Pilot testing in progress.This site is under active development and data may be reset without notice. Please don't submit real care requests yet.
Skip to main content

Legal

Health data handling procedures

Last updated: April 3, 2026

Building in public. This document is part of a technology demonstration. It has not been reviewed or approved by legal counsel and does not constitute legal advice, a binding agreement, or a final policy. Polymorphism is an Alberta home-care marketplace prototype built to showcase platform architecture โ€” not a live service accepting clients or caregivers at this time.

What we may store

Care coordination records can include intake narratives, high-level ADL needs, scheduling metadata, visit verification (EVV) timestamps, billing artifacts, and uploaded compliance documents โ€” limited to what is necessary for marketplace operations.

Access controls

Supabase Row Level Security restricts rows to the owning client or caregiver account; platform automations use a dedicated service role with audit logging recommended in production.

Encryption & residency

Data in transit uses TLS. At-rest encryption follows the database provider's defaults. Choose Canadian or contractually approved regions when provisioning Supabase for regulated workloads.

Breach notification

Material privacy incidents should be escalated to the Privacy Officer and, where required, reported to the Alberta Information and Privacy Commissioner within statutory timelines.

Retention

Health-adjacent records often require multi-year retention (commonly up to seven years for business records โ€” confirm with counsel and clinical governance).