Information Security Policy
π Quick Summary: Your Information Security at a Glance
π‘οΈ Multi-Layer Protection: Defense-in-depth security with separate systems for clinical records (Jane App, Canadian servers) and administrative communications (Google Workspace).
π Encryption Everywhere: 256-bit encryption for data at rest, TLS encryption in transit, HTTPS on all websites.
π¨π¦ Canadian Clinical Data: All clinical notes and health records stored securely within Canada via Jane App.
π§ Secure Messaging: Use Jane App’s portal for sensitive information; email is for scheduling/billing only.
β±οΈ 7-Year Retention: Clinical records kept minimum 7 years (adult clients) or until age 26 (minor clients).
ποΈ Your Rights: Access, correct, or request deletion of your information (subject to legal requirements).
π¨ Breach Notification: You’ll be notified immediately if any security incident affects your data.
π Table of Contents
βοΈ Important Notice: When Does a Therapeutic Relationship Begin?
- You complete intake paperwork through our secure client portal (Jane App),
- You agree to our clinical services terms and confidentiality notice, and
- You attend your first scheduled counselling session.
π Digital Infrastructure & Security
π Website Security (Kinsta)
- Dual-layer hardware firewalls (Google Cloud Platform and Cloudflare)
- DDoS protection and unlimited malware removal
- 256-bit SSL encryption for all website traffic (HTTPS)
- Canadian data center options for website hosting, used where feasible
π Clinical Records (Jane App)
- SOC 2 Type II certified security controls
- PIPEDA-compliant handling of personal health information
- 256-bit AES encryption at rest and TLS encryption in transit
- Data stored on secure servers within Canada
- Role-based access controls and detailed audit logging
π Administrative Communication (Google Workspace)
- A Business Associate Agreement (BAA) with Google for HIPAA compliance (US healthcare standard)
- Configuration to meet PIPEDA and PIPA requirements for Canadian privacy law
- Two-factor authentication (2FA) for all staff accounts
- Advanced phishing and malware protection
- ISO/IEC 27001 and SOC 2 Type II certifications
π Third-Party Service Vetting
- Meet Canadian privacy standards
- Provide appropriate security safeguards for your information
- Maintain independent security certifications
- Are subject to ongoing oversight and review
π Data Residency & Processing
π Clinical Data
- Processed and stored securely within Canada via Jane App
- Subject to PIPA, PIPEDA, and CCPA standards
- Accessible only to your clinician and authorized staff on a need-to-know basis
π Administrative Data
- May be stored on secure servers outside Canada (primarily the US)
- Are protected by international security standards (ISO/IEC 27001, SOC 2)
- Are subject to PIPEDA requirements for cross-border data transfers
- Never include detailed clinical notes or session content
π Website Data
- Hosted on Kinsta (Google Cloud Platform)
- Canadian data centers are used where possible
- Subject to PIPA and PIPEDA requirements
π Collection and Use of Personal Information
π Information Collected in Jane App (Clinical Records)
- Personal identification: Name, date of birth, contact information, emergency contacts
- Clinical history: Mental health history, presenting concerns, symptoms, relevant medical history
- Treatment information: Assessment notes, treatment plans, progress notes, therapeutic goals
- Intake forms: Health history, consent forms, questionnaires, relevant insurance information (if applicable)
- Billing records: Invoices, payment history, limited insurance details (no full card numbers stored in Jane)
π Information Collected in Google Workspace (Administrative)
- Appointment times, reminders, and schedule changes
- Billing and invoice communications
- Insurance-related correspondence (if applicable)
- Initial contact and general inquiries
π Website-Level Collection (Automatic)
- IP addresses (for security and fraud prevention)
- Browser type and version
- Device type and operating system
- Pages visited, time on site, and navigation patterns
- Referring websites
π Cookies & Google Analytics
- Pages visited and actions taken on the site
- General location (city/region), based on IP
- Device and browser information
- Referring URLs
- You may opt out of Google Analytics by using the Google Analytics Opt-out Browser Add-on.
- You can manage or disable cookies in your browser settings.
π― Purposes for Collection
- Providing psychotherapy and counselling services
- Conducting assessments and formulating treatment plans
- Monitoring progress and adjusting treatment as needed
- Maintaining accurate clinical documentation as required by CCPA standards
- Responding to inquiries from prospective clients
- Scheduling and confirming appointments
- Processing payments and managing billing
- Sending appointment reminders and administrative notices
- Complying with PIPA, PIPEDA, and CCPA Standards of Practice
- Fulfilling mandatory reporting obligations (detailed in our Privacy Policy & Confidentiality document)
- Responding to valid legal requests (e.g., court orders)
- Maintaining records for the required retention period
β Consent
π Consent for Initial Contact & Website Use
- The collection of your name, email, phone number, and inquiry details
- Our use of this information solely to respond to your inquiry
π Informed Consent for Clinical Services
- How and why your information is collected and used
- The limits of confidentiality
- Your rights and responsibilities as a client
- Fees, cancellation policies, and other clinical terms
π Ongoing and Specific Consent
π Withdrawal of Consent
- Submit a written request (email or letter).
- We will respond within 30 days to confirm and explain implications.
- Withdrawing consent may limit or prevent our ability to provide services.
- Legal obligations (e.g., mandatory reporting, record retention) continue to apply even if consent is withdrawn.
