Legal

PHIPA Services & Agent Agreement

Last updated: July 30, 2026

This agreement sets out Toothmind's obligations as an electronic service provider and agent to Ontario health information custodians under the Personal Health Information Protection Act, 2004. It is accepted at account creation and may be downloaded for your practice's privacy program records.

1. Parties, application, and representations

This PHIPA Services & Agent Agreement (the "Agreement") is entered into between Toothmind Inc. ("Toothmind," "we," "us," or "our"), a company incorporated in Canada, and the health information custodian identified through the acceptance process described below (the "Custodian"). It supplements our Terms of Service and Privacy Policy. If this Agreement conflicts with either of those documents on a matter concerning personal health information, this Agreement governs.

This Agreement is accepted electronically by the individual who creates the primary account for a practice (the "Account Holder"). By accepting, the Account Holder represents and warrants that they are either:

  • (a) a health information custodian within the meaning of section 3 of the Personal Health Information Protection Act, 2004 (Ontario) ("PHIPA"), or a person authorized to bind the health information custodian (including a dentistry professional corporation or practice) on whose behalf the account is created; or
  • (b) an agent of a health information custodian who has been expressly authorized by that custodian to procure the Services on the custodian's behalf, in which case the Account Holder accepts this Agreement on behalf of, and binds, that custodian.

Where the Account Holder invites additional users to the account ("Authorized Users"), the Account Holder represents that each Authorized User is an agent of a Custodian bound by this Agreement and is authorized by that Custodian to use the Services. Where notes generated through the account are destined for the records of more than one health information custodian (for example, where associates are custodians of their own patient records), this Agreement applies to each such custodian, and the Account Holder represents that they have authority to bind each of them.

Toothmind relies on these representations. Use of the Services by a person who is neither a custodian nor an authorized agent of one is a breach of this Agreement and of our Terms of Service.

2. Definitions

  • "PHIPA" means the Personal Health Information Protection Act, 2004 (Ontario) and its regulations, as amended.
  • "Personal health information" or "PHI" has the meaning given in section 4 of PHIPA.
  • "IPC" means the Information and Privacy Commissioner of Ontario.
  • "Services" means Toothmind's clinical note drafting service, including text and voice input, cross-device dictation, and note generation, as described in the Terms of Service and Schedule A.
  • "Procedural Inputs" means the procedural descriptions submitted to the Services by text or voice for the purpose of generating a draft note.
  • "Voice Data" means spoken audio transmitted to the Services for transcription.
  • "Generated Notes" means the draft clinical notes produced by the Services and returned to the user.
  • "Clinical Data" means, collectively, Procedural Inputs, Voice Data, cross-device dictation text, and Generated Notes.
  • "Account Data" means the account information described in our Privacy Policy, including email address, authentication tokens, saved clinical preferences, and custom note templates.
  • "Subprocessor" means a third party engaged by Toothmind to process data in the course of providing the Services.
  • "Privacy Breach" means any theft or loss of, or unauthorized collection, use, disclosure, copying, modification, retention, access to, or disposal of, Clinical Data or Account Data.

3. Toothmind's status under PHIPA

Toothmind provides services that enable the Custodian to use electronic means to create, use, and modify records of personal health information. Accordingly, Toothmind is an electronic service provider to the Custodian within the meaning of subsection 10(4) of PHIPA. To the extent that Toothmind collects, uses, retains, or disposes of personal health information on the Custodian's behalf and for the Custodian's purposes in providing the Services, Toothmind further acts as an agent of the Custodian within the meaning of section 2 of PHIPA, and the Custodian permits Toothmind to handle such information solely as set out in this Agreement, in accordance with section 17 of PHIPA.

Treatment of Procedural Inputs. The Services are designed so that Clinical Data contains no patient names, dates of birth, health numbers, or other direct identifiers, and the parties do not concede that Procedural Inputs constitute personal health information in Toothmind's hands. However, without conceding that classification, Toothmind agrees to handle all Clinical Data with the protections that PHIPA would require if it were personal health information. If a user submits information containing direct identifiers contrary to the Terms of Service, that information nonetheless receives the full protections of this Agreement: it is processed transiently, is not retained, and is subject to every restriction and safeguard herein. The prohibition on identifying inputs governs the user's conduct; it does not reduce the protection applied to whatever is in fact submitted.

Treatment of Voice Data. Voice input is designed for the user to dictate their own procedural summary; the Terms of Service prohibit using it to record patient conversations or ambient audio. If a user does so contrary to the Terms of Service, the resulting audio nonetheless receives the full protections of this Agreement: it is processed transiently, is not retained, and is subject to every restriction and safeguard herein. The prohibition on such use governs the user's conduct; it does not reduce the protection applied to whatever is in fact captured.

