Privacy Policy

Last updated June 24, 2026

How CarePath247 — a product of Paqads Consulting Inc. — collects, uses, discloses, safeguards, and retains personal information across our website, platform, and services, and who is responsible for what.

CarePath247 is an audit-ready care operations platform for residential care, foster care, group home, supported living, and similar care programs. This Privacy Policy explains how CarePath247, a product of Paqads Consulting Inc., an Ontario, Canada corporation, collects, uses, discloses, retains, safeguards, and otherwise manages personal information in connection with the CarePath247 website, platform, services, onboarding, support, and related communications.

CarePath247 is designed for organizations that operate regulated or licensed care environments. The platform may be used to document highly sensitive information about children, youth, residents, care recipients, foster caregivers, staff, contractors, visitors, incidents, medications, safety plans, plans of care, serious occurrences, compliance tasks, training records, approvals, signatures, and audit events. We treat that information as sensitive and apply privacy and security controls intended to support Canadian privacy, confidentiality, audit, and data-residency expectations.

This Policy should be read together with our Terms of Service, customer agreements, data processing terms, order forms, service-level terms, and any written privacy, security, or data-protection addendum between CarePath247 and a customer. If there is a conflict between this Policy and a signed customer agreement regarding customer-controlled platform data, the signed customer agreement will govern to the extent of the conflict.

1. Who we are

In this Policy:

“CarePath247,” “we,” “us,” and “our” means Paqads Consulting Inc., operating the CarePath247 platform under licence from its parent holding company, together with our authorized personnel and service providers acting on our behalf.

“Customer” means an agency, organization, operator, service provider, licence holder, government-funded provider, or other entity that subscribes to, trials, or uses CarePath247 for its programs, homes, staff, residents, children, youth, or care recipients.

“Authorized User” means an individual who is invited, provisioned, or permitted by a Customer to access the platform, including frontline workers, supervisors, administrators, executives, compliance personnel, caseworkers, reviewers, or other Customer-authorized personnel.

“Customer Data” means records, content, files, forms, entries, signatures, notes, attachments, reports, logs, metadata, exports, and other information submitted to, generated in, or stored in the platform by or on behalf of a Customer.

“Personal Information” means information about an identifiable individual, including sensitive personal information, personal health information, child/youth service information, staff information, contact information, authentication information, and usage information.

2. Our role

CarePath247 operates primarily as a service provider to our Customers. For most records created inside the platform, the Customer determines why the information is collected, who may access it, how it is used, what regulatory obligations apply, and how long it must be retained. In that context, CarePath247 processes Customer Data on behalf of the Customer and in accordance with the Customer’s configuration, instructions, agreement, and applicable law.

For certain information, such as website inquiries, demo requests, billing contacts, support communications, marketing preferences, security logs, and our own business administration records, CarePath247 determines the purposes for collection and use and acts as the organization responsible for those information practices.

CarePath247 does not provide residential care, foster care, child protection services, health care, clinical services, legal advice, licensing advice, emergency response services, or ministry reporting services. Customers remain responsible for their legal authority to collect, use, disclose, retain, correct, and report personal information entered into the platform.

3. Scope of this Policy

This Policy applies to personal information we handle through:

  • The CarePath247 public website;
  • Demo, contact, onboarding, sales, and support interactions;
  • The CarePath247 platform and related applications;
  • Email, in-app, administrative, security, and service communications;
  • Data migration, configuration, training, and implementation services;
  • Billing, account administration, and customer success activities; and
  • Platform security, audit, analytics, and improvement activities.

This Policy does not replace a Customer’s own privacy notices or information practices. Individuals whose care, placement, employment, or service records are entered into CarePath247 should contact the relevant Customer for access, correction, consent, withdrawal, complaints, or questions about the Customer’s collection and use of those records.

4. Information we collect

We collect only the information reasonably required to provide, secure, support, improve, and administer CarePath247, or as otherwise authorized by the Customer, by the individual, by contract, or by applicable law.

