PIPEDA & PIPA BC Compliance

Last updated: August 16, 2026

The short version. Carelyst is operated by Techalyst Software Inc., a British Columbia company. All persistent data lives in Canadian data centres in Toronto, and every agency's data sits in its own isolated database. We follow the ten privacy principles of PIPEDA (the federal law) and PIPA BC (the provincial law). We do not sell data, we do not use care records to train AI, biometric fingerprint images never exist anywhere in the system, and you can request a copy or deletion of your personal information at any time.

This page explains, in plain English, how personal information moves through Carelyst and who is responsible for it at each step. For the full legal text, see the Privacy Policy.

1. Which law applies

PIPEDA (Personal Information Protection and Electronic Documents Act) is the federal Canadian law governing how private-sector businesses handle personal information in commercial activity.

PIPA BC (Personal Information Protection Act) is the provincial equivalent in British Columbia. Because Carelyst is operated by Techalyst Software Inc., a BC company, PIPA BC applies to data we collect from BC residents, and PIPEDA applies to inter-provincial data flows for the rest of Canada. The two laws are substantially similar. We meet both.

Home care agencies using Carelyst may also be subject to provincial health-privacy laws in their own province, such as PHIPA in Ontario or the Health Information Act in Alberta. Those laws bind the agency as the custodian of client health information. Section 2 explains how responsibility is divided, and section 12 explains what agencies remain responsible for.

For guidance, see the Office of the Privacy Commissioner of Canada and the Office of the Information and Privacy Commissioner for BC.

2. Two roles: who is responsible for what

Carelyst handles two distinct categories of personal information, and the legal responsibility differs between them.

Account and billing data. When an agency owner signs up for Carelyst, Techalyst Software Inc. is the organization accountable for that information: the owner's name, email, login credentials, and subscription records (plan, invoices, and payment status). Card details are entered directly with Stripe and never touch our servers; we hold only the card's brand and last four digits for display. We decide how this account information is collected and used, and this page describes those practices directly.

Care data. Client records, care plans, visit notes, wellness answers, incident reports, caregiver files, schedules, and everything else an agency enters into its Carelyst workspace belongs to that agency. The agency is the organization accountable for this data under privacy law. Carelyst processes it only on the agency's instructions, as its service provider. We do not access, use, or disclose care data except to operate the service, to support the agency at its request, or as required by law.

In practical terms: if you are a client, family member, or caregiver of an agency that uses Carelyst, your privacy relationship is with that agency. Direct access, correction, and deletion requests about your care records to the agency. We support agencies in fulfilling those requests. If you are an agency owner or administrator, your privacy relationship for your own account is with us.

3. The ten privacy principles, applied to Carelyst

1. Accountability

Techalyst Software Inc. is accountable for the personal information described on this page. The privacy contact is legal@carelyst.ca. We remain responsible for personal information passed to the sub-processors listed in section 7.

2. Identifying purposes

We collect and process personal information for clearly identified purposes:

  • To run agency accounts: sign agencies up, log users in, bill subscriptions, and provide support.
  • To deliver the service on the agency's behalf: schedule visits, verify attendance, record care activity, notify caregivers and families, and produce invoices and payroll figures from verified hours.

We do not use personal information for any other purpose without asking first. We do not sell personal information and we do not use care records to train AI models.

3. Consent

Agency owners consent to our collection of their account information when they sign up, and can withdraw consent by closing their account. Staff, caregivers, and family portal users consent when they accept the agency's invitation and create their login.

For clients and their care records, consent is obtained by the agency as part of its own intake and service agreements. Two categories deserve specific mention because the law treats them as more sensitive:

  • Biometric enrollment is optional and requires the caregiver's express consent, collected by the agency before enrollment. Agencies must offer caregivers who decline an alternative clock-in method. Carelyst supports GPS, NFC, and manual verification alongside biometrics, so declining never blocks someone from working.
  • Location capture happens only at the moment a caregiver clocks in or out of a visit, and the caregiver's device asks for location permission through the standard operating system prompt.

