Privacy Policy

Effective Date: August 1, 2026

Version: 1.0

Carrick ("Carrick", "we", "our", or "us") is the brand under which Carrick Health Innovations Inc. provides its products and services.

Carrick provides healthcare technology solutions designed to help healthcare organizations improve communication, patient engagement, workflow automation, and operational efficiency.

Protecting the privacy and security of personal information is fundamental to Carrick’s mission of delivering secure healthcare technology solutions.

This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use the Service.

The terms used in this Privacy Policy have the same meaning as those defined in our Terms of Service, unless otherwise defined herein. In particular, “Personal Information,” “Customer Data,” “Organization,” “Authorized User,” “End User,” and “Service” have the meanings given in the Terms of Service.

Information We Collect

Carrick collects only the information reasonably necessary to provide, maintain, secure, and improve the Service.

Carrick processes Customer Data on behalf of Organizations for the purpose of delivering the Service. Customer Data is processed only in accordance with the instructions of the Organization, except where otherwise required by applicable law.

Where Carrick collects Personal Information directly (for example, Organization and Authorized User information), it does so with consent or as otherwise permitted or required by applicable law. For Customer Data and End User information processed on behalf of an Organization, the Organization is responsible for obtaining any consents and providing any notices required by applicable law, including any consents required under the Terms of Service, and Carrick relies on the Organization’s authority and instructions.

Organization Information

When an Organization subscribes to the Service, we may collect information such as the Organization’s name, billing information, contact details, subscription information, and configuration settings.

Authorized User Information

Authorized Users are individuals who have been granted access to the Service by an Organization. We may process information including:

End User Information

End Users (such as patients, clients, or other individuals served by an Organization) are individuals who interact with an Organization through the Service but may not have a Carrick account (sometimes referred to as Contacts or Patients). Depending on how an Organization uses the Service this information may include:

Where applicable, this information may include personal information or protected health information (PHI) that an Organization has authorized Carrick to process on its behalf.

Connected Systems Information

Organizations may choose to integrate Carrick with third-party applications or services, including electronic medical record (EMR) systems, customer relationship management (CRM) systems, identity providers, communication platforms, calendars, or other business systems.

Information received from Connected Systems is processed only as necessary to provide the Service in accordance with the Organization’s instructions.

Technical and Usage Information

When the Service is used, Carrick may automatically collect technical information to operate, secure, and improve the platform. This may include:

This information is used to maintain the reliability, performance, and security of the Service.

How We Use and Disclose Information

How We Use Information

Carrick uses information processed through the Service to:

Artificial Intelligence Features

Organizations may choose to enable artificial intelligence (“AI”) powered features within the Service. These features are optional and are configured and controlled by the Organization.

When enabled, AI-powered features may process Customer Data provided by or on behalf of the Organization in order to generate responses, automate workflows, assist with communications, patient engagement, execute prompts, or perform other functions configured by the Organization.

Organizations are responsible for determining what information is made available to AI features and for configuring prompts, scripts, workflows, and automation rules appropriate to their use of the Service.

Carrick’s AI-powered features are designed to assist Authorized Users and support Organization workflows. They are not designed to make decisions that produce legal or similarly significant effects about an individual without human involvement. Where an Organization uses AI features to inform decisions about individuals, the Organization is responsible for any human review and for meeting applicable transparency and automated decision-making requirements.

Disclosure of Information

Carrick may disclose information:

Carrick does not sell personal information. Information is disclosed only as described in this Privacy Policy or as directed by the Organization using the Service.

Data Retention

Carrick retains personal information and Customer Data only for as long as necessary to provide the Service, fulfill contractual obligations, comply with applicable legal requirements, resolve disputes, and enforce our agreements.

The length of time information is retained may vary depending on the type of information, the Organization’s configuration of the Service, applicable legal or regulatory requirements, and the terms of any applicable agreement between Carrick and the Organization.

When personal information or Customer Data is no longer required, Carrick will securely delete, anonymize, or otherwise dispose of the information in accordance with its data retention practices and applicable law.

Security

Carrick maintains administrative, technical, and physical safeguards designed to protect personal information and Customer Data against unauthorized access, use, disclosure, alteration, or destruction.

These safeguards may include access controls, authentication mechanisms, encryption, monitoring, auditing, secure software development practices, and other measures appropriate to the sensitivity of the information being processed.

While Carrick continuously works to protect the information entrusted to the Service, no method of transmitting or storing information electronically can be guaranteed to be completely secure.

