Updated December 9, 2024
Coral Health Inc. (“Coral”, “we”, “us”, “our”) is a digital health platform that provides members (“you”) with access to preventative health services and support to help navigate the hormonal and metabolic changes they may experience (“Services”). Coral’s members may access the Services through Coral Health Inc. secure applications for web and mobile devices located at coralhealth.app (the “App”), the Coral Health Inc. website located at coral.ca (the “Website”, with the App our “Platform”).
Our Platform is accessible on mobile devices or on our website. When we refer to our Platform in this Privacy Policy (“Policy”), we are referring to both the app you use on your phone or tablet or via a browser at coralhealth.app (“App”) and our website located at coral.ca (“Website”).
This Policy describes how and for which purposes we may collect, use and disclose your Personal Information, including Personal Health Information, when providing our Services to you or when you otherwise interact with us. It explains the safeguards we implement to keep your Personal Information secure, as well as your rights and choices when it comes to protecting your privacy.
In using our Platform or our Services or otherwise communicating with us, you consent to our collection, use, disclosure and storage of your Personal Information, including Personal Health Information, in accordance with the terms of this Policy.
For this reason, it is very important that you carefully review this Policy before using our Services or our Platform. If you do not agree with the terms of the Policy, we ask that you do not use our Services or Platform.
For the purposes of this Policy, “Personal Information” means information about an identifiable individual or as otherwise defined under applicable privacy laws, including information regulated under applicable health privacy laws (“Personal Health Information”).
Personal Information does not include information that no longer allows the identification of an individual, for instance because it was aggregated with other information or anonymized (“Non-identifying Information”) nor business contact information.
While Coral takes all reasonable measures to ensure that Personal Information collected through its Platform is adequately protected, the person or entity who is ultimately accountable for ensuring that Personal Information, including Personal Health Information, is collected, used and/or disclosed in compliance with applicable privacy legislation varies across provinces and jurisdictions.
In some provinces, Coral has the ultimate responsibility for protecting your Personal Information, including your Personal Health Information, collected through your use of our Services or otherwise, through your interactions with us. In other provinces, health care providers are considered the primary custodians of the Personal Health Information collected in connection with the delivery of health care services, which may include the Services provided through the Platform. In such cases, Coral supports them with that responsibility.
Should you have any questions about the structure of accountability governing your Personal Information or Personal Health Information, or this Policy more generally, you may contact our Privacy Officer at privacy-officer@coralhealth.ca.
Coral collects Personal Information from you when you request our Services, engage with our professionals or collaborators, register on or otherwise access our Website or Platform, respond to a survey or communication such as e-mail, or participate in another Platform feature.
The following information is generally collected through our direct interactions with you or through third parties, where you authorize us to at various points of your journey:
Whenever possible, we will collect Personal Information that concerns you directly from you. In certain circumstances, however, it may be appropriate or necessary for us to collect Personal Information from authorized third parties, including:
We may also collect the following information in an automated way when you access and use our Platform:
The technologies we use for this automated collection may include:
See below the member information collected by Coral.
