Privacy Policy

Last updated: April 31, 2026

1. PURPOSE

Noterro is committed to protecting the privacy of individuals who interact with us. This policy explains how we collect, use, store, and safeguard personal data to ensure transparency and build trust with our users, customers, and partners. The Organization also establishes structured privacy governance, risk assessment, and accountability mechanisms to ensure compliance with applicable data protection laws and regulations.

2. SCOPE

This policy applies to all personal data collected through the organization’s websites, applications, services, and other interactions with individuals. This policy also applies to all internal systems, third-party processors, cross-border data transfers, and any new or modified processing activities involving personal data.

3. DEFINITION

4. CUSTOMER PRIVACY STATEMENT

Noterro Inc. (“Noterro”) knows that you care about how Personal Information (as defined in section 6(1)) is used and shared. This notice describes how we treat that information. We are committed to the important goal of protecting privacy and personally identifiable information. This privacy notice is applicable to any and all services provided on noterro.com including our Noterro software as a service (the “SaaS”) and any other domain name that may be operated and/or owned by Noterro (the “Websites”).

This Privacy Statement describes Noterro's privacy practices when you visit our Websites or use the SaaS. Where applicable law requires consent for a particular collection, use, or disclosure of Personal Information, Noterro will obtain that consent as required. Your use of the SaaS may also be governed by separate terms or agreements.

5. OUR COMMITMENT TO PRIVACY

Noterro is committed to controlling the storage, use and disclosure of the Personal Information (as defined in section 6(2)) provided by its customers.

6. WHAT IS PERSONAL INFORMATION AND PERSONAL HEALTH INFORMATION?

6.1 “Personal Information” is personally identifiable information such as a name, residential address, phone number, financial records, health records, e-mail address, credit card particulars, mailing and billing information, and includes information about product and service inquiries, usage of the SaaS, Personal Health Information (as defined in the next sentence), and other information provided to us. “Personal Health Information” generally means the health information about an individual and the definition is set out in detail in Schedule “A” to this Privacy Policy.

6.2 Personal Information is stored by Noterro only when you specifically and knowingly choose to provide it to us such as when you input or upload information through the SaaS. When users of our SaaS provide Personal Information through our SaaS they are confirming that they have the consent of the person to whom the Personal Information belongs and rights to use it with the SaaS.

6.3 Any information that is publicly available or displayed, which may include a public directory listing of a name, address, telephone number and electronic address, is not considered Personal Information.

7. STORAGE AND USE OF PERSONAL INFORMATION

7.1 Information you give to us. 

Noterro stores and uses Personal Information only when you provide such information to us and when you submit information directly to us by filling in forms on our Websites or by corresponding with us by phone, email, or other means. Noterro stores and uses Personal Information solely for the purpose of permitting you to use our SaaS in accordance with our SaaS agreement. By requesting that we store, or by providing to us, Personal Information via the SaaS, you are consenting to our storage and use of such Personal Information in accordance with the SaaS agreement. Personal Information will not be used for any other purpose without your consent.

7.2 If you choose not to provide Personal Information, we may not be able to provide the SaaS Services to you or respond to your other requests.

7.3 Information we receive from other sources.

We may receive Personal Information about you from individuals or corporate entities which are subscribers to our SaaS Services, where you may be designated as a user or Registered Patient of the SaaS Services. We also automatically collect Personal Information about you indirectly about how you access and use the SaaS Services and information about the device you use to access the SaaS Services.

7.4 We may also receive non-personally identifiable information (e.g. functions and features of the SaaS that have been used, etc.) from your interaction with our SaaS.

7.5 Our SaaS does not limit the amount and type of information you may submit to it. 

7.6 Noterro will not sell, lease or trade Personal Information to other third parties.

7.7 Anonymous or information that is not Personal Information gathered by Noterro through our SaaS may be used for technical, research and analytical purposes.  We may anonymize and aggregate any of the Personal Information we collect so that it does not identify you. We may use anonymized information for purposes that include testing out IT systems, research, data analysis, improving the SaaS Services and developing new products and features. We may also share such anonymized information with others.

