This Privacy Policy explains how Confirm-IT ("Confirm-IT", "we", "us", or "our") collects, uses, discloses, and safeguards personal information in connection with our appointment-confirmation platform and related websites, applications, and services (collectively, the "Service"). The Service lets businesses send automated appointment reminders and confirmations by SMS text message, email, and AI-assisted voice calls.
We are committed to handling personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), applicable provincial privacy legislation, and Canada's Anti-Spam Legislation (CASL). By using the Service, you acknowledge the practices described in this Policy.
1. Our Two Roles
Confirm-IT handles personal information in two distinct capacities:
- As a business (controller). When you register for an account, contact us, or visit our website, we determine how your information is used. This Policy governs that information directly.
- As a service provider (processor). When our business customers upload or generate information about their own clients ("End Customers") — for example a patient's name and phone number used to send an appointment reminder — we process that information on behalf of and under the instructions of the business customer. The business customer is responsible for that information and for obtaining any required consents. If you are an End Customer and have questions about your information, please contact the business that scheduled your appointment.
2. Information We Collect
Information from account holders and their staff
- Identity and contact details: name, business name, email address, phone number.
- Account credentials and profile settings (passwords are stored hashed, never in plain text).
- Business configuration: locations, providers, appointment types, message templates, timezone.
- Billing information: plan, subscription status, usage, and payment metadata. Card details are collected and stored by our payment processor (Stripe), not by Confirm-IT.
- Communications you send us (support requests, emails).
Information processed on behalf of business customers (End Customer data)
- End Customer name, phone number, and email address.
- Appointment details (date, time, location, provider, type, status).
- Consent, opt-in, and opt-out / unsubscribe status (e.g., STOP / START keywords).
- Message content and delivery status for SMS and email.
- Voice-call metadata and, where the feature is enabled, call recordings, transcripts, and AI-generated conversation summaries.
Information collected automatically
- Log and device data: IP address, browser type, pages viewed, and timestamps.
- Cookies and similar technologies used to keep you signed in and to operate the Service (see Cookies).
3. How We Use Information
- To provide, operate, and maintain the Service, including sending the SMS, email, and voice confirmations you configure.
- To authenticate users and secure accounts.
- To process payments, manage subscriptions and credits, and meter usage.
- To provide customer support and respond to your requests.
- To monitor, troubleshoot, and improve the reliability, security, and performance of the Service.
- To detect, prevent, and address fraud, abuse, and violations of our Terms of Service.
- To comply with legal obligations and enforce our agreements.
We do not sell personal information. We do not use End Customer data for our own advertising, and we do not permit our AI subprocessors to use your or your End Customers' content to train their general-purpose models.
4. SMS, Voice, and AI Voice Processing
Sending text messages and placing calls necessarily involves disclosing the recipient's phone number and message content to telecommunications providers. Specifically:
- SMS & voice connectivity is provided through Twilio. Phone numbers and message/call content pass through Twilio and the destination mobile carriers to be delivered.
- AI voice calls use ElevenLabs (and supporting AI providers such as OpenAI) to generate speech and understand responses. When AI voice is enabled, conversation audio may be transcribed and processed to carry out the appointment-confirmation task.
- Recordings & transcripts. Where call recording or transcription is enabled, recordings, transcripts, and summaries are stored so the business customer can review the outcome of a call. Recording may be subject to consent requirements; business customers are responsible for any disclosures their jurisdiction requires.
- Consent and opt-out. Recipients can opt out of text messages at any time by replying
STOP, and can opt back in withSTART. We honour these requests and maintain opt-out status. Messaging is only sent on behalf of business customers who represent they have a lawful basis and the necessary consent under CASL and applicable law.
5. How We Share Information (Subprocessors)
We share information only as needed to operate the Service. We use the following categories of service providers ("subprocessors"), each bound by contractual obligations to protect the information they handle:
| Subprocessor | Purpose |
|---|---|
| Twilio | SMS text messaging and voice call delivery |
| ElevenLabs | AI voice generation and conversational handling |
| OpenAI | Supporting AI/language processing for voice interactions |
| SendGrid (Twilio) | Outbound email delivery |
| Stripe | Payment processing and subscription billing |
| Cloud hosting provider | Application and database hosting |
| Sentry | Error monitoring and diagnostics |
We may also disclose information:
- To comply with applicable law, regulation, legal process, or a lawful government request.
- To enforce our Terms of Service or protect the rights, property, or safety of Confirm-IT, our customers, or others.
- In connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honour this Policy or notify you of any material change.
6. Storage and International Transfers
Confirm-IT is operated from Canada. Some of our subprocessors (including Twilio, ElevenLabs, OpenAI, SendGrid, and Stripe) are located in or process data in the United States and other countries. As a result, personal information may be stored or processed outside of Canada and may be subject to the laws of those jurisdictions, including lawful access by courts and government authorities. We take steps to ensure such transfers are protected by appropriate contractual safeguards.
7. Data Retention
We retain account information for as long as your account is active and as needed to provide the Service. End Customer data is retained for as long as the business customer maintains it in the Service or until the business customer deletes it. We retain certain records (such as billing and usage logs, and opt-out records) for as long as necessary to meet legal, accounting, and compliance obligations. When information is no longer required, we delete or anonymize it. Business customers can request deletion of their account data as described below.
8. How We Protect Information
- Encryption in transit using TLS/HTTPS, and encryption of sensitive credentials at rest.
- Tenant isolation: the Service is multi-tenant and enforces account-level data separation so one business cannot access another business's data.
- Role-based access controls and the principle of least privilege for internal access.
- Hashed passwords and audited administrative access.
No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee its absolute security.
9. Your Privacy Rights
Subject to applicable law, you may:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Withdraw consent or unsubscribe from communications (note this may limit your ability to use the Service).
- Request deletion of your information, subject to legal retention requirements.
- Complain to us, and to the Office of the Privacy Commissioner of Canada, about how we handle your information.
To exercise these rights for account information, contact us using the details below. If you are an End Customer, the business that scheduled your appointment controls your information; please direct access, correction, and deletion requests to that business, and we will assist them as their service provider.
10. Cookies
We use strictly necessary cookies to operate the Service — for example, to keep you signed in and to protect against cross-site request forgery. We do not use cookies for third-party advertising. You can control cookies through your browser settings, though disabling them may prevent the Service from functioning correctly.
11. Children's Privacy
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from children. Business customers may process appointment information about minors (for example, a parent booking a child's dental appointment); that information is handled on the business customer's instructions and responsibility.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Effective date" above and, where appropriate, provide additional notice. Your continued use of the Service after an update constitutes acceptance of the revised Policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, contact our Privacy Officer:
- Email: privacy@confirm-it.co
- Confirm-IT is operated by Confirm It Technologies Inc., RR2, Pefferlaw, Ontario, Canada.
Looking for our Terms of Service?