AssignedHealth Services Agreement
Version 1.1-pilot · July 2026 (renamed from TherapyBridge to AssignedHealth) · DRAFT — pending review by an Ontario privacy lawyer. This agreement is accepted electronically. Under Ontario's Electronic Commerce Act, 2000 and PIPEDA Part 2, electronic acceptance has the same effect as a written signature.
1. Who this agreement is between
This agreement is between the health-care provider accepting it (the "Provider" — together with any clinic colleagues they invite, each accepting individually) and AssignedHealth, operated by John Akinyemi ("AssignedHealth", "we"). It governs the Provider's use of the AssignedHealth platform to assign between-session activities, share documents, and receive client submissions.
2. Roles under PHIPA
The Provider is the health information custodian of all personal health information ("PHI") handled through the platform. AssignedHealth acts solely as the Provider's electronic service provider under the Personal Health Information Protection Act, 2004 (Ontario) and its regulations. AssignedHealth is not a custodian, does not provide health care, and the platform is not the Provider's clinical record.
3. What AssignedHealth does — and does not do — with PHI
- We collect, use, and disclose PHI **only as necessary to provide the service and only on the
Provider's instructions** given through the platform.
- No secondary use, ever: no analytics on PHI, no marketing, no advertising, no sale of data,
no use of PHI to train artificial-intelligence models.
- We do not disclose PHI to anyone except as the Provider directs through the platform, or where
required by law — in which case we will notify the Provider unless legally prohibited.
4. Safeguards we commit to
- All data is stored in Canada (Amazon Web Services, Canada Central region, Montréal).
- Encryption in transit (TLS) and at rest (database and file storage).
- Access controls: individually authenticated Provider and client accounts with hashed passwords,
sign-in lockout, inactivity timeouts, and per-provider data scoping (each provider sees only their own clients).
- A tamper-resistant audit log recording access to and changes of PHI (including every view of
client records, tasks, submissions, and files), available to the Provider at any time in-app (Activity page) and exportable as CSV.
- Subprocessor: Amazon Web Services (hosting, storage, email delivery — Canada region). Emails
sent by the platform contain no PHI. We will give the Provider notice before adding or changing subprocessors.
5. Incidents and breach
If PHI in our custody is stolen, lost, or accessed, used, or disclosed without authority, we will notify the Provider at the first reasonable opportunity with the information the Provider needs to meet their own PHIPA duties (including client notification and reporting to the Information and Privacy Commissioner of Ontario, where applicable). We maintain a breach register and an incident response procedure.
6. The Provider's data rights
- Access and export: the Provider may export their complete practice data (JSON) and full audit
log at any time, in-app.
- Correction: client details can be corrected in-app; changes are audit-logged.
- Deletion: the Provider may permanently delete any client and all of that client's data
in-app at any time; deletion removes database records and stored files and is audit-logged.
- On termination by either party: the Provider has 30 days to export their data, after
which we will permanently delete all of the Provider's PHI from the platform (including stored files; encrypted backups age out within the backup retention window of 7 days) and confirm deletion in writing.
7. The Provider's responsibilities
- Obtain any consents required from clients for communicating through the platform (the platform
also captures each client's own consent at first sign-in, with a timestamp).
- Keep account credentials secure; each Provider and staff member uses their own account.
- Maintain their own clinical records per their College's requirements — the platform is a
communication and task tool, not the chart.
- Use the platform lawfully and only for its intended purpose; no uploading of content unrelated
to client care.
- The platform is not for emergencies and is not monitored in real time; this is disclosed to
clients on-screen.
8. Service and support (pilot terms)
- Pilot fee: as invoiced monthly, outside the platform. Either party may end this agreement with
30 days' notice; the Provider may stop using the service at any time.
- We aim for high availability but the pilot service is provided as-is, without uptime
guarantees. We will give reasonable notice of planned maintenance.
- Support: by email to the contact in Section 10, with responses on a commercially reasonable
timeline.
9. Liability
[To be settled with counsel. Pilot placeholder:] Each party's total liability under this agreement is limited to the fees paid in the twelve months preceding the claim, except for a party's breach of privacy obligations in Sections 3–5, gross negligence, or wilful misconduct. Nothing limits liability that cannot be limited by law.
10. General
- Governing law: Ontario, Canada.
- Privacy contact: John Akinyemi — awsapps@johnakinyemi.com.
- Changes: we will notify the Provider of material changes to this agreement; continued use
after notice constitutes acceptance of the updated version. The version accepted, and when, is recorded in the audit log.
- If any part of this agreement is unenforceable, the rest remains in effect.
By checking the acceptance box at sign-up (or the in-app acceptance prompt), the Provider agrees to this agreement. The accepted version and timestamp are recorded.