TELUS Health Services Privacy Commitment
Last updated: 17 November 2025
As a leader in privacy and data protection, TELUS Health is deeply committed to handling personal information in a responsible and transparent manner.
TELUS Health offers health, wellness, and workplace management products and services (referred to as “Services”) that are designed to build and maintain healthy communities and workplaces. The TELUS Health Services Privacy Commitment (“Commitment”) describes our privacy practices relating to the information that TELUS Health collects, uses, discloses and otherwise processes (“process” or “processes”) when you use our Services, the associated website and mobile apps (“Service Platforms”), or otherwise interact with us in connection with our Services. This Commitment may be supplemented with privacy notices aimed at providing you with additional privacy information. These supplemental notices form an integral part of the Commitment, and take precedence in case of conflict.
With the exception of limited personal information related to your eligibility for Services for which the organization that grants you access to the Services such as your employer, educational institution, or benefits provider (“Sponsoring Organization”) is accountable, TELUS Health has overall responsibility for protecting the privacy of the personal information we collect about you through the Services, and we are directly accountable to you with respect to the processing of that information. In certain jurisdictions, the healthcare practitioner employed or engaged by TELUS Health to provide or oversee the provision of Services (“Healthcare Practitioner”) is directly accountable to you for the processing of your personal information (see
Supplemental Privacy Commitment for Canada
for more information). If we refer you to a third party (e.g. specialist clinician) outside of TELUS Health to receive Services, that party will be accountable to you for any personal information shared with them. This Commitment does not apply to the processing of personal information about our websites’ and physical sites’ visitors, and prospects and contacts within our business customer, supplier and business partner organizations with whom we have or contemplate a business relationship; our processing of such personal information is subject to the
TELUS Health Corporate Privacy Commitment
. This Commitment also does not apply to subsidiaries that have their own privacy commitment, notice or statement, or non-affiliated websites linked on TELUS Health websites or products and services.
For information about TELUS Health’s privacy practices relating to customer personal information that TELUS Health processes as a service provider to business customers, please refer to our
Privacy Information for TELUS Business Customers
. In this Commitment, the words “we”, “us”, “our” or “TELUS Health” refer to TELUS Health Inc. and its subsidiaries.
Personal information, also known as “personal data”, is information that can be linked to an identifiable individual.
“Sensitive personal information”, also known as “sensitive personal data” or “special categories of data” is a subset of personal information which includes information pertaining to health, ethnic origin, genetics, sexual orientation, religious beliefs, criminal convictions, financials and biometrics.
What personal information we process and for what purposes
What personal information we process and for what purposes
We may process the following categories of personal information about you, depending on the Services you use and how you engage with us:
- Your activity metrics, such as steps walked or calories burned, entered manually or collected through devices such as smartwatches, that you sync with your Service Platform account;
- Your identity and contact information including your name, mailing and email addresses, telephone number, place of birth, demographic information, employee ID and other similar identifiers;
- Employment information such as your educational background, employment history, job details, and workplace information such as workplace environment, injuries and absences;
- Payment related information including your credit card details and other banking information;
- Information about your past or present physical or mental health including your medical history, records of treatment and services you request and/or receive from Healthcare Practitioners, reports of the results of laboratory, pathology, consultations, diagnostic imaging examinations or tests, and your family health history, dietary habits, lifestyle and interests;
- Information about your personal preferences (e.g. religious beliefs, sexual orientation);
- Information you share via feedback surveys including your communications with other users and comments in forums and message boards;
- Your profile information including your profile photo, groups you belong to, events you are attending and any other information made available on your profile;
- Information relating to the administration of your pension plan, including your demographic information, beneficiary information, contributions and payouts;
- Information about your social and economic status including information about your marital status, dependants and financial standing;
- Technical and usage information collected about your visit or use of our website or mobile apps and Services such as your IP address, device identifier, device settings, browsing information and interactions (e.g., length of time you visited, pages viewed, links clicked).
