Skip to content
OmaScan
For assessors For funders Pricing About
Try it freeTry it free

OmaScan Privacy Policy

Last updated: September 10, 2026

Effective Date: 30 days after publication · Supersedes the Privacy Policy last revised May 30, 2026

Contents

  1. 1. Introduction and Scope
  2. 2. Key Terms
  3. 3. Who We Are and Our Role
  4. 4. Personal Information We Collect
  5. 5. How We Use Personal Information
  6. 6. Artificial Intelligence Features
  7. 7. Sharing and Disclosure
  8. 8. Cross-Border Data Transfers
  9. 9. Data Retention
  10. 10. Security Safeguards
  11. 11. Breach Notification
  12. 12. Your Rights and Choices
  13. 13. Jurisdiction-Specific Disclosures
  14. 14. Children and Minors
  15. 15. Third-Party Applications and Services
  16. 16. Cookies and Similar Technologies
  17. 17. Changes to This Privacy Policy
  18. 18. Contact Information

1. Introduction and Scope

OmaScan Inc. ("OmaScan," "we," "us," or "our") provides a capture, documentation, and verification platform for clinical home accessibility assessments, used by occupational therapists and other professionals, healthcare organizations, families, contractors, and funders (the "Service").

This Privacy Policy describes how OmaScan collects, uses, discloses, retains, and protects Personal Information in connection with the Service. It applies to all users of the Service, including Professional Users, Guided Capture Users, Viewer Users, and persons who access Verification Pages, and to Subjects whose information is processed through the Service.

This Privacy Policy applies alongside the OmaScan Terms of Service and any Information Manager Agreement, Data Processing Agreement, Business Associate Agreement, or other written agreement between OmaScan and an organization. Where such an agreement provides terms more protective of the individual or required by law, those terms prevail.

Where the Service is used by or for a health information custodian or covered entity (a "Custodian"), the Custodian is responsible for obtaining any consent required by law before collecting or sharing Personal Health Information through the Service, including the consents described in Section 6 of the Terms of Service. Where OmaScan collects Personal Information directly from you (for example, when you create an account or contact us), we obtain any required consent at or before collection.

By creating an account, participating in a Capture Session, or using the Service, you consent to the collection, use, and disclosure of Personal Information for the purposes described in this Privacy Policy.

2. Key Terms

"Personal Information" means information that identifies or could reasonably be linked to an individual, including Personal Health Information.

"Personal Health Information" or "PHI" means Personal Information about an individual's physical or mental health, the health care provided to them, or information collected in connection with a health assessment. Scans of an individual's home, measurements of that home, recordings made during an assessment, annotations about functional needs, and modification recommendations are Personal Health Information when collected in a clinical context.

"Capture Session" means a session in which the Service collects information about a home or Subject, including scans, depth data, measurements, photos, audio recordings and transcripts, responses to guided questions, and capture metadata.

"Claim Record" means the structured record the Service creates for a factual statement: its value, source category (measured, observed, reported, or clinician-authored), method, device, time, capture actor, plan item, location anchor, and integrity hash.

"Guided Capture User" means an individual (for example, a family member or support worker) who performs a Capture Session under a professional's direction.

"Signed Record" means a report version electronically signed by a professional, preserved with its Claim Records and integrity hash.

"Verification Page" means the OmaScan-hosted page through which an authorized recipient can confirm limited facts about a Signed Record, as described in Section 7.

"Service Usage Data" means information about how the Service is used (account activity, device and application information, feature and capture events, session information, error logs, diagnostics, performance data), associated with your account but not intended to include scan content, information identifying Subjects, or other Personal Health Information.

"De-Identified Data" means information derived from Personal Information that has been processed in accordance with OmaScan's de-identification methodology so that it cannot reasonably be used, alone or in combination, to identify an individual or a specific home.

"Your Content" has the meaning given in the Terms of Service.

3. Who We Are and Our Role

OmaScan's role depends on how the Service is used.

When you deal with us directly (creating an account, contacting us, using the Service on your own behalf), OmaScan is the organization responsible for your Personal Information under PIPEDA and applicable provincial laws.

When the Service is used by or for a Custodian in Canada, OmaScan acts as the Custodian's information manager (Newfoundland and Labrador), Electronic Service Provider (Ontario), or equivalent, under a written agreement, and handles Personal Health Information only on the Custodian's instructions for the purposes in that agreement.

When the Service is used by or for a HIPAA covered entity or business associate in the United States, OmaScan acts as a business associate under an executed Business Associate Agreement and handles Protected Health Information only as that agreement and HIPAA permit.

If you are the Subject of an assessment and want to access, correct, or ask about your Personal Health Information, contact the Custodian responsible for your assessment; we will assist the Custodian in responding.

4. Personal Information We Collect

Account information: name, email address, password, phone number (optional), professional role or title, professional designation and license information provided at signing, and organization or practice name.

