Privacy Policy

Effective: November 15, 2025

1) Who we are & scope

Logos & Legere Psychotherapy (“we,” “us,” “our”) provides virtual psychotherapy to clients physically located in Ontario. This Policy explains how we collect, use, disclose, safeguard, and retain personal information and personal health information (PHI) in our practice and on our website.

Contact: Email: weber@legostherapy.ca Phone: (343) 789-2127

2) Our legal obligations

We are a Health Information Custodian (HIC) under Ontario’s Personal Health Information Protection Act, 2004 (PHIPA). We also meet applicable obligations under PIPEDA (federal) for personal information handled in the course of commercial activity (e.g., billing; website inquiries).

3) Definitions (plain language)

  • Personal Health Information (PHI): Identifying information about your health, the care you receive, your health number, insurance/claims, and related details maintained in your clinical record.
  • Health Information Custodian (HIC): The regulated party responsible for PHI—Logos & Legere Psychotherapy / Roja Weber as the practitioner.
  • Agent: A person or service acting on our behalf (e.g., administrative support, supervised students/contractors, practice technology vendors) who may handle information under our direction and confidentiality obligations.

4) What we collect

  • Clinical/PHI: Intake information, clinical notes, care plans, referral information, invoices/claims that include PHI.
  • Identity & admin: Name, contact details, language preferences, appointment and payment details.
  • Insurance & direct billing: Insurer name, member ID/plan details, claim information you authorize us to submit.
  • Website & communications: Contact-form submissions, email/SMS you send us; basic technical data (IP address, browser/device type, general location) and cookies/analytics necessary for site functionality and performance.

5) Why we collect & how we use information

  • Care delivery: Assessment, treatment, documentation, coordination of care, reminders, and practice administration.
  • Billing: Payment processing and direct billing to participating insurers with your authorization (we disclose only what’s necessary to process a claim).
  • Compliance: Legal and regulatory duties (e.g., record-keeping, audits, supervision/quality assurance).
  • Communication: Scheduling, service updates, policy changes, and responses to your inquiries.
  • Website: To operate, secure, and improve the site (limited analytics and essential cookies; see §13).

6) Consent

We seek informed, knowledgeable consent to collect, use, and disclose information except where permitted or required by law (e.g., risk of serious harm, abuse/neglect reporting, court orders). You can withhold or withdraw consent—we will explain implications (e.g., limits on direct billing or coordination with other providers). We may discuss “lock-box” preferences that limit how specific information is shared (subject to legal limits).

7) Disclosures (who sees your information)

We disclose only what’s necessary:

  • With your consent: to insurers for claims; to your family physician/other providers; to a person you designate.
  • Without consent (as permitted/required by law): to prevent/reduce risk of serious harm; child protection; court orders; regulatory investigations; and other PHIPA-authorized disclosures.

8) Youth & teens

Capacity and consent are assessed individually. We explain confidentiality and its limits in plain language. With the young person’s consent, we may share general progress with parents/guardians; session specifics remain private unless safety or law requires otherwise.

9) Your rights

Subject to limited exceptions under PHIPA, you can request access to your record and request corrections to incomplete or inaccurate information. We will respond within reasonable timelines and document outcomes. You may ask questions or lodge a concern with us at any time (see §17).

10) Retention & destruction

We keep clinical records for the period required by law and regulatory standards (e.g., generally 10 years from the date of last contact, or from a youth’s 18th birthday + 10 years), then securely destroy them (e.g., certified deletion for electronic records; cross-cut shredding for paper).

11) Safeguards (administrative, technical, physical)

We maintain safeguards appropriate to virtual health care and psychotherapy:

  • Administrative: Confidentiality undertakings; least-necessary access; training for agents; privacy-protective defaults; audit logs and periodic reviews.
  • Technical: Encrypted devices; strong passwords and access controls; routinely updated systems; secure/cloud platforms for EMR and video; recommended anti-virus/firewall; privacy-first configuration.
  • Physical: Controlled access to any workstations; secure storage; no unattended records; safe disposal of media/hardware.
  • Virtual-care best practices: Private space, headphones where possible, identity verification at the first visit, meeting settings that prevent unauthorized access.

12) Platforms & processors

We use reputable, privacy-appropriate tools (e.g., practice management/EMR, secure video platform, email/SMS services). Each acts as our agent/processor and is bound by confidentiality and/or data-processing terms. We configure tools for privacy-protective defaults and least-necessary data.

13) Website, cookies & analytics

Our site may use essential cookies and limited analytics (e.g., page performance, navigation) to operate and improve the site. You can manage cookies in your browser. We don’t use testimonials or client reviews in advertising. If we use third-party analytics (e.g., Google Analytics), their cookies may collect IP address and device information—see their privacy pages for details. You can opt out by adjusting browser settings or using widely available add-ons.

14) Email, SMS & calls

Email and SMS are convenient for admin matters (scheduling, reminders, practice updates), but not ideal for sensitive content. By providing contact details, you consent to admin communications; you can adjust preferences or opt out of non-essential messages at any time. We avoid sensitive clinical details by email/SMS and use secure platforms when needed.

15) Direct billing & insurance

With your written authorization, we may submit claims to your insurer. We disclose only the minimum information necessary to process the claim. You’re responsible for any amounts not covered by your plan.

16) Privacy breaches — what happens if something goes wrong

We follow a four-step breach protocol consistent with Ontario guidance: (1) Notify our Privacy Officer and assess; (2) Contain the breach; (3) Notify affected individuals (and, where required, the IPC/regulator/insurer); (4) Investigate and remediate (including policy/technical updates and training). We keep a record of all breaches and audits. If a breach poses a real risk of significant harm, we will notify you promptly and explain your options.

17) Questions, access/correction requests, concerns

Questions, access/correction requests, or privacy concerns can be directed to weber@legostherapy.ca. You may also contact the Information and Privacy Commissioner of Ontario about PHIPA matters. We will provide contact details upon request.

18) Service location & jurisdiction

We provide psychotherapy to clients physically in Ontario at the time of session. Our records are stored in Canada or in jurisdictions with comparable safeguards and contractual protections. Cross-border storage (if any) is disclosed and managed with comparable protections and PHIPA-compliant agreements.

19) Changes to this Policy

We may update this Policy to reflect legal, technical, or practice changes. We’ll post the new Effective date at the top. Substantive changes that affect how we handle your information will be communicated where appropriate.

Not an emergency service. If you are in immediate danger or crisis, call 911 or go to the nearest emergency department. This practice does not provide emergency or on-call services.