Your information

Privacy Policy

How Adaptive Path handles personal information across our website, consultations, support services, communications, and newsletter.

Last updated: July 21, 2026

Please keep sensitive details out of ordinary website forms. Do not submit detailed diagnoses, medical information, behavioural histories, or urgent safety information through a general contact or booking form. If services proceed, necessary information will be requested through the appropriate intake process.

1. About this policy

Adaptive Path Support Services (“Adaptive Path,” “we,” “us,” or “our”) is a British Columbia sole proprietorship operated by Jack Elliott. This policy explains how we collect, use, disclose, safeguard, retain, and provide access to personal information in connection with our website, consultations, support services, communications, transportation, billing, funding administration, and newsletter.

This policy applies to website visitors, subscribers, prospective clients, clients, and Client Representatives. A Client Representative may be a parent, guardian, or another person legally authorized to act for a client. Service agreements, intake forms, media consents, and information-release authorizations may provide additional details for a particular service or purpose, but they do not reduce rights provided by applicable privacy law.

Adaptive Path is responsible for personal information under its control, including information processed on its behalf by a service provider. We handle personal information in accordance with British Columbia’s Personal Information Protection Act (PIPA) and, where applicable, other Canadian laws. Canada’s anti-spam legislation (CASL) applies to our newsletter and other commercial electronic messages.

Jack Elliott is Adaptive Path’s Privacy Officer and is responsible for privacy compliance, questions, access and correction requests, and complaints.

2. Information we collect

  • Identity and contact information: names, pronouns, dates of birth or age, addresses, telephone numbers, email addresses, emergency contacts, and information needed to confirm a Client Representative’s identity or authority.
  • Intake and support information: interests and preferences, communication style, abilities, support needs, goals, routines, diagnoses or disability-related information voluntarily provided for service planning, and relevant health or safety information such as allergies, mobility, swimming ability, behaviour-related risks, or emergency needs.
  • Service records: consultations, schedules, service authorizations, pickup and drop-off instructions, activity and transportation details, attendance, session and progress notes, factual observations, communications, incident reports, and emergency actions.
  • Business and funding records: service agreements, rates, invoices, service dates, mileage and activity expenses, payment status, funding authorizations, claim information, and records reasonably needed for accounting, insurance, audit, or legal purposes.
  • Website and booking information: information submitted through a contact, subscription, or booking tool; appointment selections; IP address; browser or device details; pages viewed; referring pages; access times; cookies; and security or diagnostic logs collected by us or our website providers.
  • Newsletter information: email address, subscription status, date and method of consent or confirmation, the consent wording presented, and unsubscribe records.
  • Optional media: photographs, audio, or video only where separately and expressly authorized. We do not use a client’s likeness for public marketing without specific written permission.

We may receive information directly from the person it concerns; from a Client Representative who has authority to provide it; through observations and records made while delivering services; and, with consent or other lawful authority, from an authorized consultant, support provider, funding administrator, or other person involved in the client’s support.

3. How we use information

  • to respond to inquiries and assess whether our services are suitable;
  • to complete intake, understand goals and support needs, and plan individualized services;
  • to schedule, provide, adapt, document, and review services;
  • to support safe transportation, activities, transitions, pickup, home release, and emergency response;
  • to communicate with the client and people lawfully involved in the client’s support;
  • to document attendance, progress, incidents, decisions, and actions taken;
  • to prepare invoices and administer family, government, or third-party funding;
  • to maintain business, tax, insurance, legal, quality, safety, and complaint records;
  • to operate, secure, measure, and troubleshoot our website and business systems;
  • to send newsletters and program updates where we have a lawful consent basis; and
  • to comply with legal obligations and protect the rights, health, safety, or security of a person.

We will seek further consent before using personal information for a materially different purpose unless the use is otherwise permitted or required by law.

4. Consent, minors, and representatives

We obtain meaningful consent where required. Consent may be express or, where permitted by PIPA and appropriate to the sensitivity and circumstances, implied from a person’s actions. Optional consent, including newsletter and media consent, is not a condition of receiving support services.

Consent may be withdrawn on reasonable notice, subject to legal, contractual, funding, insurance, safety, and record-retention requirements. We will explain reasonably foreseeable consequences. For example, we may be unable to provide or safely continue a service if consent is withdrawn for information essential to that service.

For a client who is a minor, privacy decisions are handled according to the client’s capacity to understand the particular right or decision and the representative’s lawful authority. A capable minor generally exercises their own PIPA rights. A guardian may exercise a privacy right for a minor only where permitted by law, including where the minor is incapable of exercising that particular right. We may ask for information needed to verify identity, capacity, guardianship, or another form of authority.

Paying for services, receiving invoices, or administering funding does not by itself provide unrestricted access to all of a capable client’s personal information or session notes. Where appropriate, we will explain what service, safety, attendance, progress, or billing information may be shared with a Client Representative before services begin.

5. Newsletter and electronic messages

Newsletter subscription is optional and uses an affirmative opt-in. We may send newsletters, practical resources, information about upcoming free support groups, program news, and service updates only where we have a lawful consent basis. We keep reasonable evidence of consent so that we can document subscriber preferences.

