Totus Life ServicesTelePort

Privacy Policy

How we collect, use, and protect your information

Last updated: July 2026

At TelePort, protecting your privacy is at the heart of everything we build. This policy explains how we handle your personal information in compliance with Ontario's Personal Health Information Protection Act (PHIPA), the federal Personal Information Protection and Electronic Documents Act (PIPEDA), and Alberta/BC's Personal Information Protection Act (PIPA).

Information We Collect

  • Account Information: When you register as a provider, we collect your name, email address, clinic name, professional specialty, and license number.
  • Patient Information: When patients join a waiting room, we collect their name and optionally their email or phone number for appointment purposes.
  • Session Data: We record session metadata including start/end times, duration, and participant names. We do NOT record or store video, audio, or chat content from calls.
  • Usage Data: We collect anonymous analytics about how you use our platform to improve the experience for all users.

How We Use Your Information

  • To provide, maintain, and improve our telehealth platform
  • To connect patients with their healthcare providers
  • To comply with legal and regulatory obligations under PHIPA and PIPEDA
  • To send important service updates and security notices
  • We never sell your personal information or use it for advertising

Data Residency

  • All patient data is stored exclusively on Canadian servers.
  • Our infrastructure is hosted with Canadian cloud providers to ensure data never leaves Canada.
  • Video and audio streams are routed through our Canadian-hosted LiveKit SFU and are end-to-end encrypted — we cannot see or record them.
  • This Canadian data residency is a core architectural principle, not an afterthought.

PHIPA & PIPEDA Compliance

  • TelePort is designed from the ground up for PHIPA (Ontario) and PIPEDA (Federal) compliance.
  • We maintain Business Associate Agreements (BAAs) with all third-party service providers who may process health information.
  • All access to personal health information is logged in an immutable audit trail.
  • We conduct regular security assessments and penetration testing.
  • Our compliance framework extends to PIPA (Alberta/BC) and HIPAA (US) requirements.

Data Security

  • End-to-End Encryption: All video and audio calls are encrypted with AES-256-GCM using LiveKit E2EE. The encryption key is known only to participants — we cannot decrypt streams.
  • Encryption in Transit: All data transmitted between your browser and our servers is protected by TLS 1.3.
  • Encryption at Rest: Patient data stored in PostgreSQL is encrypted using the pgcrypto extension.
  • Access Control: Strict role-based access control ensures only authorized providers can access their patients' information.

Your Rights

  • You have the right to access the personal information we hold about you.
  • You have the right to request correction of inaccurate information.
  • You have the right to request deletion of your account and associated data, subject to legal retention requirements.
  • You have the right to withdraw consent for data collection at any time.
  • To exercise any of these rights, contact our Privacy Officer at privacy@totus.ca.

Cookies

  • We use essential cookies required for authentication and platform functionality.
  • We use session cookies to maintain your login state.
  • We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
  • You can control cookie settings through your browser preferences.

Third-Party Services

  • LiveKit: Our video infrastructure provider — operates under a BAA and processes encrypted media streams only.
  • PostgreSQL: Database provider — all data at rest is encrypted using pgcrypto.
  • Redis: Session caching — contains no personal health information.
  • All third-party services are contractually bound to maintain Canadian data residency and compliance with applicable privacy laws.

Contact Us

  • Privacy Officer: privacy@totus.ca
  • Security: security@totus.ca
  • General Inquiries: support@totus.ca
  • Response Time: We aim to respond to all privacy-related inquiries within 2 business days.