Hotline testing

COPD Hotline Tester Privacy Notice

How personal information is handled for invited volunteers testing the educational COPD hotline.

Policies & contents

1. Overview

PhoenixCare Inc. provides an invited, non-research COPD information and education pilot with Respiplus. This notice covers the personal information of patient volunteers using the hotline, including real health information they choose to discuss. It accompanies the Hotline Tester Terms v2.0. It does not govern ordinary website inquiries or authorize a separate clinical-monitoring or research program.

PhoenixCare’s Designated Privacy Officer is Alex Peav. Questions, privacy complaints, and requests concerning your information may be sent to admin@phoenixcare.io.

2. What the hotline does

You speak with an artificial-intelligence assistant providing general COPD information and education, for example about breathing techniques, inhaler use, adherence to an existing care plan, lifestyle measures, smoking cessation and avoiding triggers. AI answers and generated summaries can be incorrect or incomplete; confirm personal medical decisions with your healthcare professional.

The hotline does not diagnose, interpret test results, provide personalized medical advice, recommend medication or treatment changes, replace your healthcare professional, dispatch emergency services, or guarantee an immediate clinician callback.

If you have severe difficulty breathing, severe chest pain, feel faint or lose consciousness, or believe you may be experiencing an emergency, hang up and call 911.

3. Information we may collect

Depending on your call and the pilot features enabled, PhoenixCare may collect or generate:

  • your name and telephone number;
  • your relationship to the patient, such as patient, caregiver, family member, or healthcare professional;
  • your language, caller role, age/guardian confirmation where required, and the audio recording and transcript of the call;
  • the COPD-related information you choose to provide, including symptoms, medication-adherence information, inhaler questions, and feedback;
  • call metadata, such as date, time, duration, and call status;
  • your consent choices and related timestamps;
  • structured feedback, ratings, themes, and safety or clinical-alert information;
  • a phone-linked caller profile or limited health-related summary, including questions, unresolved topics or symptoms mentioned, only for separately consented cross-call continuity when enabled; this information is not anonymous.

Please do not send medical or other sensitive personal information by ordinary email or through the public website’s pilot-request form. Provide it only through the approved pilot and hotline process after receiving this notice.

5. Why we use the information

Core processing is for service delivery and necessary quality, safety and audit activities. Feedback participation, requested follow-up and cross-call recognition/memory are separate optional choices. Depending on those choices and the approved features, information is used to:

  • provide and operate the pilot service;
  • maintain service quality, safety, and an auditable record;
  • allow authorized staff to review safety and quality; arrange a follow-up contact only if you request it or a separately explained lawful care arrangement applies;
  • identify possible safety concerns for later authorized review, without emergency dispatch, continuous monitoring or a guaranteed clinician callback;
  • evaluate optional feedback about clarity, usefulness and experience, with the choice to skip feedback questions;
  • troubleshoot the service and use aggregated feedback themes for improvement;
  • support returning-caller continuity when separately consented to and enabled;
  • meet legal, privacy, security, and audit obligations.

PhoenixCare does not sell hotline personal information or use it for behavioural advertising. This notice does not authorize identifiable testimonials, unrelated marketing, research or training a provider’s general-purpose AI models on identifiable call content. A new purpose requires privacy-assessment and agreement review, a lawful basis and any further consent required. Optional refusals remain effective on future calls.

6. Service providers and processing outside Quebec

The documented hotline technology options include the providers below. The route selected for your test may use a subset; inclusion in this list is not permission to use every provider for every purpose. Before enrollment, the coordinator must identify the providers used for the selected route, including any material changes, and provide that information on request:

  • Twilio for telephone transport and call recording;
  • AWS for application processing, AI services, databases, queues, caches, and file storage;
  • Deepgram or AWS services for speech-to-text processing;
  • ElevenLabs or AWS services for text-to-speech processing;
  • OpenAI for configured AI, voice or post-call analysis functions, or AWS Bedrock for configured AI functions;
  • Vercel for the clinical dashboard and related web-hosting functions;
  • Google Workspace for authorized pilot communications and documents.

