Privacy & Terms
How Soma protects your data and the terms that govern our platform.
All documents are maintained with transparency and updated regularly.
Advertising measurement. With your consent, this website sets first-party cookies (_fbp, _eid, _fbc, _gclid, _wbraid, _gbraid, _rdt_cid and _utm_*) and loads measurement tools from Meta, Google and Reddit, so we can see which ads bring clinicians to Soma. Hashed contact details are sent to those platforms for the same purpose. None of it involves your clients or your clinical work.
Nothing is set until you choose, and you can change your mind at any time:
Privacy Policy
How Soma protects your data and handles personal information
Soma Professional Privacy Policy
Effective Date: August 23, 2026 | Version: 2.1
1. Introduction and Scope
Soma Health Solutions Inc. ("Soma," "we," "us," or "our") provides a documentation and workflow platform designed for therapists, counselors, and other licensed practitioners. This Privacy Policy describes how we collect, use, disclose, retain, and protect personal information in connection with our products and services.
This policy applies to:
- The Soma web application (soma-health.ca and associated domains)
- All related APIs, integrations, and services
- Our public website and marketing pages
Soma is a B2B software-as-a-service (SaaS) platform. We are not a clinical practice, and we do not provide clinical services. We build documentation and workflow tools that help licensed practitioners work more efficiently.
We are committed to complying with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation. This policy addresses all ten fair information principles set out in Schedule 1 of PIPEDA.
2. Definitions
Throughout this policy, the following terms have specific meanings:
- Personal Information means information about an identifiable individual, as defined under PIPEDA. This includes name, email address, professional credentials, and any data that can identify a specific person.
- Customer means a therapist, counselor, or other licensed practitioner who creates an account and subscribes to Soma's services.
- End User means any individual (including a Customer's client) whose information is handled through Soma's services by their practitioner.
- Clinical Data means information relating to a practitioner's professional practice, including session transcripts, AI-generated note drafts, and documentation created through the platform.
- Client Data means information relating to a Customer's client that the Customer brings into Soma, such as documents, transcripts, and session content, handled as Clinical Data under this policy.
- Alias means the pseudonymous identifier that a Customer assigns to each of their clients within the platform. Soma does not require or request client real names.
- Sub-processor means a third-party service provider engaged by Soma to process data on our behalf in the delivery of our services.
3. Privacy Officer
Soma has designated a Privacy Officer who is accountable for our compliance with this policy and with PIPEDA. Our Privacy Officer is responsible for receiving and responding to all privacy-related inquiries, access requests, and complaints.
Privacy Officer: Ian Vardy
Email: privacy@soma-health.ca
General Support: support@soma-health.ca
Mailing Address: Soma Health Solutions Inc., 100 Signal Hill Road, St. John's, NL, A1A 1B3, Canada
4. Information We Collect
We collect different categories of information depending on how you interact with our platform. We limit our collection to what is necessary for the identified purposes described in Section 6.
4.1 Customer Account Information
When a practitioner creates a Soma account, we collect:
- Full name and professional credentials
- Email address
- Practice name and address (if provided)
- Professional license or registration information (if provided)
- Billing and payment information (processed by our payment processor; we do not store full payment card numbers)
- Account preferences and settings
4.2 Clinical Data (Processed on Behalf of Customers)
When Customers use our documentation and workflow tools, the following data is created and stored within their account:
- Client aliases (pseudonymous identifiers created by the Customer)
- Session transcripts generated from real-time audio processing
- AI-generated note drafts (SOAP, DAP, BIRP, and other formats)
- Notes and documentation created or edited by the Customer
Alias-Based Anonymity: Client data within Soma is organized under aliases, not real names. Soma does not require, request, or store the real names of a Customer's clients. We strongly recommend that Customers use non-identifying aliases. If a Customer chooses an alias that could identify an individual, that decision is outside our control.
4.3 End User (Client) Data
Soma has no direct relationship with End Users and does not collect information from them. Client information reaches Soma only through the practitioner — documents, transcripts, and session content the practitioner brings into the platform — and is handled as Clinical Data under Section 4.2, associated with the alias assigned by the Customer rather than with identifying information held by Soma.
