Legal
Privacy Policy
Effective date: May 1, 2025 · Last updated: May 1, 2025
Clavus Technologies Inc. (“Clavus”, “we”, “us”, or “our”) operates the Clavus clinical documentation platform. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our services, and describes your rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
By using Clavus, you agree to the collection and use of information as described in this policy. If you are using Clavus on behalf of a healthcare organization, you confirm you have authority to bind that organization to these terms.
1. Who We Are
Clavus Technologies Inc. is a Canadian company providing AI-assisted clinical documentation tools for healthcare practitioners. Our servers are hosted in Canada (ca-central-1) through Supabase and Amazon Web Services. We act as a data processor with respect to any patient-related information submitted through the platform, and as a data controller with respect to practitioner account data.
Questions or concerns about this policy should be directed to our Privacy Officer at privacy@clavus.ca.
2. Information We Collect
Account Information
When you register, we collect your name, email address, professional role, specialty, and billing information. Payment card details are processed by Stripe and are never stored on Clavus servers.
Voice Recordings
Audio is never stored. When you record a voice memo, the audio is transmitted over an encrypted connection, transcribed in-memory using OpenAI’s Whisper API, and immediately discarded. The raw audio file never touches permanent storage — ours or anyone else’s.
Transcripts and Clinical Notes
Transcribed text and generated clinical notes are stored in our Canadian database and linked to your account. We strongly advise using patient codes or initials rather than full patient names in voice recordings. You are responsible for ensuring any information you input complies with your professional obligations and your patients’ consent.
Usage and Technical Data
We collect non-identifying metadata such as note format used, specialty, session duration, and feature interactions. We do not log patient identifiers in audit records. Standard server logs (IP addresses, request timestamps) are retained for up to 90 days.
Style Profile Data
If you upload sample notes during onboarding, those notes are processed by Claude (Anthropic) to extract stylistic patterns. The source notes are deleted after processing; only the extracted style descriptor JSON is retained.
3. How We Use Your Information
- To provide, operate, and improve the Clavus service.
- To generate clinical notes from your transcribed recordings.
- To personalize note output based on your documented style profile.
- To manage your subscription and process payments through Stripe.
- To send transactional emails (receipts, password resets, team invitations) through Resend.
- To detect and prevent fraud, abuse, or violations of our Terms of Service.
- To comply with legal obligations.
We do not sell your personal information. We do not use your clinical content to train AI models without your explicit, written consent.
4. Third-Party AI Processors
Clavus uses third-party AI services to provide core functionality. These services act as data processors under data processing agreements and are not permitted to use your data to train their models:
- OpenAI (Whisper) — Transcription of voice recordings. Audio is sent via encrypted API call and is subject to OpenAI’s zero-data-retention policy for API usage.
- Anthropic (Claude) — Note generation, specialty detection, and style extraction. Content sent to Anthropic is subject to their API data handling policy.
Both OpenAI and Anthropic are treated as sub-processors under PIPEDA. We maintain Data Processing Agreements with both providers. Because these processors may be located outside Canada, your data may be subject to the laws of those jurisdictions during processing.
5. Data Storage and Residency
All persistent data (accounts, notes, audit logs) is stored in Supabase’s Canadian region (AWS ca-central-1, Montreal). Stripe billing data is stored by Stripe in accordance with their privacy policy and PCI DSS compliance. Transactional email logs are stored by Resend, a Canadian-friendly provider, for up to 30 days.
6. Data Retention
We retain your account data and clinical notes for as long as your account is active. If you close your account, your data is retained for 90 days to allow for recovery, then permanently deleted unless we are required by law to retain it longer. Audit logs are retained for 2 years to support compliance obligations. You may request early deletion of your data at any time by contacting privacy@clavus.ca.
7. Security
We implement industry-standard security practices including TLS encryption in transit, AES-256 encryption at rest, row-level security enforcing tenant isolation, and role-based access controls. Finalized notes are immutable — our database enforces that they cannot be edited after finalization.
No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we take all reasonable steps to protect your information.
8. Your Rights Under PIPEDA
You have the right to:
- Know what personal information we hold about you.
- Request access to your personal information.
- Request correction of inaccurate information.
- Withdraw consent to processing (subject to legal and contractual obligations).
- File a complaint with the Office of the Privacy Commissioner of Canada.
To exercise any of these rights, contact us at privacy@clavus.ca. We will respond within 30 days.
9. Cookies and Tracking
Clavus uses session cookies required for authentication (managed by Supabase Auth). We do not use advertising cookies, cross-site tracking, or third-party analytics that share data with advertisers. You can disable cookies in your browser, but this will prevent you from logging in.
10. Children
Clavus is intended exclusively for healthcare professionals aged 18 and over. We do not knowingly collect information from minors.
11. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes by email and update the effective date above. Continued use of Clavus after the effective date constitutes acceptance of the updated policy.
12. Contact
Privacy Officer
Clavus Technologies Inc.
privacy@clavus.ca