Who we are

AdessaCare is a software product operated by Zhirov Enterprises Inc., a corporation incorporated in Ontario, Canada ([registered office address]). AdessaCare is used by home-care and personal-support-worker (“PSW”) agencies — currently one agency, in Ottawa, Ontario — to schedule visits, record what happened during a visit, and generate service records (proof-of-hours documents) for funders.

Questions about this policy: contact@adessacare.com.

The most important thing to understand: whose data this is, and who is accountable for it

This policy describes two different roles, because they matter for who you should ask if you have a concern:

If you are a client, family member, contractor, or contact of an agency that uses AdessaCare, your relationship is with that agency, and the agency’s own intake process, terms, and privacy communications govern what it collects from you and why. This policy explains what AdessaCare, the software, does with information the agency puts into it.

Whose personal information this policy covers

Personal information passes through AdessaCare about several different kinds of people, most of whom have never signed up for anything or created an account:

None of these people are AdessaCare’s customers. The agency is our customer; these are the people whose information the agency’s customer relationship with us touches.

The website

adessacare.com collects nothing. It is a static informational site: no account creation, no forms that submit data anywhere, no cookies, and no analytics or tracking scripts. If you email us at contact@adessacare.com, we receive whatever you choose to write in that email, the same as any email — nothing more.

Everything below this point describes the AdessaCare product, used by agency staff and contractors, not the marketing website.

How this policy is organized

We have organized this policy around PIPEDA’s ten fair information principles, published by the Office of the Privacy Commissioner of Canada, so that each is separately addressed and any gap is visible rather than buried in prose.

1. Accountability

Each agency using AdessaCare is accountable for the personal information under its control. Zhirov Enterprises Inc. is accountable, as a service provider, for the safeguards and instructions described in this policy and in our service-provider agreement with each agency (a separate signed document — see below). We have identified a person responsible for privacy questions, reachable at contact@adessacare.com.

2. Identifying purposes

Personal information is collected and used for one purpose: operating the agency’s home-care business — scheduling visits, recording that visits happened (and what happened during them, at a level the agency’s own funder documentation requires), generating funder-facing service records, and (where a client or their substitute decision-maker has designated a confirmation contact at intake) confirming with that contact that a scheduled visit occurred.

We do not use this information for advertising, do not sell it, and do not use it to build products for anyone other than the agency whose data it is.

3. Consent

Consent for client and contact information rides on the agency’s own existing client-intake process — AdessaCare does not run a separate consent flow of its own. This follows the Office of the Privacy Commissioner’s guidance on meaningful consent: the agency, at the point it takes on a new client, is the party positioned to explain in plain language what will be collected, why, who will see it (including that it is processed using AdessaCare’s software), and to obtain the client’s (or their substitute decision-maker’s) agreement. We recommend, and are not able to independently confirm, that each agency’s intake process names: (a) that a software provider processes the client’s information on the agency’s behalf, including outside Canada in some cases (see “Where information is processed,” below); and (b) — for the confirmation-message feature described below, if and when an agency turns it on — the specific fact that a designated contact will receive a message asking whether a scheduled visit occurred.

Contractors consent to AdessaCare’s processing of their information as part of their engagement agreement with the agency.

4. Limiting collection

We collect only what the agency’s scheduling, verification, and service-record functions require. Two things are deliberately not collected in the current version of the product: precise GPS location of a visit (verification is a location-free check-in/check-out action) and any assessment of a client’s medical condition, diagnosis, or capacity — the product has no field for either, by design.

5. Limiting use, disclosure, and retention

Information is used only for the purposes identified above. It is disclosed to a third party only: (a) to the sub-processors named below, who process it on our instructions, under contract, strictly to provide the service; (b) to the specific confirmation contact a client or their substitute decision-maker designated at intake, for the purpose already named to them; or (c) where required by law.

