Privacy policy and virtual health care policy
Last Updated: November 5, 2025
1. Introduction
Unlocked Wellness (“the Practice,” “we,” “our,” or “us”) is committed to protecting your privacy and maintaining the confidentiality of your personal and personal health information (“PHI”).
This Privacy Policy outlines how we collect, use, disclose, retain, and protect information in compliance with the Personal Health Information Protection Act (PHIPA), the Personal Information Protection and Electronic Documents Act (PIPEDA), and, where applicable, the General Data Protection Regulation (GDPR).
This policy applies to all information collected through our website, electronic systems, and psychotherapy services.
2. Definitions
Health Information Custodian (HIC):
Under PHIPA, a Health Information Custodian is an individual or organization that has custody or control of personal health information.
At Unlocked Wellness, the HIC is Megan Bouck, RP, or any other regulated clinician working under Unlocked Wellness, as applicable.
Agent:
An Agent is anyone authorized by the HIC to perform services involving PHI on their behalf, including subcontracted therapists, students, and administrative contractors.
Personal Health Information (PHI):
Identifying information about an individual that relates to their physical or mental health, healthcare history, or the provision of healthcare services.
Personal Information (PI):
Information that identifies an individual but is not necessarily related to health care, such as name, email address, or browser data.
3. Purpose and Scope
This Privacy Policy governs all personal and health information collected through:
Clinical intake and consent forms
Virtual therapy sessions and communication through the Jane App
Email, phone, or contact form correspondence
Billing, scheduling, and payment systems
Website use, analytics, and digital communication
It also outlines the safeguards in place to protect information, and your rights as a client under PHIPA and PIPEDA.
4. Adherence to PHIPA and PIPEDA
Unlocked Wellness operates in accordance with both PHIPA and PIPEDA by ensuring that:
Personal and health information is collected, used, and disclosed only for legitimate therapeutic or administrative purposes.
Access to PHI is restricted to authorized personnel.
Information is stored securely using encryption, password protection, and other safeguards.
Consent is obtained for all collection and use, except where required by law (e.g., risk of harm, court order, or professional obligations).
All clinicians, associates, and administrative agents are required to adhere to these standards and to the confidentiality obligations of their professional colleges.
5. Information We Collect
We may collect the following types of information:
Personal Information:
Name, contact details, demographic information, and emergency contact information.
Personal Health Information:
Health history, presenting concerns, treatment goals, session notes, diagnostic information, and other details necessary for therapeutic care.
Non-Identifying Information:
Website analytics, cookies, browser type, IP address, or general site usage data for security and performance monitoring.
6. How We Use Information
Your information may be used to:
Provide psychotherapy and related services
Schedule appointments and manage records
Process billing and insurance claims
Communicate with you about your care
Meet regulatory, professional, and legal record-keeping requirements
Improve our services, website, and accessibility
We only collect and use the minimum amount of information necessary for these purposes.
7. Consent and Withdrawal
Consent to collect and use personal and health information is obtained during intake and through the use of our website or services.
You may withdraw your consent at any time. If consent is withdrawn:
We will discuss your options and document your decision in your record.
Therapy services may need to be discontinued, as treatment requires informed consent.
You may choose to “lock box” your record, limiting future access in accordance with PHIPA.
8. Access to Information
Access to PHI at Unlocked Wellness is structured as follows:
Full Access:
The HIC has full access to all client records for clinical oversight, auditing, or compliance purposes.Practitioner-Only Access:
Clinicians have access only to their own client records and may not view the records of other clinicians.Administrative Access:
Administrative contractors may access limited information (e.g., appointment data, billing) but never clinical notes unless authorized by the HIC.
All access to PHI is logged, monitored, and reviewed regularly.
9. Safeguards
Unlocked Wellness uses technical, administrative, and physical safeguards to protect client information:
Technical Safeguards:
PHI stored securely within the Jane App, a PHIPA-compliant platform.
Encrypted emails and password-protected devices.
Secure Wi-Fi networks and firewall protection.
Regular software and antivirus updates.
Audit logs to monitor access.
Administrative Safeguards:
Confidentiality agreements for all agents and associates.