π» Electronic Communication
π Our Precautions
- Jane App secure portal for clinical documents, forms, and secure messaging.
- Encrypted transmission and integration with your clinical record.
- Appointment reminders, confirmations, and invoices via email
- Limited attachments via Gmail Confidential Mode with passcode, when necessary
π Your Responsibility and Risks
- Receiving administrative communications via email (scheduling, billing, basic follow-up)
- Accepting the inherent risks of email, including possible interception, unauthorized access, and misdelivery.
- Sharing detailed clinical disclosures or journal entries
- Crisis or emergency communication
π Emergencies and Crisis
- Call 911 or go to the nearest emergency room.
- Use available crisis services:
- 988 Suicide Crisis Helpline: Call or text 9-8-8 (24/7)
- Vancouver Island Crisis Line: 1-888-494-3888 (24/7)
- Kids Help Phone: 1-800-668-6868 (24/7)
π Data Retention and Destruction
π Retention Period (CCPA-Aligned)
- Adult clients: Minimum of seven (7) years from the date of last session.
- Minor clients: Minimum of seven (7) years after reaching age 19 (i.e., until at least age 26 in BC).
- Emails and scheduling data: Retained for seven (7) years (via Google Vault).
- Billing records: Retained for seven (7) years from the date of last transaction, or longer if required by tax law.
- Retained for up to one (1) year, then deleted or anonymized, unless you become a client.
π Rationale
- Continuity of care
- Legal and professional obligations
- Response to potential complaints or legal claims
- Documentation standards set by CCPA
π Extended Retention
- Legal proceedings are underway or reasonably anticipated
- A professional complaint or investigation is ongoing
- A longer period is required by law
π Professional Will & Cessation of Practice
- A designated professional executor (bound by confidentiality) will manage records.
- Clients will be notified of the status and location of their records where contact information is current.
- Clients may choose to transfer records, request copies, or have records held for the balance of the retention period.
π Secure Destruction
- Electronic records are securely deleted and unrecoverable.
- Paper records (if any) are shredded or destroyed via an accredited destruction service.
- Destruction is documented for accountability.
ποΈ Your Rights
π Right of Access
π Right to Correction
- Submit a written request specifying the corrections.
- We will respond within 30 days.
- If a correction is not made, a note of your request and our rationale will be added to your file.
- Professional opinions and clinical impressions are not changed, but your disagreement can be documented.
π Right to Request Deletion (Subject to Law)
- We cannot delete clinical records that must be retained for the seven-year minimum or while legal obligations are in effect.
- We will explain what can and cannot be deleted when you make a request.
π Right to Withdraw Consent
π Right to Breach Notification
- Notify you as soon as reasonably possible;
- Explain what happened and what information was involved;
- Describe steps taken to mitigate harm and prevent recurrence;
- Advise you of steps you can take to protect yourself;
- Report the breach to relevant authorities as required.
π Security Safeguards
π Technical Safeguards
π Administrative Safeguards
- Confidentiality agreements for all staff and contractors
- Privacy and security training, including PIPA/PIPEDA and CCPA standards
- Written policies for access control, incident response, and data handling
- Principle of least privilege (only necessary access granted)
- Immediate revocation of access on staff departure
π Physical Safeguards
- Locked offices and secure storage for any physical records
- Clean-desk practices (no unattended PHI)
- Secure disposal of printed materials (shredding)
- Secure handling and storage of encrypted devices
π Questions, Concerns, and Complaints
π Privacy Officer Contact
Privacy Officer
Introspectus Counselling Ltd.
Email: sean@introspectuscounselling.ca
Phone: 250-556-4623
Mailing Address: 132-328 Wale Rd., Colwood, BC, V9B 2W8
π Filing a Complaint
- Contact our Privacy Officer first with your concern in writing.
- If unresolved, you may contact:
Office of the Information and Privacy Commissioner for British Columbia
PO Box 9038, Stn. Prov. Govt.
Victoria, BC V8W 9A4
Phone: 250-387-5629 | Toll-free in BC: 1-800-663-7867
π Changes to This Policy
- Changes in law or regulation
- Updates to our services or technology
- Revisions to professional standards (e.g., CCPA updates)
- The “Last Updated” date and version number will be revised.
- Material changes affecting how your information is collected, used, or disclosed will be communicated directly to active clients (e.g., by email or during sessions).
π Version History
- Version 1.0, January 2026 (initial comprehensive policy)
- Version 1.1, January 2026 (CCPA alignment and clarifications)
π Relationship to Clinical Services Agreement
- Privacy Policy & Confidentiality, Covers clinical confidentiality limits, mandatory reporting obligations, therapeutic boundaries, and when information may be shared for safety reasons
- Clinical Services Agreement (provided at intake), Governs the therapeutic relationship, professional boundaries, fees, cancellations, and session logistics
- For technical/data security matters: This Information Security Statement governs
- For clinical confidentiality matters: The Privacy Policy & Confidentiality document governs
- For therapeutic relationship matters: The Clinical Services Agreement governs
π‘οΈ Final Note
Introspectus Counselling Ltd.
Sean Lewis, MA, MDiv, CCC
Canadian Certified Counsellor
132-328 Wale Road, Colwood, British Columbia
Phone: 250-556-4623
Email: sean@introspectuscounselling.ca