Plain-language summary
This summary is not the legal agreement, but a quick guide to what follows. The sections below control if there is any conflict.
- We are Delam Technologies Inc., a Canadian company headquartered in Toronto, Ontario. We build software that medical spas and wellness clinics use to run their business.
- You are a patient or guest of one of those clinics.The clinic decides what services to offer, keeps your medical records, and is the primary custodian of your health information. We process information on the clinic's behalf as their service provider.
- What the patient app collects from you: your name, phone number, email address, date of birth, optional sex, the bookings and purchases you make, payment confirmations (we never see your card number), and device information needed to deliver the app.
- What we never collect through the patient app: medical history, allergies, treatment notes, before-and-after photos, or any clinical information. Those live with the clinic.
- Where your data lives: primarily in Canada. Some service providers (payments, error monitoring, product analytics) operate from the United States. You can opt out of cross-border product analytics in the app under Settings → Privacy.
- Your rights: you can see, correct, export, or delete your information at any time from Settings → Privacy, or by writing to [email protected].
- Marketing: we and your clinic only send you promotional messages if you have opted in, and you can opt out at any time.
1. Who we are
This Privacy Policy is issued by Delam Technologies Inc. (“Delam,” “we,” “us,” or “our”), a corporation incorporated under the laws of Canada with its head office at:
Delam Technologies Inc.180 John Street, Suite 500
Toronto, ON M5T 1X5
CA
Our Privacy Officer can be reached at [email protected]. Quebec residents may also direct privacy inquiries to the same address; we will route them to the person responsible for the protection of personal information.
2. Scope and roles
This Policy applies to the Delam patient mobile app, the Delam online booking site (the “Patient Services”), and to the public Delam marketing site at delam.ai. It does not apply to the staff or clinic-facing products, which are governed by our business agreements with clinics.
Throughout this Policy we distinguish two roles:
- The Clinic.The medical spa, aesthetic clinic, or wellness business you book with through the Patient Services. Where the Clinic is a regulated health custodian (for example, under Ontario's Personal Health Information Protection Act, or PHIPA, or Quebec's Renseignements de santé, R-22.1), the Clinic is the controller or custodian of your personal health information.
- Delam.When we process information at the Clinic's direction in order to deliver the Patient Services, we are a service provider or processor for the Clinic. When we collect information directly from you for our own purposes (for example, your account credentials, your in-app preferences, or product analytics), we are an independent controller.
Each Clinic publishes its own privacy notice describing how it uses your information for its purposes. This Policy only describes Delam's practices.
3. Information we collect
3.1 Information you give us
- Account details. First name, last name, email address, mobile phone number, date of birth, and optional sex (Male / Female / Other / Prefer not to say).
- Verification codes. We send a one-time passcode by SMS to confirm your phone number. The code itself is stored only long enough to verify it.
- Booking and shop activity. The Clinic and services you book, packages or memberships you purchase, gift cards you redeem, your cart contents, reviews you write, and reward points you earn.
- Payment confirmations. Our payment processor (Stripe) handles your card data directly. We receive only a confirmation, the last four digits of the card, the brand, and an opaque token, never the full card number, expiry, or security code.
- Photos you choose to share. If you upload a photo (for example, a profile picture or an attachment to a review), we store the image and pass it to the Clinic if relevant.
- Communications with us or with the Clinic. Messages you send through the in-app inbox, email, or SMS.
3.2 Information collected automatically
- Device and app information. Operating system, OS version, device model, app version, language and locale, time zone, and a randomly generated installation identifier.
- Approximate or precise location. Only if you grant location permission, and only while you are actively using the app, so that we can show you nearby Clinics and provide directions. You can revoke location access at any time in your device settings.
- Push notification tokens. If you allow push notifications, we store the token issued by Apple Push Notification Service or Firebase Cloud Messaging so we can deliver booking reminders and other messages you have consented to.
- Product analytics events. We use PostHog to measure how the app is used (screens viewed, search queries, conversion events, errors). We do not send your name, email, phone number, or any health information into analytics events. Where required by law, this processing is consent-based and can be turned off under Settings → Privacy → Cross-border AI / analytics.
- Crash and error reports. We use Sentry to capture diagnostic information when the app crashes or misbehaves. Email addresses and phone numbers are scrubbed before transmission.
