Data Processing Agreement
Data Processing Agreement
Rivet Practitioner Data Processing & PHIPA Agent Agreement
Effective: July 5, 2026
Version: 3.0
Between: Rivet Systems Inc. ("Rivet"), Belle River, Ontario
And: the subscribing health practitioner ("you" / "the Custodian")
PURPOSE AND ROLES
1.1 You are a health information custodian under Ontario's Personal Health Information Protection Act (PHIPA), or the equivalent role under the health-privacy law of your province.
1.2 In providing the Rivet service, Rivet acts as your agent and as a provider of electronic services that enable you to use electronic means to collect, use, retain, and dispose of personal health information ("PHI"). Rivet is not a health information custodian and does not provide health care.
1.3 This Agreement authorizes Rivet to handle PHI on your behalf and sets out the conditions of that authorization, so that you meet your obligations toward agents under PHIPA section 17 and Ontario Regulation 329/04 section 6(3).
DEFINITIONS
"PHI" means personal health information as defined by PHIPA section 4, and equivalent personal or health information under other applicable law.
"Client Information" means PHI and other personal information of your clients that Rivet handles through the service.
"Privacy Breach" means the theft, loss, or unauthorized use, disclosure, copying, modification, or disposal of Client Information.
RIVET'S OBLIGATIONS
3.1 Rivet will use Client Information only to provide and support the service to you, and only as you direct or as required by law. Rivet will not use Client Information for its own purposes, will not disclose it except as set out here or as legally required, and will never use it for marketing.
3.2 Rivet will limit handling to what is reasonably necessary to provide the service (data minimization).
3.3 Rivet maintains safeguards appropriate to the sensitivity of the information:
(a) Canadian-resident storage — all Client Information at rest lives on Canadian infrastructure (Supabase database hosted in ca-central-1, Cloudflare R2 object storage in a Canadian-jurisdiction bucket). Transient request processing on Cloudflare's global edge network is bounded by short TTLs and carries no Client Information at rest.
(b) Encryption in transit and at rest — TLS for every network hop; AES-256 platform encryption on stored records; WebRTC DTLS-SRTP for video and audio sessions.
(c) On-premises AI processing — voicemail transcription (Whisper) and intent classification (Ollama) run on Canadian hardware. Client audio and transcripts are never transmitted to any third-party AI service.
(d) Access controls — Rivet staff access to Client Information is restricted to a need-to-know basis with audit logging on every access event.
(e) Append-only audit log — significant access events and state changes write to an immutable audit log retained for compliance evidence.
(f) Daily encrypted backups — operator-controlled, encrypted at rest, used for disaster recovery and not for any other purpose.
(g) Retention limits and secure disposal — per section 3.6 below.
3.4 Rivet will never record or transmit session content to any third-party AI service. This commitment covers every modality the service supports:
(a) Video sessions are not recorded, transcribed, or transmitted to any third-party AI service.
(b) Voice calls and voicemail audio are not transmitted to any third-party AI service. Voicemail transcription runs on Rivet's Canadian hardware.
(c) EMDR bilateral-stimulation sessions carry no audio or video capture beyond what the session modality itself requires; the BLS rendering happens client-side and produces no recorded artifact.
(d) Whiteboard content (drawings, annotations, persisted per-client history) stays within the Canadian-resident database; whiteboard content is never sent to any third-party AI service.
(e) Clinical assessment templates (PHQ-9, GAD-7, EMDR-specific scales, clinician-administered measures, and all other published instruments available in the service), together with completed assessment responses (item-by-item answers and derived scores), are stored as structured Client Information in the Canadian-resident database and are never sent to any third-party AI service.
(f) Progress note clinical content — DAP/SOAP note bodies, sign/lock state, and append-only addenda — is stored in the Canadian-resident database and is never transmitted to any third-party AI service.
(g) Client record data — date of birth, emergency contact, referral source, consent log, and derived risk level — is stored in the Canadian-resident database and is never transmitted to any third-party AI service.
(h) AI notes auto-fill, where supported, runs on Rivet's Canadian hardware using local models. No session content is transmitted to any third-party AI service for note generation.
(i) SMS and conversation content is stored in the Canadian-resident database and is never sent to any third-party AI service.
3.5 Rivet will notify you of a Privacy Breach within 72 hours of becoming aware of the breach, with the information you need to meet your own notification duties to affected individuals and to the Information and Privacy Commissioner. Where 72 hours is not practicable (for example, when investigation is ongoing and the facts are incomplete), Rivet will provide an initial notification within the 72-hour window stating what is known and what is still being investigated, and will follow up as facts develop.
