Personal Information Governance

In effect: August 31, 2026  ยท  Version française

Quebec law requires every enterprise to set out how it governs personal information, and to publish that in plain language. This page does that. It sits alongside the Privacy Policy, which tells you what we collect; this one tells you how we run it.

Who is responsible

GentleTaper is operated by Soutien aux Études KotobaPro, in Quebec, Canada.

The person in charge of the protection of personal information holds the title Responsable de la protection des renseignements personnels and can be reached at privacy@gentletaper.com.

These practices have been approved by that person, as the law requires. GentleTaper is run by one person, which is the honest description of the arrangement and matters for the section on roles below.

What information exists, and where it is

That is the complete list today. If it ever grows — for example if optional accounts are introduced — this page is updated before the change takes effect, not after.

Roles and responsibilities across the life of the information

There is one person. She decides what is collected and why, configures the systems that hold it, answers requests and complaints, and is accountable for all of it. No one else has access, and no staff or contractors handle personal information on our behalf beyond the service providers listed below.

A one-person business cannot separate duties the way a larger one can — the same person who sets a rule is the one who follows it. We compensate for that in the only way that actually works at this size: by collecting as little as possible. No names, no dates of birth, no addresses, no payment details, and no health information held by us at all.


How long information is kept, and how it is destroyed

Destruction means deletion from the system that held the information, including from the service provider's storage on the ordinary schedule of their backups.

Security

The measures in place are proportionate to what we actually hold, which is very little. Traffic to the site is encrypted. Access to the systems that hold anything at all is limited to the one person named above and protected by strong, unique credentials. Any information a service provider holds for us is encrypted in transit and at rest by that provider.

The strongest measure is the design itself: your health record never leaves your device, so no breach of ours can expose it.

Service providers

Three providers process information on our behalf. Each is bound by its own contract terms, may use the information only to provide the service, and may not use it for its own purposes.


If something goes wrong

We keep a register of confidentiality incidents, as the law requires, and the Commission d'accès à l'information may ask to see it.

If an incident happens, we assess whether it presents a risk of serious injury — considering how sensitive the information is, what could be done with it, and how likely misuse is. If it does, we notify the Commission and the people affected promptly, and tell them what happened and what they can do about it. We also take what measures we can to reduce the harm and to stop it happening again.

Asking for your information, or correcting it

You can ask what personal information we hold about you, ask for a copy, ask for it to be corrected, or ask for it to be deleted. Write to privacy@gentletaper.com. There is no charge and you do not have to give a reason.

We answer within 30 days of receiving the request, as Quebec law requires. If we cannot do what you asked, we tell you why, and we tell you that you may ask the Commission to review that decision.

Most of what people want is already in your own hands: the app exports your full history and deletes it on request, without involving us.

Making a complaint

If you think we have mishandled personal information, complain to us directly at privacy@gentletaper.com. Put “Complaint” in the subject line if you want it unmistakable, though we will recognise one either way.

What happens then:

You do not have to come to us first, and you can go elsewhere at any point. In Quebec, to the Commission d'accès à l'information du Québec. In the United Kingdom, to the Information Commissioner's Office. In the European Union, to the data protection authority where you live.

How these practices are kept current

They are reviewed once a year, and immediately whenever something changes what we hold or how we hold it — a new service provider, a new category of information, a new purpose.

Any project that would involve collecting personal information is assessed before it is built, not after. That assessment is a formal document, and the Commission may ask to see it.

Contact

Soutien aux Études KotobaPro
Responsable de la protection des renseignements personnels
privacy@gentletaper.com