3.3 Information we receive from the Clinic
When you visit a Clinic, the Clinic may share with us, through the Delam platform, information such as the appointments you have booked, payments and refunds processed, membership and package status, loyalty points balance, gift cards, and notes the Clinic has chosen to make visible to you. The Clinic remains responsible for what it shares with us and for the accuracy of that information.
3.4 What we do not collect through the patient app
Through the patient app, we do not ask you for, and the app does not store:
- medical history, allergies, medications, diagnoses;
- clinical photographs or treatment notes;
- government identifiers (SIN/SSN, passport, health card numbers);
- full payment card numbers, expiries, or CVVs;
- your contacts, calendar, microphone, or biometric data.
Face ID or Touch ID, where available, is used only by your device to unlock the app locally; the biometric data itself never leaves your device.
4. How we use your information
We use your personal information for the following purposes only:
- To create and secure your account, including verifying your phone number, signing you in, refreshing sessions, and protecting against unauthorized access.
- To deliver the Patient Services, including showing Clinic availability, booking and rescheduling appointments, processing payments through Stripe, managing memberships and packages, and tracking loyalty points.
- To communicate with you about your bookings (confirmations, reminders, cancellations), your account (security alerts, password resets), and platform updates. These are operational messages, not marketing.
- To send marketing by email or SMS, but only if you have opted in, and only until you opt out.
- To improve the product through aggregated analytics, a-b tests of new features, and diagnostic information from crash reports. We do not sell your information for advertising and we do not perform behavioral advertising.
- To meet legal and regulatory obligations, including tax records, fraud prevention, responding to lawful requests, and maintaining audit logs required by privacy and health-information laws.
- To enforce our Terms of Service, to defend legal claims, and to protect the safety of patients, staff, and the public.
5. Legal basis for processing
Depending on the activity and your jurisdiction, we rely on one or more of the following bases under the Personal Information Protection and Electronic Documents Act(PIPEDA), Quebec's Act respecting the protection of personal information in the private sector (the Private Sector Act, formerly Bill 64 / Law 25), and comparable laws:
- Performance of a contract: to provide the Patient Services you have asked for (account, bookings, payments, communications about those bookings).
- Consent: for marketing communications, optional location access, push notifications, and cross-border product analytics.
- Legitimate interests: for fraud prevention, securing the platform, and basic, privacy-respectful product analytics where permitted by law.
- Legal obligation: to comply with tax, accounting, anti-money-laundering, and breach-notification requirements.
Where consent is the basis, you may withdraw consent at any time, subject to legal or contractual restrictions and a reasonable notice period. Withdrawing consent may limit our ability to provide some features.
7. Cross-border transfers
Our primary databases are hosted in Canada. Several service providers listed in Section 6.2 operate from the United States. When personal information leaves Quebec or Canada, we rely on the following safeguards, consistent with PIPEDA and Quebec's Private Sector Act:
- a documented privacy impact assessment before enabling each cross-border flow;
- contractual commitments from each provider regarding purpose limitation, security, audit rights, and assistance with rights requests;
- encryption in transit and at rest;
- minimization, so that we send only what each provider needs to do its job; and
- a meaningful disclosure to you, in this Policy and at the point of collection where reasonable.
You may object to cross-border processing of product analytics in Settings → Privacy within the patient app. Disabling these analytics will not affect your ability to use the core Patient Services.
8. AI features and automated decisions
Some Delam features use artificial intelligence to help Clinics operate more efficiently, for example, drafting reply templates, suggesting appointment slots, or estimating the likelihood that a booking will not be attended (“no-show risk”).
We follow these rules:
- No fully automated clinical decisions. AI output is decision support for a licensed professional, never a substitute. Diagnoses, prescriptions, and treatment plans require human review.
- Data minimization. Identifiers such as your full name, full address, and government IDs are stripped or replaced with internal IDs before content is sent to AI providers.
- No training on your data without consent. We do not allow our AI providers to train or fine-tune their models on your identifiable personal information.
- Transparency on consequential decisions. If an automated decision (such as a fraud or no-show risk score) materially affects your booking or membership, we will tell you the main factors involved and you may request a human review by writing to [email protected].
9. Personal health information
The Delam patient app is not designed to collect personal health information (PHI) from you. PHI you provide to a Clinic, including intake forms, allergies, medications, treatment notes, or clinical photographs, is collected and controlled by the Clinic.
