Last updated July 30, 2026
This Privacy Policy explains how Neuroptek Corporation Inc. (“Neuroptek,” “we,” “us,” or “our”) collects, uses, discloses, retains, and safeguards personal information when you access or use the EyeMirage mobile application, the EyeMirage web-based electronic medical record platform, related devices, websites, support services, or other products and services that link to this Policy (collectively, the “Services”). It also explains the privacy choices and rights that may be available to you.
Depending on the circumstances, Neuroptek may handle information on its own behalf or on behalf of a healthcare professional, clinic, hospital, or other organization. When we process information on behalf of one of these organizations, that organization may be primarily responsible for your information and its own privacy notice may also apply.
We are committed to protecting personal information and personal health information in accordance with applicable privacy and health-information laws. These may include the Personal Information Protection and Electronic Documents Act (PIPEDA), applicable Canadian provincial health-information laws—including The Personal Health Information Act (Manitoba) and Ontario’s Personal Health Information Protection Act, 2004 (PHIPA)—and, when applicable to Neuroptek’s role and activities in the United States, the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and applicable U.S. state privacy laws.
If you do not agree with this Policy, please do not use the Services. If you have questions or concerns, contact our Privacy Officer at info@neuroptek.com.
Summary of Key Points
| Topic | What it means |
| Information we collect | Account and contact details; health, ocular, and test information; device and usage data; and information needed to provide and secure the Services. |
| Why we use it | To provide screening, testing, clinical-support, account, support, security, regulatory, and service-improvement functions. |
| Sensitive information | Health and ocular information is sensitive. We process it only for identified purposes, with consent or another lawful basis where applicable. |
| Sharing | We do not sell personal health information. We disclose information only as described in this Policy, including to authorized healthcare providers and service providers, or where required by law. |
| Retention and security | We retain identifiable information only as long as necessary or legally required and use administrative, technical, and physical safeguards appropriate to its sensitivity. |
| Your choices | Depending on applicable law and our role, you may request access, correction, deletion, withdrawal of consent, or other privacy rights. |
CONTENTS
1. Information We Collect?
2. How We Use Personal Information?
3. Our Legal Bases for Processing
4. When and With Whom We Disclose Information
5. De-identified and Anonymized Information
6. How Long We Retain Information
7. How We Safeguard Information
8. Your Privacy Rights and Choices
9. Do-Not-Track and Similar Signals
10. U.S. State Privacy Rights
11. Information about Minors
12. Changes to This Policy
13. Contact Us
1. Information We Collect
In short: We collect information you provide, information generated through your use of the Services, and limited information received from authorized organizations and service providers.
Information you provide
The information we collect depends on how you interact with the Services and may include:
Identity and contact information, such as your name, email address, mailing or billing address, username, and account identifiers.
Account and authentication information, such as passwords or other credentials maintained in protected form.
Health and clinical information, such as health history, family history, symptoms, physical measurements, test responses, test results, clinical notes, and information provided by you or an authorized healthcare professional.
Eye and ocular information, including images or recordings of the eyes, eye movements, pupil measurements, visual-function data, and related test data generated through EyeMirage.
Transaction and support information, such as purchases, billing details, communications with us, technical-support requests, feedback, and participation in surveys or events.
Information collected through the Services
Device and technical information. We may collect device type, operating system, browser type and version, application version, device or application identifiers, Internet Protocol (IP) address, mobile carrier or internet service provider, system configuration, crash logs, and diagnostic information.
Usage information. We may collect information about how the Services are accessed and used, including features used, test events, dates and times, pages or screens viewed, and performance or troubleshooting data.
Device permissions. With your permission, the mobile application may access features such as the camera, Bluetooth, microphone, storage, or location when required for a specific feature. You can manage these permissions in your device settings. Disabling a required permission may prevent the relevant feature from working.
Notifications. With your permission, we may send push notifications relating to your account, test status, appointments, results, or other Service functions. You can manage notifications in your device settings.
Information received from others
We may receive personal information from healthcare professionals, clinics, hospitals, caregivers or guardians, authorized account administrators, and service providers when they use or support the Services, refer you to the Services, or provide information with appropriate authority. We may also receive information when systems are integrated at an organization’s direction. The organization that provided the information may have its own privacy notice and responsibilities.
Please ensure that information you provide is accurate and complete and notify us or your EyeMirage service provider when it changes.
