Privacy Policy

Last updated: August 1, 2026

1. Overview

Rahi Health Technologies Incorporated (“Rahi,” “we,” “us”) is a federally incorporated Canadian company that builds AI-powered clinic automation software for Canadian healthcare clinics. Our registered office is at 733 Karlsfeld Road, Waterloo, Ontario, N2T 2W4.

This Privacy Policy explains how we handle personal information in two distinct contexts:

  • Our website (rahihealth.ai) — information we collect when you browse, contact us, or request a demo. See Sections 3–5.
  • The Rahi platform — clinic and patient information we process on behalf of the clinics that use our software. See Sections 6–10.

These two contexts carry different legal roles and different obligations, and we treat them separately throughout this policy.

Questions, requests, or complaints can be directed to our Privacy Officer at [email protected].


2. Our roles and the law that applies

Website and marketing. For information collected through our website and in the course of our own business (prospective customers, contacts, job applicants), Rahi determines the purposes of collection and is accountable for that information under the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applicable provincial privacy legislation.

Platform. For clinic and patient information processed through the Rahi platform, the clinic is the health information custodian (or equivalent) and Rahi acts solely as its service provider and agent. We process this information only on the clinic’s instructions and under a written service agreement. Depending on where the clinic operates, this may include:

  • Ontario — Personal Health Information Protection Act, 2004 (“PHIPA”)
  • Alberta — Health Information Act
  • British Columbia — Personal Information Protection Act and E-Health Act
  • Other provinces — equivalent provincial health privacy legislation
  • PIPEDA, where applicable

Patients who have questions about their own health information should contact their clinic, which is the custodian of that information. We will support the clinic in responding to any such request.


3. Information we collect through our website

We keep website data collection deliberately minimal.

No advertising trackers. We do not use advertising pixels, and we do not sell browsing data to anyone.

Local display preferences. Your browser may store small amounts of data locally, such as your light/dark mode preference. This stays on your device and is not transmitted to us.

Basic technical logs. Our hosting infrastructure records standard technical information — IP address, browser type, pages visited, timestamps — for security, reliability, and abuse prevention. These logs are retained for 30 days and then deleted.

If we adopt an analytics or marketing tool in the future, we will name it in this policy before enabling it.


4. Information you provide to us directly

We collect personal information when you voluntarily provide it — for example, by submitting our contact form, requesting a demo, emailing us, or applying for a job. This may include your name, job title, email address, phone number, clinic or organization name, and the contents of your message.

We use this information to:

  • Respond to your questions and requests
  • Schedule, prepare for, and follow up on demos you have asked for
  • Administer a commercial relationship, including contracting and billing
  • Assess job applications, where you have applied for a role
  • Send you information about Rahi, only where you have consented — you can opt out at any time using the unsubscribe link in any message or by emailing [email protected]

We never sell personal information. We share it only with employees and service providers who need it to respond to you or administer our business, and who are bound by confidentiality and security obligations consistent with this policy.

Please do not include patient or health information in our contact form or in emails to us. The website is not intended to receive personal health information, and is not a secure channel for it.


In limited circumstances we may be required by law to disclose personal information — for example, in response to a court order, subpoena, or lawful request from a regulator or law enforcement. We will assess the validity of any such request, disclose only what is legally required, and notify the affected individual or clinic unless we are prohibited from doing so.


6. Clinic and patient data in the Rahi platform

The Rahi platform processes information on behalf of clinics in order to automate administrative workflows — triaging referrals, classifying inbound documents such as labs and consult notes, managing patient intake and appointment communications, and supporting scheduling and waitlists.

Depending on how a clinic configures the platform, this may include patient names and contact details, health card or identifier numbers, referral content, diagnoses and clinical summaries contained in referrals or documents, lab and consult results, intake form responses, appointment history, and communications between the clinic and its patients.

We process this information only to provide the Services to the clinic and as the clinic instructs. We do not use it for our own purposes, for marketing, or to build products for anyone else.


7. Our platform data commitments

These commitments apply to every clinic, regardless of the terms of an individual service agreement.

