Trust & Security
Human Ethics Policy Statement
Prepared for NRC Ethics Board Review (IRAP Due Diligence), Memores Software Inc., SPARKS Platform. Effective February 2026.
Executive summary
Memores Software Inc. (“Memores” or “the Company”) operates the SPARKS mental wellness platform, which collects and processes personal information, including sensitive psychological assessment data and health-related information, from voluntary participants. This Human Ethics Policy Statement demonstrates our commitment to ethical research practices, transparent participant disclosure, and compliance with Canadian and United States regulations governing human subjects research and personal data protection.
Key compliance framework
- Canada: Personal Information Protection and Electronic Documents Act (PIPEDA), Tri-Council Policy Statement: Ethical Conduct for Research Involving Humans (TCPS 2)
- United States: State-specific privacy laws (California CPRA, Virginia CDPA, Colorado CPA, and others), FTC Act Section 5
- International: General Data Protection Regulation (GDPR) principles for European participants
Ethics oversight. Independent Ethics Advisory Board chaired by Dr. Michael Hawes reviews data practices, research protocols, and participant protection measures quarterly.
Regulatory reference table
| Regulation | Jurisdiction | Applicability | Compliance status |
|---|---|---|---|
| PIPEDA | Canada (federal) | ✅ Applies | ✅ Compliant |
| PIPA (BC) | British Columbia | ✅ Applies (HQ location) | ✅ Compliant |
| Law 25 | Quebec | ⚠️ If Quebec users | 🟡 Preparing (portability) |
| TCPS 2 | Canada (research ethics) | 🔵 Voluntary | ✅ Principles applied |
| CCPA/CPRA | California | ✅ Applies if CA users | ✅ Compliant |
| VCDPA | Virginia | ✅ Applies if VA users | ✅ Compliant |
| CPA | Colorado | ✅ Applies if CO users | ✅ Compliant |
| CTDPA | Connecticut | ✅ Applies if CT users | ✅ Compliant |
| UCPA | Utah | ✅ Applies if UT users | ✅ Compliant |
| GDPR | European Union | ✅ Applies if EU users | 🟡 Portability in dev (deletion now) |
| COPPA | US (children) | ❌ Not applicable | ✅ No users under 13 |
| HIPAA | US (health) | ❌ Not a covered entity or business associate | 🔵 Voluntary; built to the Security Rule |
Legend: ✅ Fully Compliant · 🟡 In Progress · ❌ Not Applicable · 🔵 Voluntary
Note: SPARKS is not a covered entity or business associate under HIPAA and is not required to comply. We built to the Security Rule anyway, so an EAP, insurer, or health plan can deploy SPARKS without carving out an exception to its own HIPAA obligations.
We store all data in accordance with HIPAA compliance, in an encrypted form, and with additional confidentiality measures in place.
End of document
This Human Ethics Policy Statement is a living document subject to updates as regulations evolve and Memores’ data practices mature. Participants and stakeholders are encouraged to contact privacy@memores.me with questions or concerns.
