OmaScan Privacy Policy
Last updated: October 2, 2026 · Version 3.1.0
Effective: on publication. Supersedes the Privacy Policy version 3.0.0 dated September 21, 2026.
1. Introduction and Scope
OmaScan Inc. ("OmaScan," "we," "us," or "our") provides a capture and documentation platform for home accessibility assessments, used by occupational therapists and other professionals and by the people they invite to collaborate. The platform is delivered through the OmaScan mobile application for iPhone (the "Mobile App"), the OmaScan web application at app.omascan.com (the "Web App"), and the services behind them (together, the "Service"). OmaScan also operates an earlier version of the Service on different infrastructure, described in Section 8, until it is retired. This Policy applies to that version as well.
This Privacy Policy describes how OmaScan collects, uses, discloses, retains, and protects Personal Information in connection with the Service. It applies to everyone who uses the Service, including Professional Users and Collaborators, and to Subjects whose information is captured through the Service.
This Privacy Policy applies alongside the OmaScan Terms of Service and any Information Manager Agreement, Electronic Service Provider Agreement, Data Processing Agreement, Business Associate Agreement, or other written agreement between OmaScan and an organization or practitioner. Where such an agreement conflicts with this Policy, the agreement prevails for the information it covers; nothing in such an agreement reduces the protections this Policy gives you as an individual.
Where the Service is used by or for a health information custodian (a "Custodian"), the Custodian is responsible for obtaining any consent required by law before collecting or sharing Personal Health Information through the Service. Where OmaScan collects Personal Information directly from you, for example when you create an account or contact us, we obtain any required consent at or before collection.
By creating an account or using the Service, you consent to the collection, use, and disclosure of Personal Information for the purposes described in this Privacy Policy.
2. Key Terms
"Personal Information" means information that identifies or could reasonably be linked to an individual, including Personal Health Information.
"Personal Health Information" or "PHI" means Personal Information about an individual's physical or mental health, the health care provided to them, or information collected in connection with a health assessment. Scans of an individual's home, measurements of that home, photos, videos and recordings made during an assessment, notes about functional needs, and equipment or modification recommendations are Personal Health Information when collected in a clinical context.
"Assessment" means one home accessibility assessment opened in the Service for one Subject, together with everything captured, uploaded, generated, or written inside it, including its title.
"Professional User" means a person who creates Assessments or captures information for them in a professional capacity, whether for their own practice, an employer, or a client.
"Collaborator" means a person invited by email to view or edit a specific Assessment.
"Subject" means the individual whose home, functional needs, or circumstances are the subject of an Assessment.
"Custodian" means a person or organization that has custody or control of Personal Health Information under applicable health privacy law, including a health information custodian under Ontario's PHIPA, a custodian under Newfoundland and Labrador's PHIA, or an equivalent role in another province or territory. A sole practitioner may be the Custodian of their own clients' information.
"Your Content" means the scans, photos, videos, recordings, transcripts, notes, measurements, annotations, placed equipment, Assessment titles, and other material that you, or people acting through your account or at your invitation, submit to or generate with the Service.
"Service Usage Data" means information about how the Service is used: account activity, device and application information, feature events, session information, error reports, diagnostics, and performance data. It is associated with your account and is not intended to include Your Content, information identifying Subjects, or other Personal Health Information.
"De-Identified Data" means information derived from Personal Information that has been processed so that it cannot reasonably be used, alone or in combination with other information, to identify an individual or a specific home. Once information has been de-identified in this way it is no longer Personal Information or Personal Health Information.
3. Who We Are and Our Role
OmaScan's role depends on how the Service is used.
When you deal with us directly, by creating an account, contacting us, or using the Service on your own behalf, OmaScan is the organization responsible for your Personal Information under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial law.
When the Service is used by or for a Custodian, OmaScan acts as that Custodian's information manager under Newfoundland and Labrador's PHIA, agent or electronic service provider under Ontario's PHIPA and its regulations, or in the equivalent role under the health privacy law of another province or territory. Where the Custodian and OmaScan have signed a separate agreement, that agreement sets the role and the permitted purposes. Where they have not, this Policy and the Terms of Service are the written terms on which we handle Personal Health Information for the Custodian: we handle it only on the Custodian's instructions and only for the purposes set out in Section 5. The Custodian remains accountable for that information under its governing law.
