Solacare Privacy Policy
This Privacy Policy (the "Policy") explains how Stellocare Inc., a federally incorporated Canadian company under the name Solacare ("Solacare", "we", "us", or the "Platform"), collects, uses, discloses, transfers, stores, retains, and protects personal information when providing its website, practitioner directory, matching, booking, payment, client portal, communication, video, and practice management functions and related services (collectively, the "Services").
This Policy applies to clients, parents or guardians, payors, practitioners, organization account owners, organization members, website visitors, and other users. It should be read together with the Terms of Service, applicable informed consent documents, organization policies, practitioner privacy notices, and any data processing addendum.
Important role notice: Solacare does not make the same decisions about all information. For account administration, Platform operations, security, subscriptions, and our own communications, we generally determine the purposes of processing. For client and clinical content created and managed through the Platform by an organization or practitioner, that organization or practitioner generally determines the professional purposes, while Solacare primarily provides hosting and technical processing on its instructions. The actual legal role must be assessed based on the specific data flow and applicable law.
Part One: Scope, Laws, and Accountability Roles
1. Scope and Legal Framework
Solacare is operated by a Canadian company and primarily provides Services to users in Hong Kong. Depending on the information, the user's location, the practitioner's professional status, and the actual service arrangements, Canadian and Hong Kong privacy laws may apply together or separately.
- Canada: the Personal Information Protection and Electronic Documents Act ("PIPEDA") and other applicable federal or provincial laws may apply when personal information is collected, used, or disclosed in the course of commercial activities.
- Ontario: where information is handled by a health information custodian governed by the Personal Health Information Protection Act, 2004 ("PHIPA"), PHIPA and its regulations may apply. Not every Hong Kong practitioner or every item of mental health information is automatically governed by PHIPA.
- Hong Kong: the Personal Data (Privacy) Ordinance, Cap. 486 ("PDPO"), and its Data Protection Principles may apply to personal data connected with Hong Kong users and operations.
- Other locations: mandatory privacy, health information, or consumer laws in the location of a user or practitioner may also apply.
We use Canadian law as the principal framework for our corporate governance and this Policy, but this Policy does not exclude any right or obligation that cannot lawfully be excluded. Where more than one law applies, we apply the protections required for the particular information and activity.
2. Data Roles of Solacare, Organizations, and Practitioners
Privacy roles depend on who decides why and how information is collected, used, and disclosed, not merely on whose system stores it. In general:
- Information controlled by Solacare includes website and account administration, login and security, subscriptions and Platform fees, credential verification, customer support, Platform analytics, legal compliance, and communications sent by Solacare. For this information, we are generally a data user under the PDPO and the accountable organization under PIPEDA.
- Information controlled by an organization or practitioner includes its client information, informed consents, clinical records, forms, messages, tasks, service plans, and internal organizational information. The organization or practitioner generally determines the professional purposes and remains responsible for notice, consent, access, retention, disclosure, and professional obligations.
- Information processed by Solacare on behalf of a customer is handled through software, storage, transmission, backup, security, and support services according to the customer's settings, instructions, and contract.
- In a PHIPA context, Solacare may act as an agent, electronic service provider, or other contracted service provider to a health information custodian, depending on the particular arrangement. The final role should be confirmed in the applicable contract and data flow.
Organizations, practitioners, and Solacare may each be responsible for different purposes. Using the Platform does not transfer to Solacare any legal or professional responsibility that an organization or practitioner cannot delegate.
3. Accountability and Privacy Management
We designate a privacy contact responsible for this Policy, internal privacy procedures, service provider review, incident response, access requests, and complaints. We review privacy and information security measures based on risk, information sensitivity, and changes to the Services.
Organizations and practitioners must also assign appropriate responsibility, maintain informed consent and records management procedures, manage member permissions, and ensure their use of the Services complies with applicable law, professional standards, and promises made to clients.