On retention: we do not commit to a fixed deletion timeline in this draft, because no automated deletion mechanism exists in the product yet — publishing a deletion promise we cannot yet perform would be worse than describing our actual, current practice. Our actual practice: personal information is retained for as long as the agency’s business relationship with its client or contractor continues, and, once a service record or its supporting entries are created, for at least as long as applicable legal retention obligations require (for example, financial and tax records are commonly subject to a six-year retention expectation under the Income Tax Act). Some tables in our database (audit and correction records, and visit records) carry a field reserved for a future retention-expiry date, so that when an automated retention/archival process is built, it can be applied without a structural change — that field is not yet populated or acted upon.

6. Accuracy

Visit records are entered by the contractor who performed the visit and reviewed by the agency. AdessaCare’s database design never overwrites a recorded figure — if a figure needs correcting, a new correction entry is added alongside the original, so both the original entry and every correction remain visible, each with who made it and why. This means the system’s own audit trail is, by design, more accurate over time, not simply “corrected in place” with the original lost. Once a service record has been approved by the agency owner, its contents are locked and cannot be altered — a later change requires a new, separately-approved record.

7. Safeguards

8. Openness

This policy is published at adessacare.com/privacy and describes our practices in plain language. We will state clearly here (and update the “Last updated” date) if our practices change materially.

9. Individual access

If you are an agency’s client, contractor, family contact, or staff member and want to know what personal information about you AdessaCare holds, or want to request a correction, please contact the agency directly — as the accountable organization, the agency is best placed to locate, verify, and act on your request, and is required to do so under PIPEDA. If you contact us directly at contact@adessacare.com, we will direct your request to the relevant agency and can confirm to you that we have done so.

10. Challenging compliance

If you believe an agency, or AdessaCare as its service provider, has not handled personal information in line with this policy, you may raise it with the agency first, or contact us at contact@adessacare.com. You may also contact the Office of the Privacy Commissioner of Canada (and, where PHIPA applies to a specific agency, the Information and Privacy Commissioner of Ontario) if you believe your concern has not been resolved.

Sub-processors — who else touches this data, and where

We use a small number of specialist service providers to run AdessaCare. We do not add a new one without updating this list.

Sub-processorWhat it doesWhere
Supabase Our application database — where agency, client, contractor, and visit data is stored. Canada (ca-central-1 / Montréal region)
Anthropic Provides AI assistance used inside the product to help draft narrative text on service records (for example, turning a contractor’s shorthand note into a complete sentence for review before it is finalized). This feature is planned and is not yet active in the product. When it is enabled: Anthropic is contractually barred from using this data to train its models, and retains API inputs/outputs only for a limited default period (30 days), not indefinitely. United States
Resend, via Amazon Simple Email Service (SES) Delivers transactional email on our behalf — for example, one-time account-access links for agency owners, and (when an agency turns the feature on) confirmation messages to a client’s designated contact. The confirmation-message feature ships turned off by default for every agency until that agency’s own intake language names it, per this policy’s consent section above. United States (Amazon SES, us-east-1 region)
Cloudflare Hosts our website and product, and provides domain-name service, from Cloudflare’s global network, which includes locations both inside and outside Canada. Global (includes locations outside Canada)

Cross-border processing. Some personal information is processed outside Canada by the sub-processors above. Neither PIPEDA nor PHIPA requires that personal information be stored only in Canada — but Canadian law requires (and we follow) an accountability standard: we remain responsible for personal information we send to a sub-processor, wherever located, and we use contracts and other means to require that sub-processor to protect it comparably. Information processed outside Canada is, while there, subject to the laws of that jurisdiction, including lawful access by that jurisdiction’s authorities — this is a general legal reality of cross-border processing, not something specific to how we’ve configured our systems.

Changes to this policy

We may update this policy to reflect changes in our practices or in applicable law. The “Last updated” date above shows when it was most recently revised. Material changes will be described in plain language at the top of the policy for a reasonable period after the change.

Contact

Zhirov Enterprises Inc. (operating AdessaCare)
[registered office address]
contact@adessacare.com