4.4 Website Visitor Data
When you visit our website (soma-health.ca), we may collect:
- IP address and approximate geographic location
- Browser type, operating system, and device information
- Pages visited, referral source, and time spent on each page
- Information submitted through contact forms or demo requests
5. How We Collect Information
We collect information through three channels:
5.1 Directly from You
Information you provide when creating an account, configuring settings, entering data into the platform, or contacting us for support.
5.2 Automatically
Technical and usage data collected through server logs, cookies, and analytics tools when you interact with our platform and website. See Section 18 for details on cookies and tracking technologies.
5.3 Through Integrations
Soma does not currently receive data through third-party integrations. If integrations are introduced, this policy will be updated before any data is received through them.
6. Purposes for Collection, Use, and Disclosure
We identify the purpose for collecting personal information at or before the time of collection. We use and disclose personal information only for the purposes identified below, or for purposes that a reasonable person would consider appropriate in the circumstances.
6.1 Customer Account Information
- To create, manage, and authenticate your account
- To process billing and payments
- To communicate about your subscription, platform updates, and service-related matters
- To provide technical support
- To verify professional credentials when required
- To measure the effectiveness of our advertising, limited to whether an account began a trial or became a paying subscription, and never involving client or clinical data (see Section 18.3)
6.2 Clinical Data
- To provide real-time transcription services
- To generate AI-assisted documentation at the Customer's request
- To store and organize documentation within the Customer's account
- To enable data export and portability
6.3 End User (Client) Data
- To process client information the practitioner brings into the platform, on the practitioner's instructions, as Clinical Data
- To de-identify that information before any AI-assisted processing
6.4 Website Visitor Data
- To analyze website traffic and improve our website content
- To measure the effectiveness of advertising campaigns
- To respond to inquiries submitted through contact forms
6.5 All Data Categories
- To maintain platform security, detect fraud, and prevent unauthorized access
- To improve our products and services using aggregated, de-identified data
- To comply with legal obligations, respond to lawful requests, and enforce our agreements
7. Consent
We rely on meaningful consent as the basis for collecting, using, and disclosing personal information. The form of consent depends on the sensitivity of the information and the reasonable expectations of the individual.
7.1 Express Consent
We obtain express, affirmative consent before:
- Processing audio during a session (Customers must confirm client consent before initiating recording)
- Using clinical data for any purpose beyond providing the requested services
- Sharing any personal information with third parties beyond our sub-processors
7.2 Implied Consent
By creating an account and using the platform, you consent to the collection and use of account information and usage data as described in this policy, and to our use of essential cookies necessary for the platform to function.
7.3 Withdrawing Consent
You may withdraw consent at any time, subject to legal or contractual restrictions, by:
- Contacting our Privacy Officer at privacy@soma-health.ca
We will inform you of the implications of withdrawing consent. In some cases, withdrawing consent may limit or prevent our ability to provide certain features of the platform.
8. How We Use Information
We use personal information only for the purposes identified in Section 6, or for purposes that are directly related and that you would reasonably expect. Specifically:
- Service Delivery: Operating the platform, processing transcriptions, generating document drafts
- Communication: Sending service-related notifications, responding to support inquiries, and providing account updates
- Platform Improvement: Analyzing aggregated, de-identified usage patterns to improve features and user experience
- Security: Monitoring for unauthorized access, detecting anomalies, and maintaining the integrity of our systems
- Legal Compliance: Fulfilling our obligations under applicable laws and regulations
We do not sell personal information. We have never sold personal information to third parties, and we will not do so in the future. We are not in the data brokerage business. Our revenue comes solely from subscription fees for our platform.
9. AI-Assisted Features and Transparency
Soma uses artificial intelligence to assist with generation and documentation workflows. We believe in full transparency about how AI is used within our platform.
9.1 AI Infrastructure
Soma's AI-assisted features are powered by enterprise-grade large language models hosted within our managed cloud infrastructure. When a Customer requests AI-generated documentation, relevant case data is processed through our AI pipeline under strict access controls. Our AI providers operate under data processing agreements with Soma and are bound by confidentiality obligations.