4.1 Website, demo, and contact information

When you visit our website, request a demo, join a founding partner program, contact us, subscribe to updates, or communicate with us, we may collect: name; work email address; phone number; organization name; role or title; program type or agency type; number of homes, programs, users, or clients; province, territory, or region; messages, inquiries, preferences, and feedback; scheduling details for demos or meetings; and related communications.

4.2 Account and user information

When a Customer creates or administers a CarePath247 account, we may collect: Authorized Username; work email address; role, permission level, home, program, or team assignment; authentication, credentials or identifiers; multi-factor authentication status; login history; password reset and account recovery information; system preferences; training and onboarding completion status; and administrative actions taken in the platform.

We do not require Customers to create unnecessary user accounts. Customers are responsible for ensuring that each Authorized User is properly authorized, trained, and assigned an appropriate access role.

4.3 Customer Data entered into the platform

Depending on a Customer’s configuration and use of the platform, Customer Data may include sensitive information such as:

  • Names, dates of birth, identifiers, placement details, home assignments, and demographic information relating to children, youth, residents, or care recipients;
  • Daily logs, communication book entries, shift notes, handover notes, read receipts, staff-on-shift signatures, and supervisory reviews;
  • Safety plans, plans of care, care goals, progress notes, review dates, amendments, and approval histories;
  • Medication administration records, medication tracking information, allergies, health-related observations, and related eMAR documentation;
  • Incidents, serious occurrences, follow-up tasks, approval workflows, ministry-clock tracking, and report preparation records;
  • Foster care records, caregiver records, home studies, matching information, contact directories, and placement-related information;
  • Staff profiles, training records, certifications, expiry dates, policies, acknowledgements, scheduling context, and compliance records;
  • Contact information for parents, guardians, substitute decision-makers, placing agencies, emergency contacts, professionals, or service partners;
  • Personal property inventories and other operational records;
  • Documents, attachments, images, PDFs, spreadsheets, exports, and migrated historical records;
  • Comments, amendments, supervisor approvals, locked records, and revision histories; and
  • Audit logs showing creation, access, viewing, editing, approval, amendment, export, deletion request, or administrative activity.

4.4 Audit, security, device, and usage information

To operate and protect the platform, we may collect technical and usage information, including: IP address; device type; browser type; operating system; approximate location derived from IP address; login and logout times; session duration; authentication events; failed login attempts; pages, screens, records, or modules accessed; actions taken within the platform; export, approval, signature, lock, amendment, or deletion events; system errors and diagnostic logs; and security alerts and access-control events.

Audit logs are a core feature of CarePath247. They are designed to support accountability, compliance, investigation, and audit-readiness. Customers should assume that platform activity may be logged, time-stamped, and retained as part of the platform’s security and audit architecture.

4.5 Support, migration, and training information

When we provide onboarding, configuration, support, migration, or training, we may collect support tickets; troubleshooting details; screenshots or sample records provided by a Customer; configuration requirements; migration files; training attendance and completion information; communications with Customer administrators or Authorized Users; and records of support access or administrative assistance.

Customers should not send sensitive Customer Data to support channels unless required for the support request and authorized by the Customer.

4.6 Payment and billing information

For paid plans, we may collect billing contact information, subscription details, invoices, payment status, tax information, purchase order details, and related financial records. If payment card processing is used, payment card information is processed by our payment service provider. We do not intend to store full payment card numbers on CarePath247 systems.

5. How we collect information

We collect information:

  • Directly from Customers and Authorized Users;
  • Through forms, fields, uploads, imports, signatures, approvals, and workflows in the platform;
  • Through website, demo, support, and onboarding interactions;
  • Automatically through authentication, security, audit, logging, and analytics tools;
  • From service providers acting on our behalf;
  • From Customer-approved integrations, where enabled; and
  • As otherwise permitted or required by law.

Where a Customer enters or imports personal information into CarePath247, the Customer is responsible for ensuring it has appropriate authority, consent, notice, legal basis, or other permission to do so.

6. Purposes for collection, use, and disclosure

We collect, use, and disclose personal information for the following purposes.

