Data Privacy & Security

How We Handle Your Data

A plain explanation of where patient data is stored, how it's protected, and what applies under Canadian privacy law.

Our privacy commitment

Root Metabolic Health is committed to complying with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal privacy law governing how private-sector organizations collect, use, and disclose personal information. Where applicable provincial health privacy legislation applies to a patient or partner organization, we aim to meet those requirements as well.

Where your personal information is stored

Your personal information, including account details, weight and health logs, and wearable device data, is stored on servers located in Canada and accessed by individuals located in Canada.

Cross-border access

While your personal information is stored in Canada, one supporting component of our platform, the authentication server for the mobile companion app, currently runs on infrastructure located in the United States. As a result:

We are working to move this component to Canadian infrastructure. If Canadian-only data residency is a requirement for your organization's evaluation, contact us directly and we will discuss our current architecture and timeline in detail.

How data moves and who can see it

Data transmitted between patient devices, the mobile app, and our servers travels over encrypted HTTPS connections. Access to patient data within our systems is limited to authorized personnel and integrated care-team tools required to operate the program.

Your rights under PIPEDA

To exercise any of these rights, or if you have questions about how your data is handled, contact us using the details below.

Evaluating Root Metabolic Health for your organization and need more detail on our data handling or infrastructure?

Talk to Our Team