1. Introduction

Web Cyte Development Inc. ("we," "us," or "our") operates Incyte, a cloud-based practice management and scheduling platform designed for wellness clinics in Ontario, Canada. This Privacy Policy describes how we collect, use, store, disclose, and protect personal information and personal health information in compliance with the Personal Health Information Protection Act, 2004 (PHIPA), the Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable privacy legislation.

By using Incyte, your clinic ("you") acknowledges this policy and agrees to its terms.

2. Definitions

TermMeaning
Personal Health Information (PHI)Identifying information about an individual in oral or recorded form, relating to physical or mental health, provision of health care, or payment for health care.
Personal Information (PI)Information about an identifiable individual that does not constitute PHI.
CustodianYour clinic, as the health information custodian responsible for PHI under PHIPA.
AgentWeb Cyte Development Inc., which provides services to Health Information Custodians and processes PHI on their behalf in accordance with PHIPA and applicable agreements.
Privacy OfficerMichael Buchok, CEO and Software Architect, Web Cyte Development Inc.

3. Information We Collect

3.1 Information You Provide

  • Business information: clinic name, address, contact details, tax information
  • Team member information: names, email addresses, roles, permissions
  • Client / patient records: names, contact information, date of birth, appointment history
  • Clinical information: chart notes, SOAP notes, intake form responses, body map annotations
  • Billing information: invoices, payment records, insurance claim details
  • Digital product and event registration data

3.2 Information Collected Automatically

  • Access logs: timestamps, IP addresses, actions performed (retained for security and audit purposes)
  • Session information: login times, browser type, device type
  • Security event data: failed login attempts, suspicious activity patterns

3.3 Information We Do Not Collect

  • Health card numbers or government-issued identification numbers
  • Social insurance numbers
  • Full payment card numbers (card processing is handled entirely by Stripe)

4. How We Use Information

  • To provide, operate, and maintain the Incyte platform
  • To process appointments, billing, and client records on your behalf
  • To send transactional emails (appointment confirmations, receipts, download links)
  • To send SMS appointment reminders (via Twilio)
  • To detect and respond to security threats and unauthorized access
  • To generate audit logs required for PHIPA compliance
  • To issue invoices and process your clinic's subscription payments
  • To improve and develop the platform

We do not sell, rent, or trade personal information or personal health information to any third party for commercial purposes.

5. Legal Basis for Processing

Web Cyte Development Inc. collects and uses PHI only as directed by you (the Custodian) and only for the purposes for which you have collected it from your clients, in accordance with PHIPA and our Data Processing Agreement. We do not use PHI for any purpose beyond providing the Incyte platform.

6. Data Storage and Security

6.1 Where Data is Stored

All data is stored on servers located in Canada (DigitalOcean Toronto region, TOR1). No PHI or PI is transferred outside of Canada.

6.2 Security Measures

  • AES-256 encryption of all personal health information fields at rest at the database field level
  • MySQL InnoDB tablespace encryption for all database files on disk
  • TLS 1.2+ encryption for all data in transit
  • Role-based access controls with least-privilege permissions
  • Mandatory two-factor authentication for all admin accounts
  • Automated security alert monitoring for brute force, off-hours access, bulk exports, and new IP logins
  • Daily encrypted database backups with 30-day retention
  • Apache web server hardening: security headers, bot probe blocking, ServerTokens Prod
  • Fail2Ban intrusion prevention and automated IP banning
  • Access logs retained for all administrative actions

7. Data Retention

Data TypeRetention Period
Client / patient recordsRetained for the period directed by your clinic, subject to applicable record-keeping requirements. Clinics may anonymize or delete records on demand through the admin panel.
Access and audit logs12 months, then purged automatically.
Billing records7 years in accordance with CRA requirements.
Security event logs6 months.
Backup data30 days of rolling encrypted backups.

8. Disclosure of Information

We do not disclose PHI or PI except:

  • As directed by you (the Custodian) in the normal course of providing the platform
  • As required by law, court order, or regulatory authority
  • To our subprocessors listed in Section 9, solely as necessary to operate the platform
  • In the event of a privacy breach, as required under PHIPA

9. Third-Party Subprocessors

ProviderRole
DigitalOcean CanadaCloud infrastructure and server hosting (Toronto, Canada)
StripePayment processing for clinic subscriptions and client purchases. Stripe is PCI-DSS Level 1 certified. Card data never touches our servers.
Mailgun (Mailgun Technologies, Inc.)Transactional email delivery via Mailgun (mail.incyteapp.ca). Clinics may configure their own SMTP sender through Business Settings.
Twilio Inc.SMS delivery for appointment reminders. Message content is limited to appointment details (patient name, appointment date/time, clinic name) sent to the client's phone number.
Zensurance / Tokio Marine CanadaCyber liability and technology E&O insurance. Policy ZMC49504.

10. Individual Rights

Individuals whose PHI is held by your clinic have the following rights under PHIPA: access to their records, correction of inaccurate information, withdrawal of consent (subject to legal exceptions), and notification of a breach affecting their information. These rights are exercised through your clinic as the Custodian.

11. Privacy Breach Notification

In the event of a privacy breach affecting PHI, Web Cyte Development Inc. will notify your clinic without unreasonable delay and no later than 24 hours after discovery. Your clinic, as the Custodian, is responsible for notifying affected individuals and the IPC as required under PHIPA.

12. Contact and Complaints

FieldDetail
Privacy OfficerMichael Buchok, CEO and Software Architect
CompanyWeb Cyte Development Inc.
Address67 Spring Creek Drive, Waterdown, Ontario, L8B 0X4
Emailinfo@webcytedevelopment.com

If you are not satisfied with our response, you may contact the Information and Privacy Commissioner of Ontario:

FieldDetail
IPC Websitewww.ipc.on.ca
Phone1-800-387-0073
Address2 Bloor Street East, Suite 1400, Toronto, Ontario, M4W 1A8

13. Changes to This Policy

We may update this Privacy Policy from time to time. The current version is always available within the Incyte admin panel and at our website. Material changes will be communicated to clinic administrators by email with a minimum of 30 days notice before taking effect.

Last updated: July 30, 2026