> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getrivet.ca/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy & security

> How Rivet handles your clients' information, what's encrypted, what's stored where, and what you control as the custodian of your records.

You're a regulated practitioner. The people who call your line are reaching
out about their mental health. Everything about how Rivet handles that
information matters — to your College, to your clients, and to you when an
audit lands on your desk.

<Note>
  Rivet is designed to be consistent with Canada's *Personal Information
  Protection and Electronic Documents Act* (PIPEDA) and Ontario's *Personal
  Health Information Protection Act* (PHIPA). Rivet acts as your **agent**
  under PHIPA s.2 — handling client information on your behalf, under your
  direction.
</Note>

## Your role and Rivet's role

<CardGroup cols={2}>
  <Card title="PHIPA and Rivet" icon="scale-balanced" href="/privacy/phipa-and-rivet">
    The legal characterization. Rivet as agent + electronic-service provider.
    Where each piece of law fits.
  </Card>

  <Card title="Your role as custodian" icon="user-shield" href="/privacy/your-role-as-custodian">
    What being a health information custodian means in practice — and what
    Rivet does on your behalf.
  </Card>

  <Card title="The Data Processing Agreement" icon="file-signature" href="/privacy/data-processing-agreement">
    The agreement you accept when you sign up. What it covers, who the
    sub-processors are, what changes when you cancel.
  </Card>

  <Card title="Client data handling" icon="database" href="/privacy/client-data-handling">
    What Rivet stores about your clients, retention defaults, and your
    client's right to deletion.
  </Card>

  <Card title="Voicemail in Canada" icon="microphone" href="/privacy/voicemail-transcription-canadian-processing">
    Voicemail audio and transcription run on Canadian hardware. The
    specific path each voicemail takes from caller to inbox.
  </Card>

  <Card title="Where your data lives" icon="globe" href="/privacy/where-your-data-lives">
    The College-auditor answer. Specific table of every kind of
    information and where it physically lives, plus the evidence Rivet
    can produce on request.
  </Card>
</CardGroup>

## Safeguards and incident response

<CardGroup cols={2}>
  <Card title="Encryption" icon="lock" href="/privacy/encryption">
    HTTPS everywhere, AES-256 at rest, biometric-locked sessions, WebRTC
    DTLS-SRTP for video.
  </Card>

  <Card title="Audit logging" icon="list-check" href="/privacy/audit-logging">
    The append-only log that records who touched what, and why metadata is
    all that goes in it.
  </Card>

  <Card title="Breach response" icon="triangle-exclamation" href="/privacy/breach-response">
    The five phases. Who Rivet notifies. How Rivet helps you meet your own
    notification obligations.
  </Card>

  <Card title="Measurement vs. clinical content" icon="ruler" href="/privacy/the-measurement-results-vs-clinical-content-distinction">
    The line between what Rivet captures and what belongs in your EHR — and
    why that line is the whole point.
  </Card>

  <Card title="Practitioner security" icon="key" href="/privacy/security-best-practices-for-practitioners">
    The handful of habits that keep your account, your sign-in email, and
    your device honest.
  </Card>
</CardGroup>
