Privacy Policy
Policy last updated: February 10, 2026
EndoDiagnosis, Inc. (hereafter referred to as “EndoDiagnosis” in this policy) acts as a health information agent and service provider in the collection and transmission of personal health information for the purpose of facilitating ENDOSURE testing. We are the Canadian Distributors for ENDOSURE, Inc. We do not provide medical care, perform testing, or retain diagnostic results.
EndoDiagnosis is aware of the importance of protecting your privacy and is committed to appropriately handling and safeguarding your personal information (which includes any personal health information submitted). We will collect, use, store and disclose your personal information responsibly, and only as required to provide our services.
We remain responsible and accountable to you for the personal information we collect and hold. To this end, we have developed this Privacy Policy, trained our professional, technical and support staff and contractors about our policies and practices, and have also appointed a Chief Privacy Officer to ensure our Privacy Policy is complied with throughout our company across Canada.
EndoDiagnosis uses Canadian-based web hosting and data storage providers wherever possible. Users of our website services are also encouraged to review our Terms of Use, which operate in conjunction with this Privacy Policy.
1.1. Personal Information
Personal information is any information that identifies you, or by which your identity could be deduced and includes any health-related information, including any information about your health care, health status or health care providers.
Business and clinic information, however (for example, your business title or business or clinic address and business telephone number) is not considered to be personal information according to privacy legislation.
Generally speaking, for patient self-referral or a physician referral, if we do not collect and send your personal information to the test centre or your selected provider, we cannot provide you with a direct referral service to the test centre or provider. We will use your personal information only for the purposes for which it is collected.
1.2. Purposes for Collection, Use and Disclosure of Personal Information
Information Collected from Clients for the purposes of referrals or support
We will only collect your personal information for the following purposes:
- to provide a direct self-referral path between clients and ENDOSURE test centres
- to connect clients and providers of ENDOSURE testing
- to connect clients with other services or providers if requested by the client
- to identify and to ensure continuous high-quality service
- to enable us and the test centre to contact and maintain communication with you, including to distribute health-care information to you and to book and confirm appointments
- to allow us to efficiently follow up for testing for research, health surveillance and statistical analysis of data purposes (on an anonymous basis)
- to comply with any other requirements mandated by a government authority
- for administrative / management activities such as planning, resource allocation, reporting or evaluation
- to comply generally with the law
- for any other purpose that may be identified to you before or at the time the information is collected
Information Collected from Clinicians and Test Providers
EndoDiagnosis collect professional information from clinicians and test providers who engage with our services for training, account registration, ordering supplies, or providing ENDOSURE testing. This information may include name, clinic details, professional license information, billing and shipping details, and account activity.
This information is used solely to:
- verify professional credentials
- manage user accounts and provide support
- fulfill orders and provide training services
- publish clinic information on our website where you have provided consent for this to be shared with patients
We may also review platform usage information and anonymized testing activity for service improvement, quality assurance, and statistical purposes.
Users with accounts on the EndoDiagnosis website may view and update their account information at any time. Authorized website administrators may access this information only for account management and support purposes.
1.3. Control of your User ID and Password for EndoDiagnosis
Clinicians, clinics and test providers who create an account on our website, are responsible for protecting their User ID and password and any actions taken with them. Do not share your User ID and password with anyone. For your protection, EndoDiagnosis may require a change of your password periodically. If you suspect that your password has been compromised, for any reason, you should change it immediately. Select a password that is meaningful to you but not obvious or easy to guess; we recommend not using personal information such as your birth date, phone number, social insurance number or similar information about your family. Do not write down your User ID and password, store it in a file on your computer or permit anyone to observe you entering your User ID and password. You can change your User ID/email address and/or your password at any time.
1.4. Consent
We will collect, use and disclose your Personal Information only on the basis of your consent, except where otherwise required or permitted by applicable laws. You may provide your consent to us either orally or in writing. By providing your personal information to us, you agree that we may use it only for the purposes outlined above.
You may withdraw your consent (which must be in writing) so as to prevent the disclosure of some or all of your personal health information to third party practitioners that would otherwise be entitled to receive your personal information for health care purposes. In such instances, if the information that is withheld is significant to your health care, then we are obligated to inform the requesting practitioner of the existence of such information, without actually disclosing the information itself.
1.5. Limits to Collection, Use, Disclosure and Retention of Personal Information
We will limit the collection of personal information to those purposes identified in this Policy. Similarly, your personal information will not be used or disclosed for purposes other than those for which the information is collected or as required, or permitted, by law.
As such, EndoDiagnosis does not collect provincial health numbers or government identifiers. We limit data collection to the minimum necessary to facilitate access to testing.
