Data Processing Addendum
Last updated July 23, 2026 · Effective July 23, 2026
PHIPA Electronic Service Provider Addendum to the BluPage Terms of Service.
This Data Processing Addendum (the “Addendum”) forms part of the agreement between the subscribing practitioner (“you,” the “Custodian”) and BluPage Technologies Inc., Toronto, Ontario (“BluPage,” “we,” “us”) consisting of the BluPage Terms of Service and Privacy Policy (together, the “Agreement”). It applies whenever you use BluPage to collect, store, or otherwise manage personal health information (“PHI”) of your clients or patients. Capitalized terms not defined here have the meaning given in the Agreement.
Recitals — Roles of the Parties
- You are a health information custodian (“HIC”) within the meaning of the Personal Health Information Protection Act, 2004 (Ontario) (“PHIPA”), or an agent of one, with respect to the PHI you store in BluPage. You remain solely responsible for the custody and control of that PHI.
- BluPage is an electronic service provider (“ESP”) to you within the meaning of PHIPA and its regulations. BluPage supplies services to enable you to collect, use, modify, disclose, retain, and dispose of PHI electronically. BluPage is not a health information custodian with respect to your PHI and does not assume custodianship under any circumstance.
- Every obligation in this Addendum is interpreted in light of that division of roles: BluPage acts only as a service provider on your behalf; all custodial duties under PHIPA — including consent, access and correction requests, and record retention — remain yours.
1. Processing Only on the Custodian’s Instructions
BluPage collects, uses, modifies, discloses, retains, and disposes of PHI only as necessary to provide the services described in the Agreement and only in accordance with your documented instructions. Your configuration of the services — including creating records, sharing booking pages, generating documents, and enabling features — constitutes your documented instructions for processing. BluPage will not access PHI stored in your account except: (a) as necessary to provide, maintain, or secure the services; (b) at your request in connection with support; or (c) where required by law, in which case BluPage will notify you unless legally prohibited from doing so.
2. No Secondary Use of PHI
BluPage does not use PHI for its own purposes. BluPage does not sell PHI, does not use PHI to train artificial-intelligence or machine-learning models, and does not use PHI for advertising or marketing.
BluPage may create and use data that has been de-identified and aggregated such that it removes any information that identifies the individual, or for which it is reasonably foreseeable in the circumstances that it could be utilized, either alone or with other information, to identify the individual. BluPage may use such de-identified, aggregated data to analyze system performance, improve its features, and report on business metrics. BluPage will not attempt to re-identify de-identified data and will not permit others to do so.
3. Security Safeguards
BluPage implements and maintains reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of PHI, designed to protect it against theft, loss, and unauthorized use, disclosure, copying, modification, or disposal. As of the effective date, these safeguards include:
- Encryption of PHI in transit (TLS) and at rest;
- Data residency in Canada — production PHI is stored in the ca-central-1 (Canada) region of BluPage’s hosting subprocessor (Section 6);
- Access controls enforced at the database layer (row-level security), so each account can access only its own records;
- Availability of multi-factor authentication for practitioner accounts, with security-sensitive operations conditioned on its use;
- Signed clinical records systematically restricted at the database level to prevent alteration, with corrections handled by append-only amendment;
- Logging of security-relevant events and administrative actions.
BluPage may update specific safeguards over time, provided the overall level of protection is not materially reduced.
4. Breach Notification
If BluPage becomes aware that PHI in its custody has been stolen, lost, or accessed, used, disclosed, copied, modified, or disposed of without authority (a “Security Incident”), BluPage will notify you at the first reasonable opportunity and without unreasonable delay after becoming aware of it. The notice will describe, to the extent known: the nature of the Security Incident, the categories of records affected, the measures taken to contain it, and the measures BluPage recommends you consider. BluPage will cooperate reasonably with you in meeting your own notification obligations under PHIPA by providing a standardized incident report and relevant technical details. Notification of a Security Incident is not an admission of fault or liability.
5. Return and Destruction of Data (End of Service)
Retention of clinical records is your obligation as Custodian, not BluPage’s. Upon cancellation or termination of your account:
- Export window. You have a 90-day grace period from the effective date of termination to export your data. BluPage provides export tools for this purpose, and will provide reasonable assistance if the tools are unavailable to you during the window.
- Secure destruction. After the 90-day window, BluPage reserves the right to securely and permanently delete all account data, including clinical records, using methods designed to render the data irretrievable.
- Your responsibility. Ensuring compliance with your professional and legal record-retention obligations before your account terminates is strictly your responsibility. BluPage is not responsible for maintaining records for terminated accounts beyond the export window.
6. Subprocessors
BluPage uses the following subprocessors to deliver the services. Only the database subprocessor stores PHI at rest; the remaining subprocessors handle limited personal information, or documents in transit, as described below.
| Subprocessor | Function | Data location | Data handled |
|---|---|---|---|
| Supabase (on Amazon Web Services) | Database, authentication, application backend | ca-central-1 (Canada) | PHI and account data — the system of record for clinical and practice records |
| Stripe | Subscription billing | Managed by Stripe | Practitioner billing identity and payment details only; no PHI and no client clinical content |
| Resend | Transactional email delivery | Managed by Resend | Booking-related names, email addresses, and transactional document payloads (such as receipts/invoices generated by the Custodian) in transit; no at-rest storage of the clinical system of record |
| Cloudflare | Application hosting and content delivery | Global edge network | Serves the application; does not store PHI at rest |
Changes to subprocessors. BluPage may engage, replace, or remove subprocessors, and will ensure any subprocessor handling PHI is bound by obligations materially equivalent to this Addendum. BluPage will give you notice of changes affecting PHI-handling subprocessors (e.g., by email or in-app notice) at least 30 days in advance, except in emergency situations where a subprocessor must be replaced immediately to maintain service availability or security, in which case notice will be provided as soon as reasonably practicable. Continued use of the services after notice constitutes acceptance of the change.
7. General
- Conflict. If this Addendum conflicts with the Terms of Service or Privacy Policy with respect to the processing of PHI, this Addendum governs to the extent of the conflict.
- Term. This Addendum applies for as long as BluPage holds PHI on your behalf, including the post-termination export window.
- Governing law. This Addendum is governed by the laws of the Province of Ontario and the federal laws of Canada applicable in it.
- Amendment. BluPage may update this Addendum to reflect changes in law or the services; material changes will be notified in the same manner as changes to the Terms of Service.
Questions about this Addendum: hello@blupage.app. See also the Terms of Service and Privacy Policy.