Privacy Policy
1. Who We Are
This Privacy Policy describes how MyCannaDoc (“MyCannaDoc,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with our clinic management software platform, websites, applications, support channels, and related services (collectively, the “Service”).
MyCannaDoc is designed for clinics and authorized clinic personnel. The Service may be used to manage clinic accounts, users, offices, patients, patient documents, recommendations, service dog letters, caregiver documents, identification cards, invoices, receipts, inventory-related items, activity monitoring, notifications, audit logs, and related operational workflows.
2. Important Roles: Customers, Users, and Patients
The Service is primarily a business-to-business software platform. Our direct customer is typically a clinic or healthcare-related organization that uses the Service (“Customer”). Individuals authorized by a Customer to access the Service are “Users.” Patients whose information is entered into the Service by a Customer or User are “Patients.”
For Patient information entered and maintained by a Customer, the Customer is generally the organization that determines why and how the information is used. MyCannaDoc processes such information to provide and support the Service. If you are a Patient and have questions about your medical record, recommendation, clinic document, or privacy rights, you should first contact the clinic that provided your care or entered your information into the Service.
3. HIPAA and Protected Health Information
The Service may store or process health information, medical documentation, patient identifiers, and other information that may be considered Protected Health Information (“PHI”) under the Health Insurance Portability and Accountability Act and its implementing regulations (“HIPAA”) when handled by a covered entity or business associate.
To the extent MyCannaDoc receives, maintains, creates, or transmits PHI on behalf of a HIPAA-covered Customer, MyCannaDoc will handle such PHI as required by a written Business Associate Agreement (“BAA”) or other applicable agreement between MyCannaDoc and the Customer. This Privacy Policy does not replace a Customer’s HIPAA Notice of Privacy Practices or any BAA.
4. Information We Collect
4.1 Account and User Information
- name, email address, phone number, role, permissions, office assignments, preferred language, and login information;
- clinic owner, administrator, staff, doctor, manager, and front desk profile information;
- professional details such as medical license number, driver license information where used by the clinic, signature image, user photo, and related profile data;
- account status, login timestamps, IP address, user agent, language settings, and security-related events.
4.2 Clinic and Office Information
- clinic name, address, country, state, city, logo, account or beta-access status, and clinic settings;
- office names, addresses, working hours, logos, and office-level assignments or restrictions.
4.3 Patient and Medical Workflow Information
Depending on how a Customer uses the Service, the Service may process:
- Patient name, contact information, date-related fields, driver license or identification information, photos, and demographic or profile data;
- Patient dog profile information, dog photos, documents, notes, uploaded files, and clinic-created records;
- recommendations, future recommendations, renewal recommendations, exemptions, caregiver recommendations, service dog verification letters, ID cards, mini recommendations, replacements, invoices, receipts, and related PDFs or files;
- inventory-related patient product sales and related financial or operational records.
4.4 Activity Monitoring, Notifications, Audit Logs, and Support Data
- clock-in/clock-out data, activity monitoring events, hourly activity buckets, alerts, and notification records;
- audit logs containing action type, entity type, actor user, clinic, office, request identifier, IP address, user agent, timestamps, and change metadata;
- support messages, troubleshooting details, screenshots you provide, issue descriptions, and communications with us.
4.5 Technical Information
- session cookies and authentication-related data required to operate the Service;
- IP address, browser type, device information, logs, error events, and security monitoring data;
- backup and system operation data required to maintain the Service.
5. How We Use Information
We use information to:
- provide, operate, maintain, secure, and improve the Service;
- create and manage clinic accounts, users, roles, permissions, offices, patients, documents, recommendations, invoices, receipts, notifications, and audit logs;
- authenticate Users, enforce permissions, prevent unauthorized access, and investigate security or support issues;
- generate clinic documents, PDFs, recommendations, letters, cards, receipts, invoices, and related files as directed by the Customer or authorized User;
- provide customer support, troubleshooting, product communications, administrative notices, and service emails;
- maintain backups, logs, and records needed for legal, compliance, security, and operational purposes;
- comply with applicable law, contracts, legal process, and regulatory obligations.
6. How We Disclose Information
We may disclose information as follows:
- To Customers and authorized Users. Clinic data is available to the Customer and its authorized Users according to roles, permissions, and clinic configuration.