We process your personal information for the following purposes:
To establish and maintain our relationship with you, and to provide Services to you
To establish and maintain our relationship with you, and to provide Services to you
- The categories of personal information collected and processed may vary depending on the type of Service selected, the information required to administer the Service, and the mode of Service delivery (e.g. via a Service Platform or TELUS Health call centre agent). To use a Service Platform, you may need to provide information to create an account. To register for Services without using a Service Platform, you may need to speak to a TELUS Health call centre agent. We record all audio conversations with call centre agents, in accordance with applicable laws and with your consent if required, for quality assurance and training purposes. Prior to receiving Services, you may be required to verify your identity. We verify your identity in accordance with our legal obligations and to help prevent fraud, including public healthcare fraud.
- For Services that enable you to consult with a Healthcare Practitioner, we may connect you through a real-time video or audio call or text-based chat functionality. At the outset of the interaction, your Healthcare Practitioner will authenticate you. All video and audio calls conducted through any Service Platform are confidential. From time to time, we may review Healthcare Practitioners’ work (e.g., by reviewing their consultation notes or your text-based conversations with Healthcare Practitioners) to ensure they are meeting the standard and quality of care expected of them by TELUS Health. We never make video recordings of consultations using a Service Platform. Although we do not record your video image, your voice may be recorded during consultations to assist with administrative activities such as dictation or generating a transcript including with the help of tools powered by artificial intelligence.
- We may use your personal information to contact you by email or push notifications to provide you with information about the Services, including Service updates, appointment reminders, instructions on how to prepare for your appointment and other important updates. In the event of an emergency, if we need to relay time-sensitive or diagnostic information to you, or if we otherwise need to get in touch with you, we may call you and, where appropriate, leave a voicemail if we are unable to reach you.
- We may use your personal information to provide support and to resolve customer issues. We record all customer support calls, in accordance with applicable laws and with your consent if required, for quality assurance and training purposes.
- For Services provided to you directly and/or that are not covered by your Sponsoring Organization, we and/or our third-party payment processor may collect and use personal information to process your payments.
To understand your needs and preferences
To understand your needs and preferences
- We may contact you regarding your experience when using the Services. You may also be prompted to provide a rating or feedback within a Service Platform. These survey invitations and feedback prompts may be sent to you based on information about your general location, the Service you used and the Service date, and your activity, profile and usage information. We may use your responses to these voluntary surveys to understand your needs and preferences and/or for research purposes.
To develop and enhance products and services
To develop and enhance products and services
- As permitted by law, we may use your personal information, including actions you take on the Service Platforms, to develop and enhance our products and services.
To market products and services
To market products and services
- In accordance with applicable laws and with your consent if required, we may use your personal information to provide you with newsletters, information about our events, marketing and sales communications about our products and services or those of the TELUS affiliates that may be of interest to you. If you do not wish to receive marketing communications from us, you can follow the “unsubscribe” instructions included in each of our marketing messages. Alternatively, you can contact us as set out in the “How to contact us” section below. Even if you unsubscribe, however, you may still continue to receive transactional and service emails from us.
To maintain the security and functionality of Service Platforms
To maintain the security and functionality of Service Platforms
- Technical and usage information is used to allow our Service Platforms to function on your device, deliver content appropriate for your device’s capabilities, deliver push notifications (if enabled), help understand our application activity, and detect anomalous behaviour to provide a secure user experience. In the event an app crashes on your mobile device, we may receive certain additional technical information, such as information about your mobile device model software version and device carrier, which allows us to identify and fix bugs and otherwise improve the performance of our applications.
- If you have enabled location tracking in a Service Platform, we may collect your precise location information according to your selected level of access. You may use our services without enabling the collection of precise location information from your device; however, this may impact the availability of certain content, features and functionality in the application. You can opt out at any time by turning off location tracking either within the application or in the settings of your mobile device. If you have not allowed us to collect your precise location, we can only determine your approximate location.
