top of page

Saguaro Care Privacy Policy

Saguaro Care

Trauma-Care, Resilience, and Workplace-Wellness Companion for Frontline Workers

Initial Effective Date : July 12, 2026

Latest Revised Date : July 12, 2026

Applies to : The Saguaro Care mobile application (iOS / Android), companion web portal, Saguaro Care Org Dashboards, and any related services (collectively, the "Service")

Version: 1.0

1. Plain-Language Summary (Read This First)

 

Saguaro Care exists to help frontline workers — first responders, healthcare staff, military and veteran communities, social workers, child-welfare workers, humanitarian-aid teams, and similar professions — recover from workplace trauma and build long-term resilience. Because the conversations and journal entries you create in Saguaro Care are among the most sensitive content you may ever entrust to a digital tool, we have engineered the Service so that:

  1. Your personal identifiers (name, email, phone number, photos, address, geolocation), all chat content, all journal entries, and all incident-log entries remain on your device in an encrypted on-device vault and are never uploaded to Saguaro Care's servers in identifiable form.

  2. Before any information leaves your phone for any purpose (e.g., crash diagnostics, optional analytics, employer aggregated reporting), an on-device redaction layer removes PII and direct or quasi-identifiers it can detect. This data-minimization-by-default approach reflects PIPEDA's "Limiting Collection" principle and HIPAA-aligned de-identification standards.

  3. Our AI runs locally on your device. Saguaro Care uses an on-device ("edge") AI model so that conversation content is processed without transmission to cloud servers, consistent with the broader industry move to private, edge-AI inference for sensitive health applications.

  4. Your employer never sees individual data. Where Saguaro Care is offered through your employer (a "Sponsoring Organization"), employer dashboards display only de-identified, aggregated, statistically protected indicators — never names, conversations, journals, or content. Aggregation is consistent with the de-identification firewall standard for employer-sponsored wellness programs.

  5. You can reset, export, or delete your data instantly. Because most of your data lives only on your phone, deletion is immediate and complete. Uninstalling the app destroys the on-device vault.

  6. You are an adult (18+). Saguaro Care is not intended for, and will not knowingly serve, anyone under 18.

  7. Crisis escalation requires explicit user action. Saguaro Care will never auto-route any disclosure to your employer, a clinician, a hotline, or emergency services. If a moment in your day requires escalation, you choose whether and whom to contact.

  8. We do not train AI on your content — ever. There is no exception, including for opt-in research cohorts.

 

If you read nothing else, read this: Saguaro Care cannot read your conversations or your journal entries. They are encrypted on your phone with keys Saguaro Care never possesses. We designed the Service this way on purpose — to earn the trust of people who already carry extraordinary professional burdens.

 

2. About Saguaro Care and Contact Details

 

Saguaro Care is the developer and operator of the Saguaro Care Service. Saguaro Care is incorporated in both the United States and Canada, with operating offices in Illinois, United States and Alberta, Canada. The Service is intended for adults (18+) only.

When Saguaro Care determines why and how personal information is processed, Saguaro Care acts as the data controller under Canadian law and the business / data controller under United States state laws. Where Saguaro Care processes information strictly on the instructions of a Sponsoring Organization that is a HIPAA "covered entity" — for example, a hospital, an EMS authority, or a group health plan — and only when expressly contracted to do so under a Business Associate Agreement ("BAA"), Saguaro Care acts as a HIPAA Business Associate as defined in 45 CFR 160.103. Saguaro Care does not act as a Business Associate by default; the BAA is the trigger.

Contact:

  • General privacy questions: info@saguarocare.com 

  • Privacy Officer / Chief Privacy Officer (PIPEDA Principle 1 – Accountability): cpo@saguarocare.com 

  • U.S. HIPAA / Business Associate inquiries: info@saguarocare.com

  • US Address: SAGUARO CARE INC., 519 BELOIT AVE, FOREST PARK, IL  60130, UNITED STATES

  • Canada Address: SAGUARO CARE CANADA LTD., 1718 KEENE CRESCENT SOUTHWEST, EDMONTON, AB, T6W 3W3, CANADA

 

3. Scope, Audience, and Regulatory Anchors

 

This Privacy Policy is designed to align with the following frameworks:

 

3.1 United States

  • The Health Insurance Portability and Accountability Act ("HIPAA") Privacy, Security, and Breach Notification Rules — applicable to Saguaro Care only when Saguaro Care has been contracted as a HIPAA Business Associate of a covered entity through a written BAA.

