Legal
Privacy Policy.
Last updated: July 30, 2026
1. Introduction
General Magic Inc., operating as gema AI (“we,” “us,” or “our”), provides AI-powered appointment booking and reminder services on behalf of healthcare clinics. This Privacy Policy describes how we collect, use, and protect your personal information when you interact with our services via phone, text message (SMS), email, or our website.
2. Who is responsible for your information
Your clinic is the custodian of your health record, not us. In Ontario, your clinic is a health information custodian under the Personal Health Information Protection Act, 2004 (PHIPA). It decides what information is collected about you, why, and who may see it.
We act as your clinic’s agent under PHIPA. In plain terms: we hold and move information on the clinic’s behalf and on its instructions. We do not decide what happens to your health information, and we do not use it for our own purposes. Your clinic’s records are kept separate from every other clinic’s — gema is not a network that moves information between clinics.
Where a clinic operates outside Ontario, or where information is not health information, the Personal Information Protection and Electronic Documents Act (PIPEDA) applies, along with any substantially similar provincial law. We apply the same protections described in this policy in either case.
A note on HIPAA. HIPAA is a United States law and does not apply to a Canadian clinic serving Canadian patients. We build to it as a readiness standard, but PHIPA and PIPEDA are the laws that bind us today, and this policy is written to them.
3. Information we collect
We collect the following types of information:
- Contact information: name, phone number, email address.
- Appointment data: service type, preferred practitioner, appointment date/time, duration.
- Health-related information: date of birth, gender, reason for visit (as provided by you).
- Communication data: phone call recordings, SMS message content, email content.
- Consent records: SMS opt-in/opt-out status, consent timestamps, method of consent.
- Technical data: IP address, browser type, device information (when using our website).
4. How we use your information
Your information is used to:
- Book, confirm, reschedule, and cancel appointments on your behalf.
- Send appointment reminders via your preferred channel (email, SMS, or phone call).
- Respond to your messages and inquiries.
- Verify your identity and phone number.
- Maintain compliance with telecommunications regulations.
- Improve our service quality.
5. SMS & phone data
When you opt in to receive text messages, we store your phone number and consent status to ensure we only send messages to people who have agreed to receive them. We record:
- Your phone number (in E.164 format).
- Consent status (opted in, opted out, or pending).
- How and when you provided or revoked consent.
- SMS message content for appointment-related communications.
We do not sell, share, or use your phone number or SMS data for marketing or advertising purposes. Your phone number and message data are used solely for appointment-related communications.
Our text message program
gema provides appointment reminder and booking communication services by SMS on behalf of participating clinics. If you opt in, you may receive appointment reminders (typically 24 hours ahead), booking and cancellation confirmations, and replies to texts you send us about an appointment.
Message frequency varies with your appointment activity — typically one to two messages per scheduled appointment, and more if you start a text conversation with the booking assistant.
Message and data rates may apply. Standard carrier messaging fees apply to messages sent and received. Contact your wireless carrier for details of your plan.
To stop: reply STOP to any message. You will get a single confirmation and then no further texts from the program. To start again, reply START to the same number.
For help: reply HELP to any message, contact your clinic directly, or visit getgema.ai.
By opting in you consent to recurring automated text messages from gema on behalf of your clinic, at the number you provided. Consent is not a condition of purchase or service, and you may opt out at any time.
6. Service providers who help run Gema
A small number of vetted providers help us deliver the service. Each receives only the minimum information needed to perform its function, and each is bound by its own privacy commitments.
- Supabase: secure database and file storage — hosted in Canada.
- Twilio: phone calls and SMS messaging.
- ElevenLabs: AI voice for phone conversations.
- Anthropic: AI language model for SMS, chat and email conversations.
- Resend: email delivery (confirmations and reminders).
- Vercel: application hosting.
- Railway: background processing.
- Fly.io: the voice server that handles live calls — hosted in Toronto.
- Stripe: billing for clinics. Stripe does not receive patient information.
If we add or change a provider that handles patient information, we will update this list.
