Legal · Privacy Policy

PxProfiler Privacy Policy

PxProfiler is a Canadian digital health platform that helps clinicians assess patient activity and fitness baseline trends. We are committed to protecting personal information and personal health information in accordance with applicable Canadian privacy laws, including PIPEDA and, where applicable, provincial health privacy laws.

Effective Date: May 11, 2026
Organization: PxProfiler, a digital subsidiary of INFN8 Solutions Inc.
01

Our Privacy Commitment

PxProfiler is designed around a privacy-first principle:

Raw health data stays on the patient’s iPhone.

When a patient runs an analysis, the PxProfiler iOS analyzer app queries Apple HealthKit locally on the patient’s device. The app computes activity and fitness trends on-device and uploads only the finished summary report to PxProfiler’s secure backend.

PxProfiler does not store raw Apple HealthKit records, including:

  • heart rate readings;
  • step logs;
  • workout route data;
  • GPS/location history;
  • raw workout records; or
  • underlying Apple HealthKit source data.

PxProfiler stores only trend summaries needed to support clinical decision-making, such as percentage changes, weekly averages, and direction-of-change indicators across movement, cardio, and endurance metrics.

02

Information We Collect

PxProfiler may collect the following information:

Patient information

  • Name;
  • Email address;
  • Activity scores;
  • Summary trend data generated by the PxProfiler iOS analyzer app.

Clinician and account information

  • Name;
  • Email address;
  • Login and authentication information;
  • Portal usage and security-session information.

Technical and usage information

We may collect limited technical and usage information to:

  • monitor app performance;
  • improve usability and user interface design;
  • detect bugs or errors;
  • maintain security;
  • understand feature usage.

PxProfiler uses analytics tools in the app for usage, performance, and interface improvement purposes.

03

Apple HealthKit Data

PxProfiler’s iOS analyzer app accesses Apple HealthKit data only on the patient’s device for the purpose of generating summary trend reports.

Raw Apple HealthKit data is processed locally and is not uploaded to PxProfiler’s backend.

PxProfiler does not use Apple HealthKit data for advertising, sale to advertisers, or unrelated commercial profiling.

04

How We Use Information

PxProfiler uses personal information and summary health information to:

  • generate and store patient activity and fitness summaries;
  • make summary reports available to the clinician assigned to the patient;
  • operate and secure the clinician portal;
  • authenticate users;
  • maintain audit trails;
  • improve app and portal performance;
  • improve product design and user experience;
  • create aggregated or de-identified insights for research, benchmarking, analytics, and product improvement.

We do not use personal health information for targeted advertising.

05

Clinician Access

Summary reports are accessible only to the clinician assigned to the patient, subject to system permissions and security controls.

Clinicians are responsible for using PxProfiler in accordance with their own professional, legal, and clinical obligations.

06

Consent

PxProfiler collects, uses, and discloses personal information with consent, except where permitted or required by law.

Patients authorize the iOS analyzer app to access Apple HealthKit data on their device. Patients may manage Apple HealthKit permissions through their iPhone settings.

Clinicians and patients may withdraw consent where permitted by law, but withdrawal may affect the ability to use PxProfiler services.

07

No Sale of Personal Information

PxProfiler does not sell personal information or personal health information to advertisers, data brokers, or third-party marketing networks.

08

Analytics, Cookies, and Authentication

PxProfiler uses analytics in the iOS app to understand app usage, performance, and opportunities for user-interface improvement.

The clinician portal uses cookies strictly for security-session and timeout requirements.

PxProfiler uses Google Firebase for secure credential management and login authentication.

We do not use portal cookies for advertising or cross-site behavioural tracking.

09

De-Identified and Aggregated Data

PxProfiler may create aggregated or de-identified data for:

  • product improvement;
  • platform performance analysis;
  • clinical benchmarking;
  • research and development;
  • statistical reporting.

PxProfiler will take reasonable steps to ensure that aggregated or de-identified data does not identify an individual patient or clinician.

We do not attempt to re-identify de-identified data except where required to test, validate, or improve privacy and security safeguards.

10

Data Storage and Location

PxProfiler uses a hyperscaler cloud provider with data hosted in a Canadian regional data centre.

Although PxProfiler’s primary hosting is in Canada, some service providers may process limited technical, support, security, or authentication information outside Canada depending on their infrastructure and service model. Where this occurs, information may be subject to the laws of the jurisdiction where it is processed.

11

Security Safeguards

PxProfiler uses administrative, technical, and organizational safeguards designed to protect personal information and summary health information against unauthorized access, use, disclosure, copying, modification, loss, or theft.

Security measures include:

  • encryption at rest using AES-256;
  • encryption in transit using TLS 1.2 or higher;
  • role-based access controls;
  • clinician-assigned patient access;
  • secure credential management;
  • security audit trails retained for seven years;
  • security timeout controls on the clinician portal.

No digital system can be guaranteed to be perfectly secure. PxProfiler maintains reasonable safeguards but cannot guarantee absolute security.

12

Retention

PxProfiler retains personal information and summary health information only as long as reasonably necessary for the purposes described in this policy, including clinical use, security, legal, audit, and business record requirements.

Security audit trails are retained for seven years.

When information is no longer required, PxProfiler will delete, anonymize, or securely dispose of it, subject to legal or contractual obligations.

13

Breach Response

If PxProfiler becomes aware of a privacy or security incident involving personal information or personal health information, we will investigate and take appropriate steps to contain, assess, and remediate the incident.

Where required by law, PxProfiler will notify affected individuals, organizations, regulators, or other required parties. Under PIPEDA, breach reporting can be required where there is a real risk of significant harm.

14

Access, Correction, Deletion, and Export

Individuals may contact PxProfiler to request access to, correction of, deletion of, or export of their personal information, subject to legal, contractual, clinical, and technical limitations.

Patients may also need to contact their clinician or clinic where the clinician controls or maintains the clinical record.

Requests can be sent to:

Privacy@pxprofiler.com

We may need to verify identity before completing a request.

15

Accuracy

PxProfiler relies on users, patients, clinicians, device permissions, and source data available through Apple HealthKit to generate summary reports.

Patients and clinicians are responsible for ensuring that account information is accurate and up to date.

16

Service Providers

PxProfiler may use trusted service providers to operate, host, secure, authenticate, analyze, or support the platform.

Service providers are permitted to access personal information only as necessary to provide services to PxProfiler and must protect that information through appropriate safeguards.

17

Children and Minors

PxProfiler is intended for use in a clinical context. Where patients are minors, clinicians and/or legal guardians are responsible for ensuring appropriate consent and authorization as required by law and clinical practice.

18

Changes to This Policy

PxProfiler may update this Privacy Policy from time to time. If material changes are made, we will update the effective date and provide notice where appropriate.

19

Governing Law

This Privacy Policy is governed by the applicable laws of Canada and the Province of Ontario, without limiting the application of other Canadian privacy or health privacy laws that may apply based on the user, clinician, patient, or clinical setting.

20

Contact

PxProfiler is a digital subsidiary of INFN8 Solutions Inc., with offices in Burlington and Toronto, Ontario, Canada.

Questions, privacy requests, or complaints may be directed to:

Privacy@pxprofiler.com