9.2 Zero-Day AI Data Retention
Three things, stated plainly:
- No data of yours is ever used to train a third party's AI models. Not your documents, not your chats, not your session notes, not your transcripts, not anything derived from them. This is contractual with every AI provider we use.
- Soma never trains on your clients' data — identifiable or anonymized. No client information, in any form, is used to train, fine-tune, or improve any model, ours or anyone else's.
- Soma may use anonymized, aggregated data to improve its own, non-third-party models — so the service keeps getting better for you. Anonymized to industry standards, so that the data cannot reasonably be re-identified to any person or to your practice. This is permitted by Section 4.5 of our Terms of Service.
Data sent to our AI infrastructure for document generation is processed in real time for the sole purpose of generating the requested output. It is not stored, cached, logged, or retained by the AI provider after the response is delivered.
9.3 Human Review Required
All AI-generated documentation drafts are clearly labeled as drafts. They are presented to the Customer for review, editing, and approval before being finalized. Soma does not make autonomous decisions about clinical documentation. The licensed practitioner retains full responsibility for reviewing, editing, and approving any AI-generated content before incorporating it into their professional records.
9.4 Real-Time Audio Processing
Audio is never stored. When a Customer uses the session transcription feature:
- The Customer must first obtain explicit consent from the individuals being recorded
- Audio is streamed and processed in real time to generate a text transcript
- Audio data is immediately discarded after processing and is never written to persistent storage
- Only the resulting text transcript is retained within the Customer's account
- Neither Soma nor any sub-processor retains audio recordings
10. Data Custodianship and Processing Roles
Understanding the respective roles of Soma and our Customers is important for clarity about data responsibilities.
10.1 The Customer as Custodian
The licensed practitioner (Customer) is the custodian of all clinical data and client data entered into or generated through the platform. The Customer determines what data to enter, how to use the platform's features, and how the resulting documentation is incorporated into their professional practice. Customers are responsible for obtaining all necessary consents from their clients, complying with their professional regulatory obligations, and managing their clinical records in accordance with applicable law.
10.2 Soma as Processor
Soma processes clinical data and client data on behalf of and under the instructions of the Customer. We do not independently determine the purposes of processing clinical data. We access clinical data only as necessary to provide the services, to maintain and improve the platform, and to comply with legal requirements. Our role is analogous to that of a data processor: we provide the tools, and the practitioner directs how they are used.
11. Information Sharing and Disclosure
We limit the disclosure of personal information to circumstances that are necessary for delivering our services or required by law.
11.1 Sub-processors
We engage trusted third-party sub-processors to support our operations, including:
- Cloud infrastructure: For secure hosting and data storage
- AI services: Enterprise-grade language model providers for AI-assisted documentation, operating under zero-day data retention agreements
- Payment processing: For billing and subscription management
- Analytics and monitoring: For aggregated, de-identified usage analysis, and error monitoring across the website and platform — monitoring runs on our own infrastructure, with reports filtered so they cannot contain clinical content
All sub-processors are bound by written agreements that require them to protect personal information to a standard comparable to this policy. Sub-processors may only process data for the specific purposes we define.
11.2 Legal Requirements
We may disclose personal information when required by law, regulation, court order, or other lawful process. Where legally permitted, we will notify the affected individual before making such a disclosure. We will challenge any request that we believe to be overbroad, vague, or otherwise improper.
11.3 Business Transfers
In the event of a merger, acquisition, or sale of substantially all of our assets, personal information may be transferred to the successor organization. We will provide notice of any such transfer and ensure that the successor is bound by commitments consistent with this policy.
11.4 Practitioner-Client Sharing
Client information in Soma is brought in and managed by the practitioner. The practitioner is responsible for managing that information in accordance with their professional and legal obligations, including anything they choose to share with their client outside the platform.
12. International Data Transfers and Data Residency
Soma Health Solutions Inc. is incorporated and headquartered in St. John's, Newfoundland and Labrador, Canada. Our primary data storage and processing infrastructure is located in Canadian data centers.