If you are the Subject of an Assessment and want to access, correct, or ask about your Personal Health Information, contact the professional or organization that carried out your assessment. We will help them respond.
4. Personal Information We Collect
Account information. Name, email address, and password, or the name and email address from your Google account if you choose to sign in with Google. Sign-in is provided by Clerk (Section 8); where you set a password, Clerk holds it in hashed form and it is never visible to OmaScan. On the earlier version of the Service, sign-in and your hashed password are held by Amazon Cognito in Canada instead.
Assessment content (Your Content). Depending on what you capture:
- 3D scans of rooms and objects produced with the device's camera and depth sensors, and measurements taken from them;
- photos and videos of the home environment;
- dictation and session audio recordings, captured only when you start recording, with a visible indicator, and the transcripts produced from them;
- typed notes, measurements, labels, annotations, equipment placed in the 3D editor, and messages you write in an Assessment's conversation;
- the Subject's name, the address of the home, the visit date, and an Assessment title you choose.
Assessment content usually contains Personal Health Information about the Subject. It may also contain images or voices of other people present in the home. You are responsible for the consents described in the Terms of Service before capturing it.
Collaborator information. When you invite someone to an Assessment we collect the email address you provide and record which Assessment they were invited to, their permission level (view or edit), and when they accepted.
Consent records. The version of the Terms of Service and Privacy Policy you accepted, what you accepted it for, and when. These records are kept in a log that is append-only for the retention period in Section 9.
Service Usage Data. Which features were used and when, associated with your user ID, name, email, and plan. It does not include the content of what you captured: no scans, photos, recordings, transcripts, notes, measurements, addresses, or Subject names.
Technical information. IP address, the device and platform information your device sends with each request, and crash and error reports you choose to share through the App Store.
Access logs. Every time an Assessment or other record is read, created, changed, or deleted through the Service, we record who did it, what was affected, when, the outcome, and the IP address and device information of the request. These logs exist to support the Custodian's obligation to audit access to Personal Health Information, and we produce them to the Custodian on request. On the earlier version of the Service, access logging covers reads and writes of scan files rather than every record, and we produce what that version records.
Communications. The content of emails and support requests you send us, and our replies.
Payments. If you purchase a paid plan, payment is handled by Stripe through Clerk Billing. Stripe collects your card details directly; OmaScan does not receive or store card numbers. We receive your plan, billing status, and a payment reference.
If you include sensitive information in free-text fields, it is stored as part of Your Content. Do not enter government identification numbers, financial account details, or health information about anyone other than the Subject.
5. How We Use Personal Information
To provide and operate the Service. Create and manage accounts; sign you in; capture, upload, process, and store Your Content; produce transcripts, captions, scan labels, and live assistant suggestions (Section 6); display Assessments in the Mobile App and the Web App; deliver invitations and give Collaborators the access you chose; and send you service messages.
To keep the Service secure. Detect, prevent, and respond to unauthorized access, misuse, and security incidents; maintain access logs; and enforce our Terms.
To maintain and improve the Service. Diagnose problems, monitor performance, measure feature adoption, and prioritise product work, relying on Service Usage Data and technical information. We do not read Your Content for these purposes.
To support you. Respond to a support request made by you or by a Custodian. Where answering the request requires access to Your Content, including Personal Health Information, OmaScan staff reach it only through a logged support pathway, only on that request, and only to the extent the request requires.
To comply with law. Meet legal, regulatory, and contractual obligations, including the audit and record-keeping obligations that Custodians pass to us, and respond to valid legal requests.
To communicate with you. Send service, security, and account messages. With your consent where required, send product news. You can opt out of non-essential messages at any time.
To create De-Identified Data. We may create De-Identified Data from Your Content and Service Usage Data and use it to operate, evaluate, and improve the Service and its AI features, to produce aggregate statistics and benchmarks, and for health research, including publication of aggregate results. Our de-identification method removes names, addresses, faces, voices, and other direct identifiers and uses aggregation, generalization, and suppression to address the identifying potential of spatial data. We do not attempt to re-identify it. Where Your Content is Personal Health Information held for a Custodian, the Custodian authorizes us to create De-Identified Data from it by accepting the Terms of Service, and may withdraw that authorization at any time by writing to security@omascan.com.