We may de-identify personal information in such a manner that it is no longer considered personal information under applicable laws, for a variety of reasons. For example, we may de-identify personal information to protect your personal information, prior to conducting analytics or research for planning or product improvement and development purposes, for reporting, or to operate and expand our business opportunities.
We collect the above categories of personal information from you and from your interactions with us. We may also collect personal information from other sources, such as your Sponsoring Organization.
What legal basis or authority do we rely on to process your personal information
We mainly process your personal information to provide you with our Services, including through your use of our Service Platforms. We also process your personal information for the purposes of our legitimate interests, where permissible under applicable laws. Such legitimate interests include operating our business and developing, improving and promoting our products and services.
In some situations, we may process your personal information based on your consent. This may be the case for processing activities that are purely voluntary, to market our products and services, share your personal information if required, or where the proposed processing under the above listed purposes could be considered as falling outside of your reasonable expectations.
In others, we may have a legal obligation to process your personal information, such as for tax reporting purposes, in response to a court order or other legally valid inquiry, or to exercise, establish or defend legal claims.
If you have questions about the legal basis we are relying upon for a specific processing activity, please contact us using the contact information under the “How to contact us” section below.
How we share your personal information
How we share your personal information
There are a variety of circumstances in which we share your personal information in order to achieve the purposes identified above.
- In accordance with applicable law and with your consent if required, we may share certain limited information with your Sponsoring Organization to enable them to administer your incentives, manage your TELUS Health account, plan or program, and otherwise act as your account administrator. The limited information we share might include information about the status of your use of the Services (e.g., whether you are an active user, whether your access has been revoked) and information needed to calculate health plan premium discounts, applicable taxation and reward redemption;
- Where you direct us to, we will share your personal information with Healthcare Practitioners or other third-party providers to deliver the Services;
- We may share your personal information with third party service providers for the purposes identified in this Commitment and supplementary privacy notices, such as hosting service providers and payment processors. We require these third party service providers to handle your personal information in accordance with our instructions, this Commitment, and applicable law, and we take steps to verify that they provide a level of protection equivalent to TELUS Health’s;
- With your consent if required by applicable law, we may share your personal information and information about the products or services you may use from one TH line of business with another TELUS Health line of business to combine with your existing user profile (if applicable) and create a single record of you across TELUS Health employer services;
- When required by law or contract, or when TELUS Health determines in its sole discretion that it is desirable to do so to protect TELUS Health’s or a third party’s interest, we may share your personal information with government, law enforcement agencies and other public institutions;
- If we sell parts of our business, sell or securitize assets, or merge or amalgamate parts of our business with other entities, we may share personal information about you in the normal course of such transactions as part of due diligence and/or on completion of the transaction;
- We may share de-identified information with our partners for a variety of reasons. For example, we share de-identified information to conduct analytics, research, for planning or product improvement and development purposes, for reporting including to the Sponsoring Organization, or to operate and expand our business opportunities.
- We may share personal information about you through online tracking technologies, such as cookies we use on our Service Platforms, for purposes such as analytics and targeted advertising as described in ourCookie Statement. You may opt-out at any time by visiting our Cookie Management Center in the footer of the website.
- We do not “sell” your personal information within the meaning of the California Consumer Privacy Act. Should we engage in such practices in the future, or share your personal information with non-affiliated third parties for marketing purposes, we will notify you and provide you with appropriate choices regarding the processing of your personal information.
- We may otherwise share your personal information with other third parties, where permitted or required by law.
Where we transfer your personal information
As a global company, we transfer your personal information to TELUS affiliates and third parties, including service providers, who process personal information outside of the jurisdiction in which you are located. Their processing may be subject to laws applicable in the jurisdictions in which they process your personal information.
We have implemented legal, technical and organizational safeguards required under applicable law to enable these cross-border transfers of your personal information. For example, we may rely on model contracts to enable such transfers, seek authorization from the relevant supervisory authorities, or obtain your consent.
