SomniCharts SomniCharts
  • Introduction
  • Subscriptions
  • العربية 中文 Dansk English Français Deutsch עברית Italiano 日本語 IRفارسی Polski Português Español
  • Login

Privacy Policy

SomniCharts Inc. — www.somnicharts.com

Effective Date: January 3, 2026

Company: SomniCharts Inc.
Registered in: Canada
Contact: admin@somnicharts.com

1. Platform Architecture & Role

SomniCharts is a sleep therapy data visualization and analytics platform.

  • SomniCharts personnel do not routinely access uploaded sleep data.
  • Sleep data is encrypted at rest (minimum 128-bit encryption or stronger).
  • Data is encrypted in transit via HTTPS/TLS.
  • Each account operates in a logically isolated user environment.
  • Sleep data is automatically deleted upon membership termination or lapse.
2. Data We Collect

Account Information:

  • Name
  • Email address
  • Billing information
  • Organization name (if applicable)

Sleep Therapy Data:

  • Uploaded CPAP and sleep therapy files
  • Therapy metrics and usage data

Sleep data is processed automatically and is not manually reviewed in the ordinary course of business.

3. Data Controller / Processor Roles

Individual Subscribers: SomniCharts acts as Data Controller for account information.

Clinics (B2B Accounts): Clinics act as Data Controllers for patient data. SomniCharts acts as a limited Data Processor solely for automated processing.

4. Automatic Data Deletion

Upon cancellation, non-renewal, or termination:

  • All uploaded sleep data is permanently deleted within a commercially reasonable timeframe.
  • No archival recovery is guaranteed.
  • Re-registered users must re-upload data.
5. Security Measures
  • Encrypted storage
  • Encrypted transmission
  • Role-based internal access control
  • Logical user isolation
  • No routine employee access to decrypted sleep data
6. International Data Transfers

Data may be processed in Canada, the United States, or other secure jurisdictions with appropriate safeguards including Standard Contractual Clauses where required.

7. Your Rights

Depending on jurisdiction (GDPR, PIPEDA, U.S. privacy laws), users may request:

  • Access
  • Correction
  • Deletion
  • Withdrawal of consent

Contact: admin@somnicharts.com

← Back to SomniCharts
© 2026 SomniCharts. All rights reserved. | v5.AI.111 | Privacy Policy | Terms of Service | Medical Disclaimer | Enterprise
Privacy Policy

Effective Date: January 3, 2026

Company: SomniCharts Inc.
Registered in: Canada
Contact: admin@somnicharts.com

1. Platform Architecture & Role

SomniCharts is a sleep therapy data visualization and analytics platform.

  • SomniCharts personnel do not routinely access uploaded sleep data.
  • Sleep data is encrypted at rest (minimum 128-bit encryption or stronger).
  • Data is encrypted in transit via HTTPS/TLS.
  • Each account operates in a logically isolated user environment.
  • Sleep data is automatically deleted upon membership termination or lapse.
2. Data We Collect

Account Information:

  • Name
  • Email address
  • Billing information
  • Organization name (if applicable)

Sleep Therapy Data:

  • Uploaded CPAP and sleep therapy files
  • Therapy metrics and usage data

Sleep data is processed automatically and is not manually reviewed in the ordinary course of business.

3. Data Controller / Processor Roles

Individual Subscribers: SomniCharts acts as Data Controller for account information.

Clinics (B2B Accounts): Clinics act as Data Controllers for patient data. SomniCharts acts as a limited Data Processor solely for automated processing.

4. Automatic Data Deletion

Upon cancellation, non-renewal, or termination:

  • All uploaded sleep data is permanently deleted within a commercially reasonable timeframe.
  • No archival recovery is guaranteed.
  • Re-registered users must re-upload data.
5. Security Measures
  • Encrypted storage
  • Encrypted transmission
  • Role-based internal access control
  • Logical user isolation
  • No routine employee access to decrypted sleep data
6. International Data Transfers

Data may be processed in Canada, the United States, or other secure jurisdictions with appropriate safeguards including Standard Contractual Clauses where required.

7. Your Rights

Depending on jurisdiction (GDPR, PIPEDA, U.S. privacy laws), users may request:

  • Access
  • Correction
  • Deletion
  • Withdrawal of consent

Contact: admin@somnicharts.com

Terms of Service

Version: 1.1
Effective Date: April 24, 2026

Governing Law: Province of Ontario, Canada

1. Nature of Service

SomniCharts provides automated sleep data visualization tools only. The platform does not provide medical services.

2. Account Eligibility

You must be 18 years or older and provide accurate registration information.

3. Subscriptions & Billing
  • Subscriptions renew automatically unless canceled.
  • Fees are billed in advance.
  • No refunds unless required by law.
4. Data Ownership

Users and clinics retain full ownership of uploaded sleep data.

SomniCharts receives a limited license to process, analyze, and display data during active membership only.

5. Automatic Data Deletion

Upon membership lapse or termination:

  • All uploaded sleep data is permanently deleted.
  • No recovery is guaranteed.
  • Re-registration requires new uploads.
6. User Isolation & Security
  • Encrypted storage (minimum 128-bit or stronger)
  • Encrypted transmission
  • Logical account isolation
  • No routine employee access to sleep data

Users are responsible for safeguarding login credentials.

7. Authorized Support Access

Authorized Support Access. To resolve technical issues or provide support, authorized SomniCharts personnel may access your account on your behalf. Every such access is recorded in an audit log retained for six (6) years, which includes the date and time of access, the reason, and any actions taken. You may request a copy of the access history pertaining to your account at any time by contacting support. Support access is governed by this agreement and by our internal access controls; no third party may access your account through this mechanism.