Certain sub-processors (such as our AI infrastructure providers) may process data in the United States or other jurisdictions. When data is transferred outside Canada, we ensure that:
- The transfer is necessary to provide the requested services
- The sub-processor is bound by contractual obligations to protect the data
- The level of protection is comparable to that required under Canadian privacy law
If you are located outside of Canada and use our platform, your data will be transferred to and processed in Canada, which is subject to Canadian privacy laws.
13. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. The following retention periods apply:
| Data Category | Retention Period |
|---|---|
| Account data (name, email, credentials) | Duration of active account + 60 days after termination |
| Session transcripts | Auto-deleted 30 days after last activity by default. Practitioners may override this default to extend retention as needed for their professional record-keeping obligations. Practitioners may also manually delete transcripts at any time. |
| Audio recordings | Never stored. Processed in real time only; immediately discarded. |
| AI-generated note drafts | Auto-deleted 30 days after last activity by default. Practitioners may override this default to extend retention. Manually deletable at any time. |
| Usage analytics | 12 months (rolling) |
| Error and performance logs | 90 days |
| Backup data | 30 days after deletion of the primary data |
Upon account termination, Customers have 60 days to export their data. After the 60-day period, all account data, clinical data, and associated records are permanently deleted from our production systems. Backup copies are purged within 30 days of primary deletion.
14. Security Safeguards
We protect personal information with technical, organizational, and physical safeguards appropriate to the sensitivity of the information. Our security measures include:
14.1 Technical Safeguards
- Encryption at rest: All stored data is encrypted using AES-256 encryption
- Encryption in transit: All data transmitted between your device and our servers is protected by TLS 1.2 or higher
- Application-level encryption: Sensitive fields (such as session transcripts and clinical content) are encrypted at the application layer in addition to storage-level encryption
- Secure authentication: Support for multi-factor authentication and secure session management
- Audit logging: Comprehensive logging of data access and administrative actions
14.2 Organizational Safeguards
- Role-based access control (RBAC): Access to personal information is restricted to authorized personnel on a need-to-know basis
- Confidentiality agreements: All employees and contractors are bound by confidentiality obligations
- Security training: Team members receive training on data protection and secure handling practices
- Vendor management: Sub-processors are evaluated for security practices before engagement and are bound by contractual data protection requirements
14.3 Infrastructure Safeguards
- Canadian data center hosting with physical access controls
- Redundant backups with encrypted storage
- Regular security monitoring and vulnerability assessments
- Incident detection and response procedures
15. Data Breach Notification
In the event of a breach of security safeguards involving personal information, Soma will take the following steps in accordance with PIPEDA's mandatory breach reporting requirements:
15.1 Assessment
We will promptly assess the breach to determine whether it creates a real risk of significant harm to any individual. Factors considered include the sensitivity of the information involved, the probability that the information has been or will be misused, and the potential consequences for affected individuals.
15.2 Notification
If a breach creates a real risk of significant harm:
- Affected individuals: We will notify you as soon as feasible, and in any event within 72 hours of confirming the breach
- Office of the Privacy Commissioner of Canada (OPC): We will report the breach to the OPC as required under PIPEDA
- Other organizations: We will notify any other organization or government institution that may be able to reduce the risk of harm
15.3 Notification Contents
Breach notifications will include:
- A description of the circumstances of the breach
- The date or time period during which the breach occurred
- A description of the personal information involved
- Steps we have taken and are taking to reduce the risk of harm
- Steps you can take to mitigate potential harm
- Contact information for our Privacy Officer
15.4 Record Keeping
We maintain records of all breaches of security safeguards, regardless of whether they meet the threshold for reporting. These records are retained for a minimum of 24 months and are available to the OPC upon request.
16. Your Rights
Under PIPEDA and applicable provincial legislation, you have the following rights regarding your personal information:
16.1 Right of Access
You have the right to request access to the personal information we hold about you. Upon receiving a written request and verifying your identity, we will provide you with an account of the information in our possession, how it has been used, and to whom it has been disclosed. We will respond to access requests within 30 calendar days of receipt.
16.2 Right of Correction
If any personal information we hold about you is inaccurate or incomplete, you have the right to request a correction. You can update most account information directly through the platform. For corrections that cannot be made through the platform, contact our Privacy Officer.
