Privacy policy.

Effective Date: 09 Sept 2025

CascaDTx Digital Therapeutics Inc. (“CascaDTx,” “we,” “our,” or “us”) is committed to protecting your privacy and safeguarding the personal health information you share with us. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our digital therapeutics applications, services, and websites (collectively, the “Services”).

Scope

This Privacy Policy applies to all personal information collected from users of our Services, including patients, caregivers, and clinicians, in accordance with:

  • British Columbia’s Personal Information Protection Act (PIPA)

  • Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA)

  • Applicable health privacy regulations in other jurisdictions where we operate

Information We Collect

We may collect the following types of information:

  • Personal identifiers: name, email, phone number, account credentials

  • Health information: medical history, symptoms, treatment adherence, side effect reporting, patient-reported outcomes

  • Device information: operating system, browser, unique device identifiers

  • Usage data: app activity, feature usage, crash reports, and analytics

  • Clinician-generated data: notes, assessments, or care plan inputs (if applicable)

How We Use Your Information

We use personal information to:

  • Deliver digital therapeutic interventions

  • Support disease management and track outcomes

  • Provide personalized insights and clinical reports

  • Ensure product safety, security, and performance

  • Conduct research and generate de-identified real-world evidence

  • Comply with regulatory, ethical, and legal obligations

Consent

We obtain your explicit consent before collecting, using, or disclosing your personal information, except where permitted or required by law. Consent may be withdrawn at any time, subject to legal or contractual restrictions.

Disclosure of Information

We do not sell personal information. We may share data only with:

  • Healthcare providers: to support patient care (with your consent)

  • Service providers: for secure hosting, analytics, or technical support, bound by strict confidentiality agreements

  • Regulators and ethics bodies: to meet compliance requirements

  • Research partners: only with de-identified or aggregated data

Data Security

We implement industry-leading safeguards, including:

  • End-to-end encryption (data in transit and at rest)

  • Role-based access controls

  • Regular security testing and monitoring

  • Data minimization and de-identification practices

  • Compliance with ISO 27001, HIPAA, and GDPR principles (where applicable)

Data Storage & Transfers

All personal data is stored on secure servers located in Canada. If data is processed outside Canada, we ensure equivalent protections are applied through contractual and technical safeguards.

Data Retention

We retain personal health information only as long as necessary to fulfill the purposes described above or as required by law. After this period, data will be securely deleted or de-identified.

Your Rights

As a user, you have the right to:

  • Access and obtain a copy of your personal information

  • Correct inaccuracies in your information

  • Request deletion of your personal information (subject to legal obligations)

  • Withdraw consent to data use

  • Ask about how your information is used and who it is shared with

Children’s Privacy

Our Services are not directed to children under 16 without parental or guardian consent.

Changes to This Policy

We may update this Privacy Policy from time to time. Any material changes will be communicated through our Services before taking effect.

Contact Us

If you have questions, concerns, or wish to exercise your privacy rights, please contact:

Privacy Officer
CascaDTx Digital Therapeutics Inc.
Vancouver, BC, Canada
Email: contact@cascadtx.com
Phone: +1 (778) 792 3328