2. How We Use Personal Information
In short: We use personal information to provide, administer, secure, support, and improve the Services and to meet legal and regulatory obligations.
Depending on the Service and our role, we may use information to:
Provide EyeMirage tests, screening, analysis, result delivery, clinical-support functions, and related services.
Create and manage accounts; authenticate users; process orders; and administer subscriptions, billing, and support.
Enable authorized healthcare professionals to review information, provide consultations, document care, or communicate with you.
Send operational communications, such as test-status updates, results, appointment reminders, security notices, and important Service information.
Maintain, troubleshoot, secure, and monitor the Services; detect or prevent fraud, misuse, unauthorized access, and other security threats.
Improve usability, reliability, accessibility, and performance, including through aggregated or de-identified information where appropriate.
Conduct quality assurance, validation, research, and development in accordance with applicable law, consent requirements, contractual restrictions, and applicable ethics or institutional approvals.
Comply with legal, regulatory, professional, audit, reporting, and record-keeping obligations; establish or defend legal claims; and protect the rights, safety, and property of users, Neuroptek, and others.
Carry out another purpose that we identify when the information is collected or that you authorize.
3. Our Legal Bases for Processing
In short: We process personal information only where we have a lawful basis under the laws that apply.
Depending on the jurisdiction, the type of information, and our role, our legal basis may include:
Your express or implied consent, where consent is appropriate and valid.
Performance of a contract or steps taken at your request before entering into a contract.
Compliance with legal or regulatory obligations.
The provision or administration of healthcare by an authorized healthcare organization or professional, where permitted by law.
Our legitimate interests or those of another organization, where recognized by applicable law and not overridden by your rights and interests.
Protection of vital interests, prevention of fraud or security threats, or establishment, exercise, or defence of legal claims.
Another basis permitted or required by applicable law.
Where we rely on consent, you may withdraw it, subject to legal, contractual, and professional restrictions and reasonable notice. Withdrawal does not affect processing that occurred lawfully before withdrawal. It may also limit or prevent our ability—or your healthcare provider’s ability—to continue providing some or all Services.
4. When and With Whom We Disclose Information
In short: We do not sell personal health information. We disclose personal information only for identified purposes, with authority, or as permitted or required by law.
We may disclose information in the following circumstances:
Healthcare and consultations. To healthcare professionals, clinics, hospitals, caregivers, or other authorized participants involved in providing or supporting your services or care.
Service providers. To vendors that perform services for us or for an organization using EyeMirage, such as secure hosting, cloud infrastructure, communications, analytics, technical support, payment processing, cybersecurity, and professional services. They may use information only as authorized and are required to protect it under appropriate contractual and legal obligations.
At your direction or with your consent. To a person or organization you authorize, including through an integration or sharing feature you choose to use.
Legal and safety reasons. To regulators, law-enforcement authorities, courts, or other parties when required or permitted by law, or when reasonably necessary to protect rights, safety, security, or property.
Business transactions. In connection with a proposed or completed financing, reorganization, merger, acquisition, sale, or transfer of all or part of our business or assets, subject to appropriate confidentiality, security, and legal requirements.
If information is processed or stored outside your province, territory, state, or country, it may be subject to the laws of that jurisdiction and may be accessible to courts, law-enforcement agencies, or regulators there. Where applicable, we use contractual and other safeguards for cross-border processing.
5. De-identified and Anonymized Information
In short: We may use information that has been de-identified, anonymized, or aggregated so that it is not reasonably capable of identifying you, subject to applicable law.
We may use such information for analytics, quality improvement, scientific research, validation, product development, and the development of future screening or diagnostic-support tools. We do not attempt to re-identify information that has been anonymized, except where permitted by law for security, quality-control, or validation purposes.
De-identification and anonymization have different legal meanings across jurisdictions. We apply the standard required by the law governing the relevant information and activity.
6. How Long We Retain Information
In short: We retain identifiable information only as long as necessary for the purposes described in this Policy or as required or permitted by law.
Retention periods vary based on the type of information, the nature of the Service, our role, the requirements of the healthcare organization or professional responsible for the record, applicable limitation periods, and legal, tax, accounting, regulatory, research, and security obligations. Health records may be subject to longer statutory or professional retention requirements.
When identifiable information is no longer required, we securely delete it, destroy it, or convert it into de-identified or anonymized information, as permitted by law. If immediate deletion is not reasonably possible—for example, because information is stored in protected backup systems—we isolate it from ordinary use and delete it in accordance with our backup-retention cycle, unless continued retention is required by law.