Part Two: Information We Collect and Its Sources
4. Categories of Personal Information
Depending on the features you use, we may collect the following information. Not every category applies to every user:
- Identity and contact information, such as name, display name, title, year of birth or age information, email address, telephone number, language, region, and emergency contact information.
- Account and authentication information, such as account identifiers, login method, multi-factor authentication status, invitations, roles, organization memberships, permissions, and login or security event records.
- Practitioner and organization information, such as professional qualifications, registration or membership, biography, service languages, scope of practice, centre address, availability, fees, insurance, and verification documents.
- Client and booking information, such as appointment time, service type, participants, referral source, payor, cancellation status, reminder preferences, and notes relating to service arrangements.
- Clinical and case content, such as informed consent, assessments, health or psychological information, case notes, service plans, risk information, forms, homework, referrals, attachments, messages, and other content entered by an organization, practitioner, or client.
- Communication and support information, such as Platform messages, emails, support requests, complaints, feedback, technical diagnostic information, and records of communications with us.
- Payment and commercial information, such as subscription plan, transaction amount, currency, payment status, refunds, chargebacks, invoices, settlements, and tax-related information. Full payment card numbers and security codes are normally collected directly by the payment processor and are generally not stored by us.
- Device, network, and usage information, such as IP address, browser, operating system, device information, time zone, language, page and feature interactions, errors, diagnostics, login records, and audit logs.
- Cookie and similar technology information, including essential login and security cookies, preferences, and analytics or other non-essential technologies used with any consent required by law.
5. Sources of Information
Information may be provided directly by you or by a parent, guardian, payor, referrer, organization, practitioner, or authorized member acting for you. We may also obtain information from account and payment providers, Platform functions, public professional registers, and, where permitted by law, fraud prevention and security services.
A person who provides information about someone else must have lawful authority to do so and must provide appropriate notice and obtain consent where required. You must not upload third-party information without authority.
6. Required and Voluntary Information
Providing information is generally voluntary, but certain information is required to create an account, verify credentials, arrange appointments, process payments, protect security, or comply with law. Where reasonably practical, the collection interface will identify required fields and the main consequences of not providing them.
Please provide only information that is relevant and reasonably necessary. Unless a feature, organization, or practitioner specifically requests it and has an appropriate basis, do not enter directly identifying clinical records in a general support request, public field, or AI matching query.
Part Three: Purposes of Collection, Use, and Processing
7. Providing and Administering the Services
We may collect, use, and process personal information to:
- create, verify, administer, and protect accounts and organization workspaces;
- provide directory, search, matching, booking, reminder, form, messaging, video, document, payment, and export functions;
- store, organize, display, transmit, back up, and delete customer-controlled information according to an organization or practitioner's instructions;
- verify the identity, credentials, membership, or authority of a practitioner or account owner;
- process subscriptions, Platform fees, service fees, refunds, chargebacks, settlements, invoices, and accounting records;
- respond to enquiries, provide technical support, investigate errors, handle complaints, and enforce agreements;
- maintain availability, monitor performance, improve usability, test functions, and perform quality assurance;
- protect users, the Platform, and third parties, and prevent fraud, misuse, and unauthorized access;
- comply with law, court orders, regulatory requirements, and valid legal process, and establish or defend legal claims.
8. Consent, Authority, and Other Lawful Bases
Depending on the sensitivity of the information, reasonable user expectations, and applicable law, we obtain express or implied consent or rely on another basis permitted by law. Meaningful consent requires a person to reasonably understand the information collected, the principal purposes, likely recipients, and significant risks or consequences.
For clinical content controlled by an organization or practitioner, that organization or practitioner is responsible for obtaining and documenting valid consent or other lawful authority for professional services, data processing, communications, video, referrals, and necessary disclosures. A Platform checkbox or account workflow may not replace complete clinical informed consent.