  • The FTC Health Breach Notification Rule ("HBNR") (16 CFR Part 318), as amended effective July 29, 2024, applicable to Saguaro Care as a "vendor of personal health records" when the Service is offered outside HIPAA. Saguaro Care acknowledges that the FTC has clarified that most health apps that draw identifiable health information from multiple sources are within the HBNR's scope.

  • The FTC Act §5 prohibition on unfair or deceptive practices.

  • The Americans with Disabilities Act ("ADA") and the Genetic Information Non-discrimination Act ("GINA") for employer-sponsored wellness programs.

  • State consumer-privacy and biometric statutes, including the California Consumer Privacy Act/CPRA, Washington My Health My Data Act, Connecticut Data Privacy Act, Illinois Biometric Information Privacy Act (BIPA), and analogous state laws.

 

3.2 Canada

  • The Personal Information Protection and Electronic Documents Act ("PIPEDA") and its 10 Fair Information Principles set out in Schedule 1.

  • Alberta Personal Information Protection Act (Alberta PIPA).

  • British Columbia Personal Information Protection Act (BC PIPA).

  • Quebec Act respecting the protection of personal information in the private sector ("Quebec Law 25"), including its confidentiality-incident regime that requires notice to the Commission d'accès à l'information du Québec ("CAI") and affected individuals where an incident presents a risk of "serious injury."

  • Ontario Personal Health Information Protection Act ("PHIPA") where Saguaro Care acts as an information manager or agent of a health information custodian.

  • Provincial Freedom of Information and Protection of Privacy ("FIPPA"/"FOIPP") regimes — including BC FIPPA, Alberta FOIP, Ontario FIPPA, and equivalent provincial statutes — where a Sponsoring Organization is a public body (e.g., a municipal fire service, a provincial health authority, or a child-welfare agency).

  • The federal Access to Information Act ("ATIA"), R.S.C. 1985, c. A-1, and the federal Privacy Act, where a Sponsoring Organization is a federal institution (e.g., the Royal Canadian Mounted Police, the Canadian Armed Forces, Veterans Affairs Canada, Indigenous Services Canada, or federal correctional services), as further described in Section 16.

 

Age affirmation. Saguaro Care is intended only for users 18+ in the United States and Canada. We do not knowingly create accounts for, or solicit information from, anyone under 18.

 

4. What Information We Collect — and Where It Lives

 

4.1 Information that stays on your device (never sent to Saguaro Care's Cloud in identifiable form)

The following categories are stored in an encrypted on-device vault and are never uploaded to Saguaro Care in a form that identifies you. This data minimization at the point of collection is a direct implementation of PIPEDA's "Limiting Collection" principle.

  • Profile basics you choose to enter: chosen nickname, age range, pronouns, occupation type (e.g., "paramedic," "ER nurse," "child-welfare worker," "active-duty service member"), language preference.

  • Conversation data: every message exchanged with the on-device AI companion, including reflections, feelings, moods, triggers, coping strategies, and any safety-related disclosures.

  • Journals and incident logs: structured and free-text entries you create about specific events, calls, shifts, deployments, or critical incidents.

  • Resilience-tracking data: mood check-ins, sleep self-reports, perceived-stress ratings, completed exercises, breathing-session results.

  • Trust contacts: any phone numbers or names you save for crisis support — these stay only in your local vault.

  • Photos, audio recordings, or attachments you add to journal entries.

 

This on-device-first approach reflects current best practice for edge-AI applications in mental health, where local inference reduces both transmission and processing risk.

 

4.2 Information that may leave your device (only after on-device PII redaction)

The following minimal, non-identifying information may be transmitted to Saguaro Care's servers strictly to operate, secure, and improve the Service:

  • Pseudonymous Device ID: a randomly generated, opaque identifier created on your device the first time you open the app. It cannot be reversed into a name, email, or phone number.

