Legal

Privacy Policy

Last updated: April 19, 2025

1. Who We Are

TapMD is operated by Revelation Media Inc., a corporation incorporated under the laws of Alberta, Canada (the "Company", "we", "us", or "our"). Our registered office is located in Edmonton, Alberta. TapMD provides a virtual care platform that connects patients in Alberta and British Columbia with licensed Canadian physicians.

2. Applicable Law

We collect and handle personal health information ("PHI") in compliance with:

  • Health Information Act (HIA) — Alberta
  • Personal Information Protection and Electronic Documents Act (PIPEDA) — federal
  • Personal Information Protection Act (PIPA) — British Columbia, where applicable
  • College of Physicians and Surgeons of Alberta (CPSA) Telemedicine Standards

If a conflict exists between these laws, we apply the standard that affords you the greatest protection.

3. Information We Collect

We collect information you provide directly and information generated through your use of TapMD:

3.1 Account Information

Name, email address, date of birth, provincial health card number, mailing address, and phone number.

3.2 Health Information

Medical history, current medications, allergies, symptoms, chief complaints, SOAP notes created by your physician, documents (referrals, lab requisitions, imaging reports), and any information you share during a consultation.

3.3 Technical Information

IP address, browser type, device identifiers, session timestamps, and audit log entries. This information is collected to maintain security, detect fraud, and meet our regulatory audit obligations under HIA.

3.4 Billing Information

Provincial health claim codes (service codes, diagnostic codes, modifier codes) and billing amounts processed through the Alberta Health Care Insurance Plan (AHCIP) or collected directly. We do not store full payment card numbers — card processing is handled by our PCI-DSS compliant payment processor.

4. How We Use Your Information

We use your information to:

  • Provide, operate, and improve the TapMD platform and virtual care services
  • Connect you with licensed physicians and facilitate consultations
  • Generate and store clinical records (SOAP notes, documents, referrals)
  • Submit billing claims to provincial health authorities on your physician's behalf
  • Maintain the audit trail required by HIA and CPSA standards
  • Send appointment reminders and care-related notifications
  • Comply with legal, regulatory, and professional obligations
  • Detect and prevent fraud, security incidents, and technical errors

We do not sell, rent, or trade your personal health information to third parties for marketing purposes.

5. Disclosure of Your Information

We may disclose your information to:

  • Your treating physician — who is a custodian of your health information under HIA and bound by professional confidentiality obligations
  • Alberta Health / provincial health authorities — for insured billing purposes only
  • Service providers — cloud infrastructure (data stored in Canada), secure fax/document delivery, and analytics providers operating under data processing agreements and bound to the same privacy standards
  • Legal and regulatory authorities — when required by law, court order, or to protect the safety of any person

Any third party that processes PHI on our behalf is required to provide equivalent privacy protections through contractual obligations.

6. Data Storage and Security

All personal health information is stored on servers located in Canada. We use encryption in transit (TLS 1.2+) and at rest, role-based access controls, and comprehensive audit logging. Access to PHI is restricted to authorized personnel on a need-to-know basis.

Despite our safeguards, no system is completely secure. In the event of a privacy breach that creates a real risk of significant harm, we will notify affected individuals and the relevant regulatory authority as required by law.

7. Retention

We retain clinical records for a minimum of 10 years from the date of last service (or until a minor patient reaches age 18, whichever is later), in accordance with HIA and CPSA record retention requirements. Account and billing records are retained as required by applicable tax and corporate law. Technical logs are retained for 12 months.

When records are no longer required, they are securely destroyed in a manner that prevents reconstruction.

8. Your Rights

Subject to applicable law, you have the right to:

  • Access — request a copy of the personal health information we hold about you
  • Correction — request correction of inaccurate or incomplete information
  • Withdrawal of consent — withdraw consent to non-essential uses of your information (note: withdrawal may limit our ability to provide services to you)
  • Complaint — file a complaint with the Office of the Information and Privacy Commissioner of Alberta (OIPC) or the Office of the Privacy Commissioner of Canada (OPC)

To exercise these rights, contact our Privacy Officer at privacy@tapmd.ca. We will respond within 30 days.

9. Cookies and Tracking

TapMD uses session cookies essential to platform operation (authentication, CSRF protection). We do not use third-party advertising trackers. Analytics data is anonymised before processing and is not linked back to individual patients.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or by a prominent notice on the platform at least 14 days before they take effect. Your continued use of TapMD after the effective date constitutes acceptance of the updated policy.

11. Contact

Questions, concerns, or access requests should be directed to our Privacy Officer:

Revelation Media Inc. — Privacy Officer

Edmonton, Alberta, Canada

Email: privacy@tapmd.ca