Privacy Policy

Who We Are:
This Privacy Policy is issued by Gallus Interactive Inc. (“Gallus Interactive Inc”, “we”, “us”, “our”), which operates the Patient Pro platform (the “Services”).
Patient Pro is an AI-powered educational platform designed to support healthcare training through simulated virtual patient interactions.
Gallus Inc. is the organization responsible for personal information collected through Patient Pro under applicable privacy laws.
1) How to Read This Policy
Scope
This Policy describes how Gallus Interactive Inc. collects, uses, discloses, retains, and protects personal information across Patient Pro.
Institutional Use (Primary Context)
For most deployments (e.g., universities, colleges):
-
The institution is the data controller
-
Gallus Interactive Inc. (Patient Pro) acts as a service provider/processor, handling data on institutional instructions
Direct Users
If you use Patient Pro independently:
-
Gallus Interactive Inc. acts as the data controller
Compliance Alignment
We align with:
-
Canadian privacy laws (e.g., PIPEDA)
-
Provincial frameworks (e.g., FIPPA/MFIPPA, FOIPPA, Québec Law 25)
-
Educational privacy expectations (e.g., FERPA where applicable)
2) What We Collect (and What We Do Not Collect)
We Collect
a) Account & Profile Information
-
Name, email address, institution, and user role
b) Interaction Data
-
Questions and responses during virtual patient sessions
-
Session activity (timestamps, navigation patterns)
-
Performance metrics and feedback
c) Audio Data
-
Voice input used during interactions (if enabled)
d) Technical Data
-
IP address, browser type, device information
-
System logs for security and performance
e) Analytics Data
-
De-identified and aggregated usage data
We Do NOT Collect
-
Facial recognition data
-
Biometric identifiers
-
Eye tracking or motion tracking data
3) How We Use Information
Gallus Interactive Inc. uses information to:
-
Deliver and operate Patient Pro
-
Enable realistic AI-driven patient simulations
-
Provide feedback and assessment
-
Improve platform functionality and user experience
-
Support educational research (where applicable)
-
Maintain system security
We do not sell personal information or use it for advertising.
4) Use of Artificial Intelligence
Patient Pro uses artificial intelligence to simulate patient interactions.
-
User inputs (text and/or audio) are processed to generate responses
-
Data may be used in de-identified or aggregated form to improve system performance
-
AI-generated outputs are for educational purposes only and do not constitute medical advice
5) Product Configuration & User Controls
-
Institutions may configure:
-
Audio recording settings
-
Data retention timelines
-
Feature availability
-
-
Users may:
-
Access their interaction data
-
Delete session data (subject to institutional policies)
-
-
6) Where We Process Data
-
Data is processed in secure cloud environments (Canada or the United States)
-
Processing locations may depend on institutional configuration
Real-Time Interactions
-
Voice interactions may be processed temporarily (in-memory)
-
Audio is not stored unless explicitly enabled
-
Data is encrypted in transit
7) Data Storage & Security
Gallus Interactive Inc. implements administrative, technical, and physical safeguards, including:
-
Encryption in transit and at rest
-
Role-based access controls
-
Secure authentication methods (e.g., multi-factor authentication where applicable)
-
Monitoring, logging, and threat detection
Access to personal data is restricted to authorized personnel only.
8) Data Retention & Deletion
Unless otherwise specified by an institution:
-
Data is retained only as necessary for educational and operational purposes
-
Audio and transcripts are stored only if enabled
-
Users may delete their own data (where permitted)
-
Backups are securely maintained and periodically purged
9) Cookies and Tracking
We use cookies and similar technologies to:
-
Maintain user sessions
-
Improve platform functionality
-
Support basic analytics
Users may disable cookies through browser settings; some features may not function properly.
10) Data Sharing & Disclosure
Gallus Interactive Inc. does not sell personal information.
We may share data:
-
With educational institutions for course delivery and assessment
-
With trusted service providers supporting the platform
-
When required by law or regulatory obligations
All third parties are subject to contractual obligations related to confidentiality and data protection.
10A) Subprocessors & Service Providers
Patient Pro, operated by Gallus Interactive Inc., uses trusted third-party service providers (“subprocessors”) to support the delivery, operation, and security of the Services.
These subprocessors may assist with:
-
Cloud infrastructure and data storage
-
Artificial intelligence and machine learning processing
-
Application hosting and performance monitoring
-
Communication and support services
For example, Patient Pro may use infrastructure providers such as Amazon Web Services (AWS) and other AI service providers to process data on our behalf.
All subprocessors are:
-
Carefully selected and vetted
-
Bound by contractual obligations related to confidentiality, security, and data protection
-
Required to process personal information only for the purposes of providing services to Patient Pro
Subprocessor Transparency
Gallus Interactive Inc. maintains an up-to-date list of subprocessors and will make this information available to institutional partners upon request.
Cross-Border Processing by Subprocessors
Some subprocessors may process data outside of Canada (e.g., in the United States). Where this occurs:
-
Processing is limited to what is necessary to deliver the Services
-
Appropriate safeguards are in place to protect personal information
-
Data is handled in accordance with applicable privacy laws and institutional requirements
11) International Data Transfers
Data may be processed in Canada or the United States depending on system configuration and subprocessor involvement.
Where cross-border data transfers occur:
-
They are limited to necessary processing activities
-
Appropriate legal, contractual, and technical safeguards are implemented
12) Legal Basis & Compliance
Gallus Interactive Inc. collects and uses personal information:
-
With consent (direct or institutional)
-
As required to deliver the Services
-
In compliance with applicable privacy laws
13) Your Rights
Users may:
-
Request access to their personal data
-
Request correction of inaccurate information
-
Request deletion (subject to institutional requirements)
-
Withdraw consent where applicable
Contact: hello@patientpro.ca
For institutional users, requests should typically be directed through your institution.
14) Children & Age Considerations
Patient Pro is intended for use in educational contexts.
Users below the age of majority should use the platform:
-
Under institutional supervision
-
With appropriate consent
15) Security Incidents
In the event of a data breach posing a real risk of harm:
-
Gallus Interactive Inc. will notify affected users and institutions
-
We will comply with legal reporting requirements
-
We will investigate and remediate promptly
16) Changes to This Policy
We may update this Privacy Policy periodically. Updates will be communicated through the platform or website.
17) Contact Information
Gallus Interactive Inc.
Email: hello@patientpro.ca
Address: 56 Thorndale Dr. Waterloo, Ont. N2L 4Y7
