Policies / Privacy Policy

Privacy Policy

Updated: August 8, 2024

At ProcedureFlow, we recognize the importance of protecting your personal information and are committed to acting in compliance with applicable data protection laws in all countries in which we operate. This Privacy Policy is here to help you understand what personal information we collect at ProcedureFlow, how we use, store, share, secure and process that information, and what rights you have with respect to your personal information. ProcedureFlow is the controller of your personal information as described in this Policy, unless specifically noted otherwise.

This policy describes how ProcedureFlow treats your personal information, not other organizations. Where we provide ProcedureFlow under contract with an organization (for example, your employer), that organization is the controller of your personal information, and has its own policies regarding storage, access, modification, deletion, and retention of data which may apply to your use of ProcedureFlow. Data that would otherwise be considered private to you will be accessible by your organization’s Administrator, who has complete control over and can access all data published within the organization's ProcedureFlow environment. This Policy does not apply to the extent we process personal information in the role of a processor on behalf of such organizations. Full details of your choices as an end user of ProcedureFlow are provided below under ‘Notice to End Users’.

Collection of personal information

We collect different kinds of information. Some of it is personally identifiable and some is non-identifying or aggregated. We collect personal information only for the purposes we’ve identified and for the uses described herein.

Use of cookies and other technologies

ProcedureFlow uses cookies, or similar technologies to record log data. We use both session-based and persistent cookies. Cookies are small text files sent by us to your computer and from your computer to us, each time you visit procedureflow.com. They are unique to your ProcedureFlow account and your browser. Session-based cookies last only while your browser is open and are automatically deleted when you close your browser. Persistent cookies last until you or your browser delete them or until they expire.

Some cookies are associated with your ProcedureFlow account and personal information in order to remember that you are logged in. Other cookies are not tied to your account but are unique and allow us to do site analytics and customization. If you access ProcedureFlow through your browser, you can manage your cookie settings there, but if you disable all cookies you may not be able to use ProcedureFlow.

In addition, we also use the following third parties to gather website analytics and for targeted advertising. You may opt-out of third party cookies directly from their websites.

Third Party Purpose Usage
Google Analytics Performance and Analytics Required
HubSpot Performance and Analytics Required
Facebook Targeting and Advertising Opt-in
VWO Targeting and Advertising Opt-in
Lead Forensics Targeting and Advertising Opt-in

Use of personal information

We may use your personal information for any of the following:

Sharing and Disclosure

There are times when personal information, content and other user information may be shared by ProcedureFlow. This Policy discusses only how ProcedureFlow may share your user information. Organizations that use ProcedureFlow may have their own policies for the sharing and disclosure of information they enter and access through ProcedureFlow.

ProcedureFlow may share your personal information as follows:

Security and retention

ProcedureFlow takes all reasonable steps to protect your information from loss, misuse, and unauthorized access or disclosure. When you enter information into ProcedureFlow, we encrypt all transmissions of that information to our service using Transport Layer Security (TLS). We follow generally accepted standards to protect the privacy, security and integrity of all information, including your personal information, that is shared with us, both during transmission and after we receive it.

We will not retain personal information longer than necessary to fulfill the purposes for which it is collected, as outlined below and elsewhere in this Policy:

Notice to End Users

Where ProcedureFlow is made available to you through an organization such as your employer, that organization is the Administrator and is responsible for the ProcedureFlow accounts over which it has control. We are not responsible for and have no control over the privacy or security practices of an individual user’s organization, which may be different than those outlined within this Policy.

If your personal information has been submitted to us on behalf of an organization and you wish to exercise any rights you may have under applicable data protection laws, please inquire with that organization directly. If you wish to make your request directly to us, please note that we will refer your request to that organization and will support them as needed to respond to your request.

As a user of ProcedureFlow, you have control over a number of things with respect to your own information and ProcedureFlow account. If you are an organization’s Administrator, you have additional choices that impact your organization's settings and privacy. For more about these privileges, choices and permissions, see our help page.

Choices for End Users

Choices for Organization Administrators

Notice to Residents of European Economic Area (EEA)

In compliance with the General Data Protection Regulation (GDPR), we will collect your personal information only with your knowledge and consent, or where we have a legal basis for doing so under applicable EEA laws.

Legal Basis for Collection of Personal Information. Our legal bases for collecting and using your personal information depends on the specific type and context for which the information is collected, and are as follows:

Where we collect your personal information on the legal basis of your consent, you have the right to withdraw your consent at any time, though in some cases, this may mean no longer being able to use ProcedureFlow. Also, please note that the withdrawal of your consent will not affect the lawfulness of our collection and use of your personal information prior to the date of said withdrawal.

Your Rights. As a resident of the EEA, you have the following rights regarding the collection and use of your personal information:

International Transfers. The international footprint of ProcedureFlow sometimes involves transfers of personal information between us and suppliers or other third parties located in countries outside of the EEA, and those countries may not require the same level of data protection as the EEA. Whenever we transfer your information, we take all necessary steps to protect it, including acting in compliance with the Data Protection Act 1998 in respect of any such transfers, binding corporate rules, and any other appropriate legal mechanisms deemed necessary. In all cases, our collection, storage and use of your personal information will continue to be governed by this Policy and will be subject to the investigatory and enforcement powers of the Office of the Privacy Commissioner of Canada pursuant to the Personal Information Protection and Electronic Documents Act (PIPEDA).

Right to Lodge Complaint. As a resident of the EEA, you have the right to lodge a complaint in the event you consider our processing of your personal information not to be compliant with the GDPR. The name and contact details of the Data Protection Authorities within the EEA can be found here.

Notification of Changes

We may change this Policy from time to time, and if we do, we'll post any changes on this page. If you continue to use ProcedureFlow after those changes are in effect, you agree to the terms and conditions of the revised Policy. If the changes are material, we may provide more prominent notice and/or seek your consent to the new Policy.

You can see past versions of our Privacy Policy and Terms of Service in our Policy Archives.

Contacting ProcedureFlow

Please feel free to contact us if you have any questions about ProcedureFlow's Privacy Policy or practices. You may email us at help@procedureflow.com or at our mailing address below:

GEMBA Software Solutions Inc.
1 Market Square, Suite 143
Saint John, New Brunswick
Canada E2L 4Z6