Effective date: August 31, 2026
Last updated August 31, 2026
Draft note. This is a compliance-informed first draft. Under processing, not final.
1. Who this policy covers, and two different roles
Tasrif Health (legal designation & jurisdiction pending incorporation), operating as Tasrif (“Tasrif,” “we,” “us”), provides AI-assisted clinical documentation software to healthcare practitioners and clinics (“practitioners,” “you,” “clinics“). In the course of providing the service, Tasrif also processes information about practitioners’ patients (“Patient Data”).
This policy describes two distinct relationships, and it matters which one applies to you:
- If you are a practitioner or clinic staff member with a Tasrif account, Tasrif is the organization responsible for your account information (name, email, billing details, login activity), and this policy describes our practices as the party that decides how that information is used.
- If you are a patient whose encounter was recorded or documented using Tasrif, your healthcare provider — not Tasrif — is the trustee/custodian responsible for your health information under Manitoba’s Personal Health Information Act (“PHIA”) and, where applicable, other provincial or federal law. Tasrif acts as an information manager/service provider processing your health information on your provider’s behalf and instructions, under a written agreement with them. Questions about how your specific health information is used should go to your healthcare provider first; this policy explains the technical and organizational safeguards Tasrif applies as their service provider.
Tasrif designates a privacy officer accountable for compliance with this policy and applicable privacy law. Reach them via the contact details in Section 11—this is also where an access, correction, or complaint request should go in the first instance.
Counsel note. Confirm this trustee/information-manager characterization against PHIA’s actual definitions and structure the Practitioner-facing Terms of Service and any separate Data Processing/Information Manager Agreement to match—the precise legal relationship affects who is directly liable for a breach and who must issue breach notifications.
Practice note. Manitoba has a large First Nations, Inuit, and Métis population, and CPSM’s own guidance on AI in practice flags Indigenous data sovereignty (OCAP®—ownership, control, access, possession) as a live consideration when deploying an AI documentation tool. That governance sits primarily between a clinic and the communities/patients it serves, not something Tasrif can unilaterally commit to as a vendor—but a clinic serving First Nations patients or communities under a data-governance agreement should confirm this policy and its own practices are consistent with that agreement before adopting Tasrif.
2. Information we collect
Account and billing information (Practitioners/Clinics): name, email address, phone number, professional role, clinic affiliation, billing contact, and payment card details (processed by our payment processor—see Section 6), and authentication data (password hash, multi-factor authentication enrollment status—never the underlying MFA secret or recovery codes in plain form). Tasrif itself never stores your full card number—that’s held only by our payment processor.
Patient Data, processed on behalf of your clinic:
- Encounter audio, captured live during a consultation. Live microphone audio is streamed directly from your browser to Amazon Transcribe Medical over an encrypted connection and is never stored by Tasrif’s own servers. Audio uploaded for one-time transcription is held only transiently—encrypted at rest—for the duration of the transcription job, then deleted immediately after the job completes or fails.
- Transcripts, AI-generated clinical notes and summaries, and any corrections a practitioner makes to them.
- Patient identifying information a practitioner enters: name, date of birth, and contact details.
- Consent status: whether, when, and by what method a practitioner recorded that patient consent was obtained (Tasrif provides the tool to record this; obtaining valid consent from the patient is the practitioner’s and clinic’s responsibility, not something Tasrif does directly).
Technical and usage information: IP address, browser/device type, log data, and session and audit-trail records (who accessed or changed what, and when—see Section 7).
We do not knowingly collect more patient data than a practitioner chooses to enter or record through ordinary use of the service.
Accuracy. Tasrif does not independently verify or alter patient data a practitioner enters or an AI-generated note produces—keeping that information accurate and up-to-date is the practitioner’s and clinic’s responsibility, consistent with their own professional record-keeping obligations. Tasrif’s audit trail (Section 7) preserves a record of every correction made, including AI-generated content a practitioner has edited.
3. How we use information
| Purpose | Applies to |
|---|---|
| Providing the Service—transcription, AI note generation, storage, and retrieval of clinical documentation | Patient Data |
| Account administration, authentication, and security (including audit logging and fraud/abuse prevention) | Both |
| Customer support | Both |
| Billing and payment processing | Account/billing information |
| Legal compliance, responding to lawful requests | Both |
| Improving the Service (aggregated, de-identified usage patterns only) | Technical/usage information |
We do not use patient data to train AI models. Note generation is performed by Amazon Bedrock; under AWS’s standard service terms, customer content submitted to Bedrock is not used to train the underlying foundation models and is not shared with third-party model providers.
Ops note. Confirm your specific AWS account’s Bedrock model-invocation-logging configuration before finalizing this sentence—the commitment is accurate to AWS’s public terms, but your account’s own logging settings should be verified rather than assumed.
We do not sell patient data or practitioner personal information, and we do not use either for third-party advertising.
4. Lawful basis for processing Patient Data
Practitioners select the lawful basis under which they process a given patient’s information, consistent with applicable Canadian privacy and health-information law:
- Consent (the default)—the patient has agreed to the processing. Tasrif’s platform tracks consent status (pending, given, or withdrawn) and—as of this policy’s drafting—blocks starting a new recording against a patient marked “pending” consent under this basis.
- Contract, legal obligation, vital interest, public task, or legitimate interest—the remaining bases recognized where consent is not the operative basis for a given patient’s care relationship.