6.1 Providing and operating the platform

We use information to create, maintain, and administer Customer accounts; provision Authorized Users; configure homes, programs, roles, forms, workflows, dashboards, reports, and alerts; enable daily logs, incident records, safety plans, plans of care, eMAR, staff compliance, policies, acknowledgements, serious occurrence workflows, reports, and exports; enable signatures, approvals, record locking, tracked amendments, review queues, and audit trails; provide in-app and email notifications; maintain availability, backup, continuity, and disaster recovery; provide Customer support and training; and perform implementation, onboarding, and data migration.

6.2 Security, privacy, compliance, and audit-readiness

We use information to authenticate users; enable multi-factor authentication; enforce role-based access controls; maintain tenant isolation; detect unauthorized access or misuse; investigate suspicious activity; create, maintain, and review audit logs; monitor system performance and availability; prevent fraud, abuse, security incidents, or policy violations; test, maintain, and improve security safeguards; support Customer audits, inspections, investigations, or compliance reviews; and comply with contractual, legal, and regulatory obligations.

6.3 Customer administration, billing, and communications

We use information to respond to inquiries; schedule demos; manage founding partner participation; negotiate and administer agreements; send service, billing, support, security, and administrative notices; provide training and customer success communications; manage subscriptions and invoices; maintain business records; and send marketing communications where permitted by law.

You may unsubscribe from marketing emails using the unsubscribe mechanism included in those communications. We may still send non-marketing service, security, support, account, billing, or legal notices.

6.4 Product improvement and analytics

We may use information to improve platform functionality; identify system errors; improve usability and accessibility; evaluate feature adoption; develop new features; improve onboarding and support; generate aggregated or de-identified statistics; and understand general website and platform performance.

We do not use Customer Data to target advertising to children, youth, residents, care recipients, or Authorized Users. We do not sell Customer Data. We do not use Customer Data to train general-purpose artificial intelligence models unless expressly agreed in writing with the Customer.

6.5 Legal and regulatory purposes

We may use or disclose information where necessary to comply with applicable law; respond to lawful subpoenas, warrants, court orders, regulator requests, or ministry requests; protect the rights, safety, security, or property of CarePath247, Customers, children, youth, residents, staff, Authorized Users, or others; investigate or respond to suspected unlawful conduct, misuse, security incidents, or breaches of contract; obtain legal, accounting, audit, insurance, cybersecurity, or professional advice; enforce agreements; and participate in a business transaction such as a financing, sale, merger, acquisition, reorganization, or transfer of assets, subject to confidentiality and security protections.

7. Children, youth, residents, and care-recipient information

CarePath247 is not a general consumer service directed to children or youth. Children, youth, residents, and care recipients do not ordinarily create their own CarePath247 accounts unless a Customer has expressly configured the platform for that purpose and has authority to do so.

Customers may use CarePath247 to store highly sensitive records about children, youth, residents, and care recipients. Customers are responsible for:

  • Determining whether they have legal authority to collect, use, disclose, and retain the information;
  • Providing required notices to individuals, parents, guardians, substitute decision-makers, placing agencies, regulators, or other relevant parties;
  • Obtaining any required consents;
  • Managing withdrawal of consent or conditions on consent where applicable;
  • Deciding whether access, correction, severance, restriction, or disclosure is permitted or required;
  • Determining whether a record may be disclosed to a ministry, regulator, placing agency, health professional, law enforcement body, parent, guardian, substitute decision-maker, or other third party; and
  • Complying with applicable licensing, child/youth services, health privacy, employment, human rights, and record-retention requirements.

If we receive a request directly from a child, youth, resident, parent, guardian, substitute decision-maker, staff member, or other individual seeking access to or correction of Customer Data, we will ordinarily direct the requester to the relevant Customer or, where appropriate, forward the request to the Customer. We do not make independent determinations about access to Customer-controlled care records except where required by law.

8. PHIPA, CYFSA, and regulated care environments

CarePath247 is designed to support Customers operating in regulated care environments, including environments where Customers may have obligations under Ontario privacy, child/youth services, health privacy, licensing, serious occurrence, accessibility, and related laws.

