Document Contents & Quick Navigation
Entity Overview & Scope of Policy
QuestCare Connect Inc. ("QuestCare Connect," "we," "our," or "us") is dedicated to empowering families, primary caregivers, care recipients, and healthcare professionals through our secure care coordination platform, including our web portal, mobile applications, APIs, and associated software features (collectively, the "Service").
This Privacy Policy details our binding commitments and procedures regarding the collection, handling, de-identification, storage, disclosure, and defense of personal data and Protected Health Information (PHI). By registering for, accessing, or utilizing any portion of the Service, you confirm that you have read, understood, and agreed to be governed by the practices described in this Privacy Policy and our Terms of Service.
In-App Acknowledgment & Tamper-Evident Audit Logging
Cryptographically Verified Electronic Records
To maintain strict evidentiary compliance with the Canadian Electronic Commerce Acts, the U.S. Electronic Signatures in Global and National Commerce Act (E-SIGN), and the Uniform Electronic Transactions Act (UETA), your consent to this Privacy Policy and our Terms of Service is recorded as a binding electronic event.
Upon your registration, onboarding, and whenever material revisions are published, our servers record an immutable audit log entry containing:
- Your verified account identifier (User UID);
- The exact version string of the legal policy agreed to (e.g., Version 2.0.0);
- An ISO-8601 millisecond-precision server timestamp;
- Your originating public IP address and resolved geographical jurisdiction;
- Your device browser, operating system fingerprint, and user-agent string.
Exhaustive Categories of Data Collected
We collect information you explicitly provide to us, data generated through platform interactions, and technical telemetry necessary for platform integrity. Data categories include:
A. Account & Profile Information
Full legal name, email address, physical postal address, telephone number, user role (Primary Caregiver, Circle Member, Professional Caregiver, Healthcare Responder), emergency contacts, avatar imagery, and profile credentials.
B. Protected Health Information (PHI)
Medical diagnoses, allergies, current medications and dosages, clinical visit summaries, uploaded laboratory tests, radiology and doctor reports (PDFs, images, OCR scans), dietary requirements, physical therapy routines, daily symptom logs, and vital signs (blood pressure, heart rate, oxygen saturation, blood glucose, body temperature).
C. Passkey & Authentication Metadata
Public authentication keys, credential IDs, and WebAuthn/FIDO2 hardware metadata for passwordless biometric sign-in. Note: QuestCare Connect NEVER captures, transmits, or stores raw biometric templates (such as fingerprints or facial scans). Biometric verification is processed purely on-device by your local operating system.
D. Caregiver Marketplace & Hiring Data
For caregiver applicants and employers: professional certifications, licenses, resumes, hourly rates, background check verification indicators, interview notes, caregiver reviews, and job application communications.
E. Financial & Payment Tokens
Payment card brand, expiration month/year, billing zip code, and last four digits. All full primary account numbers (PANs) and CVV security codes are handled directly by our PCI-DSS Level 1 certified payment processor, Stripe. We store only Stripe customer IDs and transaction receipts.
F. Communications & Technical Telemetry
Video consultation session metadata via Twilio Video (room IDs, connection timestamps, participant IDs), SMS delivery records, IP addresses, browser fingerprint, session durations, error logs, and service performance metrics.
Artificial Intelligence (AI) Governance & PHI De-Identification
Security-First Generative AI Intelligence Protocols
QuestCare Connect integrates enterprise artificial intelligence capabilities to generate automated health summaries, analyze vitals trends, compare complex medical reports, generate physician consultation questions, and synthesize dietary suggestions.
Mandatory AI Privacy Safeguards:
- Automated PHI De-Identification (Scrubbing): Before user prompts or extracted medical report texts are processed by artificial intelligence pipelines, automated de-identification and sanitization protocols scrub direct HIPAA/PIPEDA personal identifiers (including patient names, exact addresses, government identification numbers, phone numbers, and email addresses).
- Strict Zero Foundation Model Training: Your health records, vitals, report uploads, and medical chat queries are NEVER utilized to train, retrain, or improve public or commercial foundation machine learning models operated by third parties (including Google).
- Transient In-Memory Inference: Prompts dispatched to the AI model interface are processed transiently and are not archived by the foundational AI provider beyond the duration necessary to return the completion.