4. Limiting collection

We collect only what the service needs. From agency owners: name, email, optional phone, subscription and invoice records, and agency configuration; card details go directly to Stripe and are never stored by us. From staff, caregivers, and family members: the profile details the agency enters or the person provides, plus login credentials. From caregiver devices: GPS coordinates at clock-in and clock-out only. From attendance kiosks: encrypted fingerprint templates, never fingerprint images (see section 4). From marketing site visitors: contact form submissions, and usage analytics, which stop if the visitor declines the cookie banner.

5. Limiting use, disclosure, and retention

We use personal information only to provide the service, bill accurately, support agencies, and meet legal obligations. Retention windows:

Data typeRetention
Care data in an active agency workspace (clients, care plans, visits, notes, incidents)Retained while the agency's account is active and under the agency's control. Agencies manage their own records subject to their own record-keeping obligations.
Agency workspace after account closureRetained for a limited period after closure so the agency can export its data or reactivate, then permanently deleted.
Biometric fingerprint templatesDeleted from the agency's database when the agency removes the caregiver's enrollment or the caregiver's record, and removed from kiosk devices at their next sync.
Clock-in and clock-out GPS coordinatesRetained with the visit record as evidence the visit occurred, for as long as the visit record is retained.
Billing records (invoices, payment history)Retained at least 7 years as required by Canadian tax law, even after account closure.
Account informationRetained while the account is active. After closure, retained only as needed for billing reconciliation, dispute resolution, fraud prevention, and statutory compliance; removed on request once no such need remains.
BackupsBackups are retained for a rotation window and destroyed on rotation. Deleted data leaves backups when the backup containing it expires.

Requesting permanent deletion. Agency owners can request permanent erasure by emailing legal@carelyst.ca from the account email. We review every request to ensure it does not conflict with an active billing dispute, an open legal or regulatory matter, an investigation into a suspected Terms of Service violation, or a statutory retention requirement. Once no conflict exists, we complete the deletion within 30 business days. If a specific record cannot be deleted, we will explain why and when the legal basis for retention expires. Individuals whose data lives in an agency workspace should direct deletion requests to the agency, which instructs us.

6. Accuracy

Agency owners and their staff can edit records directly in their dashboard. Caregivers and family members can update their own profiles. If you spot an inaccuracy you cannot fix yourself, contact the agency, or email us for account-level information.

7. Safeguards

  • Database isolation per agency: every agency's data lives in its own dedicated database. There is no shared table where one agency's clients sit next to another's.
  • Encryption in transit: TLS on every connection, HTTPS forced site-wide, including live updates and mobile app traffic.
  • Field encryption: the most sensitive fields, including biometric templates, are encrypted by the application before they reach the database. Biometric templates get this treatment because a biometric cannot be reissued if leaked.
  • Password hashing: bcrypt with per-user salt. We never see or store plain-text passwords.
  • Two-factor authentication: available on accounts, with secrets stored encrypted.
  • Role-based access: every staff role in an agency sees only what its permissions allow. Family portal users see only their own client's information.
  • Audit trail: changes to core records (clients, caregivers, schedules, care plans, compliance documents, incidents, invoices, payments, and payroll) are logged with who did what and when, including the before and after values. Corrections to visit times additionally require a stated reason.
  • Kiosk device security: attendance kiosks authenticate with device-scoped tokens and can be revoked by the agency at any time.

8. Openness

This page and our Privacy Policy document our practices. If anything is unclear, email legal@carelyst.ca and we will explain.

9. Individual access

Agency owners can request a copy of the personal information we hold about their account at any time by emailing legal@carelyst.ca from the account email; we deliver within 30 days. Individuals whose information lives inside an agency workspace (clients, family members, caregivers) should direct access requests to the agency; we provide the agency the tools and support to fulfill them.

10. Challenging compliance

If you believe we have mishandled personal information, contact us first at legal@carelyst.ca. We respond within 30 days. If you are not satisfied, you can file a complaint with either privacy commissioner listed in section 9.

