Privacy Policy

Privacy Policy

Last updated: October 12, 2025

Who We Are:
Graceway Wellness (“we,” “our,” “the Clinic”) provides psychotherapy services in person at 700–1122 International Blvd, Burlington, ON, and online across Ontario.
Contact: info@gracewaywellness.com | (289) 204-4439


1. Scope & Legal Frameworks

This notice explains how we collect, use, disclose, and safeguard information when you visit gracewaywellness.com or receive services from us.

As an Ontario psychotherapy clinic, we are a Health Information Custodian (HIC) under Ontario’s Personal Health Information Protection Act (PHIPA) and follow the CRPO Professional Practice Standards for Registered Psychotherapists.

We also describe how we use Google Analytics on the website.



2. Definitions

Personal Health Information (PHI): identifying information about your health or health care (e.g., clinical notes, diagnoses, treatment plans, billing information).

Personal Information (PI): identifying information collected on our website (e.g., IP address, device data, contact form entries).

Agents/Service Providers: third parties acting on our behalf, such as Jane™ for booking and records.



3. What We Collect

A. When You Receive Care

Identification and contact details, health history, presenting concerns, session notes and treatment plans, appointment and billing records, correspondence, and consent forms. Collection is limited to what is necessary for assessment, treatment, and regulatory compliance.

B. When You Use Our Website

We collect essential data for site operation and security, and analytics data (Google Analytics 4) such as page views, device/browser type, and approximate location.

Google Analytics is configured not to collect personal identifiers and is used only to improve content and performance.

C. When You Book Online

Scheduling, charting, payments, receipts, and telehealth are provided through Jane™, a practice-management platform compliant with PHIPA and PIPEDA. Jane stores data in the Canadian data centre selected by the clinic.



4. Why We Collect and Use Information

  • To deliver psychotherapy safely and effectively

  • To maintain clinical, appointment, and financial records

  • To manage operations and comply with CRPO and PHIPA requirements

  • To operate and improve our website using Google Analytics



5. Consent

We obtain your informed consent for collection, use, and disclosure of PHI, except where PHIPA permits or requires otherwise.

You may withdraw consent at any time, subject to legal and clinical limits, with reasonable notice.



6. Disclosures

  • With your consent (for example, to a physician or another provider)

  • To service providers who support our operations (e.g., Jane), who are bound by confidentiality

  • As required by law, such as court orders, mandatory reporting, or regulatory compliance

We do not sell your information.



7. Google Analytics

We use Google Analytics 4 (GA4) to understand aggregate site usage.

We do not send personal or health information to Google.

You can manage analytics preferences via our cookie banner or your browser settings.



8. Cookies

We use essential cookies for website operation and optional analytics cookies for performance insights.

You can accept or reject analytics cookies through the cookie banner or your browser.



9. Safeguards

We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption, secure storage, and restricted access.

Jane implements encryption in transit and at rest, with data stored in Canada.



10. Record Retention & Secure Destruction

Records are retained for at least 10 years from the last contact for adults, or 10 years past the 18th birthday for minors, unless otherwise required.

After this period, records are securely deleted or destroyed.



11. Your Rights Under PHIPA

You have the right to access your records, request corrections, and obtain disclosure information.

If you are unsatisfied with our response, you may contact the Information and Privacy Commissioner of Ontario (IPC).



12. Breach Management & Notifications

If PHI is lost, stolen, or disclosed without authorization, we will notify affected individuals promptly and report to the IPC and relevant regulatory bodies as required.



13. Cross-Border Processing by Service Providers

Some services (such as SMS reminders or Google Analytics) may involve limited data processing outside Canada, such as in the United States.

In such cases, data may be subject to the laws of those jurisdictions.

We select vendors with strong security controls and share only what is necessary.



14. Children & Substitute Decision-Makers

Consent for minors or clients with substitute decision-makers is obtained from the appropriate party as defined by PHIPA.

Retention timelines follow CRPO standards for minors.



15. Email, Texting & Telehealth

Email and SMS are convenient but may carry privacy risks.

Avoid sharing sensitive clinical information by these methods.

Telehealth sessions occur through Jane’s encrypted platform and are never recorded.

For emergencies, call 911 or go to your nearest emergency department.



16. Complaints & Questions

For privacy questions or complaints, contact info@gracewaywellness.com

or call (289) 204-4439.

You may also contact the Information and Privacy Commissioner of Ontario for further assistance.



17. Changes to This Policy

We may update this policy to reflect legal or operational changes.

The “Last updated” date above indicates the most recent revision.

Last updated: October 12, 2025

Who We Are:
Graceway Wellness (“we,” “our,” “the Clinic”) provides psychotherapy services in person at 700–1122 International Blvd, Burlington, ON, and online across Ontario.
Contact: info@gracewaywellness.com | (289) 204-4439


1. Scope & Legal Frameworks

This notice explains how we collect, use, disclose, and safeguard information when you visit gracewaywellness.com or receive services from us.