If Carrick becomes aware of a breach of security safeguards involving Personal Information or Customer Data that it processes, Carrick will notify the affected Organization without undue delay so that the Organization can meet its own notification obligations, and will take reasonable steps to contain and investigate the incident. Where required by applicable, Carrick will comply with reporting requirements. Carrick maintains records of breaches of security safeguards as required by applicable law.

Data Storage and International Transfers

Carrick and its service providers may store and process Personal Information and Customer Data in Canada, the United States, and other jurisdictions in which Carrick or its service providers operate. The location of processing depends on the components of the Service used and the configuration selected by the Organization.

Organizations subject to privacy laws that restrict or require assessment of transfers of Personal Information outside a province or country are responsible for determining whether their use of the Service is consistent with those requirements. Carrick will provide reasonable information to assist Organizations in conducting any assessment required by applicable law.

Healthcare Privacy and Regulatory Compliance

Carrick is designed to support healthcare organizations that operate within regulated environments. We recognize the importance of protecting personal and health information and designed the Service to support our customers’ privacy and security obligations.

Where applicable, Carrick supports customers subject to healthcare and privacy legislation, including Canada’s PIPEDA, applicable provincial health privacy legislation, and the United States Health Insurance Portability and Accountability Act (HIPAA). Where required, Carrick will enter into Business Associate Agreements (BAAs) with covered entities or business associates.

Cookies and Similar Technologies

Carrick uses cookies and similar technologies on our website and within the Service to provide functionality, improve user experience, enhance security, and better understand how our website and services are used.

Website

Our public website may use cookies and similar technologies to remember user preferences, analyze website traffic, improve website performance, and support marketing and communications activities. Where required by applicable law, visitors will be provided with options to manage non-essential cookies.

Service

The Service uses essential cookies and similar technologies to authenticate Authorized Users, maintain secure sessions, remember user preferences, and support the secure operation of the platform. These technologies are necessary for certain features of the Service to function properly.

Users may configure their web browser to refuse or remove certain cookies; however, doing so may affect the functionality of the website or the Service.

Third-Party Services

Carrick uses trusted third-party service providers to support the operation, security, and delivery of the Service. These providers perform services on Carrick’s behalf and are authorized to process information only as necessary to provide these services.

Third-party service providers may support functions including:

Where third-party service providers process personal information or Customer Data on Carrick’s behalf, they are required to maintain appropriate administrative, technical, and organizational safeguards to protect the information they process.

Carrick selects service providers that support our commitment to protecting personal information and delivering secure and reliable healthcare technology services.

Your Privacy Rights

Subject to applicable law, individuals may have the right to:

Where Carrick processes personal information on behalf of an Organization, requests relating to Customer Data should generally be directed to the Organization responsible for the information. Carrick will assist Organizations in responding to such requests where appropriate and in accordance with applicable agreements.

Requests regarding personal information or privacy practices may be submitted using the contact information provided at the end of this Privacy Policy.

Carrick may need to verify an individual’s identity before responding to a request and will respond within the timeframes required by applicable law. Individuals also have the right to complain to a privacy regulator. In Canada, this includes the Office of the Privacy Commissioner of Canada or the applicable provincial privacy commissioner. Individuals in the United States whose protected health information is handled under HIPAA may raise concerns with the responsible Organization or with the U.S. Department of Health and Human Services, Office for Civil Rights. Carrick will not retaliate against an individual for exercising their privacy rights.

Children’s Privacy

The Service is intended for use by healthcare organizations and their Authorized Users. Carrick does not knowingly collect personal information directly from children.

Organizations using the Service may process personal information relating to minors including patients, clients, or other individuals under the age of majority. Where such information is processed, Carrick does so solely on behalf of the Organization and in accordance with its instructions, applicable agreements, and applicable law.

If you believe that personal information has been provided to Carrick in error or in a manner inconsistent with this Privacy Policy, please contact us using the information provided below.

Changes to this Privacy Policy

Carrick may update this Privacy Policy from time to time to reflect changes to the Service, our business practices, applicable legal or regulatory requirements, or other operational needs.

Where appropriate, we will notify Organizations of material changes using reasonable methods, which may include posting the updated Privacy Policy on our website, providing notice within the Service, or communicating directly with Organizations.

The “Effective Date” at the beginning of this Privacy Policy indicates when this version became effective. Continued use of the Service following the effective date of an updated Privacy Policy constitutes acceptance of the revised Policy.

Contact Information

If you have questions about this Privacy Policy, Carrick’s privacy practices, or the handling of personal information, please contact our Privacy Officer at:

Carrick Health Innovations Inc.

Physical Address: 132 Bond Street, St. John’s, NL A1C 1T9

Email: privacy@carrick.io

Carrick will make reasonable efforts to respond to privacy-related inquiries in accordance with applicable privacy legislation.