Privacy Policy
How Hispir Care collects, uses, and protects your personal information.
Effective June 9, 2026 · Version 1.1
1. About Hispir Care
Hispir Consulting Ltd., operating as Hispir Care ("Hispir," "we," "us," or "our"), is a private social service provider based in Calgary, Alberta. Hispir supports families of children with disabilities and the aides who provide support through Hispir.
This Privacy Policy explains how Hispir handles personal information at the public-site, account-creation, sign-in, and general Hispir Care Account stages.
This policy is governed by Alberta's Personal Information Protection Act (PIPA). Detailed guardian and aide information is governed by the role-specific Privacy Notice you accept before submitting guardian or aide intake information.
2. What this policy covers
This policy covers:
- limited technical information processed when someone visits the public Hispir site;
- account information collected when a user creates a Hispir Care Account;
- sign-in, verification, security, and account activity records;
- records of agreement, policy, and consent acceptances completed at account creation or through the general Hispir Care Account; and
- general communications and support related to your Hispir Care Account.
Additional or more specific privacy notices and consents may be presented to you for a particular role, service, form, feature, or account function, and they apply to what they are presented for. This policy continues to apply to the general public-site, account-creation, sign-in, and Hispir Care Account stages.
3. Public site information
When someone visits the public site, Hispir and its service providers may process limited technical information needed to deliver, secure, and operate the site, including:
- IP address;
- browser and device information;
- request headers;
- pages or routes requested;
- date and time of the request; and
- similar hosting, security, and delivery logs.
4. Account information we collect
When you create a Hispir Care Account, we may collect:
- first name and last name;
- email address;
- phone number;
- password;
- account role or selected user path;
- verification status;
- last sign-in and account activity records;
- optional profile photo, if you choose to add one;
- device name, IP address, browser user-agent, and similar security records; and
- records of agreement, policy, and consent acceptances, including version, timestamp, account, and related technical evidence.
If you contact Hispir by email, phone, or account support channels, we may also keep records of that communication to respond to you and maintain an account history.
5. Information entered before role-specific submission
You must accept the applicable Privacy Notice and any related agreements before you submit a guardian or aide intake form. Hispir does not receive intake information until you complete that submission.
6. Why we collect and use information
Hispir may collect and use the information covered by this policy to:
- operate, secure, and maintain the public site and the Hispir Care Account;
- create, verify, authenticate, and administer user accounts;
- send account verification, password reset, security, support, and account-related communications;
- route users to the appropriate account flow;
- maintain records of accepted agreements, policies, consents, and versions;
- prevent, detect, investigate, or respond to security, privacy, fraud, misuse, legal, or operational concerns;
- operate limited analytics, performance, and error-monitoring functions;
- respond to user questions, support requests, access requests, correction requests, or account-closure requests;
- comply with legal, regulatory, child-safety, audit, accounting, tax, business, and dispute-resolution requirements; and
- exercise or defend Hispir's legal rights.
Hispir does not sell personal information. Hispir does not use account information for marketing without separate consent.
7. Who we disclose information to
Hispir may disclose information covered by this policy only as reasonably required for the purposes described in this policy or as otherwise permitted or required by law.
This may include disclosure to:
- Hispir personnel or administrators who need access for account, support, privacy, security, legal, or operational purposes;
- service providers that host, secure, deliver, monitor, or support the public site, app, email, files, account system, and related Hispir Care Account operations;
- regulators, courts, law enforcement, child-protection authorities, government bodies, or other parties where required or permitted by law;
- professional advisers, insurers, auditors, or legal representatives where reasonably required to protect Hispir's interests; and
- another organization in connection with a proposed or completed business transaction, reorganization, financing, merger, sale, or transfer, where permitted by law and subject to appropriate safeguards.