When we process PHI on a Clinic's behalf, we act as the Clinic's service provider, agent, or business associate, depending on the law that applies. We do this under written agreements with each Clinic that meet the requirements of:
- the U.S. Health Insurance Portability and Accountability Act (HIPAA), including the 2024 Reproductive Health Rule;
- Ontario's Personal Health Information Protection Act (PHIPA);
- Quebec's Act respecting health and social services information (R-22.1); and
- comparable provincial or state health-information laws.
We encrypt PHI at rest and in transit, keep detailed access logs, apply role-based access controls, and maintain a documented breach-response process. Requests to access or correct PHI held by a Clinic should be directed to that Clinic; we will assist Clinics in responding.
10. Data retention
We retain personal information only as long as needed for the purpose it was collected, or as required by law:
- Account data: for the life of your account, then deleted or de-identified within 30 days of a deletion request, except where we must keep records (see below).
- Booking and transaction records: kept for up to 7 years to comply with tax, accounting, and audit obligations.
- Marketing preferences and opt-outs: kept indefinitely in a suppression list so we can honor your opt-out.
- Security and audit logs: typically retained 12 to 24 months.
- Backups: rolling 30-day encrypted backups, after which deleted data is overwritten.
PHI held on behalf of a Clinic is retained for the period the Clinic instructs, subject to professional-college and health-records retention requirements (often 10 years from the last interaction or, for minors, 10 years after the patient turns the age of majority).
11. Security
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information we hold, including:
- encryption in transit (TLS 1.2 or later) and at rest;
- field-level encryption of sensitive identifiers and PHI;
- role-based access control and least-privilege defaults;
- multi-factor authentication for staff and clinic users;
- continuous logging and anomaly detection;
- annual review of vendor security posture and contracts;
- a written incident-response plan with mandatory breach notification timelines (72 hours in Quebec, prompt notice under PIPEDA where there is a real risk of significant harm, and 60 days under HIPAA).
No system is perfectly secure. If you believe your account has been compromised, contact us at [email protected].
12. Your rights and choices
Subject to applicable law, you have the following rights with respect to the personal information we hold about you:
- Access. Ask whether we hold information about you and receive a copy.
- Portability. Receive a structured, machine-readable export of the information you provided.
- Correction. Ask us to correct information that is inaccurate, incomplete, or out of date.
- Deletion. Ask us to delete your account and associated information, subject to records we must retain.
- Withdrawal of consent. Withdraw any consent you have given (for example, to marketing or cross-border analytics).
- Objection and restriction. Object to or restrict certain processing.
- Automated decision review. Ask for human review of an automated decision that materially affects you.
- Complaint. Lodge a complaint with your privacy regulator (see Section 16 for contact details).
You can exercise most of these rights directly in the app at Settings → Privacy, including downloading your data and requesting account deletion (which begins a 30-day cancellation window). For any request we cannot fulfill in the app, write to [email protected]. We will respond within 30 days, or sooner where required by law.
13. Children and minors
The Delam patient app is not directed to children. You must be at least 13 years old to create an account.
In Quebec, additional protections apply to individuals under 14. We do not knowingly collect personal information directly from a child under 14 without the consent of a parent or person having parental authority, except where collection is clearly in the child's best interest and cannot reasonably be obtained otherwise.
If you believe a child under the minimum age has provided us with personal information, please contact [email protected] and we will promptly delete the information.
15. Changes to this policy
We may update this Policy to reflect changes to our practices or to legal requirements. If a change is material, we will notify you by email or through the app at least 30 days before it takes effect, and will obtain fresh consent where the law requires it. The “Effective” date at the top of this Policy always reflects the current version.
16. Contact us
For privacy questions, requests, or complaints:
Privacy Officer, Delam Technologies Inc.180 John Street, Suite 500
Toronto, ON M5T 1X5, CA
[email protected]
If you are not satisfied with our response, you have the right to contact your privacy regulator:
- Office of the Privacy Commissioner of Canada– priv.gc.ca
- Commission d'accès à l'information du Québec– cai.gouv.qc.ca
- Information and Privacy Commissioner of Ontario– ipc.on.ca
- U.S. Department of Health and Human Services, Office for Civil Rights(for HIPAA matters) – hhs.gov/ocr