  • Entitlement / license token: if you access Saguaro Care through a Sponsoring Organization, a token confirming a license may be allocated to your device (no employee ID, payroll ID, or HR identifier is transmitted to Saguaro Care).

  • Technical telemetry: crash reports, app version, OS version, device class, locale, time-zone offset. Telemetry payloads pass through our on-device PII-redaction layer before transmission.

  • Optional, consent-based analytics events: see Section 7.

 

4.3 Information shared by Sponsoring Organizations

If your employer sponsors your access to Saguaro Care, the Sponsoring Organization shares with Saguaro Care only the minimum information needed to provision your entitlement — typically a hashed cohort code (e.g., "Station 14, Shift B") and a license count. Sponsoring Organizations do not give Saguaro Care your name, employee number, or direct contact information. This aligns with the de-identification firewall model long-used for employer-sponsored wellness programs.

 

4.4 Information we deliberately do not collect

  • Behavioral-advertising identifiers (e.g., IDFA / GAID for ads).

  • Precise GPS location.

  • Biometric identifiers (e.g., face prints, voice prints, fingerprint templates). Saguaro Care has no current plans to collect biometrics. If a future feature were ever to require biometric processing, we would obtain separate, explicit, written consent and comply with all applicable biometric statutes (including Illinois BIPA, Washington My Health My Data Act biometric provisions, and Quebec's biometric registration framework) before any such feature is activated.

  • Your conversation, journal, or incident-log content — for any purpose, including AI model training. There are no exceptions, including for research. See Section 12 and Section 17.

 

5. How the "On-Device, Zero-Knowledge" Architecture Works

 

Saguaro Care uses a zero-knowledge architecture: the cryptographic keys that protect your on-device vault are derived and held only on your device, so Saguaro Care's infrastructure has no technical ability to read your content — by design, not by promise.

The edge-AI model that powers conversations runs locally on modern iOS and Android devices. This architectural pattern is consistent with the growing body of edge-AI research showing that on-device inference materially reduces both privacy and transmission risk for sensitive applications.

End-to-end encryption protects any communication between your device and Saguaro Care's servers (TLS 1.3 in transit, plus an additional application-layer envelope for telemetry payloads). The on-device vault uses authenticated encryption (AES-256-GCM) with keys held only in your device's hardware-backed keystore (Secure Enclave / Android Keystore).

 

6. How We Use Information — and the Legal Bases We Rely On

 

We use the limited categories of information described in Section 4 for the purposes shown below. For Canadian users, we identify the PIPEDA legal basis consistent with the 10 Fair Information Principles. For U.S. users, we identify the corresponding consumer-privacy or HIPAA basis where applicable.

 

​

 

PIPEDA's 10 Fair Information Principles — Accountability, Identifying Purposes, Consent, Limiting Collection, Limiting Use/Disclosure/Retention, Accuracy, Safeguards, Openness, Individual Access, and Challenging Compliance — are operationalized throughout this Policy. PIPEDA also requires that processing purposes be ones a "reasonable person would consider appropriate." Saguaro Care commits never to use frontline-worker data for any purpose inconsistent with that standard, and never for surveillance of, or adverse action against, individual workers.

 

7. Analytics: Privacy-Preserving by Default, Standard Only by Consent

 

Saguaro Care distinguishes between two strictly separated tiers of analytics:

  • Tier 1 — Privacy-preserving analytics (always on): Counts and aggregates are computed on your device and then combined with cohort data using differential-privacy techniques before being transmitted. No raw event is ever exported.

  • Tier 2 — Standard product analytics (opt-in only): With your explicit, granular consent, Saguaro Care collects redacted feature-usage events to improve the Service. Consent is collected on first launch and can be reviewed or withdrawn at any time from in-app Settings → Privacy → Analytics.

 

Saguaro Care does not use your data to train AI models — its own or any third party's — and we do not share your data with advertisers or data brokers.

