Legal
Privacy Policy
Last updated: September 3, 2026
1inQ ("1inQ", "we", "us") is a service of Interclaim, based in Montréal, Québec, Canada. 1inQ is a B2B execution platform sold to disability insurance carriers, third-party administrators (TPAs), and self-insured employers (each, a "Client"). We are not an insurer, a clinic, or a law firm, and this Policy explains how we handle personal information — including the personal information of claimants referred to us by a Client — in that role.
This Policy applies only to short-term and long-term disability (STD/LTD) insurance claims. It does not apply to workers' compensation (WSIB) claims or auto insurance accident benefits, which 1inQ does not process.
1. Information we collect
We collect the following categories of personal information, mainly submitted to us by our Clients on a claimant's file:
- Identity information: claimant name, date of birth, sex, postal code, and — when provided — email and phone number.
- Claim and health-related information: disability onset date, claim submission date, return-to-work date, the type of assessment or intervention requested, ICD-10 diagnosis codes, the claimant's occupation (NOC code), and, where a physician's requisition or clinic report is uploaded, the document itself.
- Appointment-confirmation and security metadata: whether the claimant confirmed or declined a proposed appointment time, the timestamp, the IP address and device type used, and the method of delivery.
- Financial modelling data: benefit amounts and the return-on-investment figures we calculate for a Client's internal reporting.
- Account information for Client staff who use our dashboard: name, work email, role, and organization.
- Technical information: the cookies described in Section 8, and standard web request metadata (IP address, browser type) logged for security purposes.
2. How we collect information
- From our Clients, who submit claim information to us in order to request faster diagnostic imaging, specialist assessments, surgical coordination, or rehabilitation on a claimant's behalf.
- Directly from claimants, when they respond to an appointment-confirmation request (Section 4) or a clinic booking communication.
- Automatically, through cookies and basic web analytics when someone visits www.1inq.ca or uses our dashboard (Section 8).
3. How we use information
We use personal information only to: identify the fastest appropriate private clinic or specialist for a claimant's assessment; confirm the specific appointment with the claimant before it is finalized; book and coordinate the appointment; calculate and report the financial return of doing so to the referring Client; operate, secure, and improve the platform; and communicate with claimants and Client staff about a specific claim. We do not use claimant information for advertising, and we do not sell or rent personal information to anyone.
4. Legal basis and appointment confirmation
We operate under Canada's federal Personal Information Protection and Electronic Documents Act (PIPEDA) and, for claimants in Québec, the Act respecting the protection of personal information in the private sector ("Law 25"). Our Client is responsible for having a lawful basis to refer a claim to us in the first place, including the claimant's consent to be referred for care — that consent is obtained by the Client under the claimant's own disability insurance policy and claims-handling process, before the claim ever reaches us.
Separately, once a Client selects a specific clinic and appointment time through our platform, we automatically send the claimant a brief message naming that clinic, date, and time, and asking them to confirm it still works before the appointment is finalized. This is not a request for consent to be referred for care — that decision, and the consent behind it, belongs to the Client and the claimant's own policy. It's a narrower check on one specific date, time, and location. If a claimant indicates the time doesn't work, we do not book it, and the Client is notified so a new time can be arranged. This confirmation is delivered through a unique, single-use link that is not tied to any account or password and expires after 14 days.
5. Who we share information with
- The clinic or provider booked for an appointment — once the appointment is confirmed — receives the claimant's contact and appointment details. We do not share exact benefit amounts, ROI figures, or the claimant's full claim file with the clinic.
- The referring Client sees the information on its own claim, as it does today when its staff manage that claim.
- A small number of service providers process information on our behalf so we can operate the platform (our sub-processors, listed in Section 7). They are bound by contract to use information only to provide their service to us.
- We may disclose information where required by law, such as in response to a valid court order.
We do not sell, rent, or share personal information with data brokers or for cross-context advertising.
6. Sub-processors
- Supabase — our database, authentication, and secure document storage provider.
- Vercel — our hosting provider, which also provides aggregate, privacy-respecting site analytics.
- Resend — our transactional email provider, used to send account, booking, and claimant appointment-confirmation emails.
- Google Maps Platform — receives a claimant's postal code (never their full address) to estimate driving distance to candidate clinics.
We review each sub-processor's own privacy and security practices before working with them, and we do not authorize any of them to use claimant information for their own purposes.
7. International data transfers
We host and process claimant data with Canadian-based infrastructure wherever practicable. The one exception: when Client staff search for an ICD-10 diagnosis code in our dashboard, the search text they type is sent to a free public lookup API operated by the U.S. National Library of Medicine to return matching codes. That search text is not stored by us or, to our knowledge, associated with an identifiable claimant by that API — it functions as a diagnosis-code dictionary lookup, not a data export of a claim file.
8. Cookies
We use a small number of cookies, none of which are used for advertising:
- NEXT_LOCALE — remembers whether you're browsing in English or French. Lasts 1 year.
- 2fa_verified — a signed cookie confirming a Client staff member completed two-factor authentication. Lasts 12 hours.
- org_login_context — remembers which organization's branded login page a staff member arrived through, for display purposes only; it is not used to grant access. Cleared on logout.
- Supabase authentication cookie — keeps a signed-in staff session active, set and managed by our authentication provider.
You can block or delete cookies in your browser settings; doing so may affect your ability to stay signed in or keep a language preference.
9. How long we keep information
We do not yet apply a fixed, automated retention period to claim records — this is an area we are actively building out. Today, a claim record is kept for as long as it remains open or useful for the Client's own reporting. Once a case reaches a closed status, an authorized 1inQ administrator can manually anonymize it: the claimant's name is replaced with a redaction placeholder, their birthdate/email/phone are cleared, their postal code is reduced to its first three characters (a standard Canadian de-identification technique), and confirmation-related IP/device metadata is cleared. Financial and outcome figures, and our own internal audit records, are retained afterward in de-identified form for reporting and audit purposes. You can ask us or your insurer to anonymize a specific claim's identifying information at any time; see Section 11.
10. Security
We use industry-standard encryption in transit (TLS) and at rest, require two-factor authentication for Client staff accounts, restrict access to personal information by role, keep an internal audit log of record access and changes, and store uploaded clinical documents in an access-controlled, private file store rather than a public one. No system is perfectly secure, but we design and review our practices with this data in mind. Security documentation is available to a Client's own vendor-review team on request.
11. Your privacy rights
If you're a claimant, you have the right to ask us or your insurer what personal information we hold about you, to correct inaccurate information, and to withdraw consent for any future booking (this does not undo a booking already confirmed). Because we typically process your information on our Client's behalf, the fastest path is usually to contact your insurer or TPA directly — but you're always welcome to contact us at the email in Section 14 and we will either help directly or route you to the right Client contact. If you're in Québec and believe we haven't respected your rights under Law 25, you may also contact the Commission d'accès à l'information du Québec; elsewhere in Canada, you may contact the Office of the Privacy Commissioner of Canada.
12. Children's privacy
1inQ is a business tool used in connection with adult disability insurance claims. We do not knowingly collect personal information from children, and our service is not directed at them.
13. Changes to this Policy
We may update this Policy from time to time, for example as our practices or the law changes. We'll update the date at the top of this page when we do. If a change is significant, we'll take reasonable steps to let our Clients know.
14. Contact us
Questions about this Policy, or about your personal information, can be sent to mo@1inq.ca. We aim to respond within one business day.