3.6 Rivet will retain and dispose of Client Information on the following schedule:
(a) Voicemail recordings (the audio file held by the telephony provider) — deleted from the telephony provider after 30 days.
(b) Voicemail PII in the Rivet database (caller phone number, caller name, voicemail transcripts, free-form intake fields) — nulled after 90 days.
(c) SMS message bodies in the Rivet database — replaced with [purged] after 90 days. Corresponding SMS records held by the telephony provider are also deleted at the 90-day mark.
(d) Call records (the call-log metadata held by the telephony provider) — deleted at the 90-day mark.
(e) Conversation metadata (the existence of a conversation, the participating phone number, last-activity timestamp) — retained indefinitely while you remain a subscriber; deleted in accordance with section 7.2 on termination.
(f) Clinical records (progress notes and note content — DAP/SOAP free-text body, sign/lock state, and append-only addenda; completed assessment responses — item-by-item answers and scores; derived risk level — calculated from completed C-SSRS intent/behaviour items and PHQ-9 item 9; and client record identity fields — date of birth, emergency contact, referral source, and consent log) — retained by Rivet for the duration of the practitioner's active account so the practitioner can access and export them. The practitioner is the custodian and directs retention and deletion. The practitioner's professional College record-retention requirement — commonly at least 10 years from the date of the last clinical interaction with a client (or, for a client who was a minor at the time of service, 10 years after the client reaches the age of majority; for example, in Ontario, CPLCO standards and requirements under the Regulated Health Professions Act, with analogous obligations in other provinces) — is the Custodian's obligation, to be met through the Custodian's own system of record after export from Rivet. Rivet does not retain clinical records for 10 years; Rivet's retention ends with the active account and the 90-day wind-down on termination (section 7.2). The 30-day and 90-day purge cycles applicable to voicemail recordings, voicemail PII, SMS message bodies, and call records do not apply to clinical records while the account is active.
(g) Audit log — retained indefinitely as compliance evidence.
On termination of service, Client Information is returned or securely deleted per section 7.2; clinical records are subject to the additional wind-down procedure in section 7.2.
3.7 On your request, Rivet will provide a plain-language description of the service and its safeguards, and reasonable information to help you respond to a client's access or correction request.
3.8 Rivet will flow these obligations down to its sub-processors and remains responsible for their handling of Client Information.
3.9 Service scope. As of the effective date of this Agreement, the "service" comprises the following components, each of which is governed by the obligations in this section 3:
(a) A dedicated Canadian practice phone line (voice and SMS) provisioned for your account.
(b) Voicemail capture, on-premises transcription, and intent classification.
(c) Automated SMS auto-responses based on classified voicemail intent, under your configured auto-reply policy.
(d) Two-way SMS messaging with a conversation-first inbox.
(e) Video sessions (no recording) accessed via your getrivet.ca/your-name waiting-room URL.
(f) EMDR bilateral-stimulation tools rendered within the video session.
(g) A whiteboard surface synchronized between practitioner and client during a session, with optional per-client persistence.
(h) Clinical assessment templates (PHQ-9, GAD-7, EMDR-specific scales, clinician-administered measures, and other published instruments).
(i) AI-assisted notes auto-fill, where available, running on Rivet's Canadian hardware.
(j) Progress notes (DAP/SOAP format) created within or after a session, with a sign-and-lock workflow and an append-only addendum trail for corrections. Note bodies are stored in the Canadian-resident database and are never transmitted to any third-party AI service.
(k) A client record comprising an identity rail (date of birth, emergency contact, referral source, and consent log) and a derived risk level (calculated from completed C-SSRS and PHQ-9 instrument responses; values: none, elevated, or high), displayed as a risk indicator on the client record. Encrypted in transit and subject to AES-256 platform encryption at rest; stored in the Canadian-resident database only.
(l) A structured per-client clinical export ("Copy for Jane" plain text, per-note PDF, and a full date-ranged export) that assembles progress note content, assessment question-and-answer responses, and scores from source data for handoff to the practitioner's system of record. Available regardless of Rivet-sign state; export documents are labelled to distinguish signed notes from unsigned drafts.
(m) Native iOS and Android applications that present the practice phone line, the inbox, and the session surface on mobile devices.
(n) Push notifications via Apple Push Notification service, Firebase Cloud Messaging, and web push, with payloads scoped to the minimum information needed to surface the alert.