 

8. Employer-Sponsored Access and Org Dashboards

 

Where your employer is a Sponsoring Organization, Saguaro Care provides an Org Dashboard that supports workforce-wellness decision-making without compromising individual privacy:

  1. No individual user content, identifier, or interaction is ever shown to a Sponsoring Organization. The Sponsoring Organization sees only aggregated, statistically protected metrics such as adoption rate, average resilience indicators, and aggregate exercise utilization at the cohort level.

  2. Minimum cohort thresholds prevent small-group re-identification. Metrics for any cohort with fewer than 25 active users are suppressed in the dashboard.

  3. Differential privacy and k-anonymity are applied before any metric is displayed.

  4. HIPAA-aligned plan-sponsor separation. Where Saguaro Care is offered through a Sponsoring Organization's group health plan and Saguaro Care has been contracted as a HIPAA Business Associate, Saguaro Care will sign a written Business Associate Agreement consistent with 45 CFR 164.504(e) / 164.314(a), and the plan sponsor's access to protected health information ("PHI") will be limited to plan-administration functions consistent with 45 CFR 164.504(f). Saguaro Care's dashboards display de-identified data only, supporting the required separation between plan administration and employment functions.

  5. ADA / GINA-aligned standalone programs. Where the Service is offered directly by an employer outside a group health plan, Saguaro Care's de-identification and aggregation safeguards support ADA confidentiality requirements and GINA limits on genetic information.

  6. Voluntariness. Participation through a Sponsoring Organization is always voluntary. You may decline, withdraw, or use Saguaro Care privately at any time without any employment-related consequence imposed by Saguaro Care.

  7. Sponsoring Organization Agreement. Every Sponsoring Organization signs a Data Processing & Confidentiality Agreement obligating them not to attempt to re-identify users, not to compel disclosure of individual usage, and not to use Saguaro Care data for employment-related decisions (e.g., hiring, promotion, discipline, fitness-for-duty determinations).

 

9. Sharing of Information

 

Saguaro Care does not sell, rent, or trade personal information.

 

9.1 Sub-processors

Saguaro Care uses a small, audited set of sub-processors (e.g., cloud infrastructure for non-PII telemetry, crash-reporting providers, and push-notification delivery). A current sub-processor list is published and maintained at https://www.saguarocare.com/sub-processors, including each sub-processor's name, function, processing location, and any cross-border safeguards. All sub-processors are contractually bound to confidentiality, encryption, and PIPEDA/HIPAA-compatible obligations.

 

9.2 Sponsoring Organizations

Saguaro Care shares with Sponsoring Organizations only the aggregated, de-identified metrics described in Section 8.

 

9.3 Legal compliance and safety

Saguaro Care will disclose information where required by valid legal process or where we have a good-faith belief that disclosure is necessary to prevent imminent serious harm. Because Saguaro Care cannot read your conversations or journals, our ability to respond to legal process is structurally limited to the small amount of pseudonymous metadata we hold.

 

9.4 Business reorganization

In the unlikely event of a merger, acquisition, or asset transfer, the same privacy commitments will follow your data, and we will notify you in-app or via the Sponsoring Organization.

Saguaro Care will never disclose individual user data to a Sponsoring Organization, insurer, recruiter, court, or government body without either (a) your explicit, informed, in-app authorization or (b) a binding legal order — and even then, only the limited non-content metadata we hold.

 

10. Security Safeguards

 

PIPEDA Principle 7 requires safeguards proportionate to the sensitivity of the information. Trauma-related information is among the most sensitive personal information a user can entrust to a digital tool. Saguaro Care implements:

  • Administrative safeguards: least-privilege access, mandatory background checks for staff with production access, role-based access control with audit logging, annual privacy/security training, a documented incident-response runbook, and a documented Privacy Management Program under the Privacy Officer.

  • Physical safeguards: SOC 2-aligned data-center hosting; locked, monitored facilities; hardware destruction logs for decommissioned media.

  • Technical safeguards: AES-256-GCM on-device encryption; hardware-backed keystores; TLS 1.3 in transit; certificate pinning; mandatory MFA on staff access; quarterly key-rotation review; SAST/DAST in CI/CD; annual third-party penetration test and code review; a published vulnerability-disclosure program.