8. Limitation of Liability

SomniCharts is not liable for:

  • Medical decisions
  • Therapy adjustments
  • Data loss after termination
  • Indirect or consequential damages

Total liability is limited to subscription fees paid in the preceding 12 months.

9. B2B Accounts

Clinics warrant lawful authority to upload patient data and compliance with applicable privacy laws (HIPAA, GDPR, PIPEDA).

10. Termination

Accounts may be suspended or terminated for violations. Users may cancel at any time.

Medical & Clinical Disclaimer

Effective Date: January 3, 2026

SomniCharts is a non-clinical software platform.

SomniCharts:

  • Does not provide medical advice
  • Does not diagnose or treat medical conditions
  • Does not prescribe therapy
  • Does not replace licensed healthcare professionals
  • Does not clinically interpret sleep data

All charts, analytics, and outputs are automated visualizations for informational purposes only.

Clinical interpretation and treatment decisions remain solely with:

  • The individual user
  • The treating healthcare professional
  • The subscribing clinic (in B2B use)

SomniCharts disclaims liability for medical decisions made based on platform outputs.

HIPAA Positioning

When contracting with U.S. healthcare providers, SomniCharts may execute a Business Associate Agreement (BAA) where required.

Enterprise Compliance Addendum

Effective Date: January 3, 2026

Company: SomniCharts Inc.
Registered in: Canada

This Enterprise Compliance Addendum ("Addendum") supplements the SomniCharts Terms of Service and applies to enterprise, clinic, healthcare provider, and institutional customers ("Customer").

Part I — Data Processing Agreement (GDPR / PIPEDA)
1. Roles of the Parties

For purposes of applicable data protection laws:

  • The Customer acts as Data Controller of patient or end-user personal data.
  • SomniCharts acts as Data Processor, processing personal data solely on documented instructions of the Customer.

SomniCharts does not independently determine purposes or means of processing patient data.

2. Nature & Purpose of Processing

Processing activities include:

  • Secure storage of uploaded sleep therapy data
  • Automated analysis and visualization
  • Session-based decryption for authenticated display
  • Automatic deletion upon membership termination

Processing is limited to functionality necessary to deliver the SomniCharts platform.

3. Categories of Data
  • Sleep therapy data (e.g., CPAP metrics)
  • Usage statistics related to therapy compliance
  • Limited account identifiers (name, email)

Sensitive health-related data is processed only as uploaded by the Customer.

4. Security Measures

SomniCharts implements:

  • Encrypted storage (minimum 128-bit encryption or stronger)
  • Encrypted transmission (HTTPS/TLS)
  • Logical user isolation via authenticated accounts
  • Role-based internal access controls
  • No routine employee access to decrypted patient data
  • Automatic deletion upon account termination
5. Subprocessors

SomniCharts may engage third-party subprocessors for:

  • Cloud infrastructure
  • Payment processing
  • Email delivery

All subprocessors are contractually obligated to implement appropriate security safeguards.

6. International Transfers

Where personal data is transferred outside the EEA/UK, SomniCharts relies on:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions
  • Equivalent lawful safeguards
7. Data Subject Rights

SomniCharts will assist Customer, where reasonably possible, in responding to:

  • Access requests
  • Deletion requests
  • Correction requests
  • Restriction or portability requests
8. Data Retention & Deletion

Upon termination or expiration of Customer's membership:

  • All patient sleep data is permanently deleted within a commercially reasonable timeframe.
  • No archival copies are retained.
  • Re-registration requires new data upload.
Part II — HIPAA Business Associate Addendum (BAA)

This section applies only when Customer is a U.S. Covered Entity or Business Associate under HIPAA.

1. Definitions

Terms such as "Protected Health Information (PHI)," "Covered Entity," and "Business Associate" have the meanings assigned under HIPAA (45 CFR Parts 160 and 164).

2. Permitted Uses & Disclosures

SomniCharts may:

  • Use PHI solely to provide automated analytics and visualization services.
  • Not use PHI for marketing or resale.
  • Not disclose PHI except as required to provide services or as required by law.
3. Safeguards

SomniCharts agrees to:

  • Implement administrative, physical, and technical safeguards consistent with the HIPAA Security Rule.
  • Maintain encrypted storage and transmission protections.
  • Limit workforce access to PHI.
  • Maintain logical account isolation.
4. No Routine Human Review

PHI processed within SomniCharts is handled automatically by the system.

SomniCharts personnel do not routinely access or review PHI except:

  • For authorized troubleshooting,
  • As required by law,
  • Or as requested by Customer.
5. Breach Notification

SomniCharts will notify Customer without unreasonable delay upon discovery of a confirmed breach of unsecured PHI, consistent with HIPAA requirements.

6. Subcontractors

SomniCharts will ensure that subcontractors who may access PHI agree to similar HIPAA-compliant restrictions and safeguards.

7. Term & Termination

This Addendum remains in effect for the duration of the Customer's enterprise agreement.

Upon termination:

  • PHI is permanently deleted.
  • No retention archives are maintained.
  • Deletion occurs within a commercially reasonable timeframe.
Limitation of Liability

This Addendum is subject to the liability limitations set forth in the SomniCharts Terms of Service unless otherwise agreed in writing.

Order of Precedence

In the event of conflict between this Addendum and the Terms of Service, this Addendum shall control with respect to data protection and HIPAA compliance matters.

For enterprise agreements and BAA execution, contact:

admin@somnicharts.com