Closing an account does not necessarily require deletion of all associated information. We or the relevant healthcare organization may retain information needed to comply with record-retention duties, investigate security incidents, prevent fraud, resolve disputes, enforce agreements, or meet other lawful obligations.
7. How We Safeguard Information
In short: We use administrative, technical, and physical safeguards designed to protect information in a manner appropriate to its sensitivity.
Our safeguards may include:
Encryption of information in transit and, where appropriate, at rest.
Unique user accounts, authentication controls, role-based access, least-privilege practices, and access logging.
Secure development, vulnerability management, monitoring, backup, incident-response, and business-continuity practices.
Workforce privacy and security training, confidentiality obligations, risk assessments, and policies governing acceptable use and access.
Physical and environmental safeguards for facilities and systems.
No method of electronic transmission or storage is completely secure. Although we use reasonable safeguards, we cannot guarantee absolute security. You are responsible for protecting your credentials, maintaining the security of your devices, and notifying us promptly if you suspect unauthorized access.
Privacy and security incidents
If a privacy or security incident occurs, we will investigate, mitigate risks, and provide notifications to affected individuals, healthcare organizations, regulators, or others when and as required by applicable law. Where HIPAA’s Breach Notification Rule applies, required individual notifications will be made without unreasonable delay and no later than the applicable legal deadline.
8. Your Privacy Rights and Choices
In short: Your rights depend on your location, the applicable law, and whether Neuroptek or another organization is responsible for the information.
Subject to applicable exceptions, you may have the right to:
Request access to personal information about you and information about how it has been used or disclosed.
Request correction of inaccurate or incomplete information.
Withdraw consent to future collection, use, or disclosure where processing is based on consent.
Request deletion or erasure where the law provides that right and retention is not otherwise required or permitted.
Object to or request restriction of certain processing.
Request portability of certain information in a usable format, where applicable.
Receive information about certain automated processing and challenge a decision, where applicable.
Make a complaint to Neuroptek, the responsible healthcare organization, or an applicable privacy regulator without retaliation.
To exercise a right, contact your EyeMirage service provider or Neuroptek’s Privacy Officer using the details below. We may need to verify your identity and authority before completing a request. If Neuroptek processes the information on behalf of another organization, we may refer your request to that organization or assist it in responding.
Account and communication choices
You may update certain account information through the Services or by contacting us. You can manage mobile permissions and push notifications through your device settings. Operational or legally required communications may continue even if you opt out of non-essential communications.
9. Do-Not-Track and Similar Signals
Some browsers and devices offer “Do Not Track” or similar signals. Because there is not a single universally accepted standard governing these signals, the Services do not currently respond to all such signals. Where a law requires us to recognize a specific browser-based privacy preference signal, we will do so as required.
10. U.S. State Privacy Rights
In short: Residents of certain U.S. states may have additional rights under state privacy laws.
Depending on the state and whether an exemption applies—including exemptions for information governed by HIPAA or other medical-information laws—you may have rights to confirm processing; access, correct, delete, or obtain a copy of personal information; opt out of certain targeted advertising, sale, sharing, or profiling; limit certain uses of sensitive information; and appeal a denied request.
We do not discriminate against you for exercising an applicable privacy right. We may ask for information reasonably necessary to verify your identity and request. You may be permitted to use an authorized agent, subject to verification requirements. We will respond within the period required by applicable law and will explain any available appeal process.
11. Information About Minors
The Services may be used in connection with care provided to minors. When personal information about a minor is collected, used, or disclosed, we rely on the authorization of a parent, guardian, mature minor, or other legally authorized person, or another lawful basis, as required by applicable law. The healthcare organization or professional providing the service may have additional consent and record-management responsibilities.
12. Changes to This Policy
We may update this Policy from time to time to reflect changes to our Services, practices, or legal obligations. The revised version will display a new “Last updated” date and will become effective when posted or otherwise communicated, unless a different effective date is stated. If changes are material, we may provide additional notice as required by law.
13. Contact Us
For questions, concerns, complaints, or privacy-rights requests, contact:
Privacy Officer
Neuroptek Corporation Inc.
3 St. Anne’s Road
Winnipeg, Manitoba R2M 2X9
Canada
Email: info@neuroptek.com
You may also have the right to contact the privacy regulator responsible for your jurisdiction. We encourage you to contact us first so that we can try to address your concern.
