// Privacy policy

Privacy policy.

How Nexavita Digital Systems collects, uses, and safeguards data under federal PIPEDA and Canadian provincial health privacy law.

Last updated: May 21, 2026Canada · PIPEDA, PHIPA, HIA, Law 25
Contents
1. Service provider role2. Information we collect3. How we use your data4. Cross-border transfers5. Telecom utility billing6. Anti-spam (CASL)7. Your rights & contact

Nexavita Digital Systems (“Nexavita,” “we,” “us,” or “our”) operates nexavita.ca and provides custom website development, AI conversational assistants, and CRM automation infrastructure for businesses and healthcare practices across Canada. This Privacy Policy explains how we collect, use, and safeguard data in compliance with the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA). It also establishes our data-processing boundaries regarding the architectural services we build for our clients under provincial health acts, including PHIPA (Ontario), HIA (Alberta), and Law 25 (Quebec).

1. Nexavita as a service provider & data processor

Nexavita acts primarily as a technology architect and Data Processor for our clients.

Walled-garden infrastructure. When we configure website forms, GoHighLevel sub-accounts, or automated AI pipelines for a client, those databases are completely sandboxed and structurally isolated. Nexavita does not own, access, mine, or share any consumer or patient data collected by our clients' respective platforms.

The Clinical Boundary Directive. Nexavita explicitly builds systems utilizing a Dual-Boundary Data Architecture. We do not design systems that store, handle, or record Personal Health Information (PHI) within generic marketing software or open-source AI models. All clinical data collected by systems we construct is routed immediately into our clients' certified, Canadian-hosted EMR or Practice Management Software.

2. Information we collect from clients and visitors

When you visit our site, request a demo, or subscribe to a Nexavita system package, we collect:

  • Business contact identifiers: name, corporate email, business phone number, clinic name, and your current practice software ecosystem.
  • Usage and analytics data: IP address, device type, geographic location, and interaction logs via tracking cookies and Google Analytics 4.
  • Billing details: payment information processed through secure, PCI-DSS compliant third-party payment gateways (e.g. Stripe). We do not store raw credit card numbers on our local infrastructure.

3. How we use your data

We utilize the business data we collect to:

  • Provision, deploy, and monitor your Vercel hosting, custom domains, and isolated GoHighLevel sub-accounts.
  • Maintain, test, and refine your custom-trained Claude API conversational workflows.
  • Execute essential service communications, priority technical support, and quarterly strategy performance updates.
  • Comply with global telecommunication validation acts (including Canadian A2P 10DLC registrations and Persona identity checks).

4. Cross-border data transfers & security controls

Nexavita implements industry-leading security controls. All administrative data, website routing, and pipeline identifiers are secured using AES-256 encryption for data at rest and TLS 1.3 cryptographic keys for data in transit.

In compliance with PIPEDA's accountability principles, we disclose that the cloud infrastructure used to run our front-end web apps (Vercel) and manage standard B2B sales pipelines (GoHighLevel) utilizes secure data centers located in both Canada and the United States. By engaging our services, you acknowledge that your corporate administrative metadata may be processed across these secure networks.

5. Telecommunications utility (wallet balance routing)

For clients utilizing our Growth, Premium, or Custom automated packages:

  • Nexavita provisions localized Canadian telecom numbers via secure, carrier-integrated routing interfaces.
  • We utilize a secure, direct-billing digital wallet architecture. All carrier network usage fees (SMS and voice utility fractions of a cent) are billed directly to the client's linked credit card via automated, independent balance top-ups.
  • Nexavita applies zero markup or hidden transaction fees to network data utility costs.

6. Anti-spam compliance (CASL)

Nexavita enforces strict adherence to the Canadian Anti-Spam Legislation (CASL). We will never transmit unsolicited commercial digital communications. You can instantly withdraw consent or update your notification preferences at any time by selecting the “Unsubscribe” footer on our emails, or replying “STOP” to any automated text notifications sent from our systems.

7. Accountability & data rectification

You retain absolute rights of access, correction, and erasure regarding any business contact data Nexavita maintains within our administrative system. To issue a data rectification request or contact our operations team regarding privacy protocols:

Privacy Compliance Officer
Privacy Department · Nexavita Digital Systems
Corporate email: nexavita@hotmail.com
Contact our teamBack to home