Legal Bases for Processing (GDPR & PIPEDA)
Under international privacy frameworks including the EU/UK General Data Protection Regulation (GDPR) and the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), we process your personal data under the following legitimate legal bases:
1. Explicit Consent (Art. 6(1)(a) & Art. 9(2)(a))
For the processing of Special Category Personal Data (health and medical information), we rely upon your explicit, informed, and affirmative clickwrap consent, which you may revoke at any time.
2. Contractual Performance (Art. 6(1)(b))
To provide care circle coordination, dispatch alerts, coordinate caregiver hiring, maintain vital logs, and fulfill our core contractual obligations under our Terms of Service.
3. Legal Compliance (Art. 6(1)(c))
To fulfill statutory record-keeping mandates, tax requirements, billing audit trails, law enforcement subpoenas, and health oversight reporting obligations.
4. Legitimate Interests (Art. 6(1)(f))
To detect fraud, prevent denial-of-service attacks, harden application security, enforce access controls, and debug platform stability.
Health Privacy Regulatory Standards (United States & Canada)
United States: HIPAA, HITECH & State Consumer Health Privacy
Role Distinction: When used by individual consumers and families to self-manage care, QuestCare Connect functions as a direct-to-consumer digital health coordinator. When QuestCare Connect contracts with healthcare providers, clinics, hospitals, or covered health plans, we execute a standardized Business Associate Agreement (BAA) and enforce the administrative, physical, and technical safeguards specified by the HIPAA Security Rule (45 C.F.R. Part 160 and Part 164, Subparts A and C).
State Consumer Health Data Acts: Under the Washington My Health My Data Act (MHMDA), Nevada SB 370, and similar statutes, we certify that we collect consumer health data solely with your affirmative authorization to provide requested care coordination services. We never sell, lease, or license consumer health data.
Canada: PIPEDA & Provincial Health Information Statutes
We comply with the 10 Fair Information Principles of PIPEDA and align with provincial health privacy laws including the Personal Health Information Protection Act (PHIPA) of Ontario, the Health Information Act (HIA) of Alberta, and the Personal Information Protection Act (PIPA) of British Columbia. Where healthcare practitioners use the platform, QuestCare Connect operates as a compliant electronic service provider / Health Information Network Provider (HINP).
Care Circles & Emergency Responder Gatekeeper
QuestCare Connect operates on a principle of least privilege and caregiver-designated circles:
- Care Circle Sharing: The Primary Caregiver controls circle membership and permissions. Members (family, aides, or professional caregivers) may only access patient profiles and tasks according to their designated role.
- Emergency Responder Gatekeeper: The platform provides an emergency response feature allowing first responders or medical personnel to view vital medical summaries, allergies, DNR status, and emergency contacts via a unique QR code or emergency access PIN. Access through the emergency gatekeeper triggers immediate audit logging, recording the IP address, timestamp, and accessed parameters.
- No Public Directory Exposure: Patient health records and circle messages are strictly private and are never indexed by search engines, made publicly crawlable, or shared with advertisers.
Third-Party Subprocessors & Infrastructure
We contract with rigorous, enterprise-grade cloud service providers bound by strict Data Protection Addenda (DPAs) and confidentiality covenants:
| Subprocessor | Purpose / Service | Data Categories Handled | Location |
|---|---|---|---|
| Google Cloud Platform | Secure cloud infrastructure, data hosting, user authentication, and encrypted storage | Account data, encrypted PHI, audit logs, uploaded files | United States / Global |
| Google GenAI / Gemini | AI diagnostic summaries, report comparisons, vitals intelligence | De-identified health reports and user prompts (zero model training) | United States |
| Stripe Inc. | Payment processing, credit purchases, billing subscriptions | Payment card metadata, billing address, transaction amounts | United States / Global |
| Twilio Inc. | Encrypted video consultations, SMS two-factor codes, alerts | Phone numbers, video room IDs, session metadata | United States / Global |
| SendGrid / Email Delivery | Transactional emails, password resets, circle invitations | Email addresses, recipient first names, invitation codes | United States |
| Google Maps Platform | Address geocoding and caregiver proximity calculations | Street addresses, city, postal code coordinates | Global |
Cross-Border Data Transfers & Infrastructure Safeguards
QuestCare Connect utilizes an isolated, enterprise-grade cloud hosting infrastructure with strict data segregation controls:
- Encrypted Data Segregation: Sensitive health records and account credentials are fully partitioned and isolated from public community spaces and service telemetry.