No transfer of custody or control. Nothing in this Agreement transfers custody or control of any record of personal health information to Toothmind. The Custodian remains the health information custodian of, and solely responsible for, the patient record, including any Generated Note the Custodian finalizes and enters into its practice management software.

4. Permitted purpose and restrictions

Toothmind shall collect, use, retain (transiently, as described in Schedule A), and dispose of Clinical Data only as necessary to provide the Services to the Custodian and its Authorized Users, namely: transcribing Voice Data, transiently holding cross-device dictation text for retrieval, generating a draft note from Procedural Inputs, and returning that note to the user. Without limiting the foregoing, Toothmind shall not:

  • use Clinical Data to train, fine-tune, evaluate, or improve any artificial intelligence model;
  • disclose Clinical Data to any person, except to Subprocessors as permitted under section 6 or where required by law (in which case Toothmind will, unless legally prohibited, notify the Custodian before complying);
  • sell Clinical Data or Account Data, or use either for advertising;
  • de-identify, aggregate, or derive datasets from Clinical Data for any secondary purpose;
  • attempt to identify any individual from Clinical Data, or use or disclose Clinical Data in a manner that could reasonably be expected to identify an individual; or
  • retain Clinical Data beyond the transient processing described in Schedule A.

Toothmind shall comply with PHIPA as applicable to its role, with the restrictions in this Agreement, and with any additional reasonable restrictions the Custodian communicates in writing, provided they are consistent with the design of the Services.

5. Safeguards and data handling

Toothmind shall maintain administrative, technical, and physical safeguards that are reasonable in the circumstances to protect Clinical Data and Account Data against theft, loss, and unauthorized use, disclosure, copying, modification, or disposal, consistent with sections 12 and 13 of PHIPA. These safeguards include, at minimum:

  • encryption of all data in transit (TLS) and encryption at rest for stored data;
  • a transient-only processing architecture for Clinical Data: Procedural Inputs and Voice Data are not written to disk or database and are discarded once the Generated Note is returned; cross-device dictation text exists only in server memory and is cleared upon retrieval or within 15 minutes;
  • access controls, including multi-factor authentication, limiting administrative access to authorized personnel, with no standing personnel access to Clinical Data in the ordinary course;
  • security and access logging of Toothmind's own systems, limited to metadata (authentication events, note-generation events by account and timestamp, administrative and infrastructure access); Toothmind does not log the content of Clinical Data. Security logs are retained for no longer than 12 months and are used solely for security monitoring, breach detection and investigation, and service integrity;
  • secure disposal such that reconstruction of the information is not reasonably foreseeable in the circumstances, consistent with O. Reg. 329/04; and
  • written confidentiality obligations binding every employee and every person acting on Toothmind's behalf who could access Clinical Data, on terms no less restrictive than this Agreement, before any such access is possible, consistent with O. Reg. 329/04, s. 6(1). All such personnel receive privacy and security training.

Toothmind shall review its safeguards regularly and maintain them in line with evolving threats, IPC guidance, and industry practice.

6. Subprocessors

The Custodian authorizes Toothmind to use Subprocessors in the following categories, as further described in Schedule A: (a) AI inference infrastructure; (b) application hosting; and (c) account data storage. Toothmind shall:

  • bind each Subprocessor by written agreement to data protection obligations no less protective than those in this Agreement, including prohibitions on retention of Clinical Data after processing and on the use of Clinical Data to train or improve AI models;
  • configure Subprocessor services to process Clinical Data in Canadian regions, subject only to the transient cross-border routing described in section 7;
  • remain fully responsible to the Custodian for the acts and omissions of its Subprocessors as if they were Toothmind's own; and
  • give the Custodian at least 30 days' notice (by email or in-application notice) before any change of Subprocessor or material change to a Subprocessor's role that affects the handling of Clinical Data. If the Custodian reasonably objects on privacy grounds, the Custodian may terminate under section 10.

7. Cross-border processing

Toothmind's AI inference infrastructure is configured to use Canadian cloud regions with a geography-bound routing profile limited to Canada and the United States. To manage capacity, an individual inference request may be transiently routed to and processed in a United States region before the result is returned. Where this occurs: the data is transmitted encrypted over the provider's private network; it is not stored in the destination region; it is designed to contain no direct patient or clinician identifiers, and their entry is prohibited; and it remains subject to the contractual protections described in section 6. Clinical Data is not stored anywhere, in Canada or elsewhere, beyond the transient processing described in Schedule A; Account Data is stored only in Canadian regions.

