow the notice-and-objection process in Schedule A of the Subscriber Agreement.

9.Cookies & analytics

10.Security

We protect information with layered safeguards: encryption in transit (TLS) and at rest; role-based access control and unique named accounts; two-factor authentication where offered; audit logging of security-relevant events; rate limiting and network protections against abuse; segregated environments and vulnerability management; confidentiality obligations and training for personnel, with access limited to those who need it; and the physical security of Microsoft Azure’s certified Canadian data centres. No system is perfectly secure — which is why Section 11 exists — but security is engineered into the Platform, not added on.

11.Breach notification

12.Retention

Plain-language summaryWhile your clinic subscribes, its data stays. When the relationship ends: 60 days to export, deletion from live systems within 90 days, backups overwritten within a further 35 days. Billing records live longer because tax law says so.
DataRetention
Customer Data (including health information)For the duration of the clinic’s subscription; after it ends, exportable for 60 days, deleted from active systems within 90 days, with encrypted backups overwritten in the ordinary cycle (not exceeding a further 35 days) — except under a legal hold or statutory requirement
Account & billing recordsAs required for legal, accounting, and tax purposes (generally 6–7 years under Canadian tax law)
Security & audit logsUp to 24 months, or longer where needed for an active investigation or legal obligation
Support correspondenceUp to 24 months after resolution
Marketing consents & opt-outsOpt-out records are kept indefinitely so they keep working

Clinics’ own records-retention obligations as custodians (including college requirements) remain theirs; the export window exists so they can be met.

13.Your rights

Patients

Clinic users & visitors

To exercise rights, contact the Privacy Officer (Section 17). We respond within the time limits set by applicable law. If you are unsatisfied, you may contact the Office of the Information and Privacy Commissioner of Alberta (oipc.ab.ca) or the Office of the Privacy Commissioner of Canada (priv.gc.ca).

14.Children

The Platform is a professional tool for clinics and is not directed at children. Health information about minors is managed by clinics as custodians under the HIA, and patient-portal access involving minors is governed by the clinic’s own policies and applicable law regarding guardians and mature minors.

15.Marketing & CASL

16.Changes to this policy

We update this policy when our practices change. Material changes affecting subscribed clinics are announced with at least 30 days’ notice by email or in-app. Each revision updates the version and effective date above and is recorded in the Version history — the date changes only when the document does.

17.Contact & privacy officer

Privacy Officer — Farhad Norouzi
Arxeon Inc. (operating Qlynic)
2705 225 11 Ave SE, Calgary, Alberta T2G 0G3, Canada
privacy@qlynic.com

Related documents

§Version history

VersionDateSummary
2.2August 14, 2026Subprocessor completeness: Microsoft Azure AI Speech (already described in Section 6) and Daily.co (live telehealth media transport) added as explicit rows in the Section 8 table; cross-border processing in Section 7 updated to name telehealth call media.
2.1August 11, 2026Ambient Scribe disclosures: real-time speech-to-text in Canada with no audio retention; transient transcripts; session metadata retained (consent attestation, duration, metrics); patient right to decline and the enforced do-not-record preference; AI-features section expanded accordingly.
2.0July 12, 2026Complete rewrite: Arxeon Inc. named; HIA information-manager role and patient request routing; full data-collection inventory; AI processing disclosure with no-training and retention commitments; Canadian residency (Azure Canada Central) with disclosed cross-border processing; complete subprocessor table; breach-notification commitments (72-hour clinic notice; PIPA individual/OIPC notice); concrete retention schedule aligned with the Terms and the Information Manager Agreement; CASL practices; privacy-officer contact; fixed the effective-date display so it changes only with the document.
1.x2025Superseded. Prior general policy without entity, HIA role, subprocessor, AI, residency, breach, or retention specifics.

© 2026 Arxeon Inc. All rights reserved. “Qlynic” and the Qlynic mark are trade-marks of Arxeon Inc.