
NutraPlanner handles sensitive client information, so privacy and security are designed in — not bolted on. Here's how your data is protected.
NutraPlanner is built around PIPEDA and Quebec's Law 25 — the privacy frameworks that govern Canadian practitioners and their clients. Our Data Processing Agreement sets out exactly how client data is handled on your behalf.
All traffic runs over TLS, and sensitive client information such as notes is encrypted at the field level, so it isn't readable directly from the database.
Access to client data is gated by role, and accounts can be protected with two-factor authentication — mandatory for practitioner and administrator accounts. We recommend an authenticator app (TOTP, using any standard app), which works offline and is the strongest option we offer; accounts can alternatively receive a one-time code by email, which is easier to start with but less secure, since the code travels through the same inbox that can reset a password. You can switch methods at any time from your security settings.
Access to and changes in client records are recorded in an audit log, so there's an accountable trail of who did what.
Client health data is soft-deleted and retained according to policy rather than erased on a misclick, and it is never sold or used for advertising.
We publish the third parties that help run NutraPlanner and what each one handles, in our Data Processing Agreement — no hidden data flows.
Third-party tools only touch client health data once a data-processing agreement covers them. When a vendor can't offer one, the integration stays off — we keep error monitoring disabled in production for exactly this reason.
You can export your account's data in a machine-readable format at any time. No lock-in and no export fees — leaving should be as easy as joining.
Our policies spell out exactly what we collect, how we protect it, and who processes it on our behalf.
We're happy to walk through how NutraPlanner handles client data.
Contact us