Privacy Policy

The Privacy Policy of Endor Health Inc. (referred to as "Endor Health," "we," or "us") was last revised on October 19, 2023. The most current version of this policy can be found at our website, accessible via https://endorhealth.com/privacy-policy. Please be aware that we maintain the right to amend this policy whenever necessary to align with relevant regulations, our present procedures, and the Endor Health platform.

At Endor Health, we are dedicated to ensuring your confidence and safeguarding your interests by providing clear insights into how we manage your Personal Information and Personal Health Information (referred to as "Information").

Endor Health is strongly committed to protecting your privacy in accordance with federal laws and regulations, including the Personal Information Protection and Electronic Document Act (PIPEDA), as well as provincial health legislation.

Definitions:

The terminology used in this policy aligns with the definitions found in Endor Health's Terms of Use.

- "Authorized Healthcare Prescriber" denotes a licensed physician or nurse practitioner practicing in a Canadian province or territory, permitted to deliver Healthcare Services and Informational Services through the Endor Health Platform.

- "Authorized Healthcare Professional" designates a regulated health professional licensed to practice in a Canadian province or territory, authorized to offer Healthcare Services and Informational Services via the Endor Health Platform.

- "Applicable Law" refers to the laws and regulations that Endor Health, Authorized Healthcare Prescribers, Authorized Healthcare Professionals, and Users are obliged to adhere to.

- "Device" signifies a mobile or desktop device owned or controlled by a User, used to access Endor Health Services.

- "Healthcare Services" includes the provision of healthcare, including the discussion of Personal Health Information (PHI) by an Authorized Healthcare Prescriber or Authorized Healthcare Provider through the Endor Health Platform.

- "Informational Services" refers to offering general information concerning a disease or condition, which is not specific to individual health information. It is intended for educational purposes only and for clarity, excluding diagnoses, treatments, or advice based on observation, examination, or assessment of a particular patient.

- "Endor Health Platform" encompasses the hardware, software, applications, websites, content, products, and services owned and operated by Endor Health Inc., enabling Authorized Healthcare Prescribers and Authorized Healthcare Providers to provide Healthcare Services and Informational Services to Users.

- "Personal Health Information" (PHI) signifies information related to an individual's health or healthcare, subject to Applicable Law, and collected, created, compiled, used, disclosed, transmitted, and/or stored on or through the Endor Health Platform.

- "User" (referred to as "you" or "your") represents an individual who has created and registered a Endor Health User Account in compliance with our Terms of Use, and is eligible to receive Healthcare Services and/or Informational Services through the Endor Health Platform.Endor Health Inc. employs various safeguards to ensure the confidentiality of User Information and to protect their privacy. It is important to note that for Informational Services, providing PHI is not mandatory, and we recommend refraining from submitting such information while accessing these services.

If you have any inquiries after reviewing this policy, please reach out to our Chief Compliance Officer, whose contact information is provided below.

What Constitutes Personal Information?

Personal Information encompasses any data that identifies an individual. This may include, but is not restricted to, your name, contact details, and information linked to your PHI. This could involve information regarding your family's health history, User identification for healthcare service provision, and your Endor Health username and password.

How Is Personal Information Collected by Endor Health?

We collect Personal Information in compliance with PIPEDA and other relevant legal provisions. Personal Information is gathered for the purpose of registering Users, establishing User accounts ("Account"), verifying login credentials, and customizing the User experience while using the Endor Health Platform.

Endor Health may obtain Personal Information directly from Users or from third parties, provided that we and/or the third party have obtained your consent or as permitted by law.

We collect and use Information only as necessary to deliver our services. This includes the development, evaluation, and enhancement of our services. We only collect Personal Information when non-identifying information is insufficient. We minimize the collection and use of Personal Information to what is necessary for the purposes stated above. For example, we do not record the audio or video aspects of interactions between Users and Authorized Healthcare Practitioners and between Users and Authorized Healthcare Providers on the Endor Health Platform.

How Do We Use User Personal Information?

Endor Health will request consent and utilize Personal Information only as necessary to provide our services, which includes:

- Facilitating, administering, and verifying User eligibility for accessing Endor Health services.