Where a Customer is subject to the Personal Health Information Protection Act, 2004, the Child, Youth and Family Services Act, 2017, or other sector-specific privacy legislation, the Customer remains responsible for determining its role and obligations under that legislation. CarePath247 will process Customer Data in accordance with the Customer’s agreement and instructions and will implement administrative, technical, and contractual safeguards intended to support confidentiality, integrity, availability, accountability, auditability, and Canadian data-residency expectations.

CarePath247 does not represent that use of the platform, by itself, satisfies all legal, licensing, clinical, ministry, or professional obligations applicable to a Customer. Customers must configure and use the platform in a manner consistent with their own regulatory requirements, policies, consents, notices, and retention schedules.

9. Consent and lawful authority

Where CarePath247 collects personal information for its own purposes, we rely on consent, contractual necessity, legal obligations, legitimate business purposes, or other grounds permitted by applicable law. We seek to identify purposes before or at the time of collection and to collect, use, and disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances.

Where a Customer enters Customer Data into the platform, the Customer is responsible for obtaining and managing any required consent, notice, lawful authority, substitute decision-maker authorization, employment authorization, ministry authority, or other legal basis.

10. Disclosure of information

We may disclose personal information as described below.

10.1 To Customers and Authorized Users

Customer Data is made available to the Customer and its Authorized Users according to the roles, permissions, homes, programs, workflows, and access rules configured by the Customer. Customers are responsible for assigning appropriate access and removing access when no longer required.

10.2 To service providers

We may disclose information to service providers that support hosting, storage, infrastructure, authentication, email delivery, scheduling, customer support, analytics, billing, payment processing, security monitoring, incident response, legal services, accounting, insurance, and other business operations. We require service providers to use personal information only for authorized purposes and to protect it using safeguards appropriate to the sensitivity of the information.

10.3 To regulators, ministries, courts, and legal authorities

We may disclose information where required or permitted by law, including in response to lawful requests from courts, regulators, ministries, law enforcement, government institutions, or other bodies with legal authority. Where the request relates to Customer Data, we will, where legally permitted and commercially reasonable, notify the Customer or direct the requesting authority to the Customer.

10.4 In emergencies or safety-related circumstances

We may disclose information where necessary to respond to an emergency, protect life, health, safety, or security, prevent serious harm, investigate misuse, or protect children, youth, residents, staff, Customers, CarePath247, or others.

10.5 Business transactions

If CarePath247 is involved in a merger, acquisition, financing, reorganization, sale of assets, transfer of business, insolvency process, or similar transaction, personal information may be disclosed to parties and advisors involved in the transaction, subject to confidentiality, security, and legal safeguards. If Customer Data is transferred to a successor, we will do so in accordance with applicable agreements and law.

10.6 Aggregated or de-identified information

We may use or disclose aggregated or de-identified information that does not identify an individual or Customer for analytics, benchmarking, product improvement, research, reporting, or business purposes, provided that we do not attempt to re-identify individuals from that information except as permitted or required by law.

11. Canadian data residency and cross-border access

CarePath247 is built around Canadian data-residency expectations. Customer Data is hosted in Canada (AWS Canada — ca-central-1 region), including backups, unless otherwise agreed in writing with the Customer or required by applicable law.

Some non-Customer Data, such as demo scheduling information, business contact information, billing communications, support metadata, website analytics, or service-provider records, may be processed by service providers located in Canada or other jurisdictions. Where information is processed outside Canada, it may be subject to the laws of that jurisdiction. We use contractual, technical, and organizational safeguards to protect information handled by service providers.

We do not intentionally store children’s care records outside Canada unless expressly agreed with the Customer or legally required.

12. Security safeguards

We use administrative, technical, physical, and contractual safeguards appropriate to the sensitivity of the information we handle. Safeguards may include:

  • Encryption in transit;
  • Encryption at rest;
  • Role-based access controls;
  • Tenant isolation;
  • Multi-factor authentication;
  • Automatic logout after inactivity;
  • Least-privilege access;
  • Audit logging;
  • Append-only or tamper-evident audit trails;
  • Secure backups;
  • Monitoring and alerting;
  • Vulnerability management;
  • Access review procedures;
  • Confidentiality obligations for personnel and service providers;
  • Secure development and change-management practices;
  • Incident response procedures;
  • Data migration safeguards; and
  • Contractual restrictions on service providers.

