Appointments as soon as today
PHIPA

Statement of Information Practices

How Revive Mind collects, uses, discloses, and protects personal health information, and how to reach our designated privacy contact.

Last updated: August 27, 2026 · Version 2026.2

This written statement is published to meet Ontario PHIPA expectations for health information custodians. It complements our Privacy Policy and explains care-specific practices, circle-of-care sharing, lockbox rights, and how to make a complaint.

Who we are

Revive Mind operates a Canadian digital mental-health platform that connects patients with licensed therapists. For the purposes of Ontario's Personal Health Information Protection Act (PHIPA), Revive Mind acts as a health information custodian (or agent of a custodian, as applicable) with respect to personal health information (PHI) collected through the platform.

What personal health information we collect

We collect PHI and related personal information needed to deliver care and operate the service safely.

  • Identity and contact details (name, email, phone, address, date of birth)
  • Booking, payment, and insurance-related information
  • Intake responses, goals, mood journals, and messages with your care team
  • Clinical documentation created by your therapist (for example SOAP notes)
  • Technical and security logs required to protect accounts and investigate incidents

Why we collect and use PHI

We collect and use PHI primarily to provide or assist in providing health care, to administer your account, and to meet legal and professional obligations.

  • Matching you with appropriate providers and delivering telehealth sessions
  • Care coordination within your circle of care under PHIPA implied consent
  • Billing, receipts, and therapist payouts
  • Responding to your access, correction, lockbox, and deletion requests
  • Safeguarding the platform (security monitoring, fraud prevention, audit)

How we safeguard PHI

PHIPA and PIPEDA require reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the information. They do not prescribe a specific cloud product checklist (for example WAF brand, IaC tool, or patch SLA). We implement safeguards through the controls below.

  • Encryption in transit (TLS) and application-level encryption at rest for sensitive fields
  • Role-based and relationship-scoped access controls (circle of care / authorization)
  • Append-only security audit logging for access, consent, and breach events, retained under our configured retention schedule
  • Session controls, multi-factor options where enabled, and retention / destruction schedules
  • Privacy breach workflow with RROSH assessment and IPC annual statistics reporting

Where PHI is stored (data residency)

Neither PHIPA nor PIPEDA currently requires PHI to be stored only in Canada. We document hosting so individuals and partners know where records physically reside.

  • Production application databases are hosted on Neon (serverless Postgres) in AWS US East (Ohio), Neon region identifier aws-us-east-2. Neon does not currently offer a Canada region.
  • Sensitive fields are encrypted at the application layer before storage; the Privacy Officer maintains the current region and subprocessor list for institutional due diligence
  • Service providers who process PHI on our behalf are bound by agreements requiring appropriate safeguards and use limited to providing the service
  • Ask privacy@revivemindtherapy.ca for the current production region summary if you need it for an RFP or custodian questionnaire

Disclosures

Disclosures for providing care to members of your circle of care may proceed under PHIPA implied consent, subject to any lockbox / express withdrawal you place on specific records.

Disclosures outside the circle of care (for example research or insurer packages that are not required for care) require your express, purpose-specific consent unless another lawful authority applies. Revive Mind does not send promotional marketing email.

Your rights: access, correction, lockbox, and complaints

You may request access to your PHI, ask for corrections, place lockbox instructions on specific clinical notes, and manage express consents from your account settings.

  • Request a copy of your record (right of access) from Settings → Manage account
  • Ask us to correct inaccurate personal information from Settings → Manage account
  • Withhold specific clinical notes from circle-of-care disclosure (lockbox)
  • Withdraw express consent for non-care purposes at any time
  • File a privacy complaint with our designated contact below; you may also contact the Information and Privacy Commissioner of Ontario

Designated contact person

PHIPA requires a designated individual who is accountable for our information practices and who can receive questions and complaints.

  • Name: Privacy Officer, Revive Mind
  • Email: privacy@revivemindtherapy.ca
  • Mail: Privacy Officer, Revive Mind, Ontario, Canada
  • We aim to acknowledge privacy requests within a reasonable timeframe and respond according to applicable PHIPA timelines.

Your better tomorrow starts today

Join thousands of Canadians getting the support they deserve, from the comfort of home.