EndoDiagnosis retains referral information only as long as necessary to confirm successful transmission to the selected test centre and to manage administrative follow-up. Referral records are routinely purged from our system within 90 days of successful transmission unless required for legal or audit purposes.
1.6. Destruction of Personal Information
We destroy our records (which include electronic records and hardware) in a way that protects your privacy. With respect to electronic records, at a minimum, we ensure that all information is wiped clean prior to disposal of electronic data storage devices.
1.7. Accuracy of Information
We will use our best efforts to ensure that information from our test centres and referrals is as accurate, complete and up-to-date as possible for the purposes that it is to be used.
1.8. Security of Your Personal Information
All personal health information in transit is protected using industry-standard encryption protocols. EndoDiagnosis takes appropriate administrative, technical, and physical safeguards to protect your information from loss, theft, unauthorized access, modification, use, copying, disclosure, or tampering.
We maintain safeguards to protect personal information stored on our systems, transmitted through our services (including email and fax transmission), and during its secure disposal and destruction.
Our safeguards include:
- Technical safeguards: encryption, firewalls, secure servers, password protection, and data minimization practices
- Administrative safeguards: access to referral data is restricted to authorized personnel only, all of whom are bound by confidentiality agreements; access is logged and monitored
- Physical safeguards: secure work environments and controlled access to systems and devices used to process personal information
Our staff are trained and advised in the importance of maintaining the security and confidentiality of personal information. We regularly review and update our security practices to reflect current standards and evolving risks.
1.9. Communicating with You
We are sensitive to the privacy of your health information. We protect personal health information regardless of its format.
Telephone: Our office or the test centre may make an attempt to contact you by phone to confirm your appointment or discuss your testing. EndoDiagnosis may confirm your preferences for leaving phone messages. If this is not possible, then we will try to call you back at a time when you can answer and we will not identify ourselves as EndoDiagnosis in the message.
Fax: When a referral is submitted online, the information is transmitted through our secure online fax service directly to the test centre selected. Our fax provider, SR Fax, specializes in secure healthcare data transmission and complies with applicable Canadian and U.S. privacy and security standards, including PIPEDA / PIPA and HIPAA. EndoDiagnosis maintains a formal service and data processing agreement with SR Fax for the secure transmission of personal health information.
EndoDiagnosis does not create or retain any physical or printed copies of your referral. We take appropriate steps to ensure that health information is transmitted only to secure fax systems at each designated test centre.
Once the referral has been successfully transmitted, responsibility for the personal health information transfers to the receiving test centre as the health information custodian.
E-mail: Any confidential information that we send via email over public or external networks will be encrypted. We employ a firewall and virus scanning software to mitigate unauthorized modification, loss, access or disclosure.
Internet and Website Usage: Referral forms and information submitted through the EndoDiagnosis website are transmitted over secure, encrypted (HTTPS) connections. We take appropriate steps to ensure that personal information entered into our website is protected during transmission.
Like most websites, our servers automatically record certain technical information when you visit the site, including your Internet Protocol (IP) address, browser type, pages visited, and time of access. This information is used for system security, troubleshooting, and anonymous statistical analysis of website usage. This information is not used to identify you personally unless you are logged into a user account.
The EndoDiagnosis website uses cookies to support website functionality, such as maintaining secure login sessions and remembering user preferences. Cookies do not collect personal health information.
Website analytics data is retained for up to 12 months and is reviewed only in aggregated, non-identifiable form.
1.10. Access to and Correction of Your Personal Information
You have the right to request access to, correction of, or information about how your personal information has been handled by EndoDiagnosis. Requests must be submitted in writing to the EndoDiagnosis Privacy Officer using the contact information at the end of this policy.
For users with website accounts (including clinicians and test providers), you may review and update your account information at any time by logging into your account.
If an error is identified in referral information submitted to EndoDiagnosis, we will correct the demographic information upon request and re-transmit the corrected referral to the selected test centre.
EndoDiagnosis facilitates the referral process but does not perform testing and does not receive or store identifiable test results. Access to test results must be requested directly from the test centre or the ordering clinician.
1.11. Privacy Inquiries and Complaints
We take all privacy inquiries and complaints seriously. If you have a privacy inquiry or complaint about EndoDiagnosis, the testing centre we referred, how we have responded to your access requests or how we manage your personal information at EndoDiagnosis, then please contact our Privacy Officer to make an inquiry or complaint.
If you feel that we have not answered your request, inquiry or complaint to your satisfaction, then we will inform you about complaint procedures to contact the relevant governmental authorities if you wish to lodge a privacy complaint about us.
1.12. Changes to this Privacy Policy
It is our practice to review our policies and procedures from time to time and therefore we may amend our Privacy Policy in the future.
Should you have an access or correction request, or any questions about our information practices or complaints about our compliance with privacy legislation, then please email us at privacy@endodiagnosis.com.