Law may permit or require collection, use, or disclosure without consent in certain circumstances, including investigating fraud, responding to an urgent safety risk, complying with a subpoena or court order, collecting a debt, or another legally authorized purpose. We do so only where there is a reasonable basis and to the extent necessary.
9. Analytics, Improvement, and De-identified Information
We may use Platform usage, error, performance, and aggregate information to maintain security, understand feature use, improve the Services, and plan capacity. We limit information to the purpose and use aggregate, pseudonymized, or de-identified information where practical.
We do not read directly identifying clinical notes or counselling conversations for ordinary product analytics or advertising. Authorized personnel may access them only in the minimum necessary scope for support, security, complaints, legal compliance, incident response, or another necessary purpose expressly authorized under this Policy.
Information that has been irreversibly de-identified so that it cannot reasonably be linked back to a person may no longer be personal information. We do not attempt to re-identify it and use contractual or technical measures to restrict service providers from doing so.
10. Artificial Intelligence and Automated Features
Some functions may use artificial intelligence or automated technology, for example to generate matching suggestions from user input and practitioner directory information, assist with search, or organize non-clinical administrative content. Where reasonably practical, the relevant interface will explain the function and information used.
Unless we provide clear notice, obtain any required consent, and implement appropriate safeguards, we do not use directly identifying clinical content to train general-purpose artificial intelligence models, and we do not rely solely on an automated result to make a decision that has legal or similarly significant effects on a user.
AI output may be incomplete or inaccurate. It is for reference only and is not medical, diagnostic, counselling, or other professional advice. Users should not submit names, contact details, identity documents, or detailed case records to an AI function unless necessary.
11. Service Communications and Direct Marketing
We may send communications necessary to complete a transaction or provide the Services, including login, security, appointment, payment, service interruption, policy update, and account notices. Opting out of marketing does not stop necessary service communications.
We use designated contact information to send marketing about Solacare products, courses, events, or related services only with any consent required by law or where otherwise permitted, and we provide an applicable unsubscribe method.
We do not sell personal information or use clinical notes, counselling conversations, assessment responses, homework, or case records for behavioural advertising, advertising audiences, or third-party product marketing.
Part Four: Access, Disclosure, Service Providers, and Cross-border Processing
12. Access by Organizations, Practitioners, and Authorized Persons
Client information may be made available to relevant practitioners, supervisors, administrative personnel, finance personnel, or other authorized organization members based on organization settings, professional arrangements, and permissions. Different roles may see different information. Organizations and account owners must apply least-privilege access and explain their internal access arrangements to users.
A parent, guardian, payor, family member, or group participant does not automatically receive another person's complete information merely because they pay, participate, or create an account. Sharing must be supported by law, valid consent, professional judgment, and appropriate permissions.
13. Controlled Access by Solacare Personnel
As the system operator, Solacare may technically be capable of accessing information stored on the Platform, but this does not mean personnel may review it at will. Only specifically authorized personnel who are subject to confidentiality and access controls may access information where there is a legitimate work need and only to the minimum extent necessary.
- Responding to technical support requested by a person with authority where the issue cannot reasonably be resolved without reviewing relevant information.
- Investigating, containing, and correcting a security incident, defect, data corruption, or unauthorized activity.
- Handling a formal complaint, payment dispute, misuse report, or user safety concern.
- Performing controlled quality assurance, data migration, backup restoration, or system maintenance where test or de-identified information cannot reasonably be used.
- Complying with a valid legal requirement, court order, or regulatory obligation.
- Performing specified work with the express authorization of the relevant organization, practitioner, or data subject.
Depending on risk, we use measures such as permission segregation, approvals, audit logging, and review. Access must not exceed what is necessary for the relevant purpose.
14. Service Providers and Subprocessors
We use third-party providers for functions such as authentication, payments, cloud infrastructure, databases, file storage, backups, email, notifications, video, real-time communications, error monitoring, support, and artificial intelligence. Providers should receive only the information reasonably necessary to provide their function.
