Privacy Policy

What personal information Merakey handles, why we handle it, where it lives, how long we keep it, and how you get it back or have it deleted.

Effective: August 12, 2026Last updated: August 12, 2026Version 2.0

1. Who we are and what this covers

Merakey Technology Corp. ("Merakey", "we", "us") is a Canadian corporation based in Ontario. We build software for healthcare and developmental services organizations.

This policy covers:

  • merakey.io and its subdomains, including the contact form, the newsletter signup, the compliance self-assessment, and the AI chat assistant on the site.
  • Meridian— automated compliance scanning that reads an agency's Home Portal data and produces QAM and MCCSS compliance reports.
  • Sentinel — an AI agent platform, deployed either on infrastructure the customer controls or hosted by us.
  • Healex — a pharmacy and eMAR platform connecting pharmacies with developmental services agencies.

It does not cover third-party sites we link to, or a customer's own privacy practices toward the people they support.

2. Our role: customer data vs. our own data

Merakey plays two different roles, and your rights differ depending on which one applies.

  • We decide (we are accountable). Information about website visitors, prospects, and the individual contacts at our customer organizations. We determine why it is collected and how it is used. This policy governs it directly.
  • Our customer decides (we act on instructions). Information inside Meridian, Sentinel, and Healex about the people an agency supports, and about that agency's staff. The customer organization remains accountable for it. We handle it only as its service provider, under a written agreement, and only on that customer's instructions. Where that information is personal health information under Ontario's Personal Health Information Protection Act (PHIPA), we act as an electronic service provider to the custodian under section 6(1) of O. Reg. 329/04, and not as a custodian and not as an agent. In that role we will not use personal health information except as necessary to provide the service, will not disclose it, and will not give anyone acting on our behalf access to it unless they first agree to the same restrictions.

If you are a client, resident, or staff member of an agency that uses our products and you want to access or correct your information, contact that agency first. We will support them in responding, but we are not permitted to disclose their data to us directly.

3. Information we collect

Information you give us

  • Contact and demo requests: name, email address, organization name, the product or topic you are interested in, and whatever you write in the message field.
  • Newsletter signup: email address.
  • Compliance self-assessment: the answers you select, and your contact details if you choose to receive the results.
  • AI chat assistant:the questions you type into the chat widget on merakey.io, and the assistant's replies. If you hand over your details through the chat, we receive those details together with a copy of the recent conversation so we can respond with context. Treat the chat as you would an email to sales: do not paste client names, health information, or credentials into it.
  • Meeting bookings: if you book a call, the name, email address, and any details you enter go to our scheduling provider (Calendly) as well as to us.
  • Account information: for product accounts, the name, work email, role, and organization of each authorized user.

Information collected automatically

  • Site analytics:we use Plausible Analytics, a privacy-focused, cookieless analytics service. It records page URL, referrer, approximate country, browser, operating system, and device type. It does not set cookies, does not fingerprint, and does not store IP addresses. Plausible's servers are located in the European Union.
  • Server and security logs: our API and hosting infrastructure record IP address, timestamp, request path, and user agent for security, abuse prevention, and debugging.
  • Product audit logs: within our products, we log who accessed what and when. These logs exist because our customers are required to have them.

4. Data our products process for customers

When an organization becomes a customer, our software processes data on its behalf. What that includes depends on the product.

ProductWhat it processesAccess model
MeridianStaff training and credential records, medication administration records, incident reports, and other compliance evidence held in the agency's Home PortalRead-only. The agency opts in and grants access; Meridian does not write back to Home Portal.
SentinelContent the customer supplies to train an agent, plus the conversations that agent has with the customer's usersSelf-hosted on customer infrastructure, or hosted by us in AWS Canada, depending on the tier purchased.
HealexPrescription, dispensing, and medication administration records exchanged between a pharmacy and an agencyProcessed under agreement with the pharmacy and the agency as the accountable parties.

We access this data only to deliver, support, secure, and troubleshoot the service, and only to the extent our agreement with the customer permits.

Not all of it is personal health information. Under PHIPA section 4(4), records about an employee that are kept primarily for a purpose other than providing health care are not personal health information, so staff training and credential records generally are not. Medication administration records are, and incident reports are to the extent they identify a person receiving services and relate to their care. We apply health-information handling to the records that warrant it rather than claiming a single label for everything.