  • Resilience and continuity: documented backup and recovery procedures for the minimal non-PII metadata we hold; tabletop incident exercises at least annually.

 

Where Saguaro Care is contracted as a HIPAA Business Associate, Saguaro Care additionally complies with the HIPAA Security Rule's administrative, physical, and technical safeguards (45 CFR §§ 164.308, 164.310, 164.312).

 

11. Data Retention and Deletion

 

  • On-device data is retained on your device for as long as you use the app. You may delete it at any time using Settings → Privacy → Reset My Data or by uninstalling the app. Once deleted, on-device data is unrecoverable.

  • Pseudonymous server-side metadata (e.g., entitlement token, opaque device ID, crash records) is retained for as long as your entitlement is active and for up to 24 months thereafter for service-integrity and audit purposes, after which it is automatically purged.

  • Optional analytics events (Tier 2) are retained for up to 13 months unless you withdraw consent earlier, in which case they are deleted within 30 days.

  • Aggregated, differentially private metrics used in employer dashboards are not tied to any individual and are retained for trend reporting under the Sponsoring Organization's contract.

  • Legal-hold exception: retention periods may be extended only where required by valid legal process.

 

This implements PIPEDA Principle 5 (Limiting Use, Disclosure, and Retention).

 

12. Responsible AI for Trauma Care

 

Saguaro Care's AI is purpose-built for trauma support and resilience-building — not a substitute for licensed clinical care. The AI follows clinician-reviewed conversational pathways, has built-in safety guardrails, and is monitored by Saguaro Care's clinical advisory team. Important commitments:

  • You are interacting with software, not a person. The AI does not replace a licensed mental-health professional.

  • No identity inference. The AI is configured not to attempt to infer your identity from your messages.

  • Local processing. The trauma-care AI runs on your device. Your conversation content is not sent to Saguaro Care or to any third-party model provider for inference.

  • No training on your content — absolute and exceptionless. Saguaro Care will not use your conversation content, journals, or incident logs to train any AI model, including for research purposes. There is no opt-in path that authorizes such training. Research participation (Section 17) is strictly limited to separately consented, structured outcomes data that does not include raw conversation, journal, or incident-log content.

  • Crisis routing — If the AI detects content suggesting risk to life, it will display in-app safety recommendations. Saguaro Care will not auto-route any disclosure to your employer, a clinician, a hotline, or emergency services. Whether to reach out to a person, an organization, or a public emergency service is always your decision. The user is responsible for their own safety. 

 

13. Your Privacy Rights

 

You may exercise the following rights at any time. Because most of your data lives only on your device, many of these rights can be exercised instantly from within the app.

 

​

 

These rights operationalize PIPEDA Principles 3 (Consent), 9 (Individual Access), and 10 (Challenging Compliance).

Quebec residents also have explicit Law 25 rights including the right to data portability, the right to information about automated decision-making, and the right to cessation of dissemination — all exercisable through the same channels above.

HIPAA-covered users (U.S.): Where Saguaro Care processes PHI under a BAA, you also retain the right of access to and amendment of your PHI under 45 CFR §§ 164.524 and 164.526, exercisable through your Sponsoring Organization's HIPAA Privacy Officer.

 

14. Breach Notification

 

In the event of a security incident affecting any non-trivial server-side metadata, Saguaro Care will:

  • Notify affected individuals without unreasonable delay and in no case later than 60 calendar days from discovery, consistent with the FTC HBNR (16 CFR Part 318) and the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414).

  • Where Saguaro Care is a "vendor of personal health records" under the FTC HBNR (i.e., Saguaro Care is not acting as a HIPAA Business Associate), report breaches of unsecured PHR identifiable health information to the FTC; notify the FTC as soon as possible and no later than 10 business days after discovery for incidents affecting 500 or more individuals, and provide notice to prominent media outlets serving the affected jurisdiction in those cases.

  • Where Saguaro Care is acting as a HIPAA Business Associate, notify the covered entity in accordance with the BAA and applicable HIPAA Breach Notification Rule timing.