Capture Session information (Your Content): 3D scans and depth data; measurements and their capture metadata (method, device, time, confidence); photos and video; audio recordings and transcripts, collected only when recording is explicitly started and indicated (see Section 5); responses to guided questions; annotations, placed equipment, notes; locations or addresses associated with Cases; and the Claim Records derived from all of the above. Capture Session information often includes Personal Health Information about Subjects.

Capture actor information: the identity or role of the person who performed each capture (for example, the professional, or a Guided Capture User such as a family member), recorded in Claim Records. For Guided Capture Users we collect the name or identifier provided in the invitation flow, contact information used to deliver the capture plan, and device and session information for the Capture Session.

Signing and integrity information: the signing professional's identity and designation, signature events, version history, edit attribution, and content hashes.

Sharing and verification access records: recipients you authorize, messages and comments on shared content, and access logs for shared content and Verification Pages (time of access, network information, and the matters displayed).

Follow-up and outcomes information (consent-gated): where the responsible Custodian enables follow-up features and the required consents are in place, information about the status and results of modifications, re-scan comparisons, and outcome measures relevant to the assessment (for example, completion of modifications, timelines, and follow-up status). We do not collect outcome information about a Subject without consent obtained by or through the responsible Custodian.

Service Usage Data: as defined in Section 2. It records that actions occurred and when, associated with your user ID, name, email, organization, role, and subscription tier. It does not include the content of what you created: not scan data, report contents, measurement values, home addresses, or other Personal Health Information.

Technical information: IP address, device type, operating system, browser type and version, device identifiers, application version, language and region settings, referring URLs.

Communications: the content of emails and support requests and our responses.

Payments: we use Stripe to process payments. Stripe collects payment details through its interface; OmaScan does not receive or store raw financial account numbers. Stripe's privacy policy applies to that information.

If you voluntarily include sensitive information in free-text fields, it is stored as part of Your Content. We recommend against doing so.

5. How We Use Personal Information

To provide and operate the Service: create and manage accounts; authenticate users; run Capture Sessions and guided capture flows; process and store Your Content; generate Claim Records, drafts, reports, funder forms, receipts, exports, and shares; preserve Signed Records with integrity hashes; provide Verification Pages to authorized recipients; support collaboration you or the responsible Custodian authorize; and communicate with you about the Service.

Audio. Audio is recorded during a Capture Session only when recording is explicitly started, with a visible indicator, and can be stopped at any time. Recordings and transcripts are used to produce the documentation of the Case and are handled as Personal Health Information where applicable.

To maintain, improve, and understand the Service: diagnose issues, monitor performance, measure feature adoption, develop features and products, support customers, and support commercial and strategic planning, relying primarily on Service Usage Data and De-Identified Data.

To secure the Service: detect, prevent, and respond to fraud, misuse, capture manipulation, unauthorized access, and security incidents, and enforce our Terms.

To comply with legal obligations and respond to valid legal requests.

To communicate with you: service messages, and, with consent where required, informational or promotional messages. You can opt out of non-essential communications.

To create De-Identified Data: we create De-Identified Data from Your Content and use of the Service for research, benchmarking, statistical and reference products, publication, analytics, and product development. Our de-identification methodology addresses the identifying potential of spatial data through aggregation, generalization, and suppression before any external use. Once de-identified in accordance with recognized standards, the data is no longer Personal Information or Personal Health Information.

We do not sell Personal Information. We do not use Personal Information for advertising.

6. Artificial Intelligence Features

Report drafting. The Service composes draft report text from the recorded Claim Records of a Case. Draft text is linked to recorded information; sections requiring clinical reasoning are presented to the professional to author. To generate drafts, forms, and analyses, relevant Case content is processed by our AI processing subprocessor listed in Section 7, under contractual terms that prohibit use of that content to train the provider's general-purpose models.

Standards assistant. Query text you submit is sent to the model provider to generate an answer with citations. Queries are not used to train general-purpose models.

Scan and photo analysis. Scan geometry and photos are processed by automated systems to produce measurements, flags, and suggestions, each recorded with its source category.

These features are tools, not advice. Outputs may contain errors and do not make clinical, regulatory, or compliance determinations. Qualified professionals review and sign all reports.

No automated decisions about you. OmaScan does not use AI to make decisions that produce legal or similarly significant effects. Outputs are provided for professional review; funding and coverage decisions are made by funders and programs, not by OmaScan.

AI training. We do not use the raw content of scans or recordings, the content of Personal Health Information, or identifiable queries to train, fine-tune, or improve general-purpose AI models without a separate written agreement. We may use De-Identified Data to improve AI features.

Human review. Where law grants a right to human review of automated processing or an explanation of principal factors, contact us at the address in Section 18.

