Privacy Policy

The privacy of your personal information, including your personal health information is very important to us. This section describes how your personal information may be collected, used, disclosed, stored and your rights related to your personal information.

About this Privacy Policy

Hippo Studios & Hippo MD

Hippo Studios Inc. ("Hippo Studios", "we", "us" and terms of similar meaning) provides Hippo MD to you subject to these terms of service (the "Terms"). Hippo MD encompasses (i) our proprietary mobile application software (the "App"); (ii) our administrative services related to your use of the App ("Admin Services"); (iii) our website at http://hippomd.ca (the "Website"); (iv) any other web application versions of the App; (v) any other mobile or web applications that we have now or in the future; and (vi) any other software provided by Hippo Studios for use with the App or otherwise.

Consenting to this Privacy Policy

By accepting the Privacy Policy when creating your Account, you expressly consent to our collection, use and disclosure of your Personal Information in accordance with this Privacy Policy. This Privacy Policy is incorporated into and subject to our Terms of Service.

Personal Information includes your personal health information ("PHI"), as applicable, personally identifiable information, which is information that can be used to identify you ("PII"), and non-personally identifiable information, which is information that cannot be used to identify you ("Non-PII").

How to withdraw Consent

You may withdraw your consent regarding this Privacy Policy. You can withdraw consent by emailing us at records@hippomd.ca, or simply stop using Hippo MD. You acknowledge that your withdrawal of consent is not retroactive.

Assumption of Valid Consent

If you continue to use Hippo MD, it will be assumed that your consent to this Privacy Policy is still valid.

Overriding Consent

If you are a Minor, and your legal guardian had originally consented to these Terms and our Privacy Policy on your behalf, you may override this consent, and withdraw consent. You must let us know by emailing records@hippomd.ca, and you must ask your legal guardian who had originally consented on your behalf to no longer use Hippo MD on your behalf.

Modification of Privacy Policy

We may revise this Privacy Policy from time to time. We encourage you to periodically review this Privacy Policy to stay informed about how we are using, disclosing and protecting the information we collect from you.

COLLECTION OF PERSONAL INFORMATION

When we collect your Personal Information

We will collect your Personal Information in the following ways:

  1. When you create an Account;
  2. When you create a Profile;
  3. When you create a Visit Request;
  4. When you use Hippo MD.

Personal Health Information

Hippo Studios, on behalf of Physicians, will collect the following PHI about you:

  1. Visit Request Information, which includes your first name, your last name, your gender, your birth date, your health card number (if applicable), health card version code (if applicable), health card expiry date (if applicable), your military or refugee health number (if applicable), and your Chief Complaint.
  2. Physician Information, which is the name of the Physician who attends to your location and completes a Visit.

Personally Identifiable Information

Hippo Studios will collect the following PII about you:

  1. Your first name and last name;
  2. Your birth date;
  3. Your gender;
  4. Your email address;
  5. Your cell phone number;
  6. Payment transaction details.

Non-Personally Identifiable Information

Hippo Studios will collect the following Non-PII about you:

  1. Tracking and/or analytics services. We may use mobile application tracking and/or analytics services. These services may record unique mobile gestures such as tap, double-tap, zoom, pinch, scroll, swipe and tilt but do not collect PII or PHI that you do not voluntarily enter into the App. We use this information to understand user behavior and optimize application performance.
  2. Cookies. Cookies are small files placed on your hard drive that assist us in providing our services. We may use cookies to collet usage information, determine our total audience size and traffic and determining which areas of the Website are of greatest interest to users.
  3. Web Beacons/Pixel Tags. These are invisible tags placed on certain pages of our Website. When you access our Website, pixel tags generate a notice of that visit. They usually work in conjunction with cookies, registering when a particular computer visits a particular page. If you turn off cookies, the pixel tag will simply detect an anonymous website visit. We may use web beacons to recognize users and access traffic patterns.

No Collection of Physician Charts

During your Visit, the Physician may keep a record of the consultation, which may include your health history, your current symptoms, and treatment notes ("Chart"). Hippo Studios will not be collecting this Chart and will have no direct access to this Chart. Your Chart remains with and is the sole responsibility of the Physician.

No Collection of Credit Card Information

While you may be required to enter your credit card information to pay the Visit Fee, we do not collect your credit card information. For credit card payments, we use a third-party payment processor called Stripe (http://stripe.com) ("Payment Processor"). This means that we do not collect and will not have access to any of your credit card information. We will, however obtain certain transaction details from the Payment Processor, which we will use in accordance with this Privacy Policy.