User Information | Purpose for Collection |
First name, last name | Your legal first name and last name are collected during the creation of your Coral account. Coral collects and uses your name to personalize your account and customer support, to contact you via phone, SMS and in emails, and to confirm your identity. |
Physical address | Your address is collected during your registration with Coral. It is used to confirm your eligibility to use Coral’s services as a location is needed to ensure that you are in a province that can utilize Coral services and to match you with a healthcare practitioner licensed in your region. It is also used in case emergency services need to be sent to your location. |
Your email is collected during the creation of your Coral account. Your email is stored and used as your login to the Coral platform. We use your email address as the main point of contact for communication of Coral services, including sending you information about our services, and to provide customer support. Non-essential communication may also be delivered via email, including internal marketing such as Coral newsletters and notifications about new products and services. You may opt-out of any non-essential communications at any time. | |
Phone number | Your phone number is collected during the creation of your Coral account. Your phone number is used to receive communication from Coral via phone call and SMS. We may use your phone number to send you information about your treatments and to provide customer support. Your healthcare practitioner may use your phone number to call you if they believe you could be experiencing a medical emergency. Non-essential communication may also be provided via SMS, including internal marketing. You may opt-out of any non-essential communications at any time. |
Date of birth | Your Date of Birth is collected to ensure you are of the eligible age to use the Coral platform and services, and as a means of identity verification. |
Payment information | Your payment information is collected and used to complete purchases through the Coral platform. This may include information such as your name, credit card number, credit card expiry date and billing address. Coral employs a variety of technical, physical and administrative security measures intended to safeguard the data in the company’s possession. Your payment information is processed through Stripe, our integrated payment service provider. More details about Stripe and their security measures can be found here. |
User Information | Purpose of Collection |
Personal information, including: Legal first and last name, Email address, Phone number, Emergency contact number, Physical address, Billing address, Credit card information, Province of residence | Provide you with healthcare services Personalize plan recommendations, the platform experience, and communications Collected and stored on behalf of healthcare practitioners, in accordance with the healthcare practitioner’s provincial healthcare regulations Ensure prescriptions or plans provided to Members are safe and appropriate. |
Health information, including: Weight, Height, Biological sex, Gender identity, Allergies, Medications, Medical condition(s), Past surgeries/ hospitalizations, Medical questionnaire answers | Provide you with healthcare services Personalize plan recommendations, the platform experience, and communications Collected and stored on behalf of healthcare practitioners, in accordance with the healthcare practitioner’s provincial healthcare regulations Ensure prescriptions or plans provided to Members are safe and appropriate. |
Prescription information, including: Prescription(s) name(s), Dose of drug, Drug form, Drug dispensing information, Refill information, Symptoms | Coral healthcare practitioners may issue prescriptions to members. As such, Prescription Information is used to ensure the continued safe and appropriate use of the medication prescribed. |
Health record contents | This is a record that includes the healthcare practitioner and care specialist’s internal notes, messages with the patient, dates the patient received service, and prescription information. This record is the information needed to document your treatment plan with Coral, and is recorded in accordance with the healthcare practitioner’s provincial healthcare regulations. |
Lab results | Lab Results are collected in accordance with healthcare practitioner’s provincial health regulations. Lab results will be uploaded on the Coral EMR and App to facilitate healthcare services, and to determine the appropriateness of the treatment plan and prescription determined by a licensed healthcare practitioner. |
Customer support record | This is a record that includes notes and any other interactions, such as email or phone, that you may have had with a Coral Customer Support team member. This is collected to provide a personalized customer experience to you. |
User Information | Purpose for Collection |
Platform/App browsing history | A user’s browsing history on the Coral app is used to support and enhance app functionality. This helps us understand how you use our services, and how we can improve our products and the platform experience for users. |
Platform purchase history / Platform interaction history | Platform Purchase History and Platform Interaction History is tracked and used to support and enhance app functionality. This helps us personalize product suggestions for the users and personalize Coral marketing to the individual user. It also helps us understand how you use our services, and how we can improve our products and the platform experience for users. |
Device ID | Your Device ID is collected, stored and used for security purposes, such as monitoring for malicious activity and ensuring secure account login. |
IP address | We process your IP address to determine your rough location to ensure that you are in a province that can access the Coral platform services. A user IP address is also collected for security reasons in order to monitor for malicious activity. |
Crash data | Coral collects, stores and uses crash data to help monitor and improve app functionality, and enhance user experience. |
Performance data | Coral collects, stores and uses performance data to help monitor and improve app functionality, and enhance user experience. |
We may use your Personal Information for the following purposes:
We will not disclose your Personal Information for any purpose except as outlined in this Policy or as permitted or required under applicable law, unless we obtain your consent. No Personal Information including mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. As such, we may communicate information, to the extent necessary to achieve the stated purpose to the following parties:
Your Personal Health Information is stored in your medical record which is accessible to health care providers, employees, agents and contractors and through virtual care technologies. Personal information (which may include Personal Health Information) we collect to provide you with wellness services is not stored in your medical record.
While we conduct best efforts to maintain your Personal Information, including your Personal Health Information locally, we do collaborate with vendors and partners who may access, store or otherwise process Personal Information in other Canadian provinces, in limited cases, and the United States. The laws applicable to the protection of Personal Information in such countries may be different from those applicable in your home country or province and may permit or require disclosure of your Personal Information to law enforcement or national security authorities.
