Back

Legal · Privacy & Data

Privacy Policy

Effective August 1, 2023 · Last updated July 24, 2026 · Policy v2.3

Important notice

This Policy explains how Biotonix Posture, a product of Solutions Biotonix Inc., protects the data you and your patients entrust to us, including personal and health-related information that can be sensitive.

It sits alongside our Terms of Service, including Schedule A on patient-data processing. Terms defined in both documents mean the same thing in each.

If you’re a practitioner (a “Member”), your patients’ information stays under your control. We act as your processor or service provider when we handle it to run the Services.

What this covers

Biotonix Posture is used by professionals who handle sensitive posture and health information. This Policy sets out what we collect, why, how we protect it, how long we keep it, and the choices you and your patients have. It’s based on Solutions Biotonix Inc. Policy v2.3.

Not legal advice. This is a plain-language version of our privacy and cookie practices. We’ve kept it accurate and readable, but it isn’t legal advice for your own practice or jurisdiction.

1.Introduction and scope

This Policy describes how Biotonix Posture, as part of Solutions Biotonix Inc., protects the confidentiality, integrity, and availability of the data we hold, especially personal and health-related information that can be sensitive. It sets out how we govern that data, how we secure it, and how we handle privacy.

It applies to all data we process at Biotonix Posture, wherever it comes in: the website at www.biotonixposture.com, payment and billing accounts at www.biotonixposture.com/my-account, the professional platform at app.biotonix.com, the Biotonix Assistant mobile app, and any support or communication channel around them. The same standards apply across the whole organization.

We use terms like “Personal Data,” “Processing,” “Data Subject,” “Member,” and “Patient Data” the way applicable data-protection laws define them, and the way our Terms of Service define them where that’s relevant.

2.Governance and responsibility

We handle data on a few principles: collect it lawfully and openly, only for a stated purpose, keep it accurate, keep no more than we need for no longer than we need, and protect it. We follow the legal standards and try to stay transparent with the people whose data we hold.

Senior management is ultimately responsible for meeting our legal obligations on data protection. Day to day, that work is led by our Vice-President of Technologies, Sébastien Lacoste (Eng.), who keeps leadership informed, reviews our policies, advises staff on the tricky questions, makes sure training happens, handles data-subject requests, and signs off on unusual disclosures and contracts with subprocessors.

Every staff member has to read and follow the policies for the personal data they touch. And we work with vetted subprocessors, such as Solulan (SOC 2 certified), to strengthen security around our Microsoft Office 365 environment through their backup and Data Loss Prevention systems.

3.What we collect

Solutions Biotonix Inc. holds personal and sensitive data. For Biotonix Posture, it falls into a few groups.

Member account data

Your name, email, professional credentials where they apply, password, contact details, and subscription and payment information, handled through www.biotonixposture.com/my-account.

Patient and client data, entered by Members

Name, an optional reference number, date of birth, gender, language preference, an optional email for sharing reports, posture assessment photos, the AI-generated analysis (deviations and measurements), and past assessments.

Usage and communication data

Login and interaction logs across the platform and app, device information (type and OS), IP address, and diagnostics. We also keep records of support requests sent to info@biotonixposture.com or through other channels.

Members give us most of this directly when they create an account, subscribe, and use the platform or app, including entering patient data and capturing photos. Usage data is collected automatically.

4.How we use data

We use data to run and improve the AI-powered posture assessment, to set up and manage Member accounts and subscriptions, and to let Members carry out evaluations, generate reports, and manage patient data. It also lets us pass reports to a patient by email when the Member asks, answer support requests, and analyze how the platform is used so we can make it work better, usually with anonymized or aggregated data.

We may use anonymized or de-identified data to develop and refine our AI. Beyond that, we use data to keep the platform secure, prevent fraud, enforce our Terms & Conditions, and meet our legal and regulatory obligations.

5.Sharing and disclosure

Patient data and reports go only where the Member directs, such as an email address the Member enters for a patient. We share data with vetted vendors and subprocessors (for example Solulan and Microsoft Azure) that run services for us like cloud hosting, payment processing, security monitoring, and backup, under confidentiality agreements and only for the purposes in this Policy.

We may disclose data when the law requires it, through a subpoena or other legal process, or when we reasonably believe it’s needed to protect our rights, keep users safe, investigate fraud, or answer a government request. If the business is ever part of a merger, acquisition, or sale of assets, data may transfer with it, under confidentiality commitments.

We don’t sell your data. Biotonix Posture doesn’t sell personal data to third parties.

6.Security

We protect data with technical, administrative, and physical safeguards against unauthorized access, disclosure, alteration, loss, and destruction. The risks we watch most closely are lost user data and leaks from unsecured environments.

In practice, employee access follows least privilege, and multi-factor authentication is mandatory on every Office 365 account. Staff log off at the end of the day. Sensitive data from Biotonix applications is stored in Microsoft Azure on servers in Canada, our partner Solulan handles backups, and we build on premium Microsoft security products that Solulan helps us tune.