USE OF PERSONAL INFORMATION

How we use your Personal Health Information

Hippo Studios uses your PHI to:

  1. Receive Visit Requests on behalf of Physicians. Knowing this information beforehand will assist the Physician with providing medical care to you during their Visit;
  2. To verify your health coverage on behalf of Physicians;
  3. Act as the contact person on behalf of the Physicians when it comes to access or correcting your PHI;
  4. For Visits that are covered by the applicable provincial health insurance plans, the Canadian Forces, or the Interim Federal Health Program, to processes claims for payment on behalf of Physicians;
  5. For Visits that are not covered by the applicable provincial health insurance plans or if you have Quebec health coverage, to receive payment of the Visit Fee on behalf of Physicians;
  6. Enable you to create Profiles for yourself or Minors for whom you are legal guardian for; and
  7. To provide you with a list of past Visits in the App ("Visit History").

Other than as specified in this Section, Hippo Studios will not use your PHI for any other purpose without your written authorization, or unless otherwise permitted or required by law.

Hippo Studios will not permit its employees, contractors, representatives, directors, officers, etc. to have access to your PHI unless they agree to be bound by a confidentiality agreement that includes the above restriction.

How we use your Personally Identifiable Information

We will use your PII to:

  1. To troubleshoot problems;
  2. Detect and protect us against error, fraud and other criminal activity;
  3. To enforce our terms of service;
  4. Provide you with system or administrative messages;
  5. Inform you of site updates and notices related to privacy or security;
  6. To send you information about your relationship or transactions with us;
  7. To contact you about the status of your Visit Request;
  8. To contact you to inquire, confirm or verify details relating to your Visit Request; and
  9. Deliver you information that may be relevant to your interests (if you have opted in to receive such information).

How we use your Non-Personally Identifiable Information

We use Non-PII for purposes such as measuring the number of users of various features of Hippo MD and making Hippo MD more useful to you. We may use your Non-PII for research purposes, for marketing and promotional purposes, and to develop new learning tools and solutions. We may analyze trends, administer Hippo MD, track your movement, and gather demographic information in an aggregate anonymized non-personally identifiable way. We may also perform internal research on our users demographics, interests, and behavior to better understand, protect and serve you and your community.

DISCLOSING YOUR PERSONAL INFORMATION

Personal Health Information

Hippo Studios discloses your PHI to:

  1. Physicians, since we are collecting information on behalf of the Physicians. For clarity, the only Physician who will have access to your information is the Physician dispatched to you. The Physician's treatment of your Visit Request Information is subject to the Physician's own policies and procedures;
  2. Health Coverage Verification Programs such as provincial health card validation portals or Medavie Blue Cross (for Military or Refugee health coverage), since we need to verify your health coverage;
  3. Insurance Plans, such as your applicable provincial health insurance plan or Medavie Blue Cross (if you have Military or Refugee health coverage), if we need to process claims for payment on behalf of Physicians.

Other than as specified in this Section, Hippo Studios will not disclose to anyone else your PHI without your written authorization, or unless otherwise permitted or required by law.

Hippo Studios will not permit its employees, contractors, representatives, directors, officers, etc. to have access to your PHI unless they agree to be bound by a confidentiality agreement that includes the above restriction.

Third-Party Service Providers

Some portions of the Hippo MD are reliant on third party service providers, including but not limited to Amazon Web Services, Microsoft Azure, MLabs, Plivo, Mailgun, Stripe. These service providers may be supplied with or have access to your Personal Information solely for the purpose of providing these services to you on our behalf. Such service providers are best-in-class and have appropriate confidentiality and security standards. In any event, whatever PHI and PII is disclosed to these third party service providers, it is only ever disclosed to them in encrypted form.

Legal Requests

We cooperate with law enforcement inquiries and demands for information that are made under force of law. Therefore, we may disclose your Personal Information (a) to any governmental authority as part of an investigation to determine our compliance with any applicable law, rule, or regulation (including privacy laws, rules, and regulations), in accordance with the applicable law (b) in response to a court order, subpoena, discovery request, or other lawful judicial or administrative proceeding, in accordance with the applicable law (c) as otherwise required under any applicable law.