5. QuickBooks Online (Intuit) integration

Sentinel offers an optional integration with QuickBooks Online. The integration is off unless a customer turns it on.

  • Authorization.A customer connects their own QuickBooks Online company through Intuit's OAuth 2.0 flow and explicitly grants access. We never ask for, receive, or store QuickBooks usernames or passwords.
  • What we access.Accounting data needed to do the job: customers, items and services, invoices, and payment records. We read payment and invoice status to determine what has been billed and what has been paid, and we create or update invoices in the connected QuickBooks company at the customer's direction.
  • What we do with it. We use QuickBooks data solely to provide the billing and revenue-integrity features the customer has enabled. We do not sell it, use it for advertising, or use it to train AI models.
  • How it is stored.OAuth access and refresh tokens are encrypted at rest and held only as long as the connection is active. Accounting data we retrieve is stored encrypted in AWS Canada (ca-central-1) and access is limited to the customer's own account and to the Merakey staff supporting it.
  • How to disconnect. A customer can disconnect at any time from the integrations screen in Sentinel, or from Apps → Connected Apps inside QuickBooks Online. Disconnecting immediately revokes our access. We delete the stored OAuth tokens on disconnection and delete the accounting data we retrieved within 60 days, unless the customer asks us to keep it or the law requires retention.

Intuit is the processor of the data held in QuickBooks Online, and Intuit's own privacy policy governs it there.

6. Cookies, analytics, and site storage

We do not use advertising cookies, cross-site trackers, or third-party marketing pixels on merakey.io. What we do use:

TechnologyPurposeType
Plausible AnalyticsAggregate page-view and referrer statisticsCookieless; no personal identifiers stored
Browser session storageKeeps your chat conversation on screen if you reload the pageStays in your browser tab; cleared when you close it. Never sent to us on its own.
Session cookieKeeps you signed in to a Merakey product and shows the correct navigationStrictly necessary; set only when you sign in

Because we set no analytics or advertising cookies, there is nothing to opt out of through a consent banner. We do not use any technology that identifies, locates, or profiles an individual visitor. If we ever introduce one, Quebec's Law 25 requires it to be off by default; we would tell you first, leave it deactivated, and let you turn it on.

7. How we use information

  • To provide, operate, support, and secure our products.
  • To respond to your inquiry, send the report or assessment result you asked for, and schedule meetings.
  • To send product and company updates, if you asked for them. Every such message has an unsubscribe link.
  • To understand which pages of our site are useful, in aggregate only.
  • To investigate security incidents, prevent abuse, and enforce our terms.
  • To meet our legal, tax, and regulatory obligations in Canada.

We do not sell, rent, or trade personal information, and we do not share it with third parties for their own marketing.

We collect personal information with your knowledge and consent, except where the law allows or requires otherwise. Submitting a form, subscribing, or messaging the chat assistant is your consent for us to use those details to reply and to follow up about the subject you raised.

You can withdraw consent at any time by emailing privacy@merakey.ioor by using the unsubscribe link in any email. Withdrawing consent may mean we can no longer provide a service you have asked for; we will tell you if that is the case. Withdrawal does not apply retroactively, and it does not override a customer organization's own instructions about data held in its account.

9. AI processing and automated decisions

  • We do not train models on customer data.Content, conversations, compliance records, and accounting data belonging to a customer are not used to train, fine-tune, or improve any model, either ours or a third-party provider's.
  • Where the models run.Sentinel's healthcare tier runs self-hosted models with no calls to third-party AI APIs. Other tiers, and the assistant on this website, may use a third-party model provider. Which providers are in use for a given deployment is documented in that customer's agreement, and we give notice before adding a new one.
  • No automated decisions about individuals. Our products do not make decisions that produce legal or similarly significant effects about a person without human involvement. Meridian flags possible compliance gaps; a person at the agency decides what to do about them.
  • Human review. No one at Merakey reads conversations routinely. Our staff access them only for a named reason: you ask for support, we are investigating a security or abuse report, or the law requires it. That access is limited by role, logged, and performed by staff in Canada.
  • Prompts and logs. Conversations, prompts, and the traces our systems keep for debugging are retained on the schedule in section 14. Content flagged for security or abuse review may be kept longer while that review is open.
  • AI output can be wrong. Model output is generated text and may be inaccurate. It is not legal, regulatory, clinical, or accounting advice, and it should be reviewed by a qualified person before it is relied on.