We assess providers in proportion to the sensitivity of the information and, where reasonably practical, use contracts requiring them to follow instructions, maintain appropriate security, restrict further disclosure, assist with incidents, and delete or return information when services end. Some providers may also act as independent controllers under law or for services they provide directly to you, such as payment and identity verification providers.
A current list of principal providers or provider categories may be made available on the Platform or upon request. Providers may change as the Services develop. Where a change materially affects processing, we provide notice according to applicable arrangements.
15. Other Circumstances of Disclosure
In addition to the persons and providers described above, we may disclose information:
- with the consent or instruction of you, the relevant organization, or another legally authorized person;
- to complete a referral, record transfer, payment, insurance, or other service you request;
- where required or permitted by law, including a valid court order, subpoena, search warrant, regulatory requirement, or other legal process;
- to investigate fraud, a security threat, serious misuse, or a breach of the Terms, or to protect a person's rights, life, health, safety, or property;
- to professional advisers, insurers, auditors, or financing parties, subject to confidentiality and purpose restrictions;
- in connection with a proposed or completed merger, financing, reorganization, sale, asset transfer, insolvency, or similar transaction, subject to appropriate confidentiality and use restrictions.
We review government and law enforcement requests and respond only where we reasonably believe the request is valid, legally binding, and applicable to us. Unless prohibited by law or inappropriate, we may notify the affected customer or individual.
16. Cross-border Storage and Processing
Solacare operates in Canada, and we, organizations, practitioners, and service providers may access, store, or process information in Canada, Hong Kong, the United States, or other jurisdictions. Information may therefore be subject to local law and may be requested by local courts, governments, or law enforcement through valid legal process.
Cross-border processing does not remove our responsibility under applicable Canadian law for information under our control. We use measures proportionate to risk, such as data minimization, provider review, contractual safeguards, access restrictions, encryption, and other reasonable protections. For transfers from Hong Kong, we also take account of guidance and recommended contractual clauses issued by the Hong Kong Privacy Commissioner.
Where an organization or practitioner independently directs a transfer, activates an integration, or permits overseas members to access information, that organization or practitioner must assess legality, notice, consent, and safeguards.
Part Five: Security, Accuracy, Retention, and Privacy Incidents
17. Information Security Measures
We use administrative, technical, and physical safeguards appropriate to the sensitivity, volume, format, purpose, and risk of the information. Measures may include encryption in transit and at rest, separate key management, role-based access, least privilege, multi-factor authentication, environment segregation, backups, logging, monitoring, vulnerability and update management, provider review, personnel confidentiality, and incident response procedures.
Safeguards evolve with risk and technology. No internet transmission, cloud service, or electronic storage can be guaranteed absolutely secure. Users must also protect their accounts, devices, networks, and exported information and promptly report suspicious activity.
18. Accuracy and Completeness
We take reasonable steps, appropriate to the purpose and likely impact, to keep information under our control accurate, complete, and current. Users, organizations, and practitioners must update information they provide and maintain clinical records according to professional responsibilities.
Some clinical records may not lawfully or professionally be overwritten or deleted. A correction may instead be made through an annotation, addendum, or correction entry that preserves record integrity and an audit trail.
19. Retention and Deletion
We retain personal information only for as long as reasonably necessary to fulfil the relevant purpose, perform agreements, maintain security, resolve disputes, and comply with law. Retention arrangements consider information type, sensitivity, limitation periods, professional standards, backup cycles, and deletion feasibility.
- Account, subscription, payment, tax, and transaction information may be retained for accounting, tax, fraud prevention, dispute, and legal requirements.
- Credential verification and compliance information may be retained while an account is active and for a reasonable period afterward to evidence verification and address complaints.
- Security, login, and audit logs may be retained for security investigation and compliance needs.
