Security and confidentiality
At GOrendezvous, the security and confidentiality of your data are our top priorities. We combine advanced technical measures with strict internal processes to ensure a secure and reliable environment for your information. This page summarizes our commitments.
- Law 25: Strengthened rights, responsible management of the life cycle of personal information.
- PIPA: Law respecting the protection of personal information in the private sector. (Quebec)
- PHIPA: Personal Health Information Protection. (Ontario)
- PIPEDA : Personal Information Protection and Electronic Documents Act. (Canada)
We are often asked whether GOrendezvous holds any form of official “compliance” or certification from professional orders. It is important to clarify that these organizations do not formally endorse or certify software solutions or external providers.
That said, we work in close collaboration with our users and maintain ongoing dialogue with professional orders and associations to adapt our platform to the realities of each practice. Our team closely monitors the evolution of technological standards, legislation, and ethical considerations to ensure our security and privacy features remain up to date.
By choosing GOrendezvous, you can be confident that we adhere to industry best practices and continuously evolve our platform hand in hand with professionals and their needs.
Access control
Multi-factor authentication (2 steps) reinforces account protection.
Each employee logs in using their unique login and password.
Sessions are also protected by an automatic logout process after a period of inactivity.
Each form or note records the date and time of creation or modification, as well as the identity of the employee who performed the action.
You can hide client names on the schedule, define granular permissions per employee (read, edit) and share only the necessary files, according to the principle of least privilege.
-
End-to-end encryption
All your data is encrypted both during transfer (in transit) and while stored (at rest). - Secure SSL/HTTPS connection This prevents anyone from reading or altering the information transmitted between your browser and our servers.
-
Hosting in Canada
Your data is hosted on Amazon Web Services (AWS) in data centers located in Canada, which comply with internationally recognized security standards.
-
Redundancy and continuous backup
To prevent any data loss, your information is copied in real time to a secondary server, continuously backed up, and can be restored in the event of a failure, incident, or disaster. -
Security monitoring and testing
Our systems are protected by automated detection mechanisms and alerts for suspicious activity. In addition, we work with external cybersecurity auditors who regularly test and validate the robustness of our protections. -
Advanced network protection with Cloudflare
We partner with Cloudflare, a global leader in cybersecurity, to safeguard the platform against attacks and ensure service availability at all times.
Protected data
Data security doesn't rely on a single measure, but on several layers of protection working together.
End-to-end encryption
All your data is encrypted during transfer (in transit) and when stored (at rest).
Secure SSL/HTTPS connection
This prevents anyone from reading or modifying the information transmitted between your browser and our servers.
Hosting in Canada
Your data is hosted by Amazon Web Services (AWS) in data centers located in Canada, in compliance with world-class security standards.
Redundancy and continuous backups
To avoid any loss, your data is copied in real time to a second server, backed up continuously and restorable in the event of a breakdown, incident or disaster.
Security monitoring and testing
Our systems are protected by automated detection mechanisms and alerts in the event of suspicious activity. What's more, we call on external auditors specialized in cybersecurity to regularly check the robustness of our protection.
Advanced network protection with Cloudflare
We work with Cloudflare, a world leader in cybersecurity, to protect the platform against attacks and guarantee service availability at all times.
See more than one customer at a time
Frequently asked questions
Here are the most frequently asked questions about these features.
-
Is GOrendezvous compliant with Law 25?
Yes. GOrendezvous complies with Law 25 (Québec) as well as the Act Respecting the Protection of Personal Information in the Private Sector (ARPPIPS), PIPEDA (Canada), and PHIPA (Ontario).
With two founders from the IT sector, GOrendezvous has always taken a proactive approach to privacy and data protection since the company was founded in 2012. Our platform already met the requirements of Law 25 before it even came into force.
Our Privacy Policy and Terms of Use were drafted with the support of a team of specialized privacy and cybersecurity lawyers.
-
Do my data stay in Canada?
Yes — always.