10. Who we share information with

We disclose personal information only in these situations:

  • To service providers that host or support our systems, under contracts requiring comparable protection and limiting them to our instructions. See the list below.
  • To the customer organization whose account the data belongs to.
  • Where the law requires it — a valid court order, warrant, subpoena, or a regulator acting within its authority. We review each request, disclose no more than is required, and notify the affected customer unless we are legally prohibited from doing so.
  • In a corporate transaction such as a merger or sale of assets, subject to confidentiality protections and to this policy continuing to apply.
  • With your direction or that of the accountable organization.

11. Service providers and subprocessors

ProviderPurposeLocation
Amazon Web ServicesHosting, storage, backups, databases for all productsCanada (ca-central-1, Montreal)
Plausible AnalyticsCookieless website analytics for merakey.ioEuropean Union
CalendlyMeeting scheduling, only if you book a callUnited States
jsDelivr (CDN)Delivers the 3D graphics library used by one animation on our home page. Your browser requests the file directly, so jsDelivr sees your IP address.Global content delivery network
Intuit (QuickBooks Online)Accounting platform, only where a customer connects it to SentinelUnited States / as determined by Intuit

Customers can request the current subprocessor list for their deployment and advance notice of changes. Ask at privacy@merakey.io.

12. Data residency and cross-border transfers

Where product data lives.All personal health information and customer product data processed by Meridian, Sentinel (hosted tier), and Healex is stored and processed in AWS's Canadian region, ca-central-1 in Montreal, including databases, file storage, backups, and model artifacts. We do not replicate it to regions outside Canada, and AI inference for these products is pinned to Canadian endpoints.

What that does and does not mean. AWS is a US-headquartered provider operating Canadian infrastructure. Choosing a Canadian region controls where data is stored and processed. It does not put the provider itself beyond the reach of its home jurisdiction. No provider can promise otherwise, and we do not.

Two narrow exceptions apply to our own website and sales operations, not to product data: aggregate, cookieless site analytics are processed by Plausible in the European Union, and if you choose to book a meeting, your booking details are processed by Calendly in the United States. Where a customer connects QuickBooks Online, Intuit holds that accounting data on its own infrastructure under its own terms.

While information is in another country, it may be accessible to the courts and law enforcement of that country under its laws. If you would rather not have your booking handled by a US provider, email us and we will arrange the meeting directly.

For individuals in Quebec: the information described above may be communicated or held outside Quebec. Before entrusting personal information to a provider outside Quebec, we assess the sensitivity of the information, the purpose, the protections in place, and the legal framework of the destination, and we put a written agreement in place. You can ask our Privacy Officer for the categories of information involved and the destinations concerned.

13. How we protect information

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access control, with staff access limited to what their job requires and reviewed periodically.
  • Audit logging of access to customer data.
  • Encrypted, automated daily backups with point-in-time recovery, held in the same Canadian region.
  • Encrypted storage of credentials and integration tokens, including OAuth tokens.
  • Annual third-party penetration testing and a documented incident response plan. Our SOC 2 Type II audit is in progress.

No system is perfectly secure. We commit to safeguards proportionate to the sensitivity of the information, not to a guarantee that a breach can never occur.

14. How long we keep information

CategoryRetention
Contact form, chat, and assessment submissions24 months after the last interaction, then deleted
Newsletter subscribersUntil you unsubscribe, then removed within 30 days
Customer product data (Meridian, Sentinel, Healex)For the term of the subscription, then returned and deleted within 90 days of termination
QuickBooks OAuth tokensDeleted on disconnection
QuickBooks accounting data retrieved by SentinelDeleted within 60 days of disconnection
Security and audit logs12 months
BackupsRolling 30 days; deleted records age out of backups on that cycle
Invoices and financial recordsAs required by Canadian tax law (currently 6 years)

We may keep information longer where a legal hold, investigation, or regulatory obligation requires it, and will delete it once that ends.