- Providing services on your behalf, such as contacting your pharmacy.

- Facilitating communication with applicable service providers in your jurisdiction with whom we have contractual
relationships, including but not limited to Physicians, Nurse Practitioners, and Pharmacists.

- Monitoring User purchases, arranging refills, and managing prescription renewals.

- For billing purposes, which may encompass private insurance and provincially insured services.

- Customizing the User experience while using the Endor Health Platform, including updates and service notifications.

- Collecting feedback on our operations and enhancing Endor Health services.

- Investigating legal claims.

- Implementing loss prevention, anti-fraud measures, and complying with regulatory and legal requirements.

- Pursuing other lawful purposes for which we may obtain consent.

When and to Whom Is User Personal Information Shared?

Endor Health Inc. employs a range of safeguards to safeguard the privacy of Endor Health Platform Users and the confidentiality of their Information. Situations in which Information may be shared include:

- Transferring Personal Information to service providers such as Physicians, Nurse Practitioners, Pharmacists, telephone support, or data storage and processing providers.

- In the event of an emergency, at the reasonable discretion of Endor Health or a third-party service provider, disclosing information to emergency contacts, public authorities, agents of public authorities, or other parties with whom we have contractual relationships.

- Disclosing Information to an insurer with proper consent.

- Disclosing Personal Information to a potential acquirer in connection with a transaction involving the sale of some or all of Endor Health's business.

When and How Do We Obtain Consent?

Consent is obtained when Personal Information is collected, prior to using or disclosing this information for any purpose. Consent can be provided electronically, in writing, or orally. The type of consent required, whether expressed or implied, depends on the sensitivity of the Information and reasonable User expectations in the given circumstances. We may rely on a third party to obtain your consent for sharing Personal Information with us.

You have the right to revoke your consent at any time by providing written notice to Endor Health, explicitly instructing that your personal health information should not be used or disclosed for healthcare purposes without consent.

Where Do We Store Personal Information?

We store your information electronically within Canada, using computer systems with restricted access, located in facilities equipped with physical security measures. In general, we have established appropriate physical, technological, and organizational safeguards to protect Information against loss, theft, unauthorized access, use, and disclosure.

How Long Will We Use, Disclose, or Retain User Personal Information?

Unless we provide notice to the contrary, we will retain your Information on the Endor Health Platform on your behalf until you or we terminate your User Account. Upon termination of your User Account, we will delete the Information associated with your User Account.

Endor Health will use and disclose your Information for as long as required to fulfill the purposes for which it was collected and as permitted by law.

How Can Users Review Personal Information We Have Collected, Used, or Disclosed or Correct Inaccurate Personal Information?

You can access your Information to ensure its accuracy, completeness, and currency by submitting a request to support@endorhealth.comUsers can update and correct any Information, except for Information viewed or created by an Authorized Healthcare Prescriber or Authorized Healthcare Provider. To correct Information in these cases, make a request to support@endorhealth.com.

To access or request the correction of Information in their notes on the Endor Health Platform or their medical records, Users should contact the Authorized Healthcare Prescriber or Authorized Healthcare Provider who provided Healthcare Services.

How Quickly Will We Respond to User Written Requests?

We will make every effort to respond to each written User request within 30 days of receipt. If we cannot meet your request within this time frame, we will inform you in writing. You have the option to file a complaint with the Privacy Commissioner of Canada or the appropriate provincial privacy governing body.

Is There a Cost for Users to Request Details About Their Personal Information or Our Privacy Practices?

Endor Health will not impose any costs on Users for accessing their Personal Information in our records or for obtaining information about our privacy practices. We will, however, provide Users with an estimate of any appropriate costs, if applicable. Users may be required to provide sufficient information to allow access to the existence, use, or disclosure of their Personal Information. Any identifying information obtained will be used exclusively for this purpose.Do You Verify Users Requesting Their Personal Information?Users may be asked to provide sufficient information to enable access to the existence, use, or disclosure of their Personal Information. Such identifying information will be used solely for this purpose.

Who Is Accountable for My Personal Information?

In most of the provinces where Endor Health operates, we assume overall responsibility for safeguarding the privacy of your Personal Information, including PHI collected in connection with the provision of health services through the Endor Health Platform by healthcare providers such as physicians or nurse practitioners.

