Privacy Policy

Version: 2026-09-13 · Effective: September 13, 2026

How TherapyCRM handles account, technical, client and optional connected-calendar information for Canadian therapy practices.

  • Practices control their clients’ health information; TherapyCRM processes it for the practice.
  • Client information is not sold, used for advertising, or used to train AI models.
  • Primary data and uploaded files are stored in the United States, session data in Canada, and database backups in Germany; the application processes data in Germany.
  • Practice owners can disable AI-assisted features, and qualified users must review AI output.
  • Optional calendar connections use selected calendars for synchronisation and availability; exported appointment copies contain generic labels and times.
  • Google calendar data is subject to Google API Services Limited Use requirements.
  • Routine database backups use 30-day scheduled retention and seven-day soft-delete recovery; cleanup is asynchronous.

Adds optional Google and Microsoft calendar disclosures covering account and event access, source-owned synchronisation, generic exports, visibility, provider sharing, retention, removal and Google API Services Limited Use. Corrects the storage disclosure to identify US databases and uploaded files, the Canadian session cache, German database backups and German application processing. Adds the confirmed full postal address for the Privacy Officer. Explains the 30-day routine database-backup retention and seven-day soft-delete recovery period, with asynchronous cleanup. Other policy provisions are unchanged.

1. Scope and our role

This Privacy Policy explains how DataInn ("TherapyCRM", "we", "us") handles personal information in connection with the TherapyCRM web application, parent portal, attendance app, AI assistant, and related support (the "Services"). It applies to the practices that subscribe to the Services ("Customers"), their staff, and — through the parent portal — the families the practice serves.

We act in two different roles. For account, billing, and usage information about our Customers and their staff, we decide how the information is used and are accountable for it. For the client and family information a practice records in the Services ("Client Information"), the practice is the custodian or accountable organisation; we process that information only on the practice's instructions as its service provider or agent. If you are a client or parent, your practice is your first point of contact for access, correction, and consent questions, and this Policy describes what we do on the practice's behalf.

2. Where the Services are offered

The Services are offered to practices located in Canada, outside the Province of Quebec. We have not designed the Services for Quebec's specific privacy and language requirements and make no representation that they are suitable for use there, or in any other country. Practices are responsible for confirming suitability for their jurisdiction before placing personal information in the Services.

3. Information we handle

Account and practice information (we are accountable):

  • names, email addresses, phone numbers, roles, and credentials of practice owners and staff;
  • practice name, address, province, time zone, and billing details (payment card details are collected and stored by our payment processor, not by us);
  • records of acceptance of our Terms and this Policy, including the version, the person accepting, the time, and the network address used.

Client Information (the practice is accountable; we process on its instructions):

  • client and family demographic and contact details, guardian and custody information, and consents;
  • appointments, attendance, schedules, and waitlists;
  • treatment plans, goals, session data, progress notes, assessments, and uploaded documents;
  • insurance, funding, and invoicing details;
  • messages sent to families through the Services and portal activity.

Technical information (we are accountable):

  • device, browser, and network details; sign-in events; security and audit logs; and usage and performance measurements needed to operate and secure the Services.

3A. Optional calendar connections

Calendar connections are optional features for authorised practice staff. When a practice enables calendar synchronisation, a staff member may connect Google Calendar or Microsoft Outlook / Microsoft 365 and choose which calendars to synchronise. Authorised practice administrators can configure a connection for a branch or the whole practice. Connecting a calendar does not give TherapyCRM access to your email messages, contacts, or files.

Information accessed and stored

With your permission, TherapyCRM accesses your provider account identifier and email address to identify the connected account; calendar identifiers, names, time zones and access permissions so you can choose calendars; and events in the calendars you select. We use event identifiers, start and end times, all-day status, busy/free status, privacy status, recurrence information and provider links to synchronise events and determine availability. Provider responses may include other event fields, but TherapyCRM discards descriptions, attendees, locations and attachments instead of retaining or displaying them.

Personal calendar events are labelled Busy in TherapyCRM, and their original titles are not retained in the event cache. An authorised administrator may choose to show titles for a shared calendar; private or confidential events remain labelled Busy. Retained event titles and provider links, and the access and refresh tokens needed for background synchronisation, are encrypted. Scheduling metadata, including event times and busy status, is stored under the Services' normal storage and access safeguards.