No system can be guaranteed to be completely secure. Customers and Authorized Users must protect their credentials, use appropriate devices and networks, maintain current access lists, promptly remove users who no longer require access, and notify us immediately of any suspected unauthorized access or security incident.

13. Audit logs, locked records, and amendments

CarePath247 is designed to support record integrity and audit-readiness. Depending on configuration, the platform may lock approved records, track amendments, preserve revision histories, and record who created, viewed, modified, approved, signed, exported, or amended a record and when.

Audit logs and revision histories may not be editable by ordinary users and may be retained for security, compliance, operational, evidentiary, or contractual purposes. Customers should ensure their Authorized Users understand that their platform activity may be recorded.

14. Cookies and similar technologies

Our website and platform may use cookies, local storage, pixels, logs, and similar technologies to operate the website and platform; authenticate users; maintain sessions; support security controls; remember preferences; understand website performance; troubleshoot errors; measure feature usage; and improve services.

We do not use cookies to serve behavioural advertising to children, youth, residents, or care recipients. Browser settings may allow you to block or delete cookies, but some website or platform features may not function properly without necessary cookies.

15. Email and in-app notifications

CarePath247 may send in-app and email notifications relating to documentation, review tasks, compliance deadlines, expiring certifications, unread handover notes, approvals, incidents, serious occurrence workflows, account activity, support, billing, security, and service administration.

Customers are responsible for configuring notifications appropriately and ensuring that notification recipients are authorized to receive the information. We recommend limiting sensitive information in email notifications where possible and using in-platform access controls for detailed records.

16. Data exports, reports, APIs, and integrations

CarePath247 may allow Customers and Authorized Users to generate reports, export records, print records, download PDFs or spreadsheets, migrate data, or connect approved integrations or APIs. Once Customer Data is exported, downloaded, printed, transmitted, or integrated into another system by or on behalf of a Customer, the Customer is responsible for protecting that information outside CarePath247.

Customers should ensure that exports are made only by authorized personnel, for authorized purposes, and in accordance with applicable privacy, licensing, employment, child/youth services, health privacy, and record-retention obligations.

17. Retention and deletion

We retain personal information only as long as reasonably necessary for the purposes described in this Policy, as required by applicable law, or as set out in the applicable Customer agreement.

For Customer Data, retention is generally governed by the Customer’s agreement, configuration, instructions, and applicable legal obligations. CarePath247 does not determine a Customer’s statutory or regulatory record-retention schedule.

Upon termination or expiry of a Customer’s subscription, we may provide an opportunity to export Customer Data and may delete or de-identify Customer Data in accordance with the Customer agreement, our standard retention procedures, and applicable law. Backup copies may persist for a limited period in disaster recovery or backup systems and will be protected from ordinary access until overwritten or deleted in accordance with our normal backup cycle.

We may retain certain records for longer where necessary for security, audit, legal, regulatory, tax, billing, dispute, compliance, backup, or legitimate business purposes.

18. Access, correction, and individual rights

Individuals may have rights to access, correct, or request information about personal information, subject to legal limits.

For Customer Data, requests should be directed to the relevant Customer because the Customer controls the record, determines legal authority, and decides whether access, correction, severance, restriction, or disclosure is permitted or required.

If we receive a request relating to Customer Data, we may refer the requester to the Customer or notify the Customer so the Customer can respond. We may assist the Customer in locating, exporting, correcting, restricting, or deleting Customer Data where required by the Customer agreement or applicable law.

For personal information CarePath247 controls directly, such as demo requests, marketing preferences, billing contact details, support communications, or website records, you may contact us at privacy@carepath247.com. We may need to verify your identity before responding.

19. Accuracy

Customers and Authorized Users are responsible for ensuring that Customer Data entered into the platform is accurate, complete, timely, and updated as required for the Customer’s purposes. CarePath247 provides tools that may help Customers maintain structured records, version history, approvals, review schedules, amendments, and audit trails, but we do not independently verify the accuracy of Customer-entered care records.