In particular, for transfers outside of the European Economic Area and the United Kingdom, we rely upon the European Commission’s approved EU Standard Contractual Clauses, which can be accessed
here
. For transfers from the United Kingdom, we rely upon the International Data Transfer Addendum to the EU Standard Contractual Clauses, issued by the Information Commissioner and laid before Parliament in accordance with s.119A of the Data Protection Act 2018 on 2 February 2022, which can be accessed here
.
What rights do you have with regards to your personal information
What rights do you have with regards to your personal information
Local laws may provide you with certain rights with regards to your personal information. For example, you may have the right to:
- Request access to and obtain a copy of your personal information, including confirming whether we are processing your personal information;
- Request correction of your personal information where it is inaccurate, incomplete or outdated. In some cases, we may provide self-service tools that enable you to update your personal information;
- Request deletion of your personal information;
- Request restriction of our processing of your personal information;
- Withdraw consent, which you may have provided for certain processing activities, at any time;
- Object to the processing of your personal information by us;
- Request data portability, i.e. obtain a copy of your personal information in a commonly used format to transmit it to another organization, or request that we do so on your behalf;
- Request the review of decisions which are taken solely based on automated processing and that significantly affect you.
These rights may be limited, such as when fulfilling your request would reveal personal information about another person, or when you ask us to delete information which we are required or permitted by law to retain.
If you wish to exercise these rights, please see the “How to Contact Us” section below. Only you, or someone legally authorized to act on your behalf, may make a request related to your personal information. To authorize an agent, you will need to provide written authorization signed by you and your designated agent and contact us as set forth in the “How to Contact Us” section below. You will not receive discriminatory treatment for exercising any rights conferred to you by applicable privacy laws.
To protect your privacy, we will take steps to reasonably verify your identity before fulfilling your request. These steps may involve asking you to provide information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative. Examples of our verification process may include asking you to provide the email address we have associated with you and following the instructions we provide to you.
We will endeavor to provide a written response to your request or complaint within one month unless applicable law requires a shorter response time. If you have unresolved concerns, you have the right to complain to your privacy regulator. Relevant contact details are available
here
. We will not take any action against you for filing a complaint.If you would like to receive further information about your rights or how to enforce them, please contact us using the “How to Contact Us” section below.
How long we retain your personal information
How long we retain your personal information
TELUS Health retains your personal information as long as necessary to fulfill the purposes for which it was collected or as otherwise required or permitted by law. In addition, TELUS Health retains data on matters that are likely to give rise to a legal challenge for applicable statutory limitation periods. TELUS aims to keep its files current and disposes of data pursuant to its Records Retention Policy.
How we protect your personal information
TELUS Health is committed to protecting the security of your personal information. We use a variety of security technologies and procedures to help protect your personal information from unauthorized access, use, or disclosure. For example, we store the personal information you provide on limited access computer servers that are located in controlled facilities, and we protect certain sensitive personal information through encryption in transfer and at rest.
Children’s Privacy
Children’s Privacy
We will not knowingly provide products or services to children or persons under the age of majority in their jurisdiction without the permission of their parent or guardian. If you are a child or minor and want to access our Services, your parent or guardian must contact TELUS Health on your behalf and provide consent to the processing of your personal information.
How to contact us
How to contact us
If you have any questions or concerns about our privacy practices, or wish to exercise any rights in respect of your personal information, please contact us at
[email protected]
or at:TELUS Health
c/o Chief Data & Trust Officer
25 York Street, Floor 30
Toronto ON, M5J 2V5
c/o Chief Data & Trust Officer
25 York Street, Floor 30
Toronto ON, M5J 2V5
In certain jurisdictions, such as the European Union, we may appoint a Data Protection Officer as required by law. To get in touch with our Data Protection Officer, email
[email protected]
.
Modifications to this Commitment
Modifications to this Commitment
We will review this Commitment annually and update it thereafter as needed to reflect changes in laws, our data management practices, and in other circumstances. We will notify you when material changes to this Commitment are made to the extent we hold personal information about you which is subject to this Commitment, either by email or by posting the revised Commitment on our website.