BC Addiction Hub
PrivacyTermsReturn to care navigator
Privacy

Privacy Notice

We designed the Hub to minimize personal information. The public care navigator does not require a patient account. Access requests collect only the information needed to review and administer protected tools.

Last updated July 30, 2026

1. Who is responsible for privacy

BC Addiction Hub is responsible for the personal information under its control. The designated Privacy Lead can be reached at addictionhubca@gmail.com.

2. Information we collect

Patient care navigator

The public care navigator does not require a patient account and is not intended to create or store a medical record. Pathway progress saved “on this device” remains in that browser's local storage. Clearing browser data may remove it.

Optional reminders

On the Application Tracker page, a token holder may choose to provide an email address and/or mobile number for tracking-update alerts or a requested day-before reminder. These contact details are encrypted at rest and sent to the applicable messaging provider only to deliver the messages requested by the user. Messages do not name a program, treatment, diagnosis, medication or application status; they direct the recipient to visit BC Addiction Hub and enter the secure token. Device calendar links are handled by the user's chosen calendar application and do not include the token.

Anonymous Application Tracker

The Application Tracker does not ask for a patient name, date of birth, address, personal health number or clinical note. It stores the selected program, an anonymous tracking code, application status and milestone timestamps. If the token holder expressly opts into reminders, it also stores an encrypted email address and/or mobile number, keyed one-way lookup hashes used only to find a matching recovery contact, an encrypted copy of the tracker token used to resend the private link, and the selected notification preferences. The recovery search does not query contact information in plaintext. It may also store a snapshot of the program-level capacity reported when the tracker was created. Although direct identifiers are not collected, an addiction-treatment application status is sensitive and is protected accordingly.

The complete secure tracking token is issued to the applicant after a participating service receives an application, including an online application. A private tracker link places the token after the # sign in the browser address. That fragment is not sent in ordinary web requests or referrer headers. Outside the optional recovery record, the tracker database stores only a one-way hash of the token. Anyone who obtains the complete token may be able to view the tracker, so users should keep it private and avoid saving it on a shared device. If the user chooses “Save on this device,” the token is retained only in that browser for up to 30 days. The user may remove it sooner with “Forget this device.” Local expiry or removal does not delete the service-managed tracker. A Home Screen bookmark containing a private link must be removed from the device separately.

Clinician access

When someone requests access to the protected clinician workspace, we collect their name, submitted email, request status and the timestamps needed to administer the request. We do not ask for a CPSBC number and do not collect patient information through the clinician access form.

Live Capacity Exchange access

When someone requests permission to update a program's capacity, we collect their name, submitted email, role, program named, request status and administration timestamps. Approved staff may submit program-level capacity, estimated wait and short operational notes. Public capacity information does not include the updater's name or email.

Technical information

Our hosting, security and sign-in providers may process standard technical information such as IP address, browser type, device information and request logs to operate and protect the site.

3. Why we use information

  • To receive, review and manage clinician and centre access requests.
  • To secure the protected clinician workspace.
  • To publish current program-level capacity reported by approved centre staff.
  • To provide reminders only when a user expressly requests one.
  • To resend a private tracker link when a user opts into contact-based recovery.
  • To display anonymous application milestones and publish program-level median response times only after a minimum sample threshold is met.
  • To operate, troubleshoot and improve the site.
  • To comply with applicable legal obligations.

We do not sell personal information.

4. When information is shared

Information may be processed by service providers supporting secure hosting, sign-in, database operations, email notifications or requested text reminders. We limit use to the service being provided. Information may also be disclosed where required or permitted by law.

5. Retention and protection

We use reasonable administrative and technical safeguards appropriate to the limited information collected. Clinician access records used to make an approval decision are retained for at least one year after that decision, and then only as long as reasonably required for access administration, security, legal or business purposes. Capacity-update history may be retained to support accuracy, accountability and audit. Application trackers are created through an approved centre workspace after a participating service receives an application. They are retained for up to one year after the most recent status update unless a longer period is required by law or an authorized deletion request applies. Optional notification contact details and preferences are deleted when the tracker is deleted or expires, and the token holder may remove them from the tracking page at any time. Records are deleted or de-identified when no longer required.

6. Your choices and rights

You may ask to access or correct your personal information, withdraw consent where applicable, or request account closure by contacting the Privacy Lead. Withdrawing or deleting access information will end access to the corresponding protected workspace.

7. Please do not submit patient identifiers

Do not enter names, personal health numbers, dates of birth, addresses or other identifiable patient information into the Hub Assistant, clinician chatbot, access form or other free-text fields. The only exception is an email address or mobile number entered in the dedicated optional reminder fields on the Application Tracker.

8. Questions or complaints

Contact the Privacy Lead at addictionhubca@gmail.com. You may also learn about privacy rights through the Office of the Information and Privacy Commissioner for British Columbia.

BC Addiction Hub

Research prototype supporting access to addiction-care information.

Privacy NoticeTerms of UseContact