Where consent is the basis and a patient withdraws it, the practitioner records the withdrawal in Tasrif; going forward, that status is reflected in the platform.
5. Where is your information stored, and for how long?
Location. Tasrif’s infrastructure—database, file storage, encryption key management, transcription, and AI note generation—runs in Amazon Web Services’ Canada (Central) region. We do not operate infrastructure in the EU, UK, or elsewhere.
Ops note. This statement should only be published once every AWS service in use—including KMS and any object storage—is confirmed configured to the Canada region in production, not just the transcription/AI services; this was flagged as an open verification item internally.
Retention. Patient data is retained for as long as your clinic’s account is active, unless your clinic has configured a specific automatic retention period for its organization (available as an administrative setting; not automatically enabled). Where no retention period is configured, Tasrif does not automatically delete Patient Data—this reflects the reality that clinical records are often required to be kept for a minimum period under professional/regulatory rules, and it is the Clinic’s responsibility, not Tasrif’s, to configure a retention period consistent with those rules once one applies.
Erasure. A clinic may request that a specific patient’s record be erased. Tasrif fulfills this by anonymizing the patient’s record and all associated encounters, notes, and consultation transcripts—replacing identifying content while preserving the clinical record’s structure and the audit trail of what happened—rather than deleting rows outright, so nothing else your clinic depends on (billing history, other patients’ shared records) is disrupted.
Account information. Retained for the duration of your relationship with Tasrif, plus a limited period afterward as needed for legal, tax, and dispute-resolution purposes.
6. Who we share information with
We share information only as follows:
- With the practitioners and clinic staff, your clinic is authorized to access a given patient’s record, per your clinic’s own access controls.
- With our sub-processors, who process information on our behalf under contract, solely to provide the service:
- Amazon Web Services (AWS)—infrastructure, database hosting, encryption key management (AWS KMS), object storage, Amazon Transcribe Medical (speech-to-text), and Amazon Bedrock (AI note generation). All in AWS’s Canada (Central) region.
- Payment processor — name to be inserted once selected — for monthly card billing (see Terms of Service, Section 5). We never store your full card number ourselves.
- Transactional email provider — name to be inserted — for account verification, password reset, and notification emails.
- When legally required—to comply with a valid legal process (court order, subpoena, or regulatory demand), or to protect the rights, property, or safety of Tasrif, our users, or others, consistent with applicable law.
Recommendation. Publish and maintain a current sub-processor list at tasrif.app/subprocessors—a specific, verifiable commitment Canadian healthcare buyers look for.
We do not sell patient data or practitioner personal information to anyone.
7. Security measures
- Sensitive fields—patient name, date of birth, contact details, transcripts, and clinical notes—are encrypted at rest using AES-256-GCM, with per-record encryption keys wrapped by AWS Key Management Service (envelope encryption).
- All data in transit is encrypted (TLS).
- Multi-factor authentication is required for every account.
- Access is role-based, scoped to a practitioner’s clinic and permissions.
- Every view, edit, and export of a patient record, encounter, or consultation is logged with who, what, and when and is available for your clinic’s own review.
- Passwords are hashed (bcrypt) and never stored or transmitted in plain form; repeated failed login attempts trigger a temporary account lock.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting patient data, we will notify the affected clinic without undue delay, with enough detail for the clinic to meet its own obligations as trustee under PHIA—including, where PHIA requires it, notifying affected patients and the Manitoba Ombudsman. Where Tasrif itself is directly responsible for a notification to a regulator or individual under applicable law (for example, regarding Practitioner account data we hold as the accountable party), we will make that notification ourselves.
8. Your rights
If you are a practitioner, you may access, correct, or request deletion of your own account information by contacting us (Section 11) or through your account settings.
If you are a patient, rights regarding your health information are generally exercised through your healthcare provider, who is the trustee/custodian of that information. Depending on applicable law, you may generally:
- Request access to your personal health information;
- Request correction of inaccurate information;
- Withdraw consent to future processing (this does not affect the lawfulness of processing already carried out and may affect your provider’s ability to continue certain care-related documentation);
- Complain to the applicable regulator—in Manitoba, the Manitoba Ombudsman; federally, the Office of the Privacy Commissioner of Canada.
You may also raise a concern about how Tasrif itself has handled information directly with our Privacy Officer (Section 11) before or instead of escalating to a regulator. We will investigate and respond within a reasonable time.
9. Children and minors
Where a practitioner’s patient is a minor, consent and authorization to process that minor’s health information is obtained by the practitioner/clinic from the minor’s parent, guardian, or the minor themselves where they are legally capable of consenting to their own care, consistent with applicable provincial law. Tasrif does not independently verify age or consent capacity—this responsibility sits with the clinic providing care.
10. International data transfers
We do not currently transfer patient data outside Canada. If this changes—for example, as part of a future U.S. market expansion—we will update this policy in advance and put appropriate safeguards in place before any such transfer occurs.
11. Contact us.
Tasrif Health—legal designation (Inc./Ltd./Corp.) & jurisdiction to be confirmed on incorporation
Registered business address—to be inserted
Privacy Officer / privacy inquiries and data subject requests: support@tasrif.app
Recommend a dedicated privacy@tasrif.app address (and a named individual, not just a title) once volume warrants it, distinct from general support—PIPEDA’s accountability principle expects a real accountable person, not just an inbox.
12. Changes to this policy
We will post any changes to this policy here and update the “Last updated” date above. Material changes affecting how patient data is handled will be communicated to clinics in advance.