We do not sell Personal Information. We do not use Personal Information for advertising or marketing profiles, and we do not permit our service providers to do so.
6. Artificial Intelligence Features
The Service uses Google's Gemini models on Google Cloud Vertex AI, and Amazon Transcribe on Amazon Web Services, both in Canada, for four features:
Captions. When you upload a photo or video, the model writes a short factual description of the space and objects shown. The model is instructed not to describe people, not to read names, addresses, or other visible text, and not to draw clinical conclusions. Captions are stored with the media, and deleting the Assessment deletes them.
Transcription. When you record dictation or a session, and when you upload a video, the speech is transcribed into text with speaker labels by Amazon Transcribe or, for some recordings, Gemini. Transcripts are stored with the Assessment, and deleting the Assessment deletes them. A dictation or session audio file is itself deleted thirty days after upload (Section 9); a video is Your Content and is kept with the Assessment.
Live assistant. During a capture session in the Mobile App, Gemini suggests next steps and answers questions about the capture plan. It receives only a text summary of the session, such as what the scan found, measurements taken, and the answer you typed or spoke. No photos, video, audio, or scan data are sent, and replies are not stored on OmaScan's servers.
Scan labels. For a 3D scan with photos, Gemini receives the captions already written for those photos, not the photos or the scan, and returns a room type and a short label. The label is stored with the scan, and deleting the Assessment deletes it.
Your choice. These features run only when the owner of the Assessment has turned on AI features, and one choice covers all four. Turning it off stops new AI processing; existing results stay until they are deleted.
How Gemini is used. For captions and transcription, your photo, video, or audio is sent with an instruction and nothing else. For the live assistant and scan labels, only the text described above is sent. Processing occurs on a regional endpoint in Montreal, Canada. Under Google Cloud's published terms for its generative AI services, Google does not use customer prompts or outputs to train its models. Google may retain a prompt for a limited period, in the same region, solely to investigate suspected abuse of its service.
How Amazon Transcribe is used. Your audio or video file is sent to Amazon Transcribe in the Montreal region (ca-central-1) with no other Assessment or account information. A temporary copy, encrypted with a key that OmaScan controls, is deleted once the transcript is stored or the transcription fails, and within one day in any case. Our Amazon Web Services accounts are opted out of Amazon's use of AI-service content, so Amazon does not store or use your recordings to improve its services.
These features are tools, not advice. Captions, transcripts, scan labels, and assistant suggestions can contain errors. They do not make clinical, regulatory, or compliance determinations, and the responsible professional reviews all content before relying on it.
No automated decisions. OmaScan does not use AI to make decisions that produce legal or similarly significant effects about any person.
AI training. We do not use Your Content, Personal Health Information, or identifiable inputs to train, fine-tune, or improve general-purpose AI models, and our agreements with, and settings for, our AI providers commit them to the same restriction. We may use De-Identified Data to evaluate and improve AI features.
If we add AI features that process Your Content in new ways, we will update this Section before they are enabled for you.
7. Sharing and Disclosure
With people you choose. Your Content is shared with the Collaborators you invite, at the permission level you choose. Invitation emails identify you and the Service; they do not include the Assessment title, the Subject's name, or any other Assessment content. The Collaborator sees the Assessment only after signing in.
With Custodians and within care relationships. Where an Assessment is carried out by or for a Custodian, Personal Health Information is available to that Custodian and to the people and organizations the Custodian, the Subject's consent, or applicable law authorize to receive it, for example to provide, authorize, fund, or coordinate care and home modifications.
