Sign InNutraPlanner handles sensitive client information, so privacy and security are designed in — not bolted on. Here's how your data is protected.
NutraPlanner is built around PIPEDA and Quebec's Law 25 — the privacy frameworks that govern Canadian practitioners and their clients. Our Data Processing Agreement sets out exactly how client data is handled on your behalf.
All traffic runs over TLS, and sensitive client information such as notes is encrypted at the field level, so it isn't readable directly from the database.
Access to client data is gated by role, and accounts can be protected with TOTP-based two-factor authentication using any standard authenticator app.
Access to and changes in client records are recorded in an audit log, so there's an accountable trail of who did what.
Client health data is soft-deleted and retained according to policy rather than erased on a misclick, and it is never sold or used for advertising.
We publish the third parties that help run NutraPlanner and what each one handles, in our Data Processing Agreement — no hidden data flows.
Our policies spell out exactly what we collect, how we protect it, and who processes it on our behalf.
We're happy to walk through how NutraPlanner handles client data.
Contact us