- The principal retention period for clinical content is determined by the organization or practitioner controlling the record based on law, professional standards, client age, and the service circumstances.
- Information in backups may remain until it is overwritten or securely deleted through the normal rotation cycle and remains subject to restricted use and security safeguards.
Closing an account does not necessarily result in immediate deletion of all information. Legal, professional recordkeeping, dispute, payment, security, or backup requirements may require continued retention. When information is no longer required, we delete, destroy, or de-identify it through reasonable procedures.
20. Privacy Incidents and Notification
If unauthorized access, use, disclosure, loss, alteration, or destruction is suspected or occurs, we investigate, contain, assess risk, remediate, and retain appropriate records under our incident response procedures.
- Where PIPEDA applies and there are reasonable grounds to believe the breach creates a real risk of significant harm, we notify the Office of the Privacy Commissioner of Canada and affected individuals as soon as feasible and maintain the records required by law.
- Where an organization or practitioner controls the information, we notify the relevant customer as required by contract and law and provide reasonable assistance with its duties to individuals, professional regulators, or other authorities.
- Where PHIPA applies, we cooperate with the relevant health information custodian in fulfilling notification, containment, investigation, and reporting duties.
- For Hong Kong information, we consider notification to affected individuals and the Hong Kong Privacy Commissioner based on the nature and risk of the incident and applicable PCPD guidance.
The content, timing, and method of notification depend on applicable law, the state of the investigation, and the need to prevent further harm.
Part Six: Your Rights and Choices
21. Access, Correction, and Copies
Subject to applicable law and exceptions, you may ask whether we hold personal information about you, obtain access to it, learn how it has been used and disclosed, and correct information that is inaccurate or incomplete. We may require enough information to verify identity and authority.
For clinical content controlled by an organization or practitioner, contact that organization or practitioner first. Solacare may forward a request to the relevant controller or provide technical assistance under its lawful instructions. We do not independently decide whether the clinical substance of a professional record should be changed.
Law may permit access to be refused or restricted, including where information concerns another person, is protected by legal privilege, would reveal confidential commercial information, cannot reasonably be severed, or could create a legally recognized serious risk. Where a request is refused, we or the relevant controller provide reasons and complaint information to the extent required by law.
22. Withdrawing Consent, Deletion, Restrictions, and Account Choices
You may withdraw consent on reasonable notice, subject to legal, contractual, and technical restrictions. Withdrawal does not affect prior lawful processing or information that law permits or requires us to continue processing. Withdrawing consent to necessary processing may prevent some or all Services from continuing.
You may request account closure, opt out of marketing, or ask us to delete information under our control that is no longer required. Deletion rights are not absolute. Clinical records, transactions, security information, legal claims, and backups may need to be retained.
Where PHIPA applies, an individual may give a consent directive or restriction to the relevant health information custodian. The custodian determines whether and how it can be implemented and its effect on services under law and professional obligations.
23. Cookies, Analytics, and Communication Preferences
Essential cookies support login, account security, sessions, and core functions. Disabling them may prevent the Services from operating properly. Non-essential analytics or other technologies are managed through any consent mechanism required by law. Browser and device settings may not control every Platform technology.
You may unsubscribe from marketing through a message link or account setting. Necessary security, transaction, appointment, legal, and service administration notices generally cannot all be disabled.
24. Rights in Hong Kong, Canada, and Ontario
- Hong Kong: the PDPO generally provides access and correction rights and regulates collection purposes, use, retention, security, openness, and data user practices. You may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong.
- Canada: PIPEDA generally provides rights relating to identified purposes, meaningful consent, access, accuracy challenges, withdrawal of consent, and challenging compliance, and permits complaints to the Office of the Privacy Commissioner of Canada.
- Ontario: where PHIPA applies, individuals generally exercise access, correction, and consent directive rights through the relevant health information custodian and may complain to the Information and Privacy Commissioner of Ontario.