This list is descriptive of the current scope and is updated by version when the scope materially changes.
SUB-PROCESSORS
4.1 Rivet uses the following sub-processors to deliver the service:
Supabase — database storage (Postgres and Auth) — Canada (ca-central-1).
Cloudflare (R2) — object storage for greeting audio — Canada.
Cloudflare (Workers, KV, Durable Objects) — application hosting, video signaling, transient session state — global edge network (no Client Information at rest; transit and short-TTL caches only).
Twilio — telephony (voice and SMS) and recording capture; recordings deleted at 30 days, SMS bodies and call records deleted at 90 days per section 3.6 — United States.
Metered.ca — WebRTC TURN relay for video sessions when a direct peer connection isn't possible (cannot decrypt session media) — Canada.
Stripe — payment processing for subscription billing (no PHI sent) — United States and Canada.
Resend — transactional email delivery (magic-link sign-in, system notifications); message bodies contain no PHI — United States.
Apple Push Notification service — iOS push delivery; payloads minimized to alert subject lines — United States.
Google Firebase Cloud Messaging — Android push delivery; payloads minimized to alert subject lines — United States.
Expo / EAS — mobile application build and over-the-air update delivery — United States.
Persistent Client Information at rest is stored on Canadian infrastructure (Supabase ca-central-1 and Cloudflare R2 Canada-jurisdiction bucket). Sub-processors outside Canada either (a) deliver in-transit services that do not retain Client Information beyond the operational minimum (telephony, push, email), or (b) receive only non-PHI inputs (Stripe receives billing identifiers, not Client Information).
4.2 Rivet will keep the sub-processor list current and will give notice of a new sub-processor that handles Client Information before it begins doing so. Material changes to this list trigger a new version of this Agreement and re-acceptance per the change procedure documented at acceptance time.
YOUR OBLIGATIONS
5.1 You hold the authority, and have obtained and will maintain the consents, required to collect, use, and disclose Client Information and to authorize Rivet to handle it on your behalf.
5.2 You configure your auto-reply messages and account so that the service is used lawfully and within professional and College standards.
5.3 You promptly handle client access, correction, and consent-withdrawal requests as the custodian, with Rivet's reasonable assistance.
5.4 You acknowledge that acceptance of this Agreement is captured electronically through the Rivet service at sign-up or at re-acceptance, with timestamp, IP address, the practitioner-identifying account email, and the SHA-256 hash of the Agreement text at the time of acceptance. Electronic acceptance satisfies the written-agreement requirement of PHIPA section 10(2) per Ontario's Electronic Commerce Act, 2000 section 11.
BREACH COOPERATION
On a Privacy Breach, Rivet and you will cooperate in good faith on investigation, containment, and notification. As custodian, you are responsible for any notification to affected individuals and to the Commissioner; Rivet will provide the facts and assistance you reasonably need within the timing committed in section 3.5.
TERM AND TERMINATION
7.1 This Agreement runs while you subscribe to Rivet.
7.2 On termination, Rivet will, at your option and within 30 days, return or securely delete Client Information, except where law requires retention (for example, billing records under CRA rules, or audit-log evidence retained for compliance purposes).
For clinical records (progress notes, assessment responses, risk assessments, and client record identity fields), the following wind-down procedure applies: Rivet will make all clinical records available for export in a structured format on or before the termination date. Clinical records will be deleted on your written instruction, or at the end of a 90-day wind-down period from the date of termination, whichever occurs first. This period exists to allow you to export records and transfer them to your system of record before deletion. You remain responsible, as custodian, for ensuring clinical records are retained in accordance with your College requirements following export from the Rivet service.
GENERAL
8.1 Liability — Each party's aggregate liability arising out of or related to this Agreement is limited to the fees paid by you to Rivet in the twelve (12) months preceding the event giving rise to the claim. This cap does not apply to liability arising from a party's gross negligence or wilful misconduct, or from breach of confidentiality or privacy obligations relating to Client Information.
8.2 Governing law — Ontario and the laws of Canada applicable there.
8.3 Order of precedence — If this Agreement conflicts with Rivet's Terms of Service, this Agreement governs for matters of PHI and privacy.
ACCEPTANCE
By checking the acceptance box, entering your name, and continuing to use the Rivet service, you agree to this Agreement as the practitioner identified by the account email on file. Your acceptance is recorded electronically with timestamp, IP address, and the version of this Agreement, satisfying the written-agreement requirement of PHIPA section 10(2) per Ontario's Electronic Commerce Act, 2000 section 11.