How calendar information is used and shared

We use connected-calendar information to display external events, synchronise appointment copies, check availability and prevent conflicting bookings when blocking is enabled. External events remain read-only in TherapyCRM and are edited or deleted in their original calendar service. TherapyCRM appointments are edited or cancelled in TherapyCRM; their external copies follow those changes. Editing an external copy does not edit its TherapyCRM appointment, and synchronisation may restore that copy.

TherapyCRM exports generic Appointment or Group appointment labels, start and end times, and private/busy status to the calendars you select. It does not export patient names, clinical notes, appointment descriptions, locations, attendees or reminders. The integration does not send invitations or change calendar-sharing permissions. Calendar providers and people who already have access to the selected calendar may see the exported copies under that provider's permissions and privacy terms. Personal or shared external events imported from one provider are not automatically copied to another provider.

Within TherapyCRM, external events and availability are shown to people whose practice role and calendar access permit them to see the relevant staff, branch or practice schedule. Personal event details are hidden as described above; busy times may still affect scheduling for that staff member. Shared-calendar blocking, if enabled, treats imported busy times as unavailable for the selected branch or practice. Our contracted infrastructure providers process stored calendar information to operate the Services as described in this Policy. Your chosen calendar provider processes information under its own terms, settings and storage locations; TherapyCRM's storage-region commitments do not control copies held in your external calendar account.

Your choices, retention and removal

You choose the calendars, synchronisation direction and availability-blocking settings. Synchronisation normally covers the previous 30 days and the next 365 days. Cached events outside that period are removed during successful reconciliation; this is a rolling display window, not a retention promise for provider copies or audit records.

Removing a selected calendar immediately stops its imported display and availability blocking. Its local event cache and synchronisation mappings are deleted when removal cleanup completes. You can request removal of the TherapyCRM-created copies in that external calendar; cleanup may require reconnecting if provider access has expired or been revoked. Removing a connection without that cleanup leaves external copies in the provider until you delete them there. Removing a calendar does not delete unrelated provider events or TherapyCRM appointments.

After removing the account's selected calendars, you can disconnect the account to clear its stored calendar access credentials. You may also revoke access in your Google Account's third-party connections settings or your Microsoft account's application-permission settings. Revoking access at the provider stops authorised API access but does not itself remove previously stored TherapyCRM cache entries or external copies; use TherapyCRM's removal controls or contact support@therapycrm.io for assistance. Connection identity may remain to support reconnection; audit and acceptance records and backup copies follow the retention provisions in Section 11. Privacy and deletion inquiries may also be directed to our Privacy Officer in Section 16.

Google API Services Limited Use

TherapyCRM's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google user data only to provide or improve the calendar and scheduling features visible to users. We do not sell Google user data, use it for advertising or credit decisions, or use it to train general-purpose AI models.

We transfer Google user data only as needed to provide or improve these user-facing features with your consent, for security purposes, to comply with applicable law, or as part of a business transfer after obtaining your explicit prior consent. Our personnel and contractors may access that data only with your affirmative agreement to view specific data, where necessary for security or legal obligations, or as permitted for aggregated internal operations under Google's policy. These Google-specific limits also apply to data derived from Google APIs and take precedence over broader use or sharing provisions elsewhere in this Policy.

4. Why we use information

  • to provide, secure, support, and improve the Services;
  • to carry out a practice's instructions, including sending appointment reminders and other communications the practice configures;
  • to manage subscriptions, billing, and account security;
  • to produce audit trails and security records required of a health-information service provider;
  • to meet legal obligations and respond to lawful requests.

We do not sell personal information, use Client Information for marketing, or use it to train artificial-intelligence models. Improvement work uses aggregated or de-identified measurements wherever possible.

5. Consent

Customers consent to our handling of account and technical information by accepting our Terms. Each practice is responsible for obtaining every consent needed for the Client Information it places in the Services — including consent from a parent or legal guardian for minors and consent for communications sent on its behalf — and for confirming a guardian's authority before granting portal access. Where the Services ask for a consent to be recorded, the recording is a convenience for the practice, not a substitute for the practice's own consent practices.

6. AI-assisted features

Some features use third-party artificial-intelligence models to draft, summarise, extract, or answer questions. Before any text is sent to a model provider, names, contact details, dates of birth, addresses, and similar identifiers are removed or replaced with placeholders, and the original values are restored only inside the Services. Only model providers hosted in North America are used, under terms that prohibit them from using content to train their models and that limit any retention to the short period needed to operate and secure their service. AI output is assistive only and must be reviewed by a qualified person. A practice owner can disable AI features for the whole practice in Practice Settings.