7. Where your information is stored and processed
Your records are stored in Canada. The database that holds appointments, patient records, conversation history and call recordings is hosted in Canada (Amazon Web Services, Canada Central region). The server that handles your live phone call runs in Toronto, Ontario.
Some processing happens outside Canada. The phone network, the AI services that understand and generate speech, and our email delivery are provided by the companies listed above, several of which operate in the United States. This means information can pass through systems outside Canada while your call or message is being handled, even though the record we keep is stored in Canada.
Information handled outside Canada may be accessible to authorities in those countries under their laws. We select providers that offer protections comparable to those required here.
8. Artificial intelligence
Gema uses AI to answer calls and messages, understand what you need, and book appointments. You are told at the start of a call that you are speaking with an automated assistant.
Your conversations are not used to train AI models. General Magic does not train AI models. The AI providers we rely on process your information only to generate a response for you, and are contractually prohibited from using it to train or improve their models. We hold written data-processing agreements with each of them and keep those agreements on file.
A person is always available. If you would prefer to speak with clinic staff, say so at any point and the call will be transferred, or the clinic will call you back.
9. How long we keep information
Gema is not your clinic’s medical record. Your clinic’s own system holds your health record and keeps it for the period its regulator requires. We hold the operational details of booking and reminding you about appointments. These are the limits we work to — the longest we intend to hold each kind of information:
- Call recordings: 90 days.
- Conversation transcripts (calls, SMS, chat, email): 12 months.
- Call records (who called, when, how long): 24 months.
- Appointment and patient records: kept while your clinic uses Gema, then returned to the clinic or destroyed.
- Consent and unsubscribe records: kept indefinitely — we have to remember that you opted out so we do not contact you again.
We delete on this schedule. You can also ask us to delete your information at any time, and we will act on that regardless of where it sits in the cycle.
We also keep a record of who accessed your information, so we can answer that question if you ask. Those access records are kept for seven years. See section 13 for what that log does and does not cover.
10. De-identified and aggregate information
We produce statistics about how clinics use the service — how many calls are answered, how often appointments are booked outside office hours, how frequently people cancel. These are counts and averages. We use them to run and improve the service, and to describe how it performs.
These figures are counts and averages. They are produced from your clinic’s own data and reported at the level of a clinic or the platform, never as a description of an individual.
We do not sell your personal health information. We have not shared data with any research organisation. If we ever do, it will be de-identified first — your name, phone number, email address, date of birth and the free text of what you said removed rather than hidden, dates reduced to the month, and small groups suppressed so that a figure can never be narrowed back down to one person. It would be under a written agreement forbidding any attempt to re-identify anyone and forbidding onward disclosure, your clinic would decide whether its data is included, and it could decline without any effect on its service. We will update this policy before that starts, not after.
11. If you are a clinic, a supplier, or a business contact
This section is about business contacts, not patients. If you work at a clinic and we contacted you about gema, this is what we hold and why.
- What we collect: your business name, business email address, business phone number, business address, publicly listed services and hours, and public review information.
- Where it comes from: your own website and public listings, or you gave it to us — for example by requesting a demo.
- When you use a demo we built for you: we record which pages you open and when, on our own platform, and we use that to decide when to follow up.
- Why we may email you: under Canada’s Anti-Spam Legislation (CASL) we rely either on your express consent, where you asked us to get in touch, or on implied consent where your business address is published without a statement that you do not want unsolicited messages, and our message is relevant to your role. Ask us which basis we relied on for you and we will tell you. Where you filled in our demo form, that basis is your own request, and we record it.
- Outbound calls — only if you ask for one. When you request a demonstration you can tick a box asking us to call your line after your posted closing time and record the greeting a caller hears, so we can play it back to you. We only call a number where that box was ticked and the number was given to us for that purpose. We do not cold-call. If you did not ask, we do not call, whatever we may know about your business.
- How those calls work: one call, placed after your posted closing time and never after 9:30pm on a weekday or 6pm on a weekend. Nothing is said. If a person answers we hang up and the recording of that call is deleted. We keep only recorded greetings, only for the business they belong to, we delete them on request, and you can withdraw the permission at any time.
