Prepared by: NTL Learning Solution Inc. (“NTL”), operator of TCM CRM

Last updated: August 31, 2026

1. Purpose and scope

This Privacy Impact Assessment (PIA) assesses the privacy risks of TCM CRM, a clinic-management application built for Traditional Chinese Medicine (TCM) and acupuncture practitioners, initially serving clinics in British Columbia. It covers:

  • The TCM CRM clinic application (clinical charting, patient records, payments, consent capture, voice dictation).
  • The tcmcrm.ca marketing site (lead capture only — demo requests, free-trial signups).
  • The vendor command center (NTL’s internal tenant-management console).

It does not separately assess third-party platforms (Supabase, Cloudflare, Square, Groq) beyond describing NTL’s due-diligence basis for relying on them as sub-processors/infrastructure providers.

  • British Columbia’s Personal Information Protection Act (PIPA) — the governing private-sector privacy statute for BC clinics using the Service. CCHPBC’s own Professional Standard: Record-Keeping explicitly defers to PIPA for security and breach-notification obligations (§2.2, §2.3, §2.9).
  • CCHPBC Professional Standard: Record-Keeping (in effect April 1, 2026) — governs what BC TCM/acupuncture licensees must document, retain, and secure.
  • Health Professions and Occupations Act (HPOA) and the Complementary Health Professionals Regulation (B.C. Reg. 130/2025) — the current regulatory framework for CCHPBC and its licensees.
  • PIPEDA may apply to NTL directly for cross-provincial or federally-regulated activity; PIPA is treated as substantially similar legislation for BC-based commercial activity.

Not yet assessed: privacy statutes of other provinces. This PIA will be supplemented before onboarding clinics outside BC.

3. Data flows and roles

TCM CRM’s architecture is a dedicated-instance model, not a shared multi-tenant database: each clinic’s Service instance runs on its own Supabase (database) and Cloudflare (hosting) accounts, which the clinic — not NTL — owns. NTL provisions this infrastructure on the clinic’s behalf during onboarding and hands over the credentials.

This has a material privacy consequence worth stating plainly: after onboarding, NTL does not have standing access to a clinic’s live patient data. NTL’s relationship is closer to a systems integrator / software vendor than a classic SaaS processor holding client data on its own infrastructure. NTL regains access only if a clinic explicitly grants it (for example, for support), which is logged and time-boxed.

Data Controller Processor / infrastructure holder Where it lives
Marketing site leads (demo requests, trial signups) NTL NTL (via NTL’s own Supabase project) NTL’s tcmcrm-marketing Supabase project (Canadian region)
Patient/clinical/payment records The clinic The clinic (own Supabase project, provisioned by NTL) Clinic’s own Supabase project, Canadian region by default
Voice dictation audio The clinic Groq (transient, sub-processor) Not persisted — see Section 4
Card payments The clinic Square (sub-processor) Square’s own systems; TCM CRM stores the resulting payment record, not card data

4. Personal information collected, by category

Per CCHPBC’s Record-Keeping Standard §1.2 (which defines the minimum a licensee must document — TCM CRM’s structured charting schema was built to satisfy this):

  • Patient identifying information: full name, sex/gender, date of birth, contact information, emergency contact.
  • Clinical data: medical history, allergies, medications, risk factors, current health conditions, clinical assessments, working diagnoses (including TCM pattern differentiation), treatment plans and treatment provided (including acupuncture points used), response to treatment, follow-up recommendations.
  • Appointment/visit dates and a daily appointment log.
  • Billing records and receipts: patient name, date, service, fees, practitioner name/licence number.
  • Consent records: informed consent captured before initial treatment, consistent with CCHPBC’s Professional Standard: Informed Consent, which explicitly permits electronic consent.
  • Referring-practitioner information and inter-practitioner communications.
  • Voice dictation audio: captured client-side, sent to Groq’s hosted Whisper API for transcription, and not retained after transcription — no audio is written to any database or storage bucket. Only the resulting text becomes part of the patient record.

5. Retention

CCHPBC’s Record-Keeping Standard sets the controlling retention period for BC licensees: patient health care records, appointment logs, billing records, and receipts must be retained for a minimum of 16 years from either the date of the last entry, or from the patient’s age of majority, whichever is later.

Product implication: TCM CRM does not silently delete patient records, and any future self-service export/delete feature will not allow deletion of records still inside this retention window without an explicit, documented override consistent with the clinic’s own obligations.

6. Sub-processors and third parties

Sub-processor Role Data touched Notes
Supabase Database, auth, and edge functions All clinical/patient data (in the clinic’s own project) Region selectable at provisioning; Canadian region by default for BC clinics
Cloudflare Static hosting, CDN, DNS No patient data at rest — serves the compiled application only
Square Point-of-sale card payment processing Card payment amounts/status; card numbers never touch TCM CRM’s own systems Square is PCI-DSS compliant as a payment processor in its own right
Groq Voice-to-text transcription Transient audio only, not retained See Section 4

7. Risks identified and how they’re managed

  1. Onboarding credential handling. During setup, NTL may temporarily hold or generate account credentials on a clinic’s behalf. NTL’s standard procedure: credentials are handed over immediately on completion, no copies are retained, and clinics are prompted to rotate any password or token NTL set up on their behalf.
  2. Sub-processor data residency. Every BC clinic’s database project defaults to a Canadian region at provisioning time.
  3. Post-onboarding support access. Any support access to a clinic’s live instance is clinic-initiated, logged, and time-boxed rather than standing access — formalized in NTL’s Data Processing Agreement.
  4. Breach notification. NTL maintains a breach-response procedure (detection, containment, risk assessment, notification to the affected clinic and, where required under PIPA, the BC Privacy Commissioner) since NTL is the technical operator during an incident even though the clinic is the legal data controller.
  5. Multi-province expansion. This PIA is BC-specific and will be reassessed — not simply relabelled — before onboarding clinics in any other province, since provincial privacy statutes and health-college recordkeeping rules are not uniform across Canada.

Questions about this assessment

This PIA is reviewed and updated as the product and its regulatory environment evolve. Questions can be sent to [email protected].