7.8 Noterro will only ask for information about you that we need and will only ask for it when we need it. When we ask you for the information, we will explain to you why we need it and what we are going to do with it. Access to Personal Information within Noterro is restricted to authorized personnel whose roles require access to perform legitimate business, support, security, operational, or technical functions. Access is provided on a need-to-know basis and is subject to appropriate access controls and confidentiality obligations.

7.9 Noterro reserves the right to store and process your Personal Information in Canada and in any other country where Noterro or its affiliates, subsidiaries, or service providers operate facilities in accordance with and as permitted by applicable laws and regulations. Some of these countries may have data protection laws that are different from the laws of your country and in some cases may not be as protective. When we transfer, store, or process Personal Information outside of your jurisdiction, we take appropriate safeguard to require that your Personal Information remains protected in accordance with this Privacy Policy and applicable law. At your request we will share the names and details of the organizations who are storing or transmitting information at the request of Noterro.

7.10 Noterro Scribe and AI-Assisted Dictation

Certain features of the SaaS, including Noterro Scribe, use AI-assisted transcription to convert dictated content into text for use in clinical notes. When Scribe is used, Noterro sends only the content dictated by the user for processing and does not send other information from the patient record as part of that request. Because Scribe is used within the context of an existing patient note, your dictation does not need to include, and should not include, the patient's name or other identifying details such as date of birth, address, or contact information. Noterro does not automatically review or filter dictated content before it is sent for processing, so you are responsible for the content of your dictation, including for avoiding these details where the laws, regulations, or professional standards applicable to your practice prohibit including them. The dictated content is processed by Amazon Web Services, which is also Noterro's underlying cloud infrastructure provider, using a service built specifically for healthcare use, on infrastructure located in the United States. That service temporarily stores and processes the dictated content only for the purpose of transcribing it, applying AI to the resulting transcript to generate draft content suitable for a clinical note, and returning that content to Noterro. Neither the dictated content nor the AI-generated output is used to train AI models. Once processing is complete and the resulting content has been returned to Noterro, the dictated content is not retained by that service. The returned content is then made available within Noterro for the clinic to review, verify, and use as part of the clinical note.

8. DISCLOSURE

Noterro shall not disclose Personal Information except: (i) as may be required to provide the SaaS; (ii) as you may direct; (iii) via the SaaS as a result of your actions; and (iv) as the law may require.

9. YOUR RIGHTS IN RESPECT OF YOUR PERSONAL INFORMATION

9.1 Depending on where you live, the type of Personal Information involved, and the laws that apply, you may have some or all of the following rights in respect of Personal Information that Noterro holds or processes:

9.2 If you wish to exercise a privacy right relating to Personal Information that Noterro controls directly, you may do so by emailing privacy@noterro.com. We may ask you to verify your identity before providing access to or transferring Personal Information. Where available, you may also access or correct certain account information by logging into your Noterro account. If your request concerns Personal Information or Personal Health Information that a clinic or health care provider stores in Noterro about you, you may need to direct your request to that clinic or provider. In those circumstances, Noterro will assist the clinic or provider as required by applicable law and our contractual obligations. We intend to respond to requests directed to Noterro within the time required by applicable law.

10. USE OF COOKIES

10.1 Noterro uses a browser feature called a cookie to collect information anonymously and track user patterns on our Websites. A cookie is a small text file that is placed on your hard disk by a website. “Cookies” contain a unique identification number that identifies your browser, but not you, to our computers each time you visit our Website. Cookies tell us which pages of our Website are visited and by how many people.

10.2 The use of cookies is an industry standard and many major browsers are initially set up to accept them. You can reset your browser to either refuse to accept all cookies or to notify you when you have received a cookie. However, if you refuse to accept cookies, you may not be able to use some of the features available on our Website.

11. ACCURACY

Noterro will try to ensure that any information is accurate, complete and up-to-date. However, please inform Noterro of any change in the information. In the event you have questions about the accuracy of factual information we store, you will have access to that information in order to verify and update it. If we have disclosed inaccurate information about you to a third party, we will be pleased to contact the third party in order to correct the information.

12. SECURITY

Noterro is committed to protecting privacy. Security measures, such as locked filing cabinets, restricted access or the use of passwords and encryption have been adopted to protect Personal Information against loss or theft, as well as unauthorized access, disclosure, copying, use or modification. Our employees have been trained to respect privacy at all times and those employees with access to the Personal Information shall use the Personal Information strictly in accordance with this Privacy Policy.