16.3 Right of Deletion
You may request the deletion of your personal information. We will delete or de-identify the information, except where retention is required by law or is necessary for the completion of a transaction or the fulfillment of a legal obligation. Deletion requests are processed within 30 calendar days.
16.4 Right of Data Portability and Export
You have the right to receive a copy of your personal information in a structured, commonly used, and machine-readable format. This includes session transcripts, note drafts, client records, and account data. Export functionality is available through the platform, and additional formats can be requested from our Privacy Officer.
16.5 How to Make a Request
To exercise any of these rights, contact our Privacy Officer:
- Email: privacy@soma-health.ca
- Mail: Soma Health Solutions Inc., 100 Signal Hill Road, St. John's, NL, A1A 1B3, Canada
We will acknowledge receipt of your request within 5 business days and provide a substantive response within 30 calendar days. If we require additional time, we will notify you of the reason for the delay. There is no fee for making a request, except in cases where requests are manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee.
17. Automated Decision-Making and AI
Soma uses AI to generate draft documentation based on session transcripts and practitioner input. This section explains how automated processing works within our platform.
17.1 What AI Does
AI-assisted features generate structured documentation drafts — assessment reports, clinical notes (in formats such as SOAP, DAP, and BIRP), summaries and letters — from session transcripts, documents, and practitioner inputs. These drafts are intended to reduce documentation burden by providing a starting point and suggestions that the practitioner can review, edit, and finalize.
17.2 What AI Does Not Do
- AI does not make clinical decisions or recommendations
- AI does not autonomously finalize or submit documentation
- AI does not profile individuals or make predictions about them
- AI-generated content is never treated as a final record without human review
17.3 Human Oversight
Every AI-generated draft requires review and explicit approval by the licensed practitioner before it is saved as a completed record. The practitioner has full control to edit, reject, or regenerate any draft. This ensures that professional judgment remains the final authority over all documentation.
18. Cookies and Tracking Technologies
We use cookies and similar technologies on our website and platform for the following purposes:
18.1 Essential Cookies
Required for the platform to function properly. These handle authentication, session management, and security. They cannot be disabled without impairing platform functionality.
18.2 Analytics Cookies
We use analytics tools on our public website to understand how visitors find and use our site. This data is aggregated and does not identify individuals. Analytics cookies are not used within the authenticated platform application.
18.3 Advertising Measurement
We measure how well our advertising works, so we know which campaigns bring clinicians to Soma.
On our public marketing website, this uses first-party cookies (named in Section 18.1) together with server-side measurement.
Within the platform, we do not run advertising pixels, load advertising scripts, or set advertising cookies.
We report subscription milestones to an advertising platform only if you have asked us to. This is off unless you tick the optional box when you create your account, and you can switch it off at any time in Settings — it takes effect immediately. It is never a condition of using Soma, and nothing about the product changes either way.
When it is on, what we send is a record that an account reached a subscription milestone — that a trial began, or that a subscription was paid. That record identifies you by your own account email address in hashed (irreversible) form and, where you reached us from an advertisement, by the identifier of that advertisement click. Where relevant it includes the subscription amount.
We never send any client, clinical, session, document, or case content to an advertising platform. Nothing you create in Soma, and nothing about the people you work with, forms any part of an advertising signal. This measurement concerns your own subscription to Soma and nothing else.
To turn it off, use the Advertising measurement switch in Settings. Because this happens on our servers rather than in your browser, clearing cookies or changing browser settings does not affect it — the Settings switch is what stops it. You can also email privacy@soma-health.ca and we will do it for you.
18.4 Managing Cookies
You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. Please note that blocking essential cookies will prevent you from using certain features of the platform.
19. Children's Privacy
Soma's platform is designed for use by licensed practitioners. We do not knowingly collect personal information directly from children under the age of 13.
If a practitioner works with minor clients, the practitioner is responsible for:
- Obtaining appropriate parental or guardian consent as required by law and professional standards
- Using non-identifying aliases for minor clients within the platform
- Complying with all applicable laws regarding the privacy of minors
If we become aware that we have inadvertently collected personal information from a child under 13 without appropriate consent, we will take prompt steps to delete that information.
