Where it runs. Your clinic's copy runs on AWS in Canada (ca-central-1). Patient records, appointments, messages and call transcripts are stored there, encrypted at rest; the fields that identify a patient are encrypted a second time inside the database.
Who can see what. Staff sign in with a password and a second factor. Admin, doctor and receptionist roles limit what each person can open. An audit log that cannot be edited records who looked at or changed which record.
Backups. The database is backed up daily in ca-central-1 and copied to a second Canadian region (ca-west-1). Backups are held for 35 days and cannot be deleted early.
What the receptionist collects. What a booking or a message needs: name, phone number, date of birth to confirm identity, and the appointment details. There is no field for a health-card number, so it cannot record one. A symptom or a health worry is handed to staff, not assessed.
Recording. Every call opens by saying it is an AI assistant on a recorded line. Transcripts go into the clinic's records, where staff can read them. A written retention schedule says how long transcripts and messages are kept and when they are erased.
What leaves Canada. The live audio of a call passes through two vendors that process it in the United States: Twilio carries the phone leg and OpenAI turns speech into speech. Neither holds your patient database. We can show you exactly what each receives.
The laws we design against. Nova Scotia's Personal Health Information Act (PHIA) and Canada's PIPEDA. We make no claim of a badge or a stamp: neither law issues one. We say what we built, and we put it in writing.
Documents on request. A data-flow diagram, the retention schedule and the list of vendors that touch call audio. A written service-provider agreement for your clinic is part of going live.