As an Ontario psychotherapy clinic, we are a Health Information Custodian (HIC) under Ontario’s Personal Health Information Protection Act (PHIPA) and follow the CRPO Professional Practice Standards for Registered Psychotherapists.

We also describe how we use Google Analytics on the website.



2. Definitions

Personal Health Information (PHI): identifying information about your health or health care (e.g., clinical notes, diagnoses, treatment plans, billing information).

Personal Information (PI): identifying information collected on our website (e.g., IP address, device data, contact form entries).

Agents/Service Providers: third parties acting on our behalf, such as Jane™ for booking and records.



3. What We Collect

A. When You Receive Care

Identification and contact details, health history, presenting concerns, session notes and treatment plans, appointment and billing records, correspondence, and consent forms. Collection is limited to what is necessary for assessment, treatment, and regulatory compliance.

B. When You Use Our Website

We collect essential data for site operation and security, and analytics data (Google Analytics 4) such as page views, device/browser type, and approximate location.

Google Analytics is configured not to collect personal identifiers and is used only to improve content and performance.

C. When You Book Online

Scheduling, charting, payments, receipts, and telehealth are provided through Jane™, a practice-management platform compliant with PHIPA and PIPEDA. Jane stores data in the Canadian data centre selected by the clinic.



4. Why We Collect and Use Information

  • To deliver psychotherapy safely and effectively

  • To maintain clinical, appointment, and financial records

  • To manage operations and comply with CRPO and PHIPA requirements

  • To operate and improve our website using Google Analytics



5. Consent

We obtain your informed consent for collection, use, and disclosure of PHI, except where PHIPA permits or requires otherwise.

You may withdraw consent at any time, subject to legal and clinical limits, with reasonable notice.



6. Disclosures

  • With your consent (for example, to a physician or another provider)

  • To service providers who support our operations (e.g., Jane), who are bound by confidentiality

  • As required by law, such as court orders, mandatory reporting, or regulatory compliance

We do not sell your information.



7. Google Analytics

We use Google Analytics 4 (GA4) to understand aggregate site usage.

We do not send personal or health information to Google.

You can manage analytics preferences via our cookie banner or your browser settings.



8. Cookies

We use essential cookies for website operation and optional analytics cookies for performance insights.

You can accept or reject analytics cookies through the cookie banner or your browser.



9. Safeguards

We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption, secure storage, and restricted access.

Jane implements encryption in transit and at rest, with data stored in Canada.



10. Record Retention & Secure Destruction

Records are retained for at least 10 years from the last contact for adults, or 10 years past the 18th birthday for minors, unless otherwise required.

After this period, records are securely deleted or destroyed.



11. Your Rights Under PHIPA

You have the right to access your records, request corrections, and obtain disclosure information.

If you are unsatisfied with our response, you may contact the Information and Privacy Commissioner of Ontario (IPC).



12. Breach Management & Notifications

If PHI is lost, stolen, or disclosed without authorization, we will notify affected individuals promptly and report to the IPC and relevant regulatory bodies as required.



13. Cross-Border Processing by Service Providers

Some services (such as SMS reminders or Google Analytics) may involve limited data processing outside Canada, such as in the United States.

In such cases, data may be subject to the laws of those jurisdictions.

We select vendors with strong security controls and share only what is necessary.



14. Children & Substitute Decision-Makers

Consent for minors or clients with substitute decision-makers is obtained from the appropriate party as defined by PHIPA.

Retention timelines follow CRPO standards for minors.



15. Email, Texting & Telehealth

Email and SMS are convenient but may carry privacy risks.

Avoid sharing sensitive clinical information by these methods.

Telehealth sessions occur through Jane’s encrypted platform and are never recorded.

For emergencies, call 911 or go to your nearest emergency department.



16. Complaints & Questions

For privacy questions or complaints, contact info@gracewaywellness.com

or call (289) 204-4439.

You may also contact the Information and Privacy Commissioner of Ontario for further assistance.



17. Changes to This Policy

We may update this policy to reflect legal or operational changes.

The “Last updated” date above indicates the most recent revision.

Last updated: October 12, 2025

Who We Are:
Graceway Wellness (“we,” “our,” “the Clinic”) provides psychotherapy services in person at 700–1122 International Blvd, Burlington, ON, and online across Ontario.
Contact: info@gracewaywellness.com | (289) 204-4439


1. Scope & Legal Frameworks

This notice explains how we collect, use, disclose, and safeguard information when you visit gracewaywellness.com or receive services from us.

As an Ontario psychotherapy clinic, we are a Health Information Custodian (HIC) under Ontario’s Personal Health Information Protection Act (PHIPA) and follow the CRPO Professional Practice Standards for Registered Psychotherapists.

We also describe how we use Google Analytics on the website.