Your side matters too. Members are responsible for keeping their credentials confidential across www.biotonixposture.com/my-account, app.biotonix.com, and the Biotonix Assistant app.

7.Retention

You own your data and can delete it permanently at any time from within the mobile app.

Otherwise we keep active user data for as long as the account is active, and delete inactive user data after 24 months of inactivity unless the law requires us to hold it longer. Transactional records like payments, invoices, and connection logs stay at least 7 years for compliance and audit. Anonymized data may be kept indefinitely for statistics and service improvement, since it no longer identifies anyone. We may also hold data a little longer while we investigate a cybersecurity incident, until that investigation closes.

8.Your privacy rights

Members can access, correct, or delete their own account information, within legal and contractual limits, either from the mobile app or by writing to the Data Protection Lead.

Patients and clients should send requests about their data to the Member who collected it, since that practitioner or trainer is the controller of that information. We’ll help Members respond as the law requires. For data we hold directly, contact the Data Protection Lead, Sébastien Lacoste, or email info@biotonixposture.com.

Depending on where you and your patients are, the law may give data subjects rights such as access, correction, deletion, portability, objection, and withdrawal of consent. Where those rights apply to data we hold, we honour them under the applicable law.

9.Compliance and international transfers

We’re committed to the data-protection laws that apply to our work. The main one is Québec’s Law 25, the Act respecting the protection of personal information in the private sector, which governs how we operate.

Depending on where you and your patients are, other rules can also apply to a given interaction, such as Canada’s federal PIPEDA or, for users in the European Union, the GDPR. Where one of those applies, we aim to handle personal information in line with its core principles of lawfulness, transparency, data minimization, and security. This Policy on its own isn’t a certification of compliance with any particular framework.

Data lives on servers in Canada. When it crosses a border for another reason, such as a subprocessor, we put the safeguards the law requires in place.

10.Handling incidents

An incident means something like unauthorized access, a data leak or loss, malware or ransomware, a phishing attack, or a critical system failure that exposes data. When one happens, we work through a set process.

First we detect and flag it, using security tools such as antivirus, SIEM, and logs, an internal alert channel, and a severity rating from minor to critical. Then we contain it by isolating the affected systems or accounts, applying countermeasures like temporary firewall rules, and telling the people who need to know, including management, the Data Protection Lead, and partners such as Solulan. We work out where it came from, assess the damage and which data was touched, and apply fixes and procedure updates.

Where notice is required, we tell the relevant authority, such as Québec’s Commission d’accès à l’information, and we inform affected users when their data is at risk, along with any impacted partners. We report voluntarily where that’s the right thing to do. Afterward we document the incident and what we learned, adjust our procedures and training, and fold it into a continuous-improvement plan.

11.Updates to this Policy

We’ll update this Policy from time to time as our practices or the law change, and the “Last updated” date at the top shows the latest revision. When a change is significant, we’ll tell Members through a suitable channel, such as email or a notice in the platform.

12.Contact

Questions or concerns about this Policy can go to:

Data Protection Lead: Sébastien Lacoste, VP Technologies
General support: info@biotonixposture.com

Solutions Biotonix Inc.
25, rue du Roi
Sorel-Tracy, Québec  J3P 4M2
Canada

Annex

Effective August 1, 2023 · Last updated July 24, 2026. How we use cookies and similar technologies on our website and platform.

C.1What cookies are

Cookies are small text files a website stores on your device when you visit. They let the site recognize your device and remember things about your visit, like your preferences or that you’re logged in.

C.2How we use them

We use a few kinds. Essential cookies keep the website and platform working, from secure login to account management and navigation, and you can’t turn these off. Performance and analytics cookies tell us which pages get used most and where people hit errors, which helps us fix and improve things; some come from third-party tools like Google Analytics, and what they collect is usually aggregated and anonymized. Functionality cookies remember choices like your language so the site feels less generic on your next visit.

C.3Your choices

On your first visit, a banner lets you accept or reject the non-essential cookies. You can also manage cookies in your browser, which can block them, delete the ones already stored, or warn you when new ones arrive. Check your browser’s help pages for how. One caveat: block the essential cookies and parts of the website and platform may stop working.

C.4Third-party cookies

Some cookies come from third-party services on our site, like analytics providers or payment processors. We don’t control those, so check their own privacy and cookie policies to learn more.

C.5Updates

We may revise this Cookie Policy now and then, and we’ll flag significant changes where the law requires it.

C.6Contact

Questions about cookies can go to info@biotonixposture.com.

Disclaimer. What Biotonix Posture provides is for education and general posture assessment, not medical evaluation, diagnosis, or treatment. Results vary from person to person, and a qualified healthcare professional should review and approve the system’s recommendations before you act on them. If you have pain, discomfort, new or worsening symptoms, or you suspect a condition affecting your musculoskeletal system, stop and see a licensed healthcare provider. Don’t rely on this software alone to diagnose or treat serious spinal, skeletal, or neurological conditions. It supports clinical judgment and personalized care. It doesn’t replace them.

Back to top