Sale of Business

We may also disclose Personal Information to the acquirer or its agents in the course of the sale of our business. If we do this, the disclosure will be subject to confidentiality arrangements customary in such transactions.

STORAGE AND RETENTION OF YOUR PERSONAL INFORMATION

Retention of Personal Information

We retain Personal Information for only as long as required to fulfill the identified purposes for which it was collected or as required by law. When you create an Account or Profile, archived Personal Information that you have provided will not ordinarily be erased unless and until your entire account on Hippo MD is deleted, and even then we may retain some or all of your Personal Information on back-up files; provided, however, we assume no obligation or guarantee to archive any information and do not warrant that any archived information will later be made available to you.

Personal Information Stored Outside Canada

You acknowledge and understand that Hippo Studios, through the use of third-party service providers, your Personal Information is stored and processed outside of Canada. In any event, whatever PHI and PII is stored outside Canada, it is stored in encrypted form.

Data Storage in Hippo Studios' Database

You consent to allowing Hippo Studios to store your Personal Information in our electronic systems. Your PHI and PII is stored in our database in encrypted form, and anytime it is transmitted, it is transmitted in encrypted form. For both data storage and transmission, we use generally accepted industry standards for encryption.

PROTECTING YOUR PERSONAL INFORMATION

Hippo Studios strives to protect your Personal Information, including your PHI and PII. We use commercially reasonable administrative, technical, and physical measures to safeguard your PII and PHI in our possession against loss, theft and unauthorized use, disclosure or modification. We follow generally accepted industry standards to protect the information submitted to us, both during transmission and once we receive it. For data transmission security, we use standard encryption protocols (SSL/HTTPS) for transmission of information. The encryption process protects your information by scrambling it before it is sent to us from the App. When PHI and PII are stored, it is stored in our systems in encrypted form. Our hosting service providers for our database and application as well as our encryption key management service are renowned and reputable third-party hosting service providers whose privacy, security, transparency and industry-specific standards are best-in-class. Our systems and databases are backed up regularly to help protect your Personal Information in case of an incontrollable catastrophe.

Unfortunately, no data transmission over the mobile applications and the internet and no storage of data, even in an encrypted form, can be guaranteed to be 100% secure. Therefore, while we strive to make all reasonable efforts to use commercially acceptable means to protect your PHI and PII, we cannot warrant the security of any information you transmit to us, and you acknowledge that there is always some risk when transmitting information to us through Hippo MD.

You acknowledge that Hippo Studios are not responsible for any breach of security or for any actions of the Physicians.

The Payment Processor used for credit card transactions is certified to PCI Service Provider Level 1.

REGARDING YOUR PERSONAL HEALTH INFORMATION

This section highlights some of your rights regarding your PHI.

Contact Person

Your contact person regarding your PHI is Adrienne Ng, and can be reached at records@hippomd.ca.

Accessing your PHI

You have the right to obtain access to your PHI in either electronic or paper format. For instructions on how to get a copy of your PHI or Chart, please email records@hippomd.ca. While we do not have direct access to your Charts, we will contact the applicable Physician and obtain a copy of your Chart for you. We reserve the right to charge you a reasonable cost-based fee, such as for photocopying or postage.

If you are requesting access to your PHI, we, of course, have to take reasonable steps to verify your identity before releasing your PHI to you.

Correcting your PHI

You have the right to make corrections to your PHI. For instructions on how to make corrections to your PHI or Chart, please email records@hippomd.ca. While we do not have direct access to your Charts, we will contact the applicable Physician and make the correction of your Chart for you.

If you are requesting a correction to your PHI, we, of course, have to take reasonable steps to verify your identity before correcting your PHI for you.

Communicating in a Specific Way

When corresponding with Hippo Studios about your PHI, you may ask us to communicate with you in a specific way. Please let us know your email or phone number at which you would like us to contact you.

Complaints to Hippo Studios

You may make a complaint about our practices relating to your PHI by emailing records@hippomd.ca.

Complaint to the Commissioner

You may make complaint to the Commission regarding our practices relating to your PHI by contacting:
Information and Privacy Commissioner of Ontario
2 Bloor Street East, Suite 1400
Toronto, Ontario
M4W 1A8

QUESTIONS OR CONCERNS

It is our goal to make our privacy practices easy to understand. If you have questions or concerns, please email our privacy officer at privacy@hippomd.ca.