Totus Life ServicesTelePort

Data Retention Policy

How long we keep your information and when it is securely destroyed

Last updated: July 2026

This Data Retention Policy explains how TelePort manages the lifecycle of personal health information, what we keep, how long we keep it, and when and how it is securely destroyed. Our retention framework balances legal requirements under BC PIPA, Ontario PHIPA, Alberta PIPA, PIPEDA, Quebec Law 25, and all provincial health information statutes with the privacy principle of data minimization.

Retention Summary

Data CategoryRetention PeriodDestruction Method
Account InformationAccount duration + 7 yearsSecure deletion
Session Metadata7 yearsSecure deletion
Video/Audio ContentNot recorded (E2EE)N/A
Audit Logs7 yearsImmutable — deleted after retention
Consent Records7 years from last activitySecure deletion
Application Logs90 daysAutomated rotation
Security Event Logs2 yearsSecure deletion
BackupsDaily (30d), weekly (12w), monthly (7yr)Secure overwrite

1. Purpose & Scope

This Data Retention Policy defines how TelePort manages the lifecycle of personal health information (PHI) and other data collected through our platform. It applies to all data categories including account information, patient health information, session metadata, audit logs, and communication records. Our policy is designed to balance the legal obligation to retain health records with the privacy principle that data should not be kept longer than necessary. It complies with BC's Personal Information Protection Act (PIPA), Ontario's PHIPA, Alberta's PIPA, PIPEDA, and all applicable provincial health information statutes and regulatory college requirements across Canada.

2. Retention Periods by Data Category

Account Information:

- Provider accounts: Retained for the duration of the account, plus 7 years after closure (to comply with regulatory college record-keeping requirements)

- Patient accounts: Retained for the duration of active care, plus 7 years from the date of last contact (or 10 years for minors in some provinces)

Session Metadata:

- Call start/end times, duration, participants: Retained for 7 years

- Encryption keys (used for E2EE): Ephemeral — never stored on our servers

- Video/audio recordings: Not applicable — TelePort does not record or store consultation content

Audit Logs:

- All access logs and audit trail records: Retained for 7 years

- Immutable audit logs are append-only and cannot be modified or deleted during the retention period

Communication Records:

- Patient consent records: Retained for 7 years from the date of last consent activity

- Contact form inquiries: Retained for 2 years

- Support ticket correspondence: Retained for 3 years after ticket closure

Technical Logs:

- Application logs: Retained for 90 days

- Error logs: Retained for 1 year

- Security event logs: Retained for 2 years

- Network traffic logs: Retained for 1 year

Billing and Financial Records:

- Payment records: Retained for 7 years (required by Canada Revenue Agency)

3. Provincial Variations in Retention Requirements

Health record retention requirements vary by province. TelePort applies the longest applicable retention period to ensure compliance across all jurisdictions:

British Columbia: College of Physicians and Surgeons of BC requires records be kept for 16 years from date of last entry for adults, and 16 years after the patient turns 19 for minors. BC's PIPA requires personal information be retained only as long as necessary for the identified purpose.

Ontario: PHIPA requires health records be retained for at least 10 years from the date of last record entry for adults, and 10 years after the patient turns 18 for minors. The Medicine Act, 1991 and regulations under various health professions acts impose additional record-keeping requirements.

Alberta: The Health Professions Act requires regulated members to keep records for at least 7 years from the date of last service for adults, and 7 years after the minor reaches 18.

Other Provinces: Most provinces require health record retention of 7-10 years from the date of last entry, with extended periods for minors. Healthcare providers using TelePort are encouraged to familiarize themselves with their specific regulatory college's requirements.

Federal (PIPEDA): Personal information shall be retained only as long as necessary for the fulfillment of the purposes for which it was collected. Organizations are also subject to statutory limitation periods for civil actions (typically 2 years), which inform the minimum retention period for records that may be needed for legal proceedings.

4. Secure Disposal & Destruction

When data reaches the end of its retention period, it is securely destroyed in accordance with industry best practices and regulatory requirements:

Electronic Data:

- Database records: Permanently deleted using secure deletion protocols that overwrite the data

- Backups: Rotated and overwritten according to the backup retention schedule

- Audit logs: Retained in their original immutable format for the full retention period before deletion

Physical Media:

- TelePort operates on Canadian cloud infrastructure and does not maintain physical media containing PHI

Destruction Verification:

- All data destruction is logged with timestamp, operator, and description

- Annual verification that destruction procedures are effective

- Certificates of destruction are available upon request

5. Data Minimization & Collection Limits

TelePort only collects the minimum amount of personal information necessary to provide telehealth services. Specifically:

- We do NOT collect or store video or audio content from consultations

- We do NOT require patients to provide health card numbers or other government identifiers

- We do NOT collect financial information — payment processing is handled by our payment processor

- We limit session metadata to what is necessary for service delivery and audit compliance

- We do NOT use personal information for advertising, profiling, or any purpose not directly related to healthcare delivery

Our data minimization approach is a core architectural principle that reduces both privacy risk and our compliance burden.

6. Backup & Disaster Recovery

Data is backed up to ensure continuity and integrity:

- Daily automated backups of all databases

- Weekly full backups stored in a separate Canadian region

- Backups are encrypted at rest using AES-256

- Backup retention follows a graduated schedule: daily (30 days), weekly (12 weeks), monthly (7 years)

- Disaster recovery testing occurs quarterly

- Recovery Time Objective (RTO): 4 hours for critical systems

- Recovery Point Objective (RPO): 1 hour for critical data

Backups containing PHI are subject to the same access controls, encryption standards, and retention policies as production data.

7. Legal Hold & Litigation

Where TelePort receives a legal notice, preservation request, or becomes aware of litigation involving data in our custody, we will:

1. Immediately place a legal hold on the relevant data, suspending any deletion or destruction

2. Document the hold order, effective date, and scope

3. Ensure the hold is communicated to all relevant team members and systems

4. Preserve the data in its existing format without modification

5. Lift the hold only upon written authorization from legal counsel or after the matter is resolved

Legal holds override standard retention and deletion schedules for the affected data.

8. Questions & Requests

Patients and providers may request information about our data retention practices or request deletion of their data (subject to legal retention requirements):

Privacy Officer: privacy@totus.ca

Data Access Requests: privacy@totus.ca

General Inquiries: support@totus.ca

We will respond to data-related requests within 30 days as required by PIPEDA. Requests for early deletion will be honoured unless we are legally required to retain the data.