13. QUESTIONS OR CONCERNS

13.1 If you have any questions or concerns about the Personal Information about you held by Noterro or about the compliance by Noterro with our Privacy Policy, please contact our Privacy Officer at: privacy@noterro.com.13.2 Noterro has procedures in place to receive and respond to complaints or inquiries about its handling of Personal Information. They will describe the complaint procedures to anyone who makes inquiries or lodges complaints.

13.3 If you are not satisfied with the response from us after making a complaint, you may have recourse to additional remedies under applicable privacy legislation. For further information, please contact the federal Privacy Commissioner or your provincial Privacy Commissioner, as applicable.

14. WHEN IS THIS PRIVACY POLICY IN FORCE? WILL THE PRIVACY POLICY EVER CHANGE?

14.1 The foregoing policies are effective as of the “Last Update” date stated above. Changes to this policy are effective when they are posted on this page.  Noterro reserves the right to change this policy at any time with reasonable notice to users posted on the Website of the existence of a new Privacy Statement. This statement and the policies outlined here are not intended to and do not create any contractual or other legal rights in or on behalf of any party.

15. THIRD-PARTY LINKS

Our website or services may contain links to third-party websites. We are not responsible for their privacy practices and encourage you to review their privacy policies.

16. PRIVACY OF MINORS

Noterro's SaaS customer accounts are intended for businesses and practitioners. Noterro does not knowingly enter into a direct SaaS customer relationship with an individual who is under the age required to enter into the applicable agreement in their jurisdiction. However, clinics and practitioners may use Noterro to provide services to, and maintain records about, patients or clients who are minors. The clinic or practitioner is responsible for ensuring that the collection, use, and disclosure of Personal Information or Personal Health Information relating to a minor is permitted under applicable law. Rules governing consent by or on behalf of minors vary by jurisdiction and may depend on the individual's capacity rather than a fixed age. For example, under Ontario's Personal Health Information Protection Act, 2004, individuals are generally presumed capable unless there are reasonable grounds to believe otherwise; capacity depends on whether the individual can understand the information relevant to the decision and appreciate the reasonably foreseeable consequences, with additional rules applying to individuals under 16.

17. UPDATES TO THIS POLICY

Noterro will update this policy periodically to reflect changes in laws, regulations, or business practices. Please make sure to review our privacy policy regularly for the latest version.

18. SCHEDULE “A”

DEFINITION OF “PERSONAL HEALTH INFORMATION”

“Personal Health Information” has the meaning given to that term under the Personal Health Information Protection Act, 2004, S.O. 2004, c. 3, Sched. A (“PHIPA”), as amended from time to time.

In general, PHIPA defines Personal Health Information as identifying information about an individual, in oral or recorded form, that relates to the individual's physical or mental health; the provision of health care to the individual; certain plans for home and community care services; payments or eligibility for health care or coverage; the donation, testing, or examination of body parts or bodily substances; the individual's health number; the identity of the individual's substitute decision-maker; or the individual's digital health identifier or other identifying information related to the creation of that identifier.

PHIPA also provides that identifying information may constitute Personal Health Information when it is contained in a record that contains Personal Health Information, subject to statutory exceptions. Under PHIPA, identifying information includes information that identifies an individual or that could reasonably be used, either alone or with other information, to identify an individual.

This Schedule is intended as a plain-language summary for convenience. If there is any inconsistency between this summary and PHIPA, the current wording of PHIPA governs.

19. AMENDMENTS TO THIS COMMITMENT

We conduct an annual review of this Commitment, amending it as necessary to ensure compliance with evolving legislation, data management protocols, and other applicable circumstances. Should material changes occur, individuals whose personal information we retain will be notified either via email or through a notice posted on our website.

20. HOW TO CONTACT US

If you have any questions or concerns about our privacy practices, or wish to exercise any rights in respect of your personal information, please contact us at privacy@noterro.com.

In certain jurisdictions, such as the European Union, we may appoint a Data Protection Officer as required by law. To get in touch with our Data Protection Officer, email privacy@noterro.com.