The Custodian acknowledges this processing model and can describe it to patients using the plain-language text in Schedule B. Toothmind shall notify the Custodian in advance, as a material change under section 9, of any change that would expand the geographic scope of processing.

8. Privacy breach notification and cooperation

Toothmind shall notify the Custodian at the first reasonable opportunity upon becoming aware of a Privacy Breach or a reasonably suspected Privacy Breach affecting the Custodian's account or Clinical Data, consistent with section 17 of PHIPA. Notification will describe, to the extent then known: the nature and scope of the breach, the data and accounts affected, the period involved, the containment measures taken, and a contact for follow-up, with reasonable updates as the investigation proceeds.

Toothmind shall further:

  • take immediate steps to contain the breach and mitigate its effects;
  • investigate the cause and implement remedial measures to prevent recurrence;
  • cooperate with the Custodian in meeting the Custodian's own obligations under section 12 of PHIPA, including notice to affected individuals, reporting to the IPC where applicable, and the Custodian's annual breach statistics; and
  • provide the Custodian with the information reasonably required in connection with any review or investigation by the IPC, including relevant security log extracts.

The parties acknowledge that statutory notification of individuals and of the IPC is the Custodian's responsibility as health information custodian; Toothmind will not make such notifications on the Custodian's behalf except as agreed or required by law.

9. Service performance, changes, and oversight

Draft-only outputs and human review. Generated Notes are drafts. The Custodian is responsible for ensuring that every Generated Note is reviewed, edited as needed, and approved by the treating clinician before it is entered into any patient record, consistent with the Terms of Service and the recordkeeping expectations of the Royal College of Dental Surgeons of Ontario.

Notification of quality issues. Toothmind shall notify Custodians proactively (by email or in-application notice) if it identifies a systematic accuracy, reliability, or output-quality issue in the Services that could reasonably affect the content of Generated Notes, and shall suspend or correct the affected functionality as appropriate.

Material changes. Toothmind shall give advance notice of any material change to its data practices, data flows, Subprocessors, processing locations, or the categories of data handled by the Services, before the change takes effect. New features involving new collections, uses, or disclosures of Clinical Data will be described in such notice and, where reasonably practicable, made opt-in.

Annual attestation. Upon request, and no more than once per year, Toothmind will make available to the Custodian a summary attestation of its security and privacy practices sufficient to support the Custodian's vendor assessment obligations under PHIPA and IPC guidance. This attestation is provided in place of individual audit rights, which are impracticable for a multi-tenant service; Toothmind may additionally make available summaries of third-party security assessments as they are completed.

Reporting by the Custodian. The Custodian and its Authorized Users should report suspected inaccuracies, unexpected outputs, or privacy concerns to info@toothmind.com; Toothmind will investigate reports in good faith.

10. Term, termination, and data disposition

This Agreement takes effect upon acceptance and continues for as long as the Custodian or any of its Authorized Users has an active account. Either party may terminate as set out in the Terms of Service; the Custodian may additionally terminate on written notice if Toothmind materially breaches this Agreement and fails to cure within 30 days, or as provided in section 6. The Custodian may close its account and initiate deletion at any time directly within the application.

Upon termination or account closure:

  • Clinical Data: the parties acknowledge that, by design, Toothmind retains no Clinical Data, and there is accordingly no Clinical Data to return or destroy;
  • Account Data: deleted within 30 days of account closure, subject to legal retention obligations, and disposed of in accordance with section 5; and
  • Security logs: retained only for the balance of their retention period in section 5, then disposed of securely.

Sections 3, 4, 5 (as to residual data), 8, 11, and 12 survive termination.

11. Liability

Privacy breach liability. Notwithstanding the limitations of liability in the Terms of Service, Toothmind is liable to the Custodian for direct damages arising from a Privacy Breach caused by Toothmind's failure to comply with this Agreement, up to an aggregate cap of the greater of (a) two times the fees paid by the Custodian in the 12 months preceding the event, and (b) CAD $10,000.

General cap. Toothmind's aggregate liability for all other claims under this Agreement is limited to the fees paid by the Custodian in the 12 months preceding the event giving rise to the claim.

Clinical content. Nothing in this Agreement alters the allocation of responsibility for the clinical content of notes: as set out in the Terms of Service, the Custodian and its clinicians are solely responsible for reviewing, editing, and approving Generated Notes before use in any patient record, and Toothmind is not liable for loss arising from reliance on a Generated Note without adequate review. The Custodian's indemnity in the Terms of Service respecting prohibited inputs and uses remains in effect.

12. General

Governing law. This Agreement is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, and the parties attorn to the exclusive jurisdiction of the courts of Ontario. Nothing in this Agreement limits the jurisdiction of the IPC.

