Totus Life ServicesTelePortUs

Privacy Policy

How we collect, use, and protect your information

Last updated: August 2026

At TelePortUs, protecting your privacy is at the heart of everything we build. This policy explains how we handle your personal information in compliance with Ontario's Personal Health Information Protection Act (PHIPA), the federal Personal Information Protection and Electronic Documents Act (PIPEDA), and Alberta/BC's Personal Information Protection Act (PIPA).

Information We Collect

  • Account Information: When you register as a provider, we collect your name, email address, clinic name, professional specialty, and license number.
  • Patient Information: When patients join a waiting room, we collect their name and optionally their email or phone number for appointment purposes.
  • Session Data: We record session metadata including start/end times, duration, and participant names. We do NOT record or store video, audio, or chat content from calls.
  • Appointment Data: When providers enable booking, we collect appointment details (patient name, email, phone, scheduled time) to send confirmations and reminders. With provider consent, appointment events may sync to the provider's Google Calendar.
  • File Data: Files exchanged during a call are encrypted in transit and at rest (AES-256-GCM). They are retained only as long as needed (default maximum 90 days) and then securely shredded — bytes overwritten before deletion, recorded in the audit log.
  • Payment Data: Subscription payments are processed by Stripe (PCI-DSS Level 1). We never see or store full card numbers — only the last four digits, brand, and expiry.
  • Usage Data: We collect anonymous analytics about how you use our platform to improve the experience for all users.

How We Use Your Information

  • To provide, maintain, and improve our telehealth platform
  • To connect patients with their healthcare providers
  • To comply with legal and regulatory obligations under PHIPA and PIPEDA
  • To send important service updates and security notices
  • We never sell your personal information or use it for advertising

Data Residency

  • All patient data is stored exclusively on Canadian servers.
  • Our infrastructure is hosted with Canadian cloud providers to ensure data never leaves Canada.
  • Video and audio streams are routed through our Canadian-hosted LiveKit SFU and are end-to-end encrypted — we cannot see or record them.
  • This Canadian data residency is a core architectural principle, not an afterthought.

PHIPA & PIPEDA Compliance

  • TelePortUs is designed from the ground up for PHIPA (Ontario) and PIPEDA (Federal) compliance.
  • We maintain Business Associate Agreements (BAAs) with all third-party service providers who may process health information.
  • All access to personal health information is logged in an immutable audit trail.
  • We conduct regular security assessments and penetration testing.
  • Our compliance framework extends to PIPA (Alberta/BC) and HIPAA (US) requirements.

Data Security

  • End-to-End Encryption: All video and audio calls are encrypted with AES-256-GCM using LiveKit E2EE. Each session uses a unique encryption key generated by our server, delivered only over authenticated channels (provider session or verified LiveKit token), stored encrypted at rest, and destroyed when the session ends. A leaked key can never decrypt other sessions.
  • Encryption in Transit: All data transmitted between your browser and our servers is protected by TLS 1.3.
  • Encryption at Rest: PHI — including clinical notes, documents, signatures, PHNs, and file contents — is encrypted at rest with AES-256-GCM at the application layer, using a fresh random IV and authentication tag per encryption. The master key lives only in the production secret store, never in the code, database, or logs. Files uploaded to the secure vault are encrypted before storage and decrypted only for the authorized provider; share links expire after 7 days or on revocation, and files are securely shredded (bytes overwritten before deletion) at the end of their retention period or on request.
  • Secure Sharing & Signing: Providers may share files via single-use secure links that patients open in any browser (no account required); revoked or expired links can no longer be accessed. Signed documents can be downloaded by the provider as a PDF; document content and signature images are stored encrypted and are decrypted only for the owning provider.
  • Insurance Pre-Verification (Coverage Checks): Providers may use TelePortUs's coverage check to verify a client's insurance eligibility before an appointment. By design, coverage checks store only an opaque client reference, the province, the insurer, and the result (eligible / needs review, session coverage, remaining balance). Policy numbers and dates of birth are used solely to perform the check and are deleted immediately after — they are never stored. Every check is recorded in the audit chain (who checked, when, which insurer). Where no automated eligibility is available, the provider is guided to the insurer's own portal; TelePortUs never stores provider or patient portal credentials.
  • AI Visit Summary (AI Scribe): Providers may offer an optional AI scribe that drafts a clinical summary of a session. The scribe is NEVER active without the patient's explicit, informed consent. During a session, a provider may send a short consent link; the patient reads the terms and liability statements, ticks a box to consent (or declines), and the decision is recorded and audit-logged (who, when, and the consent version shown). Declining has no effect on care. Audio is processed only to draft the summary, is not used to train any model, and is deleted after the summary is created. The signed summary becomes part of the patient's secure, encrypted care record.
  • Access Control: Strict role-based access control ensures only authorized providers can access their patients' information. Every access to PHI is recorded in an immutable audit log.

Your Rights

  • You have the right to access the personal information we hold about you.
  • You have the right to request correction of inaccurate information.
  • You have the right to request deletion of your account and associated data, subject to legal retention requirements.
  • You have the right to withdraw consent for data collection at any time.
  • To exercise any of these rights, contact our Privacy Officer at privacy@totuslife.org.

Cookies

  • We use essential cookies required for authentication and platform functionality.
  • We use session cookies to maintain your login state.
  • We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
  • You can control cookie settings through your browser preferences.

Third-Party Services

  • LiveKit: Our video infrastructure provider — operates under a BAA and processes encrypted media streams only.
  • Stripe: Our payment processor — PCI-DSS Level 1 certified. Processes card payments; TelePortUs never receives or stores full card numbers. Payment data is subject to Stripe's security controls and our agreement with Stripe.
  • Google Calendar (optional): If a provider enables calendar sync, we create/update appointment events in the provider's own Google Calendar via OAuth. We access only the calendar the provider authorizes, solely for appointment management. Providers can disconnect at any time.
  • Resend: Our transactional email provider — used to send appointment confirmations, reminders, and account notices.
  • PostgreSQL: Database provider — all data at rest is encrypted using pgcrypto.
  • Redis: Session caching — contains no personal health information.
  • All third-party services are contractually bound to maintain Canadian data residency (where applicable) and compliance with applicable privacy laws.

Contact Us

  • Privacy Officer: privacy@totuslife.org
  • Security: security@totuslife.org
  • General Inquiries: support@totuslife.org
  • Response Time: We aim to respond to all privacy-related inquiries within 2 business days.