20. Wearable Device Data
Soma does not collect wearable device data. If wearable integrations are introduced in the future, this policy will be updated before any such data is collected, with explicit consent requirements described at that time.
21. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, our products, or applicable law.
- Material changes (changes that reduce your privacy protections or introduce new categories of data collection) will be communicated via email at least 30 days before they take effect. You will have the opportunity to review the changes and, if you disagree, to close your account before the changes become effective.
- Non-material changes (clarifications, formatting updates, or changes that do not reduce your rights) will be posted on this page with an updated effective date.
We encourage you to review this policy periodically. The effective date at the top of this page indicates when the policy was last revised.
22. Complaint Process
If you believe that Soma has not handled your personal information appropriately or has not complied with this policy, you have the right to challenge our compliance.
22.1 Internal Complaint Process
Please direct your complaint to our Privacy Officer:
- Email: privacy@soma-health.ca
- Mail: Soma Health Solutions Inc., 100 Signal Hill Road, St. John's, NL, A1A 1B3, Canada
We will acknowledge receipt of your complaint within 5 business days. Our Privacy Officer will investigate the matter and provide a written response within 30 calendar days. If additional time is needed, we will inform you of the reason and the expected timeline.
22.2 Office of the Privacy Commissioner of Canada
If you are not satisfied with our response, or if you wish to file a complaint directly, you have the right to contact the Office of the Privacy Commissioner of Canada:
- Website: www.priv.gc.ca
- Toll-free: 1-800-282-1376
- Address: 30 Victoria Street, Gatineau, Quebec, K1A 1H3, Canada
23. Contact Information
For any questions, concerns, or requests related to this privacy policy or our handling of your personal information, please contact us:
Soma Health Solutions Inc.
Privacy Officer: Ian Vardy
Privacy Inquiries: privacy@soma-health.ca
General Support: privacy@soma-health.ca
Mailing Address: 100 Signal Hill Road, St. John's, NL, A1A 1B3, Canada
Jurisdiction: Province of Newfoundland and Labrador, Canada
24. Legal Relationship
This Privacy Policy forms part of our Terms of Service. By creating an account or using the Soma platform, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your personal information as described in this policy.
In the event of a conflict between this Privacy Policy and the Terms of Service, the Terms of Service shall prevail, except where doing so would result in a reduction of the privacy protections described herein.
25. Customer Responsibilities
As a licensed practitioner using the Soma platform, you hold certain responsibilities with respect to data privacy:
- Client consent: You are responsible for obtaining informed consent from your clients before using recording, transcription, or any other feature that requires it
- Professional review: You must review all AI-generated content before incorporating it into your professional records
- Alias management: You should use non-identifying aliases for clients. If you choose an alias that could identify a client, that risk is your responsibility
- Regulatory compliance: You are responsible for complying with the regulatory requirements of your profession and jurisdiction, including record retention obligations that may extend beyond the periods described in this policy
26. Accuracy of Personal Information
We take reasonable steps to ensure that personal information in our possession is accurate, complete, and up to date for the purposes for which it is used.
- Customers can update their account information (name, email, credentials, practice details) directly through the platform at any time
- If you identify an inaccuracy in information that cannot be corrected through the platform, contact our Privacy Officer and we will make the correction promptly
- Where we are unable to make a requested correction (for example, where the information is accurate as recorded), we will note the disagreement on file
Soma Health Solutions Inc.
100 Signal Hill Road, St. John's, NL, A1A 1B3, Canada
This policy is effective as of August 23, 2026.
This policy addresses all ten fair information principles under Schedule 1 of PIPEDA: Accountability (Section 3), Identifying Purposes (Section 6), Consent (Section 7), Limiting Collection (Section 4), Limiting Use, Disclosure, and Retention (Sections 8, 11, 13), Accuracy (Section 26), Safeguards (Section 14), Openness (this policy in its entirety), Individual Access (Section 16), and Challenging Compliance (Section 22).
This document is automatically synchronized from our source repository.
For the most current version, please refresh this page.
Based in Canada. Working Globally.
Headquartered in Newfoundland & Labrador. Supporting clinicians across North America and beyond.