With service providers. Our service providers may access Personal Information only as necessary to perform their functions for us, under written contracts that restrict use and require safeguards. Where Personal Health Information is held for a Custodian, we disclose it only to the subprocessors listed below and only for the purposes described in Section 5, or as a separate agreement with that Custodian otherwise permits. We impose on each subprocessor obligations at least as protective as those we owe the Custodian. Our current subprocessors are:
| Provider | Purpose | Information processed | Location |
|---|---|---|---|
| Google Cloud (Google LLC) | Hosting, database, file storage, message queues, logging, and AI processing (Vertex AI, Gemini) | All Your Content, account records, access logs | Canada (Montreal, northamerica-northeast1) |
| Clerk, Inc. | Account creation, sign-in, session management, billing | Name, email address, hashed password, sign-in and session records, plan | United States and other countries where Clerk or its subprocessors operate |
| Amazon Web Services, Inc. | Transcription (Amazon Transcribe, Section 6); and the earlier version of the Service (Section 8): hosting, database, file storage, authentication (Amazon Cognito), and content delivery network | Audio and video sent for transcription and the transcripts returned, held temporarily; account records, Your Content, and access logs held on the earlier version; web and API traffic in transit through the content delivery network | Canada (Montreal, ca-central-1; database backups in Calgary, ca-west-1). Content delivery edge locations include ones outside Canada, in transit only |
| Stripe, Inc. and Stripe Payments Canada, Ltd. | Payment processing for paid plans | Name, email address, payment card details (held by Stripe only), billing history | United States |
| Resend, Inc. | Sending invitation and account emails | Recipient email address, inviter's name, delivery logs | United States |
| PostHog, Inc. | Product analytics | Service Usage Data and technical information; no Your Content | United States |
| Apple Inc. | App distribution and crash reporting through the App Store | Diagnostics you choose to share with developers | United States |
We keep this list current and update this Policy when it changes materially. Where a separate agreement with a Custodian sets a notice procedure for subprocessor changes, we follow it.
With your identity provider. If you choose to sign in with your Google account, Google authenticates you and provides your name and email address for your OmaScan account, and Google learns that you use the Service. Google does this as your own identity provider under its agreement with you, not as a service provider acting for us, so its privacy policy governs what it does with your Google account information. No Assessment content and no Personal Health Information is sent to Google in this way. You can avoid it by creating an account with an email address and password instead.
For legal and safety reasons. We may disclose Personal Information where we believe in good faith that it is necessary to comply with a legal obligation, respond to a valid governmental request, enforce our agreements, protect the rights, property, or safety of OmaScan, our users, or others, or respond to an emergency involving a risk of death or serious harm. We will notify you before disclosing your Personal Information in response to a governmental or legal request unless the law prohibits it or notice would impede a lawful investigation or create a risk of harm. Requests concerning Personal Health Information held for a Custodian are referred to the Custodian.
In a business transaction. In a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, Personal Information may be transferred subject to this Policy or equivalent protections, and we will notify you.
With your consent, for other purposes.
8. Where Information Is Stored and Cross-Border Transfers
Your Content, Assessment records, and access logs stay in Canada. They are stored and processed on Google Cloud in the Montreal region (northamerica-northeast1), encrypted with keys that OmaScan controls. Our Google Cloud configuration prevents these resources from being created outside that region, and Gemini processing under Section 6 uses a regional endpoint in the same region.
Recordings sent for transcription stay in Canada. Amazon Transcribe processes them, and holds the temporary copy described in Section 6, in the Montreal region (ca-central-1).
The earlier version of the Service. Until it is retired, OmaScan also operates an earlier version of the Service on Amazon Web Services in the Montreal region (ca-central-1), with database backups replicated to the Calgary region (ca-west-1). Account records, Your Content, and access logs held there stay in Canada, and Your Content and the database are encrypted with keys that OmaScan controls. Sign-in for that version is provided by Amazon Cognito in the same region rather than by Clerk. Its web application and API responses are delivered through a content delivery network whose edge locations include ones outside Canada. Those responses include Assessment content such as addresses, measurements, and notes, and the network decrypts and re-encrypts them at the edge location serving you. Scans, photos, and video are fetched directly from Canada and do not pass through it. Nothing is stored there, but while it is being handled it is subject to the law of the country the edge location is in. Requests to that version are also screened by a web application firewall operating in the United States. To block common attacks it inspects request metadata such as your IP address, and the beginning of a request's contents, which can include information you type into an Assessment. It does not keep a copy of the contents it inspects. This affects accounts created before the Service moved to its current infrastructure. When that environment is retired, records held there are either migrated to the current version of the Service or destroyed under Section 9, and we will tell affected Custodians which, before it happens, and update this Policy.