We never train on your data. Clinic and patient data is never used to train, fine-tune, or improve AI models — ours or anyone else’s. Where we use third-party model providers to deliver the Services, those providers are contractually prohibited from retaining clinic data or using it for training, and we do not enable any feature that would permit it.

Data stays in Canada. Clinic and patient data is stored and processed on encrypted infrastructure located in Canada and is subject to Canadian law. The one exception is data a clinic chooses to send to a third-party system it has connected itself (for example, its own EMR or communications provider), which is governed by the clinic’s arrangement with that provider.

Every action is auditable. Each decision and action the platform takes on a clinic’s behalf is recorded in an audit trail the clinic can review at any time.

Clinics stay in control. Clinics own their data. They can request export or deletion at any time, subject to their own record-keeping obligations and any legal hold.

Encryption. Data is encrypted in transit (TLS) and at rest.

Access is limited and logged. Rahi personnel access clinic data only where necessary to provide, support, or secure the Services. Access is role-based, logged, and subject to confidentiality obligations and background screening.


8. Service providers and subprocessors

We use a limited set of third-party providers to operate the platform — for example, cloud hosting, and AI model providers. Every provider that may handle clinic or patient data is bound by a written agreement requiring:

  • Canadian data residency, where applicable
  • Confidentiality and security safeguards no less protective than our own
  • A prohibition on using the data for training or for any purpose other than delivering the service to us
  • Prompt notification of any security incident

We maintain a current list of subprocessors that process clinic data, available to any clinic on request at [email protected]. We will notify clinics before adding a subprocessor that will process their data.


9. Retention

Website and marketing information. Technical logs are retained for approximately 30 days. Contact and demo-request information is retained for as long as needed to respond and to maintain the commercial relationship, and for up to 24 months after our last interaction, unless you ask us to delete it sooner. Job application materials are retained for up to 12 months.

Clinic and patient data. Retained for the term of the clinic’s service agreement. On termination, we make the data available for export for 30 days, after which it is deleted or returned at the clinic’s election, except where retention is required by law. Backups are purged on a rolling 35-day cycle.

Where data cannot be fully deleted from a system for technical reasons, we isolate it and prevent any further use.


10. Security and breach notification

We maintain administrative, technical, and physical safeguards designed to protect personal information against loss, theft, unauthorized access, disclosure, copying, use, or modification. These include encryption in transit and at rest, role-based access control, logging and monitoring, secure development practices, and periodic review of our security posture.

No system is completely secure. If we become aware of a privacy breach involving clinic or patient data, we will notify the affected clinic without unreasonable delay and provide the information the clinic needs to meet its own notification obligations to patients and to the applicable privacy commissioner. For personal information we hold in our own right, we will notify affected individuals and regulators where required by PIPEDA’s breach reporting provisions.


11. Your rights

Subject to applicable law, you have the right to:

  • Access the personal information we hold about you
  • Correct information that is inaccurate or incomplete
  • Request deletion of your personal information, subject to legal and record-keeping requirements
  • Receive a copy of your personal information in a portable format
  • Withdraw consent to our collection, use, or disclosure at any time
  • Make a complaint about how we have handled your personal information

To exercise any of these rights, email [email protected]. We will respond within 30 days, or tell you if we need more time and why. We may need to verify your identity before acting on a request.

If you are a patient of a clinic that uses Rahi, please direct requests about your health information to your clinic, which is the custodian of that information. If you contact us directly, we will refer you to the clinic and assist the clinic in responding.

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada, or the privacy commissioner or ombudsperson in your province.


12. Children

Our website is not directed at children. The platform may process health information about patients of any age, including minors, on behalf of clinics — that information is handled under the clinic’s authority and the same protections described in Sections 6 through 10.


Our website may link to sites we do not operate. We are not responsible for their content or privacy practices, and we encourage you to review their policies.


14. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will post the revised version here and update the “Last updated” date. If a change is material, we will provide notice before it takes effect — to clinics through the contact on file, and on this website. If you do not agree with a change, contact us and we will not use personal information we already hold in a manner other than what you previously agreed to.


15. Contact us

Privacy Officer
Rahi Health Technologies Incorporated
733 Karlsfeld Road, Waterloo, Ontario, N2T 2W4, Canada