Privacy Policy
For Clinics and Licensed Mental Health Professionals
Effective Date: Feb 19, 2026
Cognitai Health Inc. (“Cognitai,” “we,” “us,” or “our”) is committed to protecting the personal and professional information of clinics and licensed mental health professionals (“Providers”) who use our platform.
This Privacy Policy explains how we collect, use, store, and safeguard information related to Provider accounts and professional use of the Cognitai platform.
This policy applies separately from the Privacy Policy for Clients/Patients.
We currently operate in Canada and store Provider data in Canada, including the Province of Quebec. If we expand into other jurisdictions (including the United States), additional agreements (such as a Business Associate Agreement under HIPAA) may apply.
1. Our Role
Cognitai operates as a Software-as-a-Service (SaaS) platform supporting licensed mental health professionals.
1.1 With Respect to Patient Data
- Under Canadian privacy law (PIPEDA and Quebec’s Law 25), Cognitai acts as a Service Provider / Processor on behalf of Providers.
- In the United States (if applicable), Cognitai acts as a Business Associate under HIPAA pursuant to a signed Business Associate Agreement (BAA).
Providers remain responsible for clinical decision-making and compliance with their professional, ethical, and regulatory obligations, including obtaining any required consents and authorizations for collection and processing of patient data (including session-related content where used).
1.2 With Respect to Provider Account Data
Cognitai acts as an independent data controller for personal information relating to Provider accounts, billing, security, and platform administration.
2. Information We Collect
We collect information necessary to establish, maintain, secure, and bill Provider accounts.
2.1 Professional and Account Information
- Full name
- Professional email address
- Business contact information
- Clinic name and address (if applicable)
- Professional license number (optional)
2.2 Billing and Payment Information
- Subscription plan details
- Credit usage records
- Billing contact information
- Payment information processed through authorized third-party payment processors
Cognitai does not store full credit card numbers. Payment transactions are handled by secure and compliant payment service providers.
2.3 Security and Technical Information
- IP addresses (for authentication and fraud prevention)
- Device identifiers (for security and account protection)
- Access logs and timestamps
- System activity logs
2.4 Usage and Performance Data
We collect de-identified and aggregated technical data for:
- System performance monitoring
- Platform reliability
- Security analysis
- Technical optimization
We do not use identifiable Provider or Patient data to train AI models unless explicitly agreed in writing.
2.5 Patient Data Processed Through the Platform (on behalf of Providers)
When Providers use Cognitai to support care delivery, Cognitai may process patient/client data on behalf of the Provider as a Service Provider / Processor. The specific categories depend on the features enabled and the information Providers and patients choose to provide. This may include:
- Patient identifiers and account information (e.g., name, email address, device identifiers)
- Self-reports and worksheet responses (including basic well-being tracking)
- Journal entries (text and/or voice, where available)
- Optional wearable-derived metrics shared via Apple HealthKit (if authorized by the patient)
- Clinician-entered information (e.g., intake/clinical information, clinician notes, session notes, clinical summaries)
- Session-related content (including recordings and/or transcriptions) where enabled by the Provider and used with appropriate consents and authorizations
Providers remain responsible for determining what information is collected and for obtaining required consents and authorizations.
We do not use identifiable Provider or Patient data to train AI models unless explicitly agreed in writing.
3. How We Use Provider Information
We use Provider information to:
- Create and manage accounts
- Provide access to the platform
- Process subscriptions and credit usage
- Maintain billing records
- Provide customer support
- Ensure system security and integrity
- Comply with legal and regulatory requirements
We do not use Provider contact information for marketing communications without explicit consent.
We do not sell Provider personal information.
4. AI Governance
Cognitai does not use identifiable Provider or Patient data to train artificial intelligence models.
We may use de-identified and aggregated system-level technical data solely for:
- Improving platform stability
- Monitoring security
- Enhancing system performance
Any participation in research initiatives or AI training programs would require separate, explicit written agreement.
5. Data Residency and Transfers
All identifiable Provider data is stored in Canada, including the Province of Quebec.
We do not transfer identifiable Provider data outside Canada except where legally required.
In limited circumstances, anonymized or de-identified technical data may be processed temporarily outside Canada for infrastructure, security, or system reliability purposes under strict contractual safeguards.
6. Service Providers and Infrastructure
Cognitai uses trusted third-party infrastructure and service providers to operate the platform, including cloud hosting, secure data storage, payment processing (if applicable), and monitoring services.
These service providers:
- Process data only on our documented instructions
- Are contractually prohibited from using Provider or Patient data for independent model training, retention beyond instructed processing, or any purpose other than providing services to Cognitai
- Are bound by confidentiality and security obligations
- Must implement appropriate technical and organizational safeguards
Where required by applicable law, Cognitai conducts appropriate due diligence and risk assessments prior to engaging service providers.
Additional information regarding categories of subprocessors may be provided upon reasonable request.
7. Data Security
We implement industry-standard safeguards appropriate for a health technology platform, including:
- Encryption in transit using TLS 1.2 or higher
- Encryption at rest using strong cryptographic standards
- Role-based access controls (RBAC)
- Access logging and monitoring
- Incident response procedures
While no system can guarantee absolute security, we maintain administrative, technical, and physical safeguards designed to protect Provider information.
8. Data Retention
We retain Provider personal information only as long as necessary to:
- Provide services
- Maintain billing and accounting records
- Comply with legal obligations
Upon account termination:
- Provider account data will be securely deleted or anonymized, subject to legal retention requirements.
- Certain financial or compliance-related records may be retained as required by applicable law.
9. Provider Rights
Subject to applicable law, Providers may have the right to:
- Access their personal information
- Request correction of inaccurate information
- Request deletion (subject to legal and contractual limitations)
- Withdraw consent for optional communications
Requests may be submitted to trust@cognitai.org.
10. International Expansion
If Cognitai expands into jurisdictions outside Canada, including the United States:
- Additional contractual agreements (such as a Business Associate Agreement under HIPAA) may apply.
- We will maintain compliance with applicable healthcare and privacy regulations.
11. Changes to This Policy
We may update this Privacy Policy from time to time.
If material changes are made, we will provide notice via email or within the Provider dashboard where required by law.
12. Contact Information
Cognitai Health Inc.
1250 Rue Guy, Suite #600
Montréal, QC H3H 2L3
Email: trust@cognitai.org
If you have questions regarding this Privacy Policy or our data practices, please contact us.