Account credentials are processed outside Canada. Sign-in for the Service is provided by Clerk. To create and manage your account, Clerk stores your name, email address, and hashed password, together with sign-in and session records, on infrastructure operated by Clerk and its subprocessors, primarily in the United States. Clerk does not commit to a specific country. No Assessment content and no Personal Health Information is sent to Clerk. If you choose to sign in with Google, Google authenticates you and provides your name and email address to Clerk. That exchange happens on Google's identity infrastructure, which is not limited to Canada, and Google learns that you use the Service. It carries no Assessment content and no Personal Health Information.
Payments, invitation emails, and analytics are processed in the United States. Stripe, Resend, and PostHog process the information listed in Section 7 on infrastructure in the United States. None of them receives Your Content; invitation emails carry no Assessment content.
Information processed outside Canada, or passing through it, is subject to the laws of that country and may be accessed by that country's courts, law enforcement, and national security authorities under those laws. We rely on written contracts that require each provider to protect the information to a standard equivalent to this Policy, and we remain accountable for it while it is in their hands.
Before moving any category of Personal Information to a country it is not already held in, we would assess the privacy and security implications, put appropriate contractual protections in place, obtain the agreement of affected Custodians where Personal Health Information is involved, and update this Policy before the transfer. We have no plans to do so.
9. Data Retention
We keep Personal Information for as long as needed for the purposes in this Policy and to meet legal, regulatory, and contractual obligations, and no longer. Current periods:
| Information | Retention |
|---|---|
| Account information | While your account is open. Deleted within thirty days of a verified deletion request. Otherwise up to seven years after closure where needed for billing records, disputes, or legal obligations. |
| Your Content, including Personal Health Information | For Assessments carried out for a Custodian: as directed by that Custodian under its record-keeping obligations and any separate agreement with us. Otherwise: until you delete the Assessment or your account. OmaScan does not set its own retention period for Personal Health Information. |
| Dictation and session audio files | Thirty days after upload, then deleted automatically. The transcript is kept with the Assessment. |
| Temporary copies sent to Amazon Transcribe | Deleted once the transcript is stored or the transcription fails, and within one day in any case. |
| Transcripts and captions | With the Assessment, until it is deleted. |
| Collaborator invitations | With the Assessment they belong to. |
| Consent records | Ten years after the account is closed. |
| Access logs for Assessments and other records | One year, longer where required for an investigation or legal obligation. |
| Service Usage Data | While your account is open and up to seven years after closure, then deleted or de-identified. |
| Technical and application logs | Thirty days. |
| Email delivery logs | Thirty days, held by Resend. |
| Communications | Up to two years after the matter is resolved. |
| Backups | Database backups are kept for thirty-five days and overwritten on a rolling basis. Deleted files remain recoverable for up to sixty days, then are purged. |
| Records on the earlier version of the Service | Scan files deleted there stay under a storage retention lock for up to one year before they can be purged, and access logs for that version are kept for seven years. The periods above apply to everything else. |
| De-Identified Data | May be retained indefinitely. |
When you delete an Assessment that is not held for a Custodian, its records are removed from the live database immediately and its files and backup copies are purged within sixty days, or within the period in the table above for the earlier version of the Service. Where an Assessment is held for a Custodian, deletion follows that Custodian's retention instructions; the Custodian may require that Assessments be retained and may restrict who is permitted to delete them. If you close your account, Assessments you created for a Custodian remain subject to that Custodian's instructions. Where Your Content includes Personal Health Information held for a Custodian, we return or securely destroy it on the Custodian's written instruction, or on written notice that the Custodian has stopped using the Service, as the Custodian directs and in respect of the records the instruction or notice identifies, and confirm destruction in writing.
Despite the periods above and despite any instruction to delete, we may retain Personal Information for as long as we need it to meet a legal obligation, to answer a regulatory investigation or audit, or to comply with a court order, a preservation order, or a legal proceeding to which we are a party. For Personal Health Information held for a Custodian, we retain it on these grounds only where the law requires or a legal proceeding compels it, and not for our own claims or disputes with the Custodian. We tell the affected Custodian when we do this and what we are holding, we hold no more than the matter requires, and we delete it once the matter ends.
