We use the Jane App at AERCS Therapy, ensuring that your data is protected with top-notch encryption, and we strictly adhere to Canadian health regulations. It’s all about giving you a secure and hassle-free experience!
Strict Data Control
Unlock Hope and Healing with a Complimentary 20-Minute Phone Call Consultation
Are you ready to take the first step towards a brighter future? At AERCS, we're here to support you on your path to well-being. Our complimentary intake call is your opportunity to connect with us, confidentially share your journey, and discover the transformative support we offer. By taking this call, you're not just talking; you're taking control of your well-being, paving the way for tailored therapy that can change your life. Don't wait—book your call today and embrace the healing journey that awaits you.
• Your meeting with AERCS is simply one click away, placing you in a virtual waiting room before your video call begins.
• Jane App is PHIPA and PIPEDA compliant (regulation for the way Canadian client health information is stored).
• End-to-end encryption ensures our video call is between service provider and client only.
Notice to Patients
If you are a patient of one of our Subscriber clinics or practitioners, your clinic or practitioner controls your patient information, including your contact information, billing details and patient records. Please contact your clinic or practitioner for any questions about your patient information. See the section titled Patient Data below for further information.
Why Jane Collects Personal Information
Information Jane Collects from You
Contact Information. We collect your contact information, such as your name, email address and organization, when you fill out our online forms or set up your user account for our Services. We use your contact information to activate your user account, give you access to the Services, and to send you notices about your user account. We may also use your contact information for marketing purposes, such as promotional emails, direct mail and sales contacts. You can opt-out of our marketing communications at any time by unsubscribing or contacting us at [email protected]. Please note that Jane does not collect or manage the contact information of patients, or any marketing or other communications between a Subscriber and its patients.
When a Subscriber subscribes to our Services, we also collect credit card information to process payment. Credit card information is provided directly to our payment processor and is processed in a PCI-compliant manner. We do not keep your credit card information. Note that when credit card information is referred to as being “stored”, this means we have a “token”. The token replaces sensitive information and acts as a non-sensitive placeholder that can be used by the payment processor to reference your credit card information when payments need to be processed.
Log and Device Information.
When you access and browse our Services, we collect information about how you are accessing our Services, such as your internet or mobile network connection, your browser or the type of mobile device you are using (if applicable). We use this log and device information to identify how our Services are being accessed and used so we can optimize them for the types of connections, browsers and devices being used. This information is not used to market or send promotions at an individual user level.
Cookies and Tracking Information.
- To learn about use of our websites, such as user traffic patterns and the effectiveness of our navigational structure
- To identify email open rates in order to gauge the effectiveness of certain communications or marketing campaigns to clinics
- To allow you to login to secure areas of our Services
- To store your login credentials for easy access to our Services
Legal Basis (GDPR EU/UK).
For personal information that is subject to the General Data Protection Regulation (GDPR), we rely on the following legal bases for collecting and using your personal information:
- Your consent
- Our legitimate interests (which are not overridden by your privacy rights), such as operating our business, understanding and improving our Services, direct marketing related to our Services, communicating with our Subscribers and users about our Services, events or related resources, improving our websites and protecting our legal rights and interests.
You may withdraw your consent at any time. Where we are using your personal information for our legitimate interests, you have the right to object to that use. See below under Your Rights for how to withdraw consent or object.
If you are a patient of one of our Subscriber clinics, please contact your clinic or practitioner if you have any questions about the legal basis for collecting and using your personal information. Our Subscribers may have a different legal basis for collecting and using a patient’s personal information, such as providing health care or treatments as a regulated healthcare professional.
Subscribers use our clinic management platform to collect personal information from their patients and create patient records. These records may include a patient’s name, address, health insurance and billing information, medical charts, appointment history and other patient data (“Patient Data”). This information is sometimes referred to as “personal health information”, “protected health information”, “data concerning health” or “sensitive data” depending on the location of the Subscribers and the privacy laws applicable to them. If you are a patient, Patient Data is collected from you when you visit your Subscriber clinic or practitioner and when you set up an account with the Subscriber clinic through our online booking website.
Subscribers retain sole control over Patient Data and may be referred to as a “health information custodian”, a “covered entity” or a “controller” depending on their location and the privacy laws applicable to them.
- What Patient Data to collect;
- How the Subscriber will use the Patient Data;
- How long the Subscriber will store Patient Data; and
- On what basis the Subscriber may delete Patient Data.
Subscribers are responsible for complying with laws and regulations governing the use of Patient Data, and for determining the legal basis for such use.
Jane is a service provider to Subscribers and may be referred to as an “agent”, “business associate” or “processor” of the Subscriber. Jane stores Patient Data in its secure data centers and makes it available to Subscribers and their users through our clinic management platform. Jane otherwise has no control over Patient Data. Jane will only access Patient Data on the instructions of the Subscriber or its practitioners or staff or, in rare cases, where needed in order to prevent or address technical problems or if required by law or court order.
Patient Data is stored in the regional data centre for the location chosen by the Subscriber during the sign-up process. We currently have regional data centres in Canada, the United States, UK, and Australia, though this may change from time to time. If we do not have a data centre in the Subscriber’s region, Patient Data will be stored in our Canadian data centre, unless otherwise requested by the Subscriber. Please note that we use US-based service providers for appointment reminders sent by email or SMS and, therefore, Patient Data contained in appointment reminders will go through and may be stored temporarily in the United States. All our data centres and service providers maintain a high level of security and are compliant with applicable privacy laws.