This is a summary, not complete legal advice. Your actual rights depend on applicable law, our or a customer's data role, and statutory exceptions.
25. How to Make a Privacy Request
Make a request using the contact information at the end of this Policy and provide enough information to identify the relevant account, information, and scope. To protect privacy, we may verify identity, guardianship, representative authority, or organization authorization.
We respond within the time required by applicable law or notify you of a lawful extension. Where permitted, a reasonable fee may apply to a large or complex access request or the cost of reproducing information, and we will advise you in advance.
Part Seven: Minors, Professional Services, and Other Special Circumstances
26. Children and Minors
The Platform may be used by practitioners and organizations to provide professional services to minors, but account creation, consent, and access arrangements must reflect the minor's capacity, local law, the nature of the service, and professional standards. Age alone does not determine capacity in every circumstance.
Where parental, guardian, or substitute decision-maker consent is required, the relevant organization or practitioner must obtain and document valid authority. Where a minor is capable of consenting, their privacy and the scope of parental access must also be handled according to law and professional duties. A payor does not automatically receive clinical content merely because they pay.
If we learn that information was provided without appropriate authority, we may restrict the account, contact the relevant organization or practitioner, and take deletion or other steps consistent with law and recordkeeping duties.
27. Privacy Responsibilities of Organizations and Practitioners
- Provide clients with a clear personal information collection notice, clinical informed consent, and an explanation of internal access arrangements.
- Collect only information reasonably necessary for professional services and maintain accuracy and appropriate retention.
- Set and regularly review member permissions and promptly revoke access when a person leaves or changes roles.
- Continue to protect information after it is exported, downloaded, printed, or transferred.
- Respond lawfully to access, correction, consent, complaint, and privacy incident matters.
- Confirm legal and professional requirements based on the practitioner's location, the client's location, and cross-border practice.
An organization or practitioner is responsible for the content of any custom form, message, notice, or privacy statement it sends to a client through the Platform.
28. Video, Communications, and Recording
The Platform may transmit video, audio, text, and attachments. Solacare does not routinely record professional sessions unless a feature expressly provides recording and all necessary consents have been obtained. Users must not independently record, photograph, screenshot, or redistribute sessions or messages without lawful authority and appropriate notice.
Technical records may be generated about transmission, notifications, and delivery status. Platform messaging is not an emergency channel and does not guarantee immediate review.
29. Third-party Sites, Integrations, and User-selected Services
The Services may link to or integrate third-party websites, payment, calendar, video, communication, or other tools. A third party may independently process information under its own terms and privacy policy. Before activating an integration, a user or organization should review those practices and confirm authority to transmit information.
This Policy does not apply to third-party sites or services we do not control, although we remain responsible for applicable due diligence and contractual measures for providers that process information on our behalf.
Part Eight: Policy Administration, Complaints, and Contact
30. Changes to This Policy
We may update this Policy because of changes to law, regulation, technology, providers, functions, or operations. The current version states its effective and last updated dates.
Where a change materially affects collection, use, disclosure, or user choices, we provide prominent notice through email, account notice, or a Platform announcement where reasonably practical and obtain new consent where required by law.
31. Enquiries, Complaints, and Resolution
We investigate enquiries and complaints about this Policy or our information practices fairly and may request further information. Where a matter concerns clinical content controlled by an organization or practitioner, we may refer it to that controller and help coordinate, but the organization or practitioner remains responsible for its obligations.
We do not retaliate against a person for making a privacy enquiry or complaint in good faith. You may also complain to a privacy regulator with jurisdiction, although we encourage you to give us an opportunity to address the concern first.
32. Contact Us
Privacy contact: Nicholas Wong; Email: [email protected].
The formal corporate mailing address and address for legal service should be confirmed by counsel and inserted before publication. Do not send complete clinical records, identity documents, or other highly sensitive information by ordinary email. We will provide a more appropriate secure submission method where needed.