Our commitment
ByteSuite operates a PIPEDA-aligned privacy program for clinics in British Columbia, Québec, and Ontario. We apply the applicable provincial privacy requirements alongside PIPEDA where it applies. Broader Canadian availability is coming soon. This policy is not a certification, and it does not replace the clinic’s own legal duties or patient notice.
01 · Scope and roles
Who this policy covers.
“ByteSuite,” “we,” “us,” and “our” mean the ByteSuite service and the people operating it. This policy applies to our public website, clinic software, support, synchronization, and related services.
For patient records a clinic enters, imports, or manages in ByteSuite, the clinic ordinarily determines the purposes and means of care and record-keeping. ByteSuite provides the software and related services under the clinic’s instructions and applicable agreements. The clinic remains responsible for its own patient notice, consent or other lawful authority, clinical-record duties, and response to patient requests.
For information collected directly through this website or in a ByteSuite business relationship, ByteSuite may act as the organization responsible for that information.
02 · Information and purposes
What we may handle.
Depending on the services a clinic enables, ByteSuite may handle patient and clinic information such as identity and contact details, appointment and treatment information, insurance and claim information, payment and ledger information, communications, imported records, and information generated through use of the service. We may also handle clinic-user account, device, security, support, and configuration information.
We use information to provide, secure, maintain, troubleshoot, improve, and support ByteSuite; to carry out clinic-authorized workflows; to meet legal and contractual obligations; to prevent fraud, misuse, and unauthorized access; and to communicate about the service. Optional functions, including certain AI, transcription, communication, and integration features, may involve additional information handling. Their availability and use remain subject to the clinic’s configuration, instructions, and applicable law.
Website visitors may provide contact information when they email us or complete the Request Access form. That form collects a name, email address, clinic name, city, and details about the visitor’s current software and priorities. We use it to respond to the request and communicate about ByteSuite, and we store it in our service infrastructure. Our hosting and security providers may also receive limited technical information, such as IP address, device and browser information, request timing, and security logs, to deliver and protect the website.
03 · Event history and records
A durable record of supported change.
ByteSuite is local-first. The clinic’s encrypted local database is the operational source of truth for clinic work. Where cloud synchronization is enabled, ByteSuite may transmit and retain selected clinic events and associated data in durable service infrastructure.
We retain this event history to preserve the integrity of supported workflows, enable authorized synchronization and reconciliation, investigate errors or security incidents, maintain an audit trail, and reproduce supported service state when necessary. This retention may continue after an event is changed, superseded, or removed from a current view where retaining the history is necessary for those purposes, required by law, or subject to a legal hold.
Event history is not a promise of a complete backup, complete clinic reconstruction, or the ability to recreate every aspect of a clinic’s records. We do not represent that cloud event history alone can reproduce the full clinic state, including records or files that are outside the supported synchronization scope.
04 · Safeguards and service providers
Protection proportionate to sensitivity.
We use administrative, technical, and organizational safeguards appropriate to the sensitivity of the information and the service involved. These measures include access controls, authentication, clinic and device boundaries, security monitoring, and encryption for the production clinic database. No method of storage or transmission is perfectly secure, and no safeguard can eliminate every risk.
We may use carefully selected service providers to host, operate, secure, or support parts of ByteSuite and enabled features. Those providers may process information in Canada or in other jurisdictions, depending on the service configuration. Information processed outside a person’s province or Canada may be subject to the laws of that jurisdiction, including lawful-access requirements. We require service providers to protect information in a manner consistent with their role and applicable obligations.
We do not sell personal information. We do not use patient information for unrelated advertising.
05 · Your choices and requests
Access does not always mean deletion.
Individuals may have rights to request access to, correction of, or information about personal information, and to raise a privacy concern. A patient should normally begin with the clinic that holds the patient relationship and clinical record. ByteSuite will assist clinics as required by applicable agreements and law.
Requests to delete information are assessed in context. We may need to retain information, including clinical records, event history, audit records, security evidence, or information subject to a legal hold, where necessary for service integrity or to meet legal, regulatory, contractual, or records-management obligations. When deletion is not available, we will explain the applicable limitation where appropriate.
We may need to verify identity, authority, and the scope of a request before acting. We will handle requests in accordance with applicable law and any applicable clinic agreement.
06 · Changes and contact
Questions belong with people.
We may update this policy when our services, legal obligations, or privacy practices change. We will post the revised policy here and change the effective date. Where a change is material, we will provide additional notice where required.
For a privacy question, concern, or request about ByteSuite, contact us at info@bytesuite.co with “Privacy enquiry” in the subject line. Please do not include detailed patient information in an unencrypted email. We will direct the request to the appropriate privacy contact and respond through an appropriate channel.