Where CarePath247 controls information directly, we take reasonable steps to keep it accurate and up to date for the purposes for which it is used.

20. Privacy incidents and breaches

We maintain incident response procedures to identify, assess, contain, investigate, mitigate, document, and respond to suspected privacy or security incidents.

Where a privacy or security incident involves Customer Data, we will notify the affected Customer in accordance with the Customer agreement and applicable law. Customers are generally responsible for determining whether notification to individuals, regulators, ministries, placing agencies, health information custodians, service providers, insurers, or other parties is required, unless applicable law imposes direct notification obligations on CarePath247.

Where an incident involves personal information under CarePath247’s control, we will assess the incident and provide required notices to affected individuals, regulators, Customers, service providers, or other organizations where required by law.

Customers and Authorized Users must promptly notify us at the contact details below if they suspect unauthorized access, credential compromise, misdirected disclosure, improper export, lost device, or other privacy or security issue involving CarePath247.

21. Automated features and human decision-making

CarePath247 may automate administrative and compliance-support features, such as review queues, deadline tracking, ministry-clock reminders, missing-documentation alerts, certification expiry tracking, and dashboard notifications.

CarePath247 does not make child placement decisions, clinical decisions, licensing decisions, serious occurrence determinations, staffing decisions, employment decisions, or eligibility decisions. Customers remain responsible for professional judgment, regulatory reporting, legal compliance, and human review of records and workflows.

22. Artificial intelligence

Unless expressly agreed in writing with a Customer, CarePath247 does not use Customer Data to train general-purpose artificial intelligence models. If CarePath247 introduces AI-assisted functionality, we will implement it in accordance with applicable law, customer agreements, security safeguards, transparency expectations, and any applicable opt-in or configuration requirements.

23. Accessibility

CarePath247 aims to provide privacy information in a clear, accessible, and usable format. If you require this Policy or related privacy information in an accessible format or need communication support, please contact us.

24. Customer responsibilities

Customers are responsible for:

  • Ensuring they have lawful authority to use CarePath247 for the information they enter;
  • Providing required privacy notices;
  • Obtaining and managing required consents;
  • Configuring homes, programs, users, permissions, roles, notifications, exports, and workflows appropriately;
  • Training Authorized Users;
  • Maintaining confidentiality of credentials;
  • Removing access promptly when personnel change roles or leave;
  • Reviewing audit logs and access rights where appropriate;
  • Ensuring records are accurate and complete;
  • Responding to access, correction, consent, and complaint requests relating to Customer Data;
  • Determining required retention periods;
  • Managing legal holds and litigation holds;
  • Complying with applicable ministry, licensing, child/youth services, health privacy, employment, human rights, and professional obligations; and
  • Notifying CarePath247 promptly of suspected privacy or security incidents.

25. Third-party websites and services

Our website or platform may link to third-party websites, scheduling tools, payment processors, support tools, integrations, or other services. This Policy does not apply to third-party websites or services that are not operated by CarePath247. Customers and users should review the privacy policies and terms of those third parties.

26. Complaints and questions

If you have questions about this Policy or CarePath247’s privacy practices, or if you wish to make a privacy complaint about information under CarePath247’s control, contact the CarePath247 Privacy Office, Paqads Consulting Inc., at privacy@carepath247.com. Please include enough detail for us to understand and respond to your request. We may ask for additional information to verify identity or authority.

If your request relates to records created by a Customer in the CarePath247 platform, we may refer you to that Customer or notify the Customer so that it can respond.

27. Changes to this Policy

We may update this Policy from time to time to reflect changes in our services, security practices, legal requirements, or business operations. The “Last updated” date at the top of this Policy indicates when it was last revised.

If we make material changes, we will provide notice in a manner appropriate to the change, which may include posting the updated Policy on our website, notifying Customers, or providing in-platform notice.

28. Contact

For privacy questions, accessibility requests, security concerns, or data-protection inquiries, contact privacy@carepath247.com.

For urgent security matters involving suspected unauthorized access to the platform, Customers should contact CarePath247 support immediately and include “Security Incident” in the subject line.