7. Sharing and Disclosure

With users and recipients you authorize. Content is shared with the users and recipients you or your organization designate.

With Custodians and within authorized care and funding relationships. Where the Service is used for an assessment carried out by or for a Custodian, Personal Health Information is made available to the Custodian and to persons and organizations authorized by the Custodian, the Subject's consent, or applicable law to receive it in the course of providing care, authorizing care, funding care, auditing claims, or coordinating modifications and services.

Verification Pages. For a Signed Record, an authorized recipient (for example, a reviewer for a funder or program to which the report was submitted) may access a Verification Page displaying limited information: integrity status, the signing professional's identity and designation, counts of Claim Records by source category, plan completeness, standards comparison results, re-scan status, and, where relevant, the role (not the full identity) of the capture actor. Verification Pages are designed not to display clinical narrative. Access is logged.

With service providers and subprocessors, who may access Personal Information only as necessary to perform their functions and under contractual protection. Current subprocessors:

  • Amazon Web Services: cloud infrastructure and storage (Canada (Central) region, ca-central-1)
  • Google Cloud (Vertex AI / Gemini): AI processing for drafting, forms, standards assistance, and analysis, under terms prohibiting training on our customers' content
  • Vercel: web application hosting and delivery
  • Stripe: payment processing
  • Resend: email delivery and sharing notifications
  • PostHog: product analytics (Service Usage Data)

We maintain a current subprocessor list and will update this Policy when it changes materially.

For legal and safety reasons. We may disclose Personal Information where we believe in good faith it is necessary to comply with a legal obligation, respond to a valid governmental request, enforce our agreements, protect the rights, property, or safety of OmaScan, our users, or others, or respond to an emergency involving risk of death or serious harm. We will notify you before disclosure of a governmental or legal-process request for your Personal Information unless prohibited or unless notification would impede a lawful investigation or create risk of harm.

In a business transaction. In a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy, Personal Information may be transferred subject to the protections of this Policy or equivalent protections.

With your consent, for other purposes.

8. Cross-Border Data Transfers

Personal Information provided through the Service is stored in Canada (AWS ca-central-1). Service Usage Data is processed by PostHog on servers in the United States; it does not include scan content or Personal Health Information. AI processing under Section 6 occurs in the regions and under the safeguards specified in our subprocessor terms.

For customers enrolled in OmaScan's United States program, Protected Health Information may be stored and processed in a United States region under the applicable Business Associate Agreement.

Before moving any category of Personal Information to a new country, we assess privacy and security implications, apply contractual and technical safeguards (including standard contractual clauses or equivalents where applicable), and update this Policy. Information transferred outside the jurisdiction of collection may be subject to the laws of the receiving country, including lawful access by authorities there. If you are in a jurisdiction that restricts cross-border transfers (for example, Quebec or the European Economic Area), we will apply the required conditions before any transfer.

9. Data Retention

We retain Personal Information as needed for the purposes in this Policy and to meet legal, regulatory, and professional obligations. Standard periods:

  • Account information: duration of the account plus a reasonable period after closure for billing, disputes, and legal obligations
  • Personal Health Information in Your Content: as directed by the responsible Custodian or required by law
  • Signed Records and their Claim Records: retained immutably for the period required by the Custodian's instructions, applicable law, professional retention obligations, or the legitimate needs of a claim, audit, appeal, or dispute in which the record was used
  • Verification access logs and audit logs: ten years, longer where required for investigations or legal obligations
  • Service Usage Data: duration of the account plus up to seven years after termination, then deleted or de-identified
  • Technical logs: ninety days, longer where required for investigations or legal obligations
  • Communications: a reasonable period after resolution
  • De-Identified Data: may be retained indefinitely

When information is no longer needed, we securely delete or de-identify it. If you close your account, content associated with a Custodian's Cases remains available to that Custodian and is retained per its obligations.

10. Security Safeguards

We implement administrative, technical, and physical safeguards designed to protect Personal Information against loss, theft, and unauthorized access, use, disclosure, modification, or destruction, including:

Technical: encryption in transit (TLS 1.2+) and at rest; on-device encryption of capture data before sync; content hashing and version integrity for Signed Records; role-based access controls on the principle of least privilege; access logging for Personal Health Information; automated monitoring; regular patching; secure development practices. Personal Health Information is excluded from application logs and analytics by design.

Administrative: written security and privacy policies; confidentiality obligations for personnel and contractors; privacy and security training; privacy impact assessments for significant changes; vendor risk review before engaging subprocessors; incident response procedures; a designated clinical quality pathway as the only route for human access to Personal Health Information, with access logged.

Physical: certified data centers of our cloud providers with physical access controls and redundancy.

No security measure is perfect. Protect your account with a strong unique password, keep credentials confidential, enable multi-factor authentication where available, and keep devices updated.