  • Under PIPEDA, notify the Office of the Privacy Commissioner of Canada ("OPC") and affected individuals of any "breach of security safeguards" that creates a "real risk of significant harm," and maintain breach records for at least 24 months.

  • Under Quebec Law 25, notify the Commission d'accès à l'information du Québec ("CAI") and affected individuals of any confidentiality incident posing a risk of "serious injury," and maintain an incident register.

  • Provide notice that is clear, conspicuous, and reasonably understandable, identifying the categories of data involved, the steps users can take, and contact information for follow-up.

 

Because conversation and journal content never leaves your device, the practical blast radius of any server-side incident is structurally limited to non-content metadata — by architectural design.

 

15. Cross-Border Data Considerations

 

Saguaro Care's primary data-processing infrastructure is regionally segmented based on each user's permanent location:

  • U.S. users: non-PII metadata is processed in U.S.-region infrastructure.

  • Canadian users: non-PII metadata is processed in Canadian-region infrastructure.

This data residency model addresses cross-border considerations under Quebec Law 25 and BC PIPA, both of which require organizations to assess and document the privacy implications of any out-of-province transfer. Because PII and content never leave your device, the cross-border footprint of the Service is structurally minimized. For the limited non-PII metadata processed in Saguaro Care's cloud, contractual safeguards (data-processing agreements; standard contractual clauses where relevant) apply.

Saguaro Care will provide users with the name of the country in which their data is stored and processed, and the contact information for any out-of-jurisdiction recipients of their non-PII metadata, in accordance with PIPEDA's "Openness" principle.

 

16. Public-Sector Sponsoring Organizations: FIPPA/FOIPP and the federal Access to Information Act

 

Many frontline organizations are public bodies and are therefore subject to public-sector access and privacy laws.

 

16.1 Provincial public bodies — FIPPA / FOIPP

Where the Sponsoring Organization is a provincial or municipal public body (e.g., a municipal police service, a provincial health authority, a child-welfare agency, a school board), the relevant Freedom of Information and Protection of Privacy Act ("FIPPA"/"FOIPP") applies — including BC FIPPA, Alberta FOIP, Ontario FIPPA, and equivalents in other provinces. In those engagements:

  • Saguaro Care's contract with the Sponsoring Organization includes terms aligning processing with the FIPPA/FOIPP standards applicable to that organization.

  • Saguaro Care will not respond directly to FIPPA/FOIPP access requests for individual user content because Saguaro Care does not hold it. Such requests must be directed to the Sponsoring Organization and will be limited to records that organization itself holds.

  • Aggregated, de-identified dashboard metrics may be disclosed under FIPPA/FOIPP access regimes when the Sponsoring Organization receives a valid request, because they are not personal information.

 

16.2 Federal institutions — Access to Information Act (ATIA) and federal Privacy Act

Where the Sponsoring Organization is a federal institution — e.g., the Royal Canadian Mounted Police, the Canadian Armed Forces, Veterans Affairs Canada, Correctional Service of Canada, Indigenous Services Canada, or other federal departments — the Access to Information Act ("ATIA"), R.S.C. 1985, c. A-1, governs public access to records under the institution's control, and the federal Privacy Act governs the institution's handling of personal information.

In those engagements:

  • Saguaro Care's contract with the federal institution includes terms aligning Saguaro Care's processing with the institution's obligations under the ATIA and the Privacy Act, including record-control determinations and the institution's right to inspect compliance.

  • Because the records of user conversations, journals, and incident logs are not held by Saguaro Care (they reside on the user's device), Saguaro Care will not respond directly to ATIA requests for those records. ATIA requests should be directed to the federal institution; Saguaro Care will assist the institution's Access to Information and Privacy ("ATIP") office to the extent required by contract.

  • Aggregated, de-identified Org Dashboard metrics may be records under the control of the federal institution and subject to ATIA disclosure analysis by the institution's ATIP office.

  • The institution's heads of access and privacy retain final authority over ATIA exemptions (e.g., third-party information, security, personal information) applied to any record.

 

16.3 General principle

In every public-sector engagement, Saguaro Care positions itself as a technology service provider whose architecture preserves individual confidentiality — the user's content is not in Saguaro Care's hands to disclose. Public-sector transparency obligations attach to the public body and to the limited aggregated information that body holds.