2. Definitions

Personal Health Information (PHI): identifying information about your health or health care (e.g., clinical notes, diagnoses, treatment plans, billing information).

Personal Information (PI): identifying information collected on our website (e.g., IP address, device data, contact form entries).

Agents/Service Providers: third parties acting on our behalf, such as Jane™ for booking and records.



3. What We Collect

A. When You Receive Care

Identification and contact details, health history, presenting concerns, session notes and treatment plans, appointment and billing records, correspondence, and consent forms. Collection is limited to what is necessary for assessment, treatment, and regulatory compliance.

B. When You Use Our Website

We collect essential data for site operation and security, and analytics data (Google Analytics 4) such as page views, device/browser type, and approximate location.

Google Analytics is configured not to collect personal identifiers and is used only to improve content and performance.

C. When You Book Online

Scheduling, charting, payments, receipts, and telehealth are provided through Jane™, a practice-management platform compliant with PHIPA and PIPEDA. Jane stores data in the Canadian data centre selected by the clinic.



4. Why We Collect and Use Information

  • To deliver psychotherapy safely and effectively

  • To maintain clinical, appointment, and financial records

  • To manage operations and comply with CRPO and PHIPA requirements

  • To operate and improve our website using Google Analytics



5. Consent

We obtain your informed consent for collection, use, and disclosure of PHI, except where PHIPA permits or requires otherwise.

You may withdraw consent at any time, subject to legal and clinical limits, with reasonable notice.



6. Disclosures

  • With your consent (for example, to a physician or another provider)

  • To service providers who support our operations (e.g., Jane), who are bound by confidentiality

  • As required by law, such as court orders, mandatory reporting, or regulatory compliance

We do not sell your information.



7. Google Analytics

We use Google Analytics 4 (GA4) to understand aggregate site usage.

We do not send personal or health information to Google.

You can manage analytics preferences via our cookie banner or your browser settings.



8. Cookies

We use essential cookies for website operation and optional analytics cookies for performance insights.

You can accept or reject analytics cookies through the cookie banner or your browser.



9. Safeguards

We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption, secure storage, and restricted access.

Jane implements encryption in transit and at rest, with data stored in Canada.



10. Record Retention & Secure Destruction

Records are retained for at least 10 years from the last contact for adults, or 10 years past the 18th birthday for minors, unless otherwise required.

After this period, records are securely deleted or destroyed.



11. Your Rights Under PHIPA

You have the right to access your records, request corrections, and obtain disclosure information.

If you are unsatisfied with our response, you may contact the Information and Privacy Commissioner of Ontario (IPC).



12. Breach Management & Notifications

If PHI is lost, stolen, or disclosed without authorization, we will notify affected individuals promptly and report to the IPC and relevant regulatory bodies as required.



13. Cross-Border Processing by Service Providers

Some services (such as SMS reminders or Google Analytics) may involve limited data processing outside Canada, such as in the United States.

In such cases, data may be subject to the laws of those jurisdictions.

We select vendors with strong security controls and share only what is necessary.



14. Children & Substitute Decision-Makers

Consent for minors or clients with substitute decision-makers is obtained from the appropriate party as defined by PHIPA.

Retention timelines follow CRPO standards for minors.



15. Email, Texting & Telehealth

Email and SMS are convenient but may carry privacy risks.

Avoid sharing sensitive clinical information by these methods.

Telehealth sessions occur through Jane’s encrypted platform and are never recorded.

For emergencies, call 911 or go to your nearest emergency department.



16. Complaints & Questions

For privacy questions or complaints, contact info@gracewaywellness.com

or call (289) 204-4439.

You may also contact the Information and Privacy Commissioner of Ontario for further assistance.



17. Changes to This Policy

We may update this policy to reflect legal or operational changes.

The “Last updated” date above indicates the most recent revision.

Graceway Wellness

Phone: (289) 204-4439

E-mail: info@gracewaywellness.com

Location: 1122 International Blvd, Burlington (at Burlington-Oakville border), ON

“For from his fullness we have all received, grace upon grace.” John 1:16 ESV

Therapy 
  Tribe verified counsellor, Sara Tawadros
Verified listing on Psychotherapy Matters professional directory

Graceway Wellness

Phone: (289) 204-4439

E-mail: info@gracewaywellness.com

Location: 1122 International Blvd, Burlington (at Burlington-Oakville border), ON

“For from his fullness we have all received, grace upon grace.” John 1:16 ESV

Therapy 
  Tribe verified counsellor, Sara Tawadros
Verified listing on Psychotherapy Matters professional directory

Graceway Wellness

Phone: (289) 204-4439

E-mail: info@gracewaywellness.com

Location: 1122 International Blvd, Burlington (at Burlington-Oakville border), ON

“For from his fullness we have all received, grace upon grace.” John 1:16 ESV

Therapy 
  Tribe verified counsellor, Sara Tawadros
Verified listing on Psychotherapy Matters professional directory