11. Breach Notification

We maintain a breach response process to identify, contain, investigate, and remediate incidents. If a breach of safeguards affects your Personal Information and creates a real risk of significant harm, we will: notify you without unreasonable delay, targeting notification within 72 hours of confirming the breach unless a longer period is permitted by law or needed to complete the investigation; describe the incident, the information affected, our response, and protective steps you can take; where affected information is held for a Custodian, notify the Custodian at the first reasonable opportunity so it can fulfill its own notification obligations; where affected information is not held for a Custodian, notify the applicable regulator as required; and keep records as required by law. If you believe your account or information has been compromised, contact security@omascan.com immediately.

12. Your Rights and Choices

Subject to applicable law and identity verification, you may: access your Personal Information; correct inaccurate or incomplete information; request deletion, subject to our legal and contractual retention obligations, including the retention of Signed Records and their Claim Records under Section 9 where they form part of a clinical record or support a submitted claim (in such cases, corrections are made by new attributed versions rather than alteration of the signed version); request portability in a structured, machine-readable format; withdraw consent, without affecting prior processing and possibly affecting our ability to provide the Service; object to or restrict certain processing; request human review of automated processing that significantly affects you; and complain to us or to the privacy regulator in your jurisdiction (Canadian regulators are listed at www.priv.gc.ca).

To exercise these rights, contact security@omascan.com. We respond within the time required by law, typically 30 days under Canadian privacy law. Requests concerning Personal Health Information held for a Custodian are answered with, or directed to, that Custodian.

13. Jurisdiction-Specific Disclosures

Canada. PIPEDA and applicable provincial laws govern our processing. If dissatisfied with our response, you may contact the Office of the Privacy Commissioner of Canada or your provincial commissioner. Where provincial health privacy laws apply (for example, PHIA (NL), PHIPA (Ontario), HIA (Alberta), PHIA (Nova Scotia)), requests concerning Personal Health Information held for a Custodian are generally directed to that Custodian.

Quebec. OmaScan's compliance program has not yet been assessed against Quebec's Law 25, and the Service is not currently offered for use subject to Quebec law. We do not knowingly onboard Quebec Custodians at this time. If Law 25 nonetheless applies to specific processing, you may contact our Privacy Officer (Section 18) and the Commission d'accès à l'information du Québec.

United States. For organizations enrolled in OmaScan's US program, OmaScan acts as a business associate under HIPAA pursuant to an executed Business Associate Agreement. Individuals' HIPAA rights (access, amendment, accounting of disclosures) are exercised through the covered entity responsible for their care; we support covered entities in fulfilling them. State privacy laws may grant additional rights; contact us to exercise any that apply.

European Economic Area and United Kingdom. The Service is not currently offered in the EEA or UK, and OmaScan does not represent GDPR or UK GDPR compliance. The rights framework in Section 12 is designed to be compatible with GDPR-style rights, and we will update this Policy before offering the Service in those regions.

14. Children and Minors

Account holders. Accounts may be created and operated only by persons of the age of majority in their jurisdiction (18 or 19 depending on the Canadian province or territory). Minors may not register or operate accounts. Guided Capture Users must also be of the age of majority.

Subjects. Subjects may include minors (for example, a child whose home is assessed for accessibility). The responsible Custodian is solely responsible for obtaining all legally required consents from the parent, legal guardian, or substitute decision-maker, and for ensuring lawful collection, use, and disclosure of the minor's Personal Health Information. If we learn we have collected Personal Information from a person under the age of majority without appropriate consent, we will delete it.

15. Third-Party Applications and Services

Where you import scan files produced by third-party applications, those applications' terms and privacy policies govern their own collection and processing; OmaScan receives only the file you upload. The Service may link to or integrate with other third-party services with their own privacy practices, for which we are not responsible.

16. Cookies and Similar Technologies

We use essential cookies and similar technologies (such as local storage) to operate the Service, remember preferences, authenticate you, and authorize actions, and an analytics cookie set by PostHog to associate Service Usage Data with a device and user identifier. We do not use third-party advertising cookies and do not sell information to advertisers. You can control cookies in your browser; disabling some may affect functionality.

17. Changes to This Privacy Policy

We may update this Policy. For material changes we will notify you by email, in-Service notice, or posting with an updated "Last Revised" date, and, where law requires, obtain renewed consent before material changes take effect. Changes that only narrow our practices or expand your rights may take effect on posting. Continued use after the effective date constitutes acceptance, except where consent is required.

18. Contact Information

OmaScan Inc.
748 Old Broad Cove Rd
Portugal Cove-St. Philip's, NL A1M 1P1, Canada
Email: security@omascan.com

See also the OmaScan Terms of Service.

OmaScan
Product
For assessors For funders Pricing
Company
About Resources Try it free Contact

Built in Canada. Privacy details in our policy.

© 2026 OmaScan Inc. · info@omascan.com · Terms · Privacy