PHIPA Service Provider and Data Processing Addendum
Last updated: September 1, 2026
This PHIPA Service Provider & Data Processing Addendum (“DPA”) forms part of the agreement between 12677776 Canada Ltd., operating as EMERGE Healthcare Co. (“EMERGE”), and the healthcare organization or professional using the EMERGE Platform (“Customer”).
1. Purpose
This DPA describes EMERGE’s obligations when processing personal information, including personal health information (“PHI”), on behalf of a Customer.
Where the Customer is a health information custodian (“HIC”) under Ontario’s Personal Health Information Protection Act, 2004 (“PHIPA”), EMERGE acts as a service provider and, where applicable, agent to the Customer.
Nothing in this DPA transfers custody or control of the Customer’s clinical records to EMERGE.
2. Customer instructions
EMERGE will process Customer PHI only:
- to provide and support the Services;
- on documented instructions from the Customer;
- for security, integrity and operational purposes reasonably necessary to provide the Services; or
- where required by law.
EMERGE will not independently use Customer PHI for advertising or marketing.
3. Confidentiality and workforce access
Access to PHI by EMERGE personnel will be limited to authorized personnel who require access for legitimate support, operational, security or other permitted purposes.
Personnel with such access will be subject to confidentiality obligations and appropriate privacy and security training.
Access privileges will be based on role and need.
4. Safeguards
EMERGE will maintain reasonable administrative, technical and organizational safeguards appropriate to the sensitivity of PHI.
These safeguards include, as applicable:
- encryption;
- authentication and access controls;
- role-based permissions;
- logging and monitoring;
- vulnerability management;
- secure infrastructure;
- workforce security practices;
- incident-response processes;
- backup and recovery measures; and
- vendor-management controls.
Additional details are described in the EMERGE Security White Paper.
5. Subprocessors
EMERGE may use third-party subprocessors where reasonably necessary to provide the Services.
EMERGE will require subprocessors handling Customer PHI to:
- use the information only for contracted purposes;
- maintain appropriate safeguards;
- protect confidentiality; and
- comply with applicable contractual restrictions.
EMERGE remains responsible for managing its subprocessors in accordance with this DPA.
A current list of material subprocessors will be made available through EMERGE’s Trust Centre or upon request.
6. Data location and access
Data-location requirements applicable to the Customer will be specified in the Customer agreement or applicable Platform configuration.
Where a Customer requires that PHI remain within Canada for storage and processing, EMERGE will configure applicable services and subprocessors in accordance with the agreed requirements.
7. Security incidents
EMERGE will maintain a process for identifying, investigating and responding to security incidents.
Where EMERGE becomes aware of an unauthorized access, use, loss or disclosure involving Customer PHI, EMERGE will notify the affected Customer without unreasonable delay and provide reasonably available information necessary for the Customer to evaluate its legal and regulatory obligations.
EMERGE will reasonably cooperate with the Customer’s investigation and mitigation activities.
8. Access, correction and individual requests
Where EMERGE receives a request from an individual concerning PHI controlled by a Customer, EMERGE will ordinarily direct the person to the applicable Customer.
EMERGE will reasonably assist Customers in responding to access, correction, consent, complaint and other privacy requests relating to information processed through the Platform.
9. Legal demands
Where legally permitted, EMERGE will notify the Customer before disclosing Customer PHI in response to a compulsory legal demand.
EMERGE will disclose only information reasonably required by the applicable legal obligation.
10. Artificial intelligence
Where an AI-enabled EMERGE feature processes PHI, the processing will remain subject to this DPA.
AI subprocessors will be subject to appropriate contractual confidentiality, security and data-use restrictions.
Customer PHI will not be used by EMERGE or its AI subprocessors to train general-purpose models or models for unrelated customers unless expressly authorized by the Customer and permitted by law.
AI prompts, transcripts, temporary audio and generated outputs will be retained only for the period required to provide the applicable feature, meet Customer instructions or satisfy legal or security obligations.
Where an AI-generated output is saved into a patient’s chart by an authorized user, it becomes part of Customer Data.
11. De-identification
EMERGE will not re-identify information that has been properly de-identified except where expressly authorized or required to validate privacy safeguards.
Secondary use of de-identified or aggregated information will be limited to purposes permitted under the Customer agreement and applicable law.
12. Retention, export and deletion
During the Customer relationship, EMERGE will retain Customer PHI in accordance with Customer instructions, applicable Platform functionality and legal requirements.
Upon termination, EMERGE will provide a reasonable process for return or export of Customer Data.
After the applicable retention or transition period, EMERGE will securely delete or render inaccessible Customer PHI unless continued retention is required by law or agreed with the Customer.
Backup copies may remain for a limited period pursuant to normal backup-retention cycles and will remain protected while retained.
13. Compliance assistance
Subject to reasonable confidentiality restrictions, EMERGE will make appropriate documentation available to support Customer security and privacy reviews.
This may include, as appropriate:
- security documentation;
- relevant audit or assurance reports;
- privacy documentation;
- architecture information;
- subprocessor information; and
- responses to reasonable customer security questionnaires.
14. Priority
If this DPA conflicts with general terms concerning the handling of Customer PHI, this DPA will govern with respect to that PHI.