NutraPlanner

Built to protect client health data

NutraPlanner handles sensitive client information, so privacy and security are designed in — not bolted on. Here's how your data is protected.

Built around Canadian privacy law

NutraPlanner is built around PIPEDA and Quebec's Law 25 — the privacy frameworks that govern Canadian practitioners and their clients. Our Data Processing Agreement sets out exactly how client data is handled on your behalf.

Encrypted connections, encrypted sensitive data

All traffic runs over TLS, and sensitive client information such as notes is encrypted at the field level, so it isn't readable directly from the database.

Role-based access and two-factor authentication

Access to client data is gated by role, and accounts can be protected with TOTP-based two-factor authentication using any standard authenticator app.

Audit logging on client data

Access to and changes in client records are recorded in an audit log, so there's an accountable trail of who did what.

A careful data lifecycle

Client health data is soft-deleted and retained according to policy rather than erased on a misclick, and it is never sold or used for advertising.

Transparent about our subprocessors

We publish the third parties that help run NutraPlanner and what each one handles, in our Data Processing Agreement — no hidden data flows.

Read the details

Our policies spell out exactly what we collect, how we protect it, and who processes it on our behalf.

Questions about security?

We're happy to walk through how NutraPlanner handles client data.

Contact us