 

17. Children and Adults-Only Confirmation

 

Saguaro Care is intended only for users 18 years of age or older in the United States and Canada. We do not knowingly collect personal information from minors. If we discover that an account has been created by or for a person under 18, we will: (i) prevent further use; (ii) delete on-device account-bootstrap data; and (iii) purge any associated pseudonymous server-side metadata.

 

18. Localization and Accessibility (Roadmap)

 

This Privacy Policy is currently published in English (United States). Saguaro Care recognizes that:

  • Quebec Law 25 strongly favors French-language privacy notices for Quebec residents,

  • Many frontline workforces in both Canada and the United States include first-language French and Spanish speakers, and

  • Accessibility under provincial human-rights and accessibility statutes is a continuing obligation.

 

Accordingly, French (Canadian) and Spanish (U.S.) translations of this Privacy Policy are planned as a future capability extension. Until those translations are published, French-speaking and Spanish-speaking users may contact info@saguarocare.com to request a written summary of any provision in the language of their choice.

 

19. Updates to This Privacy Policy

 

We may revise this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be announced in-app and, where required, communicated through your Sponsoring Organization at least 30 days before they take effect. The current version, version number, and effective date are always available at https://www.saguarocare.com/privacy-policy. Prior versions will be archived and accessible for transparency.

 

20. Contact, Complaints, and Regulator Information

 

  • Saguaro Care Privacy Officer / Chief Privacy Officer: cpo@saguarocare.com (PIPEDA Principle 1 – Accountability)

  • U.S. HIPAA / Compliance: cpo@saguarocare.com

  • General privacy questions: cpo@saguarocare.com

  • Subprocessor list: https://www.saguarocare.com/sub-processors

  • Canadian regulators: Office of the Privacy Commissioner of Canada (priv.gc.ca); Office of the Information and Privacy Commissioner of Alberta; Office of the Information and Privacy Commissioner for British Columbia; Commission d'accès à l'information du Québec (CAI); Information and Privacy Commissioner of Ontario (IPC).

  • U.S. regulators: Federal Trade Commission (ftc.gov); U.S. Department of Health and Human Services, Office for Civil Rights (HIPAA matters); relevant state Attorneys General (state consumer-privacy and biometric matters).

  • Federal Canada (for ATIA / Privacy Act matters involving a federal-institution Sponsoring Organization): the institution's ATIP Office; the Office of the Information Commissioner of Canada (oic-ci.gc.ca); the Office of the Privacy Commissioner of Canada.

 

You are not required to contact Saguaro Care before contacting a regulator. We do, however, welcome the opportunity to address your concern first.

 

Changes Log (Quick Reference)

 

For traceability against clarifications, the following substantive changes were made in this version:

  1. HIPAA Business Associate positioning sharpened: Saguaro Care is a BA only when expressly contracted under a written BAA (Sections 2, 8, 10).

  2. FTC HBNR positioning added as the primary U.S. health-breach regime when HIPAA does not apply, including 10-business-day FTC notice for 500+ user incidents and media-notice requirement (Sections 3, 14).

  3. Canadian provincial laws named explicitly: Alberta PIPA, BC PIPA, Quebec Law 25, and Ontario PHIPA (Section 3).

  4. Federal ATIA framework added in a new sub-section under Section 16 covering federal-institution Sponsoring Organizations (Section 16.2).

  5. ≥25-user minimum cohort threshold confirmed as the dashboard suppression rule (Section 8).

  6. Cross-border / data residency clarified: U.S. user data in U.S. regions; Canadian user data in Canadian regions, based on permanent location (Section 15).

  7. Crisis-escalation model explicitly stated as opt-in / no auto-routing (Sections 1, 12).

  8. AI training prohibition strengthened with an absolute "no exceptions,(Sections 7, 12).

  9. Future localization addressed as a roadmap commitment rather than a current capability (Section 18).

  10. Biometric features explicitly disclaimed and gated behind a future-consent requirement (Section 4.4).

bottom of page