Every commercial email we send identifies us, carries our mailing address, and contains a one-click unsubscribe. If you unsubscribe we record it permanently and stop emailing you — that record is the one thing we will not delete on request, because deleting it is how people get contacted again by mistake. If you would also rather not receive a demonstration call, tell us and we will note it.
12. Your rights
You have the right to:
- Access: get a copy of the information we hold about you.
- Know who has seen it: ask for a history of who accessed your record and when.
- Correction — through your clinic: your clinic is the custodian of your health record, and correcting it is its decision to make, not ours. Ask your clinic. If you tell us instead we will pass it on, but we do not change a clinical record on our own initiative.
- Deletion: ask us to delete your information.
- Opt out of SMS: reply STOP to any message.
- Withdraw consent: at any time.
How to make a request: contact your clinic, or email us at privacy@generalmagic.ai. Your clinic is the custodian of your health record and we act on its instructions, so we will work with them to answer you. We aim to respond within 30 days, which is the limit PIPEDA sets. If we need longer we will tell you why, and tell you that you can complain to the regulator.
Where your clinic must keep a record of your care, we remove the details that identify you rather than deleting the appointment itself — so the clinic’s file stays complete but is no longer linked to you.
13. Data security
Your information is encrypted while it travels and while it is stored. Access is restricted to authorised systems and staff.
Access by General Magic staff into a clinic’s account is limited and audited. It requires a stated reason, is read-only by default, is time-limited, and the session is recorded. Making any change requires deliberately promoting the session with a second, separate reason. In our internal client tools, contact details such as email, phone number and date of birth are masked until a staff member deliberately reveals them, and each reveal is logged against the individual it concerned.
What the access log covers. We record, immutably, when a patient record is opened in our internal tools, each time a masked contact detail is revealed, and every export, erasure and recording playback — who did it, and when. We monitor that log for unusual patterns. To be accurate about its limits: it does not yet capture every screen in the clinic’s own dashboard. Views such as the calendar and the call log read from the database directly and are not individually recorded, so the accounting we can give you is complete for the events listed above rather than for every glance at a screen. We are extending the coverage.
14. If there is a data breach
If we detect or are told about a breach affecting your information, we notify the clinic within 72 hours of confirming it. Because your clinic is the custodian, the law puts the decision to notify you in its hands — our job is to give it the facts fast enough and completely enough that it can make that decision properly, and to support it in notifying you and the regulator.
Under PHIPA, your clinic must tell you at the first reasonable opportunity if your health information is stolen, lost, or used or disclosed without authority, and must notify the Information and Privacy Commissioner of Ontario in the circumstances the law sets out. Under PIPEDA, a breach that creates a real risk of significant harm must be reported to the Privacy Commissioner of Canada and to you.
We keep a record of every breach — including ones we conclude created no real risk of significant harm — for a minimum of 24 months, as PIPEDA requires, and in practice for seven years. Those records are available to the regulator on request.
15. Children and young people
We do not offer our services directly to children. Where a clinic treats a young person, we handle their information on the clinic’s instructions and on the same terms as anyone else’s. Ontario law lets a young person who understands the decision make their own choices about their health information, and lets a parent or guardian act otherwise. Your clinic decides which applies; we follow its instruction.
16. Contact us
Our Privacy Officer is Chris Melnick-MacDonald, Head of Product. They are accountable for our compliance with this policy and with privacy law, and they are the person your question or complaint reaches.
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
- Privacy Officer: privacy@generalmagic.ai
- Website: getgema.ai
- Mail: General Magic Inc., P.O. Box 14043, Glebe, Ottawa, Ontario K1S 3T2, Canada
If your question is about your own health record, your clinic can usually answer it fastest, because it is the custodian. Either route works — write to us and we will coordinate with them.
17. If you are not satisfied
Please raise a concern with us or with your clinic first — we would rather fix it directly. You also have the right to complain to a privacy regulator:
- Health information in Ontario — Information and Privacy Commissioner of Ontario: ipc.on.ca
- Other personal information — Office of the Privacy Commissioner of Canada: priv.gc.ca
18. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page with a new “Last Updated” date.