4. Sensitive data, handled specifically

Biometric fingerprint data

Some agencies use shared attendance kiosks with a fingerprint scanner so caregivers can clock in without a personal phone. Because biometric information is sensitive, here is exactly how it works:

  • Professional capture hardware. Kiosks use SecuGen fingerprint scanners whose sensors are certified under the FBI's PIV image-quality standard: purpose-built identity hardware, not consumer parts.
  • Fingerprint images are never stored. The scanner converts a fingerprint into a mathematical template (ISO 19794-2 format). The raw fingerprint image is discarded immediately on the device and is never stored, transmitted, or reconstructable into an image of the finger.
  • Matching happens on the device. When a caregiver clocks in, the comparison runs locally on the kiosk. Fingerprint data is not sent anywhere to perform a match.
  • Encrypted everywhere it rests. On the kiosk, templates are encrypted with keys held in the device's hardware keystore. In the agency's database, template data is encrypted again at the application layer before storage.
  • Scoped to one agency. Templates live only in the enrolling agency's own database and its allocated devices. They are never shared across agencies or used for any purpose other than clock-in verification.
  • Optional, with alternatives. Enrollment requires the caregiver's express consent, and GPS, NFC, or manual verification is always available instead.
  • Deletable. Removing an enrollment deletes the template from the database and removes it from devices at their next sync.

Location (visit verification)

GPS coordinates are captured at exactly two moments: when a caregiver clocks in to a visit and when they clock out. Carelyst does not track caregivers between visits, in the background, or off shift. The two coordinate pairs are stored with the visit record as evidence the visit happened where it should have.

Health information

Care plans in Carelyst can include diagnoses, medications, care goals, and tasks. Visit records can include notes, wellness check answers, and incident reports. This is health information and we treat it accordingly: it lives only in the agency's isolated database in Canada, it is never used for advertising, analytics profiling, or AI training, and access is limited by the agency's own role permissions. The agency, as the care provider, is the custodian of this information; Carelyst processes it on the agency's instructions only.

5. Data residency

All persistent data (databases, uploaded files and documents, backups) is stored in Canadian data centres, specifically DigitalOcean's Toronto region. The application servers, every agency database, and file storage all run there.

Two narrow exceptions involve data transiting non-Canadian infrastructure:

  • Push notifications are delivered through Google's Firebase Cloud Messaging, and on iPhones through Apple's push service. The notification content (for example, a shift reminder title and body) passes through those networks in transit.
  • Map previews and address lookup in the agency dashboard use OpenStreetMap services. The address or location being searched or displayed is sent from the user's browser to OpenStreetMap Foundation servers to draw the map. No names or care records accompany it.

The voice assistant on our marketing site is a separate case: it is provided by 1n1.ai and covered by 1n1.ai's own policies (see section 6). It affects marketing site visitors only; no agency, client, or caregiver data is ever involved.

6. Processing we do ourselves

Two parts of the service look like third-party services but are not, and we want to be transparent about both:

  • Live updates. Real-time dashboard and app updates are delivered by a server we host ourselves on the same Canadian infrastructure as the rest of the platform. No third party sees this traffic.
  • The marketing site voice assistant. The voice assistant on carelyst.ca is powered by 1n1.ai, which is operated by the same company as Carelyst (Techalyst Software Inc.). The assistant only runs when you choose to start a conversation, and it has no connection to the Carelyst application: no agency, client, caregiver, or family data is ever available to it. How 1n1.ai handles voice conversations is described in the 1n1.ai PIPEDA page and privacy policy.

7. Sub-processors

We use the following sub-processors to deliver the service. Each is bound by its own terms and privacy policy governing data passed to it.