All your data are hosted on Amazon Web Services (AWS) data centers located in Canada, and your data never leave Canadian territory.
AWS Canada complies with the highest international security standards and undergoes regular audits conducted by independent external firms.
-
Is GOrendezvous certified or approved by professional orders?
Professional regulatory bodies generally do not endorse or certify external software providers directly. Therefore, there is no official certification issued by these organizations.
However, GOrendezvous works closely with its users and maintains ongoing dialogue with professional orders and associations to adapt the platform to the realities of each practice.
Our team also closely monitors evolving technological standards, legal requirements, and ethical considerations to continuously improve our security and privacy features.
-
Can my patients share images, X-rays or files with me?
Yes, your patients will be able to share files with you directly from their intake form, in a secure way. They will be virus-checked, then centralized in their client file.
-
Do my colleagues have access to my files?
Your colleagues will only have access to your files if you activate the necessary permissions. There are several levels of permissions, depending on your preferences.
-
Are patient data used for advertising purposes?
No. Never.
GOrendezvous processes and stores data strictly for the purpose of delivering our services.
We:
- Do not sell any data to third parties
- Do not create advertising profiles from patient data
- Do not share information with commercial partners for marketing purposes
-
Are mental health notes protected differently?
All clinical data benefit from the same high level of encryption and protection.
Mental health session notes are accessible only to the professional who created them. Sharing them with colleagues always requires explicit authorization from the practitioner.
GOrendezvous complies with the specific requirements of the Ordre des Psychologues du Québec (OPQ) regarding record management and destruction.
-
Why choose GOrendezvous to manage your practice?
By choosing GOrendezvous, you benefit from a platform that follows industry best practices and continuously evolves to meet the needs of healthcare professionals.
-
Is the platform’s security tested by external experts?
Yes.
External non-intrusive social engineering tests have been conducted with GOrendezvous employees to evaluate resistance to phishing attempts.
The results confirmed that:
- Email filtering systems effectively protect against common and advanced phishing attacks
- Google-recommended security best practices are properly implemented
This evaluation is conducted annually.
These tests are carried out by Cybersécurité 42 inc., led by Guy-Paul Dubois.
-
What technological infrastructures protect GOrendezvous?
GOrendezvous relies on Amazon Web Services (AWS) Canada and Cloudflare, two global leaders in digital infrastructure security and availability.
- AWS is regularly audited by independent cybersecurity firms and agencies.
- Cloudflare continuously protects the platform from various types of cyberattacks and helps maintain service availability.
-
Are GOrendezvous infrastructures audited?
Yes.
The infrastructures supporting the platform undergo regular audits conducted by independent external firms, helping maintain a high level of security and reliability.
-
Are my data used to train AI models?
No.
Your textual or audio data are never used to train, improve, or fine-tune artificial intelligence models.
GOrendezvous AI operates in an isolated environment without persistent memory. Each AI process is intentional, temporary, and task-specific, and the data are not retained once the task is completed.
-
What happens in the event of a security breach?
GOrendezvous has automated monitoring systems and alerts in place to detect suspicious activity.
Our data are replicated in real time on a secondary AWS server. In the event of an incident, AWS can fail over to a new server without service interruption.
In compliance with Law 25, any confidentiality incident is recorded in a breach register, and affected individuals are notified according to legal requirements.
-
Is GOrendezvous compliant with personal information protection laws?
Yes. A formal evaluation of GOrendezvous’ privacy policies and procedures was conducted by Me René W. Vergé, a lawyer specializing in cybersecurity and privacy protection.
The analysis concluded that GOrendezvous has implemented appropriate policies and procedures that comply with the requirements of PIPEDA and PHIPA.
-
How can I retrieve my data if I leave GOrendezvous?
Even after canceling your subscription, you retain free read-only access to your account.
You can export client files in PDF format at any time.
If you need to modify or complete a file, a temporary monthly reactivation will restore full editing access.
GOrendezvous continues hosting your data free of charge after cancellation.