Staff training on PHIPA and data protection.
Limited data retention and anonymization when possible.
Use of initials or Jane client ID numbers in internal communication.
Physical Safeguards:
Locked filing cabinets and restricted office access.
Secure destruction of paper and electronic records after retention periods.
Private spaces for confidential communication.
10. Virtual Health Care Practices
Virtual sessions are delivered through secure, encrypted video platforms (Jane App). To protect confidentiality:
Both therapist and client should participate from private, secure locations.
Headphones are recommended to prevent being overheard.
Clients are asked to verify their identity at session start.
Public Wi-Fi networks should be avoided whenever possible.
Unlocked Wellness does not record or store video or audio from virtual sessions.
11. Retention and Destruction
Records are maintained for a minimum of 10 years from the last date of service, or 10 years after a client turns 18, whichever is later.
After the retention period:
Paper files are destroyed by cross-cut shredding.
Electronic files are permanently deleted or encrypted beyond recovery.
Any hardware containing PHI is securely wiped or physically destroyed.
12. Breach Protocol
In the event of a privacy breach (loss, theft, or unauthorized disclosure):
Contain: Immediate steps will be taken to secure and isolate affected data.
Notify: The HIC will notify affected individuals and determine if notification to the Information and Privacy Commissioner of Ontario (IPC) is required.
Investigate: The cause and extent of the breach will be reviewed.
Remediate: Corrective actions, additional safeguards, or training will be implemented.
All breaches are logged and reviewed to prevent recurrence.
13. Accuracy, Access, and Correction
Unlocked Wellness takes reasonable steps to ensure information is accurate and complete.
You have the right to:
Access your personal or health record.
Request corrections if information is inaccurate or incomplete.
Request a summary or disclosure history.
Requests can be made in writing to connect@unlockedwellness.ca, and responses will be provided within 30 days as required by PHIPA.
14. Use of Cookies and Analytics
Our website may use cookies or analytics tools to track anonymous visitor data such as page views and time spent on the site.
This helps us improve content and accessibility. No personal health information is collected through these tools.
Users can disable cookies through their browser settings.
15. Third-Party Services
We may use third-party service providers (e.g., Jane App, Google Analytics, secure email servers) that handle limited information on our behalf.
All such providers are selected for compliance with privacy laws and required to use information only for specified purposes.
Unlocked Wellness is not responsible for the privacy practices of linked external websites.
16. Complaints and Inquiries
If you have a question or complaint about how your personal information is handled, please contact:
Privacy Officer / Health Information Custodian
📧 connect@unlockedwellness.ca
📍 Ontario, Canada
We have procedures in place to receive and respond to complaints or inquiries. We will provide a description of these procedures upon request.
If you are not satisfied with our response, you may contact one of the following authorities:
Information and Privacy Commissioner of Ontario (PHIPA)
www.ipc.on.ca | 1-800-387-0073
Office of the Privacy Commissioner of Canada (PIPEDA)
www.priv.gc.ca | 1-800-282-1376
17. Policy Updates
This Policy is reviewed annually and updated as needed to remain compliant with evolving legislation and ethical standards.
Updates will be posted on our website with a revised “Last Updated” date. Continued use of our services or website indicates acceptance of the updated policy.
18. Acceptance of This Policy
By using our website, submitting information, or engaging with Unlocked Wellness services, you signify your acceptance of this Privacy Policy.
If you do not agree with this Policy, please do not use our Site or provide personal information. Your continued use of the Site or services following any changes to this Policy will constitute acceptance of those changes.
19. Contact Information
If you have any questions about this Privacy Policy, the practices of this Site, or your dealings with Unlocked Wellness, please contact:
Unlocked Wellness – Privacy Officer / Health Information Custodian
📧 connect@unlockedwellness.ca
📍 Ontario, Canada
If you are not satisfied with our response after making a complaint, you may have recourse to additional remedies under PHIPA and/or PIPEDA. For further information, please contact the Information and Privacy Commissioner of Ontario or the Office of the Privacy Commissioner of Canada, as applicable.
This Policy was last updated on November 5, 2025.