Legal
For clinics that need a formal processor agreement covering the patient data Auremwell handles on their behalf.
Last updated: July 2026
When you use Auremwell to handle patient calls and bookings, your clinic acts as the data controller and Auremwell acts as the data processor, processing personal information only on your documented instructions.
Auremwell processes call audio, transcripts, and patient-provided booking details solely to answer calls, schedule appointments, send missed-call text-backs, and display activity in your dashboard — nothing beyond what's needed to deliver the service you've configured.
Anyone with access to patient data through Auremwell is bound by confidentiality obligations, whether they're a member of our team or a subprocessor described below.
We use a small number of infrastructure subprocessors (telephony, hosting, and calendar providers) to deliver the service. We'll notify you before adding a new subprocessor that will handle your patients' data, so you can raise objections.
Patient data is encrypted in transit and at rest, access is restricted to what's operationally necessary, and we maintain the ability to detect and respond to security incidents.
If we become aware of a breach affecting your patients' data, we'll notify you without undue delay so you can meet your own notification obligations under PIPEDA, Loi 25, or other applicable law.
Where a patient exercises an access, correction, or deletion right directly with Auremwell, we'll route the request to your clinic and assist you in responding to it.
When your Auremwell account is closed, we'll return or delete patient data processed on your behalf, except where retention is required by law.
We'll provide reasonable information to demonstrate compliance with this agreement and support audits requested by regulators with jurisdiction over your clinic.
To get a countersigned DPA on file for your clinic, reach out through our contact page or email hello@auremwell.ca and we'll send one over.