What Safeguards Are in Place to Protect User Personal Information?

Endor Health takes the security of your information very seriously. We have implemented measures to protect User Personal Information, including physical, organizational, contractual, and technological safeguards to prevent loss or theft, unauthorized access, disclosure, copying, use, or modification of Information.

Endor Health personnel are bound by our policies, practices, and Applicable Law to protect Information.

Users also play a crucial role in safeguarding their privacy and the confidentiality of their Information. You can do so by following these precautions:

- Create a strong and unique password for your User Account, and update it regularly.

- Do not share your User Account or password with anyone. We will never request your password through unsolicited communications, such as letters, phone calls, or email messages. If you receive such a request, please contact us.

- Log out of your User Account when you are done using it, especially if you share your Device with others.

- Secure your Device with a strong and unique password.

- Choose a quiet and private location for receiving services from Authorized Healthcare Prescribers or Authorized Healthcare Providers.

Despite the safeguards we have in place and our commitment to protecting Information, we cannot guarantee the absolute security or error-free transmission or storage of Information. Electronic means for transmitting and storing Information come with inherent risks, which can be minimized but not entirely eliminated by adopting appropriate security measures, as Endor Health does. These risks include interception, loss, corruption, unauthorized access, use, and disclosure of Information, as well as delays in accessing Information.

Cookies and De-identified Data

Endor Health may collect and utilize data (information that no longer identifies a User) for monitoring compliance with the Endor Health Platform Terms of Use, improving the platform's accessibility, and enhancing the experiences of Users and Authorized Personnel. We may also use or disclose data for product and marketing research, provided it complies with Applicable Law. Data will only be de-identified in a manner that aligns with Applicable Law.

The Endor Health Platform, email messages, and marketing materials employ "cookies" and other technologies, such as pixel tags and web beacons. These technologies help us understand platform usage, analyze trends, and administer, customize, and improve the User and Authorized Personnel experience on the Endor Health Platform.

You can decline cookies by disabling or blocking them in your web browser. Keep in mind that turning off cookies may affect the proper functioning of the Endor Health Platform. Occasionally, we may use third-party entities like ad exchanges and data companies to serve advertisements on the Endor Health Platform. These companies may also utilize cookies and other technologies to report specific information about your visits to the platform and other websites. By using the Endor Health Platform and not disabling cookies, you consent to their use for the purposes outlined in this Policy. To learn more about online advertising and opt-out options, you can visit the Digital Advertising Alliance website at www.aboutads.info/choices/ or the Digital Advertising Alliance of Canada website at www.youradchoices.ca/choices.

It's Your Choice

The Endor Health Platform provides functionality and choices for protecting your privacy, including:- Choosing your preferred mode of communication, whether audio, chat, or video, for interactions with Authorized Healthcare Prescribers or Authorized Healthcare Providers.

- Deciding to withhold Information, understanding that an Authorized Healthcare Prescriber or Authorized Healthcare Provider may be unable to provide Healthcare Services in such cases, with appropriate advisement on the implications of your choice.

- Ensuring that previous Information collected during Informational services will not be accessible to Authorized Healthcare Prescribers or Authorized Healthcare Providers unless you explicitly grant access.

- Selecting your preferred method for receiving communications, whether by email or SMS.

- Opting out of receiving non-essential communications by logging into your User Account and updating your preferences. Please note that service announcements, including updates to our policies and Terms of Use, as well as software updates, are not categorized as non-essential communications.

Contact

For assistance with using the privacy features or if you have questions about the Endor Health Platform, please contact us directly at support@endorhealth.com

At any time, you can contact us to:
- Stop receiving emails or other correspondence from us.
- Seek assistance with viewing and correcting Information.
- Close your User Account.

If you have questions, concerns, or suggestions about our privacy practices, please get in touch with our Chief Compliance Officer.

Don't forget to provide your name and contact information if you wish to receive a response.

Endor Health Inc.
ATTN: Chief Compliance Officer
support@endorhealth.com
1A Fenwick Ave.
Toronto, Ontario
M4K3H2 Canada