10. Deleting Your Account and Content
You can delete an Assessment from the Mobile App or the Web App. You can delete your account by emailing support@omascan.com from the email address on the account; we verify the request and complete the deletion within thirty days. Account deletion removes your account information, your Assessments that are not held for a Custodian, your Collaborator access, and your Service Usage Data, within the periods in Section 9. Access logs and consent records are retained for the periods in Section 9 because they exist to evidence what happened to Personal Health Information.
11. Security Safeguards
We use administrative, technical, and physical safeguards designed to protect Personal Information against loss, theft, and unauthorized access, use, disclosure, modification, or destruction. They include:
In the cloud. Encryption in transit (TLS 1.2 or higher) and at rest with customer-managed keys; a Google Cloud configuration that prevents resources on the current version of the Service from being created outside the Canadian region; role-based access on the principle of least privilege; an access log entry for every read and write of Assessment data on the current version of the Service, generated in the same code path as the access itself; automated monitoring; regular patching; and secure development practices. Application logs redact known credential, contact, and health field names, and Assessment content is not sent to analytics.
On your device. The Mobile App stores captures on the device with iOS complete file protection, so they are encrypted while the device is locked, and keeps capture metadata and the upload queue in an encrypted store whose key is held in the device keychain. Sign-in tokens are held in the keychain and are not included in device backups. Captures remain on the device after you sign out so that unfinished uploads are not lost; captured scans, photos, and video are removed when a different user signs in on the device. Protect your device with a passcode, keep it updated, and use the Service on devices your organization approves.
Our people. Written security and privacy policies; confidentiality obligations for staff and contractors; privacy and security training; vendor review before engaging a subprocessor; an incident response process; and a rule that human access to Personal Health Information by OmaScan staff happens only through a logged support pathway on the Custodian's or user's request.
Physical. Certified data centres operated by Google Cloud and, for transcription and the earlier version of the Service, by Amazon Web Services, with physical access controls and redundancy.
For Custodians. We produce access logs for a Custodian's Assessments on request, in a format the Custodian can review, so it can meet its own audit obligations.
Residual risk. No safeguard removes risk entirely. Account credentials processed outside Canada may be reached by foreign legal process, as described in Section 8. A detailed 3D scan of a home is identifying in ways an ordinary photograph is not, so an unauthorized disclosure of Assessment content could reveal where a person lives and aspects of their health. Photos you import from your device's library may carry the location where they were taken, which we keep as part of the photo. We reduce these risks through the measures in this Section, and you reduce them by limiting who you invite to an Assessment, by capturing no more than the Assessment needs, and by using a strong, unique password with multi-factor authentication where available.
12. Breach Notification
We maintain a breach response process to identify, contain, investigate, and remediate incidents involving Personal Information. We keep a record of every breach of security safeguards for at least twenty-four months, whether or not it created a risk of harm.
Personal Health Information held for a Custodian. If Personal Health Information is stolen, lost, or accessed, used, or disclosed without authority, we notify the responsible Custodian at the first reasonable opportunity, and in any event within 72 hours of confirming the incident, and provide the information the Custodian needs to meet its own obligations to notify individuals and its privacy commissioner. We provide Custodians, on request, with the information about incidents affecting their Personal Health Information that their law requires them to report.
Other Personal Information. If a breach of safeguards involving Personal Information we hold as the responsible organization creates a real risk of significant harm to you, we notify you and the Office of the Privacy Commissioner of Canada as soon as feasible, notify any other organization or government body that can reduce the risk of harm, and describe the incident, the information affected, our response, and steps you can take.
If you believe your account or information has been compromised, contact security@omascan.com immediately.
13. Your Rights and Choices
Subject to applicable law and identity verification, you may:
- access the Personal Information we hold about you;
- correct inaccurate or incomplete information;
- delete your account and Your Content (Section 10), subject to Custodian instructions and legal retention obligations;
- request a copy of Your Content and of your account and consent records in a structured, machine-readable format, subject to Custodian instructions where the content is Personal Health Information;
- withdraw consent, which does not affect prior processing and may affect our ability to provide the Service;
- object to or ask us to restrict certain processing;
- ask about how AI features processed your content and request human review of any AI output that concerns you;
- complain to us or to the privacy regulator in your jurisdiction.