8. Service providers and outside-Canada processing
Hispir's core account, database, and document storage are kept in Canada by default. To deliver and operate the public site and the Hispir Care Account, Hispir uses service providers for the functions below. Some of these providers process limited personal or technical information outside Canada, mostly in the United States:
- cloud infrastructure, database, document storage, and system logging (kept in Canada);
- website and application hosting, including usage and performance analytics;
- error and performance monitoring;
- account verification, notification, and email delivery;
- account security screening, including breached-password checking;
- address lookup and autocomplete;
- automated moderation of uploaded images;
- content and code-library delivery; and
- back-office email, document storage, and internal automation.
Additional providers may be involved at later stages and are described in the applicable Privacy Notice or consent process.
You may contact the Privacy Officer for Hispir's current list of service providers and its written policy on service providers outside Canada, including the countries where processing may occur and the purposes for which those providers are authorized to process information.
9. Cookies, browser storage, and local drafts
The Hispir Care Account uses browser storage and cookies for account and functionality purposes. This may include:
- secure session cookies for signed-in access;
- local storage needed to resume long intake forms before submission; and
- interface preferences.
Local draft storage may remain on the user's device until cleared, expired, or submitted. Users should sign out and use appropriate device security, especially on shared devices.
10. How long we keep information
Hispir retains personal information only for as long as reasonably required for legal or business purposes.
Account records are generally retained while the account is active. After an account is closed, Hispir may retain account, acceptance, audit, support, security, and related records for as long as reasonably required for:
- legal and regulatory compliance;
- tax, accounting, and business records;
- FSCD, billing, and service-related records, where applicable;
- privacy, security, consent, and audit evidence;
- complaint, investigation, insurance, limitation-period, or dispute purposes; and
- enforcement or defence of Hispir's legal rights.
If a user creates an account but does not proceed into a guardian or aide portal, Hispir may delete or de-identify the inactive account record earlier, subject to any legal, security, audit, or business reason for retaining part of the record.
Agreement, policy, consent, security, and audit records may be retained separately from an active account profile because they are used to prove what was accepted, when, and by which account.
When Hispir no longer reasonably requires personal information, it may be destroyed or de-identified in accordance with Hispir's retention and disposition practices.
11. How we protect information
Hispir uses reasonable administrative, technical, and operational safeguards appropriate to the sensitivity of the information. These include:
- encrypted connections (TLS);
- secure password hashing and breached-password screening;
- authenticated, role-based access controls;
- malware scanning for uploaded files; and
- audit records for agreement acceptance and key security events.
Hispir reviews and updates its safeguards as its operations, vendors, and risks change.
12. Privacy breaches
Hispir maintains a privacy breach response process. If Hispir becomes aware of a loss of, unauthorized access to, or unauthorized disclosure of personal information, Hispir will assess the incident and take steps it considers appropriate in the circumstances.
Where a breach creates a real risk of significant harm, Hispir will notify Alberta's Office of the Information and Privacy Commissioner without unreasonable delay, as required by PIPA. Hispir may also notify affected individuals where required by law or where Hispir determines that notice is appropriate.
13. Your rights
Subject to legal limits, you may:
- request access to personal information Hispir holds about you;
- request correction of information that is inaccurate or incomplete;
- withdraw or change consent for future collection, use, or disclosure, subject to legal, contractual, operational, and service-delivery limits;
- request account closure or deletion, subject to retention requirements; and
- make a privacy complaint to Hispir or to Alberta's Office of the Information and Privacy Commissioner.
Hispir may need to verify your identity before responding to a request. Access and correction requests should be made in writing. Hispir will respond within the time required by PIPA, generally 45 days unless the time is lawfully extended.
If you withdraw consent that is necessary for account operation, security, legal compliance, or service delivery, Hispir may be unable to continue providing some or all account access.
14. Privacy Officer
Questions, access requests, correction requests, withdrawal requests, account-closure requests, and privacy complaints can be sent to:
Privacy OfficerHispir Care
Email: privacy@hispir.com
15. Changes to this policy
Hispir may update this policy from time to time.
If a change is minor, Hispir may post or make available the updated policy. If a change is meaningful, Hispir may ask users to review and accept the updated policy before continuing to use the Hispir Care Account.
The version accepted at account creation applies until a later version is presented and accepted or otherwise takes effect in accordance with applicable law and Hispir's policy release process.