Electronic acceptance. This Agreement may be accepted electronically, and electronic acceptance is valid and enforceable in accordance with the Electronic Commerce Act, 2000 (Ontario). The Custodian may download or print a copy of this Agreement at any time for its privacy program records; the version and acceptance date are recorded against the account.

Amendments. Toothmind may amend this Agreement on advance notice by email or in-application notice. Amendments that materially reduce the protections in this Agreement do not take effect for an existing Custodian until accepted, or until the Custodian continues use of the Services after 30 days' notice, whichever is earlier. The Custodian may terminate rather than accept a material amendment.

Order of precedence. On matters concerning personal health information or the handling of Clinical Data, this Agreement prevails over the Terms of Service and Privacy Policy to the extent of any conflict.

Contact. Privacy Officer, Toothmind Inc. — info@toothmind.com.

Schedule A — Data description and handling

Procedural Inputs (typed text)

Procedure-level descriptions (e.g., tooth number, procedure type, anesthesia, materials, findings). The input is not structured to capture patient or clinician identifiers, and their entry is prohibited. Transmitted encrypted to AI inference infrastructure; processed transiently; discarded once the Generated Note is returned; never written to disk or database; never used for model training.

Voice Data

Spoken audio transmitted for transcription; deleted immediately after transcription; the audio never persists on any system. The resulting text is handled as a Procedural Input. A cancel control stops recording without transmission.

Cross-device dictation text

Held transiently in server memory only (never disk or database) to permit retrieval on another device; cleared upon retrieval or automatically within 15 minutes.

Generated Notes

Returned to the user and not retained by Toothmind. The Custodian's copy, once entered in its practice management software, is a record of personal health information in the Custodian's custody.

Account Data

Email address, authentication tokens, saved clinical preferences, custom note templates, and free-trial credits. Stored encrypted in Canadian cloud regions; retained for the life of the account; deleted within 30 days of closure.

Security logs and usage data

Metadata-only security and access logs (section 5), a daily usage counter, and error logs. No Clinical Data content is logged. Retained no longer than 12 months (logs) or as operationally necessary (counters, error logs), then securely disposed of.

Subprocessors

  • AI inference: Amazon Web Services (Amazon Bedrock), Canada region with Canada/US geography-bound routing; zero retention of prompts and outputs; no use of inputs or outputs for model training; model providers do not receive or access the data. Governed by data processing and business associate terms with AWS.
  • Application hosting: Microsoft Azure (App Service), Canadian region. Clinical Data transits the application layer in memory only in the course of routing requests and responses; it is not written to disk, database, or logs. Governed by the Microsoft Products and Services Data Protection Addendum.
  • Account data storage: MongoDB Atlas, Canadian cloud region. Stores Account Data only; does not receive Clinical Data. Governed by the MongoDB Data Processing Agreement.

Schedule B — Patient-facing disclosure template

The following plain-language text may be incorporated by the Custodian into its written public statement of information practices under section 16(1) of PHIPA, posted in the practice, or used to answer patient questions. Adapt bracketed text to your practice. This text describes Toothmind only and not other AI tools you may use.

Template notice

Our practice uses Toothmind, a Canadian software tool that helps your dentist prepare written treatment notes. Toothmind is a post-procedural tool. It is not designed to listen to or record your conversations with your dentist. After your treatment, your dentist types or dictates a short technical description of the procedure — with no names, birthdates, or health card numbers — and the tool produces a draft note. Your dentist reviews and finalizes every note before it goes into your chart, which stays in our practice's own record system. Toothmind does not keep any of this information: it is processed briefly and immediately discarded, and it is never used to train AI systems. Processing occurs on Canadian servers, although an individual request may briefly pass through secure U.S. infrastructure before being returned; nothing is stored there. Questions? Ask [contact person] at [contact details], or see our full privacy notice. You may also contact the Information and Privacy Commissioner of Ontario.

Contact-person quick answers

  • Is my visit recorded? No. Toothmind is not designed to hear or record patient conversations. Your dentist types or dictates a short technical summary after your treatment.
  • Is my name or health number sent anywhere? No. The tool isn't designed to capture that information, and our clinicians and staff are prohibited from entering it.
  • Where is my chart kept? In our own practice management system, as always. Toothmind keeps nothing after the draft note is returned.
  • Is anything used to train AI? No. That is contractually prohibited.
  • Does data leave Canada? It is not stored outside Canada. A request may be briefly processed on secure U.S. servers and immediately discarded.
  • Who reviews the notes? Your dentist reviews, edits, and approves every note before it enters your record.