Each commercial newsletter will identify Adaptive Path Support Services, include the contact information required by CASL, and provide a no-cost unsubscribe mechanism. A subscriber may unsubscribe through the link in a message, our unsubscribe page, or by contacting us. We will act without delay and no later than 10 business days after receiving the request. We may retain a minimal suppression record so that the address is not accidentally added back to the mailing list.

Unsubscribing from promotional messages does not prevent us from replying to an inquiry or sending non-promotional messages needed for an appointment, service, invoice, funding, safety matter, or existing business relationship.

6. Service providers and disclosures

We limit disclosure to what is reasonably necessary and legally authorized. Depending on the circumstances, information may be shared:

  • with the person it concerns or a verified Client Representative, subject to capacity, authority, and lawful access limits;
  • with an authorized consultant, support-team member, or other provider for agreed coordination;
  • with a government or third-party funding administrator for service authorization, invoicing, claims, audit, or payment;
  • with service providers supporting our website, communications, scheduling, storage, accounting, or other business operations;
  • with an insurer, accountant, legal adviser, or other professional adviser where reasonably necessary;
  • with emergency responders, health providers, emergency contacts, child-protection authorities, law enforcement, a court, or a government body where authorized or required by law or reasonably necessary to address a serious safety concern; or
  • with another person when the individual has consented or directed us to disclose the information.

Nothing in this policy prevents a report or disclosure required by child-protection law or another applicable law. Adaptive Path does not sell personal information.

7. Service providers, website tools, and cookies

Current services include Automattic’s WordPress.com and Jetpack services for website hosting and newsletter functions, and Google Workspace, Google Drive, and Google Calendar for business email, communications, appointment scheduling, and record storage.

These providers may process or store information in Canada, the United States, or other countries. Information processed outside Canada may be subject to the laws and lawful access processes of those countries. Adaptive Path remains responsible under PIPA for personal information under its control and takes reasonable steps to select, configure, and use providers appropriately.

Our website providers may use cookies or similar technology for site operation, preferences, security, technical performance, diagnostics, or traffic measurement. Most browsers allow cookie controls, although blocking essential cookies may affect website functions. An embedded booking tool or external link may also connect directly to another provider, whose privacy notice may apply to information it collects for its own purposes. If we introduce materially different advertising or tracking practices, we will update this policy and provide any choices required by law.

8. Safeguards and retention

We make reasonable efforts to keep personal information accurate and complete where it may be used to make a decision about a person. Clients and Client Representatives should tell us when relevant contact, authority, health, safety, or support information changes.

We use reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the information. These include limiting access, using protected accounts and devices, configuring sharing permissions, using secure disposal methods, and reviewing how service providers handle information.

Designated session-note files are encrypted locally in a Cryptomator vault before the encrypted files are synchronized to a restricted Google Drive account. Cryptomator does not automatically protect ordinary email, Google Calendar information, website submissions, or files saved outside the vault. We therefore limit sensitive information sent through ordinary channels and use additional safeguards appropriate to those records. No organization, storage system, or transmission method can guarantee absolute security.

Retention periods depend on the type of record and the reasons it is held. We retain information only as long as reasonably necessary for service delivery and for applicable safety, access, funding, tax, insurance, legal, limitation-period, and compliance needs. Information used to make a decision that directly affects an individual will be retained for at least the period required by PIPA. Consent and unsubscribe evidence may be retained as reasonably necessary to demonstrate and honour communication preferences.

When identifying information is no longer reasonably required, we securely delete, destroy, or de-identify it. Residual copies in protected backups may remain until they are overwritten through the applicable backup cycle, unless preservation is legally required.

9. Access and correction requests

An individual may make a written request for access to personal information about them under our control and for information about how it has been used or disclosed. An individual may also request correction of information they believe is inaccurate or incomplete.

Requests should provide enough detail to identify the requester and the records. We may verify identity, capacity, and representative authority before responding. We will ordinarily respond within 30 days as required by PIPA, subject to permitted extensions, fees, severing, and exceptions. Access may be limited where required or permitted by law, including where disclosure would reveal another person’s personal information, privileged information, confidential commercial information, or information subject to a safety or legal restriction.

If access or correction is refused, we will provide the explanation required by law and information about available review rights. Requests may be sent to info@adaptivepathsupportservices.com with the subject line Privacy Request.

10. Privacy incidents

If we become aware of suspected loss, unauthorized access, use, or disclosure, we will take reasonable steps to contain and document the incident, assess the risk, mitigate harm, prevent recurrence, and notify affected people or authorities where required by law or reasonably appropriate in light of the risk.

11. Privacy questions and complaints

Please first direct privacy questions, requests, or complaints to the Privacy Officer. We will acknowledge, review, and respond in a reasonable manner and will not retaliate against a person for raising a privacy concern in good faith.

Privacy Officer
Jack Elliott, Owner
Adaptive Path Support Services
info@adaptivepathsupportservices.com
(672) 667-2351

If you are not satisfied with our response, you may contact the Office of the Information and Privacy Commissioner for British Columbia.

12. Changes to this policy

We may update this policy when our practices, service providers, or legal obligations change. The current version will be posted on this page with its latest revision date. If a proposed change requires new consent, posting an updated policy alone will not replace that consent.