- Perimeter Defense & Access Gateways: Data repositories have no direct public internet exposure and are safeguarded behind zero-trust network policies and access gateways.
- De-Identified Telemetry: Operational performance and uptime metrics are fully de-identified and maintained independently of personal identifiers.
For users in Canada, the European Union, and the United Kingdom, you acknowledge that your personal data may be transferred to, stored, and processed in cloud data centers located in the United States. All transfers are protected through Standard Contractual Clauses (SCCs) approved by the European Commission and equivalent international transfer mechanisms guaranteeing an adequate level of data protection.
Technical Safeguards & Encryption Standards
All databases and storage buckets are encrypted at rest using AES-256 bit encryption. All network transmissions are secured via Transport Layer Security (TLS 1.3/HTTPS) with HSTS enforcement.
We enforce email verification, offer SMS/TOTP two-factor authentication, and support biometric FIDO2 passkeys to defend accounts against unauthorized access and credential stuffing.
All platform requests are evaluated through server-enforced authorization policies and least-privilege access controls. Users cannot bypass permissions to view care circle data unless explicitly authorized by the Primary Caregiver.
We employ regular security assessments, automated threat monitoring, anomaly detection, and continuous health compliance reviews to safeguard our systems and defend against emerging cyber threats.
Data Retention & Erasure Exceptions
We retain personal information for the active life of your account or as long as necessary to provide care coordination. Upon receiving a verified account deletion request:
- Primary Deletion: Your profile, uploaded health documents, care circle memberships, and unshared personal notes are permanently expunged or anonymized from production databases within thirty (30) days.
- Statutory & Legal Exceptions: Certain records cannot be immediately erased where retention is mandated by applicable healthcare record retention statutes, corporate accounting/tax laws (typically 7 years for financial billing records), or immutable electronic audit logs required to defend legal claims or substantiate user E-SIGN consents.
Children’s & Pediatric Health Privacy (COPPA)
QuestCare Connect is not intended for or directed to individuals under the age of eighteen (18). Minors are strictly prohibited from independently registering for accounts.
Pediatric Patient Profiles: A parent or court-appointed legal guardian may create a care profile for a minor child under their legal care. The parent or legal guardian retains sole authority over the minor’s health information, acts as the primary consent provider under the Children’s Online Privacy Protection Act (COPPA), and assumes full responsibility for all data shared within that minor’s care circle.
Regional & State Privacy Rights
California Consumer Privacy Act (CCPA / CPRA)
California residents have the right to: (1) Know what personal information is collected, used, and disclosed; (2) Delete personal information; (3) Correct inaccurate personal information; (4) Opt-out of the sale or sharing of personal data; and (5) Limit the use of sensitive personal information.
Canada (PIPEDA & Provincial Inquiries)
Canadian residents are entitled to request access to the personal data we hold about them, challenge the accuracy and completeness of their records, and request amendments. Inquiries may also be lodged directly with the Office of the Privacy Commissioner of Canada (OPC) or relevant provincial information and privacy commissioners.
European Economic Area (EEA) & United Kingdom (UK)
Under the GDPR and UK GDPR, you have the right to access, rectify, erase, restrict, object to processing, and export your personal data (data portability). Where processing relies upon consent, you may withdraw your consent at any time without affecting the lawfulness of processing conducted prior to withdrawal. You also have the right to lodge a complaint with your national Data Protection Supervisory Authority.
Exercising Rights & Contacting the Privacy Officer
To exercise your privacy rights, submit a data access or deletion request, request a copy of your audit log record, or register a privacy inquiry, please contact our designated Privacy Office:
Privacy & Legal Department
QuestCare Connect Inc.
Attn: Data Protection Officer / Privacy Officer
Province of Ontario, Canada
We will respond to all verified access, correction, or deletion requests within thirty (30) days of receipt, following reasonable identity verification to safeguard your account against unauthorized disclosure.