Privacy Policy

At Noterro, we know you care about how your personal information is used and shared. This notice describes how we treat that information. We are committed to the important goal of protecting privacy and personally identifiable information. This privacy notice is applicable to any and all services provided on noterro.com including our Noterro software as a service (the "SaaS") and any other domain name that may be operated and/or owned by Noterro ("Noterro"). By visiting and using the SaaS, you agree to the terms of this Privacy Statement.

1. CUSTOMER PRIVACY STATEMENT

Noterro Inc. (“Noterro”) knows that you care about how Personal Information (as defined in section 3(2)) is used and shared. This notice describes how we treat that information. We are committed to the important goal of protecting privacy and personally identifiable information. This privacy notice is applicable to any and all services provided on noterro.com including our Noterro software as a service (the “SaaS”) and any other domain name that may be operated and/or owned by Noterro. By visiting and using the SaaS, you agree to the terms of this Privacy Statement.

2. OUR COMMITMENT TO PRIVACY

(1) Noterro is committed to controlling the storage, use and disclosure of the Personal Information (as defined in section 3(2)) provided by its customers.

3. WHAT IS PERSONAL INFORMATION AND PERSONAL HEALTH INFORMATION?

(1) “Personal Information” is personally identifiable information such as a name, residential address, e-mail address, credit card particulars, mailing and billing information, and includes information about product and service inquiries, usage of the SaaS, Personal Health Information, and other information provided to us. “Personal Health Information” generally means the health information about an individual and the definition is set out in detail in Schedule “A” to this Privacy Policy.

(2) Personal Information is stored by Noterro only when you specifically and knowingly choose to provide it to us such as when you input or upload information through the SaaS. When users of our SaaS provide Personal Information through our SaaS they are confirming that they have the consent of the person to whom the Personal Information belongs and refers to use it with the SaaS.

(3) Publicly available information, such as a public directory listing of a name, address, telephone number and electronic address, is not considered Personal Information.

4. STORAGE AND USE OF PERSONAL INFORMATION

(1) Noterro stores and uses Personal Information only when you provide such information to us and when you transmit such information into and by way of the SaaS. Noterro stores and uses Personal Information solely for the purpose of permitting you to use our SaaS in accordance with our SaaS agreement. By requesting that we store, or by providing to us, Personal Information via the SaaS, you are consenting to our storage and use of such Personal Information in accordance with the SaaS agreement. Personal Information will not be used for any other purpose without your consent.

(2) We may also receive non-personally identifiable information (e.g. functions and features of the SaaS that have been used, etc.) from your interaction with our SaaS.

(3) Our SaaS does not limit the amount and type of information you may submit to it.

(4) Noterro will not sell, lease or trade Personal Information to other third parties.

(5) Anonymous or information that is not Personal Information gathered by Noterro through our SaaS may be used for technical, research and analytical purposes.

(6) Noterro will only ask for information about you that we need and will only ask for it when we need it. When we ask you for the information, we will explain to you why we need it and what we are going to do with it.

(7) Personal Information is stored on servers and computers located inside of Canada, which are managed by companies that meet the security requirements for Noterro and its customers.

5. DISCLOSURE

Noterro shall not disclose Personal Information except: (i) as may be required to provide the SaaS; (ii) as you may direct; (iii) via the SaaS as a result of your actions; and (iv) as the law may require.

6. USE OF COOKIES

(1) Noterro uses a browser feature called a cookie to collect information anonymously and track user patterns on our Websites. A cookie is a small text file that is placed on your hard disk by a website. “Cookies” contain a unique identification number that identifies your browser, but not you, to our computers each time you visit our Website. Cookies tell us which pages of our Website are visited and by how many people.

(2) The use of cookies is an industry standard and many major browsers are initially set up to accept them. You can reset your browser to either refuse to accept all cookies or to notify you when you have received a cookie. However, if you refuse to accept cookies, you may not be able to use some of the features available on our Website.

7. ACCURACY

Noterro will try to ensure that any information is accurate, complete and up-to-date. However, please inform Noterro of any change in the information. In the event you have questions about the accuracy of factual information we store, you will have access to that information in order to verify and update it. If we have disclosed inaccurate information about you to a third party, we will be pleased to contact the third party in order to correct the information.