To ensure adequate protection of Personal Information upon such transfers, Coral has implemented policies and guidelines to perform vendor privacy and security assessments prior to such transfers. We also use technical and contractual safeguards to protect the information we transfer and limit its transfer when it is necessary for the purposes sought.
The security of your Personal Information is very important to us. We use physical, technical, and administrative safeguards designed to secure your Personal Information from accidental loss and from unauthorized access, use, alteration, and disclosure. Such measures include:
We do our best to make sure that any information you give to us during virtual care visits is private and secure, however, as with all online communications, there is a risk that your health information may be intercepted or unintentionally disclosed. To help mitigate the risk, you should be in a private setting and should not use an employer’s or someone else’s computer/device.
You are also required to keep your username and password secure and not share it with anyone else. We will never ask you for your password in any unsolicited communication (such as letters, phone calls or email messages).
Coral retains Personal Information, including Personal Health Information, only for as long as necessary to fulfill the purposes for which the information was originally collected, unless further retention is required for legitimate legal, regulatory or organizational purposes. Some of your Personal Information, including Personal Health Information cannot be disposed of before a period determined by statutory retention requirements. Information contained in your medical record is currently stored for 10 years from the date of last entry, in accordance with applicable laws.
When Personal Information, including Personal Health Information, is no longer required to be retained, Coral will securely dispose or anonymize the information in compliance with relevant legal, regulatory and contractual requirements.
Depending on the jurisdiction in which you are located, you may have the following rights with respect to your Personal Information. Please note, the list below is a general list of individual privacy rights, and not all are applicable to Coral:
We may request specific information from you to help us confirm your identity when you exercise these rights. In certain cases, we may be authorized or required by law or professional regulation to refuse to provide you with access to, correct or delete some or all of the Personal Information that we hold about you, or we may have destroyed, erased, or made your Personal Information anonymous in accordance with our record retention obligations and practices. If we cannot provide you with access to your Personal Information, we will inform you of the reasons why, subject to any legal or regulatory restrictions.
If you wish to exercise any of the aforementioned rights, please contact us at support@coral.ca and will attempt to provide a response to you within thirty (30) days of receiving your request.
We cannot control the processing of any of your information when you access and use third party links, external applications or websites. Please note that our Platform may include links to third party websites, plug-ins, services, social networks, or applications. Clicking on those links or enabling those connections may allow the third party to collect or share data about you. If you follow a link to a third party website or engage a third party website, app or plugin, please note that these third parties have their own privacy policies and we do not accept any responsibility or liability for these policies. We do not control these third party websites, applications or vendors, and we encourage you to read the privacy policy applicable to those sites and services.
Our Platform is not intended for children under 14 years of age. If you are under 14, do not use or provide any information about yourself on this Platform.
We do not knowingly collect Personal Information from children under 14 unless we have obtained parental consent. If we learn we have collected or received Personal Information from a child under 14 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 14, please contact us at support@coral.ca.
If we make material changes to how we Process your Personal Information, we will notify you by email and on the App.. For all other changes, we include the date the Policy was last revised at the top of the page. You are responsible for ensuring we have an up-to-date, active, and deliverable email address for you, and for periodically visiting our Platform and this Policy to check for any changes.
Note that your continued use of our Services and Platform after a disclosed change to this Policy will be considered as an acceptance of the amended terms of the Policy.
You have the right to make a complaint, at any time, to the relevant supervisory authority, privacy regulator, or commissioner.
For Canadian privacy commissioner contact details see the below list:
We welcome your questions, comments, and requests regarding this Policy and our privacy practices. Please contact our Privacy Officer by email at privacy-officer@coral.ca or:
Coral Health Inc.
C/O Privacy Officer
1172 Sherbrooke St West, Montreal, QC, H3A 1H6
We have procedures in place to receive and respond to complaints or inquiries about our handling of personal information, our compliance with this Policy, and with applicable laws. To discuss our compliance with this Policy please contact us at support@coral.ca.