Back to Home

Data Privacy & Compliance

NextEyeExam is built on secure, modern infrastructure designed to meet the rigorous standards of healthcare data protection across North America.

Our Role as a Technology Intermediary

NextEyeExam operates strictly as a lead generation and marketing platform. We are not a healthcare provider (Covered Entity) nor do we manage Electronic Medical Records (EMR). We securely transmit booking requests to independent optometry clinics and temporarily verify itemized receipts solely for the purpose of issuing promotional rewards.

PIPEDA Compliance (Canada)

Personal Information Protection and Electronic Documents Act

As a Canadian-based company, we adhere strictly to the 10 Fair Information Principles of PIPEDA:

Consent:

Data is only collected after explicit, informed consent during the booking process.

Limiting Collection:

We collect only the minimum data required (Name, Email, Phone) to route your appointment.

Safeguards:

Receipts and personal data are protected by enterprise-grade encryption.

Individual Access:

Users may request the removal or modification of their data at any time.

HIPAA Readiness (United States)

Health Insurance Portability and Accountability Act

While NextEyeExam primarily serves Canadian markets, our infrastructure is designed to align with HIPAA Security Rules as a Business Associate for our US partners.

  • Transmission Security:

    All data transmitted between the patient, NextEyeExam, and the partner clinic is encrypted in transit using TLS 1.2+.

  • Access Controls:

    Our database utilizes strict Row Level Security (RLS) ensuring data is only accessible to authorized internal systems and personnel required for reward verification.

  • Storage of PHI:

    We do not store diagnostic information, medical histories, or treatment plans. Receipt images uploaded for verification are secured in private cloud buckets and deleted according to our retention policies.