8. SECURITY

Noterro is committed to protecting privacy. Security measures, such as locked filing cabinets, restricted access or the use of passwords and encryption have been adopted to protect Personal Information against loss or theft, as well as unauthorized access, disclosure, copying, use or modification. Our employees have been trained to respect privacy at all times and those employees with access to the Personal Information shall use the Personal Information strictly in accordance with this Privacy Policy.

9. ACCESS

(1) Noterro may permit you to access the Personal Information in those circumstances permitted or required by applicable privacy legislation. If Noterro refuses access to you, it will provide you with the reasons for its refusal upon request. Exceptions may include information that contains references to other individuals, information that cannot be disclosed for legal, security or commercial proprietary reasons, and information that is subject to solicitor-client or litigation privilege. Noterro will respond to your requests for access in accordance with applicable privacy legislation.

10. QUESTIONS OR CONCERNS

(1) If you have any questions or concerns about the Personal Information about you held by Noterro or about the compliance by Noterro with our Privacy Policy, please contact us at the address listed in the SaaS agreement.

(2) Noterro has procedures in place to receive and respond to complaints or inquiries about its handling of Personal Information. They will describe the complaint procedures to anyone who makes inquiries or lodges complaints.

(3) If you are not satisfied with the response from us after making a complaint, you may have recourse to additional remedies under applicable privacy legislation. For further information, please contact the federal Privacy Commissioner or your provincial Privacy Commissioner, as applicable.

11. WHEN IS THIS PRIVACY POLICY IN FORCE? WILL THE PRIVACY POLICY EVER CHANGE?

(1) The foregoing policies are effective as of the “Last Update” date stated above. Noterro reserves the right to change this policy at any time with reasonable notice to users posted on the Website of the existence of a new Privacy Statement. This statement and the policies outlined here are not intended to and do not create any contractual or other legal rights in or on behalf of any party.


SCHEDULE “A”
DEFINITION OF “PERSONAL HEALTH INFORMATION”

“Personal health information” has the meaning ascribed to it under the Personal Health Information Protection Act, 2004, S.O. 2004, ch. 3 (“PHIPA”), as such statute may be amended from time to time.

For ease of reference the following is section 4 of PHIPA.

4 (1) In this Act,“personal health information”, subject to subsections (3) and (4), means identifying information about an individual in oral or recorded form, if the information,

(a) relates to the physical or mental health of the individual, including information that consists of the health history of the individual’s family,

(b) relates to the providing of health care to the individual, including the identification of a person as a provider of health care to the individual,

(c) is a plan of service within the meaning of the Home Care and Community Services Act, 1994 for the individual,

(d) relates to payments or eligibility for health care, or eligibility for coverage for health care, in respect of the individual,

(e) relates to the donation by the individual of any body part or bodily substance of the individual or is derived from the testing or examination of any such body part or bodily substance,

(f) is the individual’s health number, or

(g) identifies an individual’s substitute decision-maker.

Identifying information

(2) In this section,

“identifying information” means information that identifies an individual or for which it is reasonably foreseeable in the circumstances that it could be utilized, either alone or with other information, to identify an individual. 2004, c. 3, Sched. A, s. 4 (2).

Mixed records

(3) Personal health information includes identifying information that is not personal health information described in subsection (1) but that is contained in a record that contains personal health information described in that subsection. 2009, c. 33, Sched. 18, s. 25 (3).

Exception

(4) Personal health information does not include identifying information contained in a record that is in the custody or under the control of a health information custodian if,

(a) the identifying information contained in the record relates primarily to one or more employees or other agents of the custodian; and

(b) the record is maintained primarily for a purpose other than the provision of health care or assistance in providing healthcare to the employees or other agents.

calendar date picker

Get started with Noterro today!

Try Noterro and discover that running your practice doesn’t need to feel overwhelming
Invoice

Get started with Noterro today!

Try Noterro and discover that running your practice doesn’t need to feel overwhelming
calendar date picker

Get started with
Noterro today!

Run your practice with less stress and more control.

No credit card required. Available 1-on-1 support.

Invoice

Get started with
Noterro today!

Run your practice with less stress and more control.

No credit card required. Available 1-on-1 support.

calendar date picker
invoice