15. Your privacy rights

Under PIPEDA, and under PHIPA and Quebec's Law 25 where they apply, you may:

  • Ask what personal information we hold about you and how it is used;
  • Get a copy of it;
  • Ask us to correct information that is inaccurate or incomplete;
  • Withdraw consent, subject to legal and contractual limits;
  • Ask us to delete information we no longer need;
  • Receive information you gave us in a structured, commonly used digital format, where Law 25 portability applies; and
  • Complain, to us or to a regulator, and receive a response.

Email privacy@merakey.io. We will acknowledge within 5 business days and respond within 30 days, as PIPEDA requires. If we need an extension we will tell you why, and how to complain about the delay. We may ask you to verify your identity before releasing information, and we will explain in writing if we have to refuse a request in whole or in part.

16. Breach notification

We maintain a documented incident response plan and a register of every confidentiality incident. Which notification applies depends on whose information was involved.

  • Information under our own control. Where a breach of security safeguards creates a real risk of significant harm to an individual, PIPEDA requires us to report it to the Office of the Privacy Commissioner of Canada and notify the affected individuals as soon as feasible. Where Quebec's Law 25 applies and an incident presents a risk of serious injury, we notify the Commission d'accès à l'information and the affected individuals promptly.
  • Customer data we process on instructions. Control rests with the customer organization, so we notify it rather than reporting on its behalf. Where personal health information is involved, we notify the health information custodian at the first reasonable opportunity so it can meet its own PHIPA duty to notify the individual and the Information and Privacy Commissioner of Ontario.

Separately from those statutory duties, our own commitment to customers is to notify them within 72 hours of confirming a breach. PIPEDA sets no 72-hour deadline; this is a contractual standard we hold ourselves to.

We keep records of every breach of security safeguards for at least 24 months, as PIPEDA requires, whether or not the breach was reportable.

17. Children's information

Our website and products are sold to organizations and are not directed at children. We do not knowingly collect personal information directly from children through merakey.io. Our products may hold records about minors who receive services from a customer agency; that information is under the agency's control and is subject to its consent and substitute-decision-maker processes, not ours.

18. Changes to this policy

We may update this policy as our products and the law change. The effective date and version at the top always reflect the current version. For material changes that affect how we handle information we already hold, we will give notice by email to account contacts, or by a notice on this site, at least 30 days before the change takes effect.

19. How we govern personal information

Beyond this policy, we maintain internal policies and practices covering the full life cycle of personal information. In summary:

  • Roles. The Privacy Officer approves these policies and is accountable for them. Engineering, support, and sales staff may handle personal information only within the scope of their role, and access is granted on a least-privilege basis and reviewed periodically.
  • Collection and use. We collect the minimum needed for an identified purpose, record that purpose, and do not repurpose information without a new basis for doing so.
  • Retention and destruction. Each category has a defined retention period, set out in section 14. When a period ends, records are deleted or irreversibly anonymized, and backups age out on their normal cycle.
  • Vendors. No provider receives personal information without a written agreement limiting it to our instructions, requiring comparable safeguards, and requiring it to notify our Privacy Officer of any incident.
  • Incidents. We keep a register of confidentiality incidents, assess the risk of harm for each, and follow the notification process in section 16.
  • Complaints. Complaints go to the Privacy Officer, who acknowledges within 5 business days, investigates, responds in writing within 30 days with the outcome and reasons, and tells you how to escalate to a regulator if you are not satisfied.

You can request a fuller description of these practices from our Privacy Officer.

20. Contact, complaints, and escalation

Our Privacy Officer is accountable for the personal information under our control and for compliance with this policy. For the purposes of Quebec's Law 25, this is the person in charge of the protection of personal information within the enterprise.

Privacy Officer / Responsable de la protection des renseignements personnels, Merakey Technology Corp.
Email: privacy@merakey.io
General inquiries: info@merakey.io
Merakey Technology Corp., Ontario, Canada

If you are not satisfied with our response, you can complain to the appropriate regulator:

  • Office of the Privacy Commissioner of Canada (PIPEDA) — 1-800-282-1376, priv.gc.ca
  • Information and Privacy Commissioner of Ontario (PHIPA, health information) — 1-800-387-0073, ipc.on.ca
  • Commission d'accès à l'information du Québec (Law 25) cai.gouv.qc.ca