- To service providers and subprocessors. We may use vendors for hosting, infrastructure, database storage, backups, security monitoring, email delivery, support, and similar services.
- To email and communication providers. If email features are enabled, transactional emails such as registration, password recovery, and notifications may be sent through an email provider such as Mailgun or another provider selected by us.
- For legal and compliance purposes. We may disclose information when required by law, subpoena, court order, regulation, or to protect rights, safety, security, and prevent misuse.
- Business transfers. Information may be transferred in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar business transaction, subject to applicable law and contracts.
- With consent or direction. We may disclose information when directed by the Customer, authorized User, Patient, or other authorized person, as applicable.
7. No Sale of Patient Data or PHI
We do not sell Patient medical information or PHI. We do not use Patient medical information or PHI for third-party advertising. If applicable privacy law uses the terms “sell” or “share” in a broader way, we will honor applicable opt-out rights to the extent required by law.
8. Security
We use administrative, technical, and organizational measures designed to protect information handled by the Service. These measures may include user authentication, role-based permissions, session controls, CSRF protections, protected file delivery, audit logging, access restrictions, storage outside the public web root, backups, and monitoring.
No system is 100% secure. Customers and Users are responsible for using strong passwords, protecting their devices and credentials, assigning appropriate roles and permissions, promptly disabling access for unauthorized or former personnel, and reporting suspected security issues to us.
9. Data Retention
We retain information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support Customer operations. Patient and clinic records are generally retained according to the Customer’s instructions, applicable law, and our agreements with the Customer.
Operational backups may be retained for up to three (3) years for disaster recovery, security, continuity, and related operational purposes. A shorter or longer period may apply where required by applicable law, a Business Associate Agreement, Customer instructions, litigation hold, security requirements, or other binding legal or contractual obligations. Backup copies may not be immediately removable from all backup systems when information is deleted from the active Service and may remain until the applicable backup cycle expires.
10. Privacy Rights and Patient Requests
Depending on your location and the type of information involved, you may have rights to access, correct, delete, receive a copy of, or restrict certain uses of your personal information.
If you are a Patient seeking access to, correction of, deletion of, or restrictions on medical records or PHI held by a clinic, please contact the clinic directly. We may assist the clinic in responding to requests when required by contract or law.
If you are a User or website visitor and wish to make a privacy request to MyCannaDoc, contact us using the details below. We may need to verify your identity and authority before responding.
11. California Privacy Notice
This section applies to California residents to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), applies to us and to the information at issue.
In the preceding 12 months, we may have collected the following categories of personal information:
- Identifiers, such as name, email, phone, IP address, account identifiers, and clinic/user identifiers;
- commercial or transaction information, such as clinic-generated invoices, receipts, and transaction-related records where entered into or generated through the Service;
- internet or electronic network activity information, such as login events, device/browser data, and usage logs;
- professional or employment-related information, such as role, clinic position, office assignment, medical license information, and staff profile details;
- sensitive personal information, which may include account login credentials, health information, medical information, driver license information, and other sensitive data depending on Customer use of the Service.
We collect and use these categories for the purposes described in this Privacy Policy. We do not sell personal information or use Patient medical information for cross-context behavioral advertising.
California residents may have rights to know, access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and not be discriminated against for exercising privacy rights. To exercise rights, contact us at support@mycannadoc.com. We may need to verify your identity, residency, or authority before completing a request, and certain information may be exempt from a request where permitted by applicable law.
12. Cookies and Tracking
The Service uses cookies and similar technologies that are necessary for login sessions, security, language preferences, and core application functionality. We do not intend to use Patient medical information for advertising tracking.
If we later add analytics, advertising, or non-essential tracking technologies, we will update this Privacy Policy and provide any required notices or choices.
13. Children
The Service is not intended for direct use by children under 18. Customers may enter information relating to minors when legally permitted and appropriate for clinic operations. Customers are responsible for obtaining any required consents and complying with applicable laws when processing minors’ information.
14. U.S. Use
The Service is intended primarily for use in the United States. If information is accessed from outside the United States, it may be processed in the United States or other locations where we or our service providers operate.
15. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date above indicates when the policy was last revised. Material changes may be communicated through the Service, email, or other appropriate methods.
16. Contact Us
MyCannaDoc
Email: support@mycannadoc.com
Phone: +1 818 647 1172