7. Where information is stored and processed

The Services use the following storage and processing locations:

Data or serviceLocation
Primary database and uploaded filesUnited States
Session cacheCanada
Database backupsGermany
Application processingGermany

Client Information and account information are therefore stored or processed outside Canada, including database backup copies stored in Germany. While information is outside Canada it is subject to the laws of that jurisdiction, including lawful access by authorities there. We require every service provider to protect information to a standard comparable to our own and to use it only to provide their service to us.

We may change or replace the providers and facilities we use, and move information between them within the countries described above, provided the safeguards in this Policy are maintained. We will update this Policy and give practices at least 30 days' notice before storing Client Information in an additional country.

Practices that require all storage or processing to remain in Canada should not place information in the Services.

8. Who we share information with

We share information only with:

  • service providers that host infrastructure, store files, deliver email and text messages, process payments, and supply artificial-intelligence models — each bound by contract to safeguard information and use it only for the service they provide to us;
  • the practice that is accountable for the information, and the people it authorises;
  • professional advisers and successors in connection with a financing, merger, or sale of the business, subject to this Policy;
  • authorities where required by law, a court order, or to protect the safety of a person.

A list of the categories of service providers we use, and the countries where they process information, is available from our Privacy Officer on request.

9. Safeguards

We apply safeguards appropriate to health information, including multi-factor authentication, role-based access control, tenant isolation between practices, automatic session time-outs, audit logging of access to and changes in client records, encryption in transit, encryption at rest provided by our hosting providers, private storage for clinical documents, rate limiting, and security monitoring. Staff access to Client Information is limited to what operating and supporting the Services requires.

Practices are responsible for their own devices, networks, staff training, the access rights they grant, and the credentials their users keep. No safeguard is perfect, and we do not guarantee that information can never be accessed without authorisation.

10. Privacy incidents

If we confirm that Client Information has been accessed, used, or disclosed without authorisation, or lost, we will notify the affected practice's designated contact without undue delay and within any period the law requires of us, tell the practice what we know, and cooperate with the practice's own obligations to notify individuals, regulators, or colleges. We keep a record of privacy incidents.

11. Retention and deletion

  • Client Information is kept for as long as the practice's subscription is active and for a read-only export window of 30 days afterwards. It is then scheduled for deletion from active systems. Routine database backups are scheduled for deletion after 30 days, followed by a seven-day soft-delete recovery period. Cleanup is asynchronous, so these configured periods do not guarantee deletion of every copy on an exact day.
  • Practices are responsible for exporting any records they must keep under their own retention obligations before the export window closes.
  • Account, billing, acceptance, and audit records are kept for as long as needed to meet legal, accounting, and security obligations, and then deleted or de-identified.

12. Your rights

Customers and their staff may ask us to access or correct the account information we hold about them. Clients and parents should direct requests to access, correct, or withdraw consent for Client Information to their practice, which is accountable for it; we will assist the practice in responding. Anyone may ask the Privacy Officer how their information has been handled, and may complain to the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner if not satisfied with our response.

13. Children and minors

The Services are used by practices that serve children and youth. Information about minors is collected by the practice under the consent of a parent or legal guardian, or of the minor where the practice determines the minor is capable of consenting, in accordance with the practice's professional obligations. We do not knowingly collect information from minors directly except through a portal account a practice has set up under a guardian's consent.

14. Compliance posture

The Services are designed to support practices subject to Canada's federal private-sector privacy law and provincial health-privacy statutes, including where TherapyCRM acts as an agent or service provider of a health-information custodian. We do not hold a privacy or security certification and do not claim one; we are pursuing an independent security attestation and will state it here only once it has been issued.

15. Changes to this Policy

We may update this Policy. Material changes are published with a new version date, and practice owners are asked to accept the new version in the application. Earlier versions are available from the Privacy Officer on request.

16. Privacy Officer and contact

Our Privacy Officer is accountable for our compliance with this Policy and can be reached at privacy@therapycrm.io. We acknowledge privacy inquiries within two business days and respond as required by law. Postal: DataInn, Privacy Officer, Suite 200, 55 Village Centre Pl, Mississauga, ON L4Z 1V9, Canada.

Version history

Published versions remain available for review.

Optional website analytics

Allow Google Analytics to measure visits and actions on these public pages? It stays off in clinical, portal and checkout screens. Google may process analytics outside Canada. Details