To exercise these rights, email security@omascan.com, or support@omascan.com for account deletion as described in Section 10. We respond within thirty days. We may extend that period by up to thirty additional days where the request covers a large volume of records or we must consult others, and we will tell you before we do. We may refuse a request only on grounds applicable law permits, for example where responding would reveal another person's Personal Information or disclose information subject to solicitor-client privilege, and we will give reasons. For Personal Health Information held for a Custodian, the Custodian leads the response and the response time is set by its health privacy law: thirty days under Ontario's PHIPA and sixty days under Newfoundland and Labrador's PHIA.
14. Jurisdiction-Specific Disclosures
Canada. PIPEDA and applicable provincial privacy laws govern our handling of Personal Information. Where a provincial health privacy law applies, for example PHIPA (Ontario) or PHIA (Newfoundland and Labrador), requests about Personal Health Information held for a Custodian are directed to that Custodian. Nothing in this Policy or the Terms of Service affects your rights under the privacy or health privacy law of your province or territory of residence, including your right to complain to your provincial or territorial privacy commissioner. If you are not satisfied with our response you may contact the Office of the Privacy Commissioner of Canada (www.priv.gc.ca) or the commissioner of your province or territory.
Quebec. OmaScan has not assessed the Service against Quebec's Act respecting the protection of personal information in the private sector (Law 25) and does not offer the Service for use in Quebec or for Subjects in Quebec. We do not knowingly onboard Quebec organizations. If you believe Quebec law applies to your information, contact our Privacy Officer (Section 19) and the Commission d'accès à l'information du Québec.
United States. Where OmaScan has executed a Business Associate Agreement with a HIPAA covered entity or business associate, OmaScan acts as that entity's business associate and handles Protected Health Information only as the agreement and HIPAA permit. An individual's HIPAA rights, including access, amendment, and an accounting of disclosures, are exercised through the covered entity responsible for their care, and we support that entity in fulfilling them. State privacy laws may grant additional rights; write to security@omascan.com to exercise any that apply. Protected Health Information is held in Canada on the infrastructure described in Section 8; HIPAA does not require United States residency.
Elsewhere. OmaScan does not represent compliance with the laws of the European Economic Area, the United Kingdom, or any other jurisdiction outside Canada and the United States, and will update this Policy before offering the Service in one.
15. Children and Minors
Account holders. Accounts may be created and used only by persons who have reached the age of majority in their province or territory. We do not knowingly create accounts for minors and will delete an account if we learn one belongs to a minor.
Subjects. Subjects may include children, for example where a child's home is assessed for accessibility. The responsible Custodian or professional is solely responsible for obtaining consent from the parent, guardian, or substitute decision-maker, and for the lawful collection, use, and disclosure of the child's Personal Health Information. If we learn that Personal Information about a minor has been collected through the Service without the consent required by law, we notify the responsible Custodian or professional, provide the information they need to respond, and act on their instructions. Where the information is not held for a Custodian, we delete it.
16. Third-Party Applications and Services
The Mobile App uses Apple frameworks on your device to capture scans, photos, video, and audio. Apple's terms and privacy policy govern the device and the App Store. Where you import files produced by other applications, those applications' terms govern their own processing; OmaScan's obligations under this Policy attach from the moment the file is uploaded to the Service. Links to other services are subject to those services' privacy practices, for which we are not responsible.
17. Cookies, Local Storage, and Analytics
The Web App uses essential cookies and local storage to keep you signed in, remember your preferences, and protect against misuse. We use PostHog to collect Service Usage Data in the Web App and the Mobile App, associated with a device identifier and your user ID. Session replay is not enabled. We do not use advertising cookies or share information with advertisers. You can control cookies in your browser; disabling essential cookies will prevent sign-in.
18. Changes to This Privacy Policy
We may update this Policy. For material changes we will notify you by email or in-app notice before they take effect and, where the law requires, obtain your renewed consent. Each version carries a version number, the version you accepted is recorded in your consent record, and previous versions are retained.
19. Contact Information
Privacy OfficerOmaScan Inc.
748 Old Broad Cove Rd
Portugal Cove-St. Philip's, NL A1M 1P1, Canada Privacy and security: security@omascan.com
Account and support: support@omascan.com
See also the OmaScan Terms of Service.