Sub-processorPurposeData handled
DigitalOcean (Toronto, Canada)Application hosting, per-agency databases, file storage, backupsAll account and care data at rest, encrypted
StripeSubscription billing in Canadian dollarsAgency owner's billing name, email, and payment method. Stripe handles card data; we never see it. No care data.
ResendTransactional email (invitations, notifications, password resets)Recipient email address and message content
Google (Firebase Cloud Messaging)Push notification delivery to the mobile appsDevice push token and notification content in transit
Apple (APNs)Downstream push delivery to iPhones and iPadsSame as above, for iOS devices
Google and Apple (identity, only if a user chooses social sign-in)Identity verification via Google Sign-In or Sign in with AppleThe provider's stable user identifier, name, and email address (which may be Apple's private relay). No care data flows back to these providers.
Cloudflare (Turnstile)Bot protection on the marketing site contact formVisitor IP address and browser signals during the human-verification check. Marketing site only; never inside the application.
Google AnalyticsMarketing site usage analytics; the cookie banner lets visitors decline, which stops analyticsPseudonymous usage data on marketing pages only; never inside the application
OpenStreetMap FoundationMap display and address lookup in the agency dashboardThe address or visit location being displayed or searched, sent from the user's browser. No names or care records accompany it.

We do not engage new sub-processors that handle your data without updating this list. Email legal@carelyst.ca to request sub-processor change notifications.

8. Your rights

Under PIPEDA and PIPA BC, you have the right to:

  • Access the personal information held about you.
  • Correct any inaccurate information.
  • Withdraw consent at any time.
  • Receive a copy of your personal information.
  • Request deletion of your personal information.
  • Be informed of any breach creating a real risk of significant harm to you.

Send your request to the right party: agency owners email legal@carelyst.ca; clients, family members, and caregivers contact their agency, which we support in responding. We respond to requests addressed to us within 30 days.

9. Complaints

If you are not satisfied with our response to a privacy concern, you can file a formal complaint with either:

Office of the Privacy Commissioner of Canada

30 Victoria Street, Gatineau, Quebec K1A 1H3

Toll-free: 1-800-282-1376

Website: www.priv.gc.ca

Office of the Information and Privacy Commissioner for British Columbia

PO Box 9038 Stn. Prov. Govt., Victoria BC V8W 9A4

Phone: (250) 387-5629

Email: info@oipc.bc.ca

Website: www.oipc.bc.ca

10. Breach notification

If we discover a breach that creates a real risk of significant harm, we will:

  • Notify affected agency owners directly by email within 72 hours of confirming the breach, so agencies can meet their own notification duties to clients and staff.
  • Notify the Office of the Privacy Commissioner of Canada as required by PIPEDA.
  • Maintain an internal record of the breach for a minimum of two years.

The notification will state what data was affected, what we are doing about it, and what you can do to protect yourself. Because agencies hold health information about their clients, we treat any incident touching care data with the urgency that provincial health-privacy laws expect of the agency.

11. Children's data

Carelyst accounts are for businesses; account holders must be at least 18. Agencies may lawfully record care information about minor clients in their care, with consent handled through the agency's own intake process, typically from a parent or guardian. We process that information only as the agency's service provider. We do not knowingly collect personal information directly from children.

12. What this page does not cover

This page covers our handling of personal information. Agencies using Carelyst keep their own obligations as care providers:

  • Client consent: obtaining valid consent for collecting and recording client health information, including from substitute decision-makers where applicable.
  • Biometric consent: obtaining express caregiver consent before fingerprint enrollment and offering an alternative clock-in method.
  • Provincial health-privacy laws: PHIPA in Ontario, the Health Information Act in Alberta, and equivalents elsewhere bind the agency as custodian of client health information. Consult a lawyer if you are unsure what applies to your agency.
  • Employee privacy: telling caregivers, in the agency's own policies, that clock-in and clock-out locations are recorded for visit verification.
  • Retention rules for care records: many provinces set minimum retention periods for health records. Configure and export accordingly before deleting.

13. Changes to this page

If we materially change our practices, we will update this page and notify active agency owners by email at least 30 days before the change takes effect.

14. Contact

Techalyst Software Inc.

Suite 1047, 1055 West Georgia Street, Unit 220
Vancouver, BC V6E 3P3, Canada

For any privacy question, email legal@carelyst.ca. We aim to respond within 5 business days.

One last note. Privacy law is technical and evolves, and health information adds provincial layers on top of PIPEDA. This page explains our practices; it is not legal advice for your agency. If you have data-processing questions your compliance review needs answered, email us and we will answer them properly.