Hotline providers may process personal information in the United States, outside Québec and Canada, where different laws and lawful government-access rules may apply. Cross-border processing requires the applicable privacy assessment and written safeguards. Provider use must be limited to the disclosed service purposes; this notice does not itself establish that a particular provider’s contract, retention or training settings have been approved.

Authorized Respiplus coordination and quality/safety personnel may access information needed for their assigned pilot roles. Participating clinic staff receive identifiable information only where your applicable program and disclosed care arrangement justify that access. Advisory reviewers without a need for identifiable data receive aggregated or properly de-identified themes. Reporting or advisory access does not create continuous clinical monitoring or an immediate response service.

7. Retention and deletion

The proposed tester schedule follows the privacy impact assessment’s 12-month baseline: recordings, transcripts and related call content are kept only as long as needed for the disclosed purposes and normally no later than 12 months after the relevant call. This is an organizational schedule, not a general legal rule requiring every call to be kept for a year. Where information is actually used to make a decision about you, a statutory minimum may apply. A health-record requirement, legal hold or specific investigation can justify a different period; the reason and applicable period must be documented.

Temporary copies, caches and optional caller memory may expire earlier. A short cache lifetime does not mean the recording or transcript elsewhere has been erased. Keeping a new summary must not restart the retention clock for older call content. Limited consent, access, security and audit records may have separate schedules or legal requirements. Backup copies must remain access-restricted and expire under the applicable backup schedule; they are not a basis for indefinite active use.

When the purpose and applicable retention requirement end, PhoenixCare must coordinate secure destruction or legally compliant anonymization across the systems and processors holding the information. Removing a name alone is not anonymization, and withdrawal does not promise immediate erasure of all copies. The Privacy Officer can explain the category-specific schedule, any retention exception and the handling of a deletion request. This proposed retention schedule is not yet in effect.

8. Who may access the information

Access is limited by role and need: PhoenixCare’s Privacy Officer and authorized technical/operations staff, designated Respiplus coordination and quality/safety personnel, participating clinic personnel where applicable to your explained program, and contracted service providers supporting the selected route. An adviser’s involvement does not automatically permit access to identifiable calls; research-only roles are outside this test.

Safeguards and material risks: required safeguards include restricted access, appropriate encryption, audit logging, confidentiality duties and processor controls. No system is risk-free. Audio and phone-linked summaries can identify you; mistaken transcription, inaccurate AI summaries, an incorrectly matched shared phone number, unauthorized access or cross-border disclosure could expose sensitive information or mislead a user. This tester design requires minimization, identity verification before using history, and limits on access and purposes. Do not share unnecessary details about yourself or other people.

9. Your choices and rights

Subject to applicable law, you may:

  • ask whether PhoenixCare holds personal information about you;
  • request access to or correction of that information;
  • withdraw consent to future optional recognition, saved health memory, feedback or requested follow-up, and stop participating in the recorded test;
  • ask PhoenixCare to delete information that is no longer required, subject to legal restrictions;
  • ask about the service providers and countries involved in processing;
  • raise a privacy complaint with PhoenixCare;
  • contact the Commission d’accès à l’information du Québec or the Office of the Privacy Commissioner of Canada.

Send privacy requests to admin@phoenixcare.io. We verify identity promptly and respond diligently to access and correction requests within 30 days of receiving the request, as required by applicable law; identity verification does not restart that period. We explain any lawful refusal or retention restriction and available recourse. Ask for a secure channel before sending identity documents or health details by email.

10. Service questions

The planned tester window is 9:00 a.m. to 5:00 p.m. Eastern Time; use the number and arrangements confirmed by your coordinator. This is not continuous clinical supervision. For technical or accessibility help, contact hello@phoenixcare.io. That address is not an emergency service or a channel for personal medical advice.

11. Changes to this notice

The approved notice and its version must be provided through the tester enrollment process in an accessible form and language. Ask the coordinator or Privacy Officer for a copy. Material changes to purposes, providers or practices must be explained before they apply, with renewed consent when required. A website link is not a substitute for delivering an accessible notice.

Questions about your privacy?

Contact PhoenixCare’s Designated Privacy Officer.

admin@phoenixcare.io

Please do not include medical information in ordinary email.