Patients have certain rights with respect to their Patient Data, which may include knowing what information your Subscriber clinic has about you, correcting any inaccurate Patient Data, obtaining a record of your Patient Data and, in certain circumstances, deleting or removing your Patient Data. Please note that Subscribers have strict legal and regulatory obligations around Patient Data and may not always be permitted to delete or remove Patient Data.
Sharing Your Information.
We do not sell or distribute personal information to third parties for their own commercial or marketing purposes. We will only share personal information we collect in the following circumstances:
Suppliers and Service Providers. In order to operate our business and provide the Services to our Subscribers and their users, we may need to share a limited amount of personal information, including Patient Data, with our third-party suppliers and service providers. Before sharing personal information, we ensure that the third parties receiving the personal information have provided appropriate safeguards, and that privacy rights are protected and preserved. Some of the areas where we use third-party suppliers and service providers include:
- Our data centers where all platform data is stored
- Customer support services to help us collect feedback and manage our support services
- Communication services to send out email and SMS notices or reminders
- Payment processors
We may share personal information in connection with negotiating or carrying out a financing or acquisition of our business, a merger or amalgamation with another business, or a sale of all or part of our company assets. Before sharing personal information, we will ensure that appropriate confidentiality and non-disclosure undertakings are in place. We will not share Patient Data in these circumstances.
Compliance with Laws
We may disclose personal information to a third party if we are required to do so by applicable law, government request, court order or regulatory body. We may also be required to disclose personal information to enforce our legal rights, to enforce security requirements, or to respond to an emergency which we believe, in good faith, requires us to disclose personal information. In such instances, if permissible, we will make every reasonable effort to give you as much notice as possible regarding the disclosure of your personal information, what information was disclosed and why. We will not disclose Patient Data unless legally required to do so.
Anonymized / Aggregated Data.
Jane may use computer-generated algorithms to gather anonymous and aggregated information from our Subscribers and their Patient Data in order to assist in our continued development and improvement of the Services, and for research, data analysis, benchmarking, statistics or trend analysis. We will ensure that none of the information we gather identifies, or could be used to identify, any user or patient. Jane may share such anonymized information with Subscribers and others, for example, by providing insights into most common conditions, most popular treatments or benchmarking fees against industry or regional norms.
We protect your personal information, including Patient Data stored in our platform, by:
- Using industry standard security controls such an encryption and an SSL (Secured Sockets Layers) certificate to ensure information is transmitted over a secured connection between your browser and our web server.
- Using state-of-the-art data centres with appropriate security and compliance certifications, such SOC 2 and EU-US Privacy Shield that are HIPAA compliant.
- Having our personnel sign strict confidentiality agreements to ensure they understand the confidential nature of the data we process, and only accessing your account when you request assistance from us.
- Requiring password protection of your user account with a password set by you. We cannot access or identify your password. The only way to recover a password is for you to initiate a reset via the email address or mobile phone number you use for the Services.
While we employ industry standard measures to protect your information, no electronic communication can ever be completely secure. You share responsibility for protection of your personal information by setting a strong password and by keeping your username and password confidential.
We retain personal information only for as long as necessary to achieve our stated purposes, or as required by applicable law. For example, Contact and Billing information is kept for as long as a Subscriber account is active and for a reasonable period after it has been deactivated in the event you or your Subscriber wish to re-activate the account. User account information may also be retained as necessary to comply with our legal obligations, resolve disputes or maintain our relationship with your Subscriber organization. Credit card information is never kept or stored by us.
If you are a patient of one of our Subscriber clinics, please contact your clinic or practitioner for information regarding the storage period for your Patient Data.
Personal information may be transferred to and processed in Canada and the United States. Before transferring your personal information, we ensure that appropriate safeguards are in place and that your privacy rights are protected and preserved. Such safeguards may include the existence of an EU adequacy decision, certification and adherence to EU-US Privacy Shield and Swiss-US Privacy Shield Frameworks, the Standard Contractual Clauses approved by the European Commission, binding corporate rules, or other legal mechanisms to safeguard the personal information being transferred.
Information about the Privacy Shield Frameworks can be found at www.privacyshield.gov
Individuals have certain rights with respect to their personal information. These rights are set out below. If you are a patient of one of our Subscriber clinics, please contact your clinic or practitioner to exercise any of these rights with respect to your Patient Data.
Correction and Deletion.
We will make reasonable efforts to ensure that the personal information we collect from you is accurate and complete. You may update, correct or delete your account information at any time by logging into your user account and modifying your personal information, including your preferences to receive messages from us. You may also update, correct or delete your personal information by contacting us as noted below.
Restriction and Objection.
In certain limited circumstances, individuals in the EU may request that we restrict our use of their personal information and, where we rely on legitimate interests as the legal basis for using your personal information, you have the right to object to such use. In these cases, we can be required to no longer use your personal information; however, this may mean that certain components of our Services cannot be made available to you. If you wish to exercise your right to restrict or object, please contact us.
You have the right to lodge a complaint with a supervisory authority (i.e., the independent public authority responsible for monitoring data protection laws in your country). You may also contact the Information and Privacy Commissioner of British Columbia (for British Columbia matters) ( http://www.oipc.bc.ca/ ) or the Privacy Commissioner of Canada (for international matters and inter-provincial matters) ( http://www.priv.gc.ca/ ).
AERCs Orangeville Location
873209 5 Line E, Orangeville, ON L9W 6A4
AERCs Toronto Location
1849 Yonge St, Floor 1, Suite 914, Toronto, ON M4S 1Y2
AERCs Mississauga Location
89 Queensway W #226, Mississauga, ON L5B 2V2