Client Disclosure Directive

Last Updated: September 1, 2026

Issued by 15336732 CANADA INC. d/b/a Moonlight AI™. This Directive is part of the Terms of Service and the Data Processing Agreement.

Purpose

Because you are implementing an Artificial Intelligence (AI) Voice Agent to interact with your clients, various telecommunications, consumer protection, and health privacy laws (including PIPEDA, PHIPA, TCPA, CASL, and professional College Guidelines) require that your clients are made aware they are speaking with, or being monitored by, an automated system.

As established in your Master Service Agreement, Moonlight AI™ provides the software, but you (the Business) are legally responsible for acquiring client consent and making proper disclosures. Failure to comply with this Directive may constitute a material breach of your Service Agreement and may expose you to regulatory liability.

Required Disclosures

You must implement all of the following disclosures prior to activating the AI service.

1. Inbound Call Greeting Update

Before a client is connected to the AI receptionist, your primary phone system (or your upstream IVR greeting) must play a brief disclosure statement.

Approved script examples:

  • “Welcome to [Business Name]. Please note your call may be answered or monitored by an AI administrative assistant to help you book your appointment faster.”
  • “Thank you for calling [Business Name]. To ensure fast service, you are being routed to our AI booking assistant. For human assistance, say ‘Emergency’ or press 0 at any time.”

Requirements: the disclosure must be audible and understandable; it must occur before the caller is connected to the AI agent; and it must not be misleading about the nature of the interaction.

2. Client Intake Form Update

You must add a consent clause to your digital and/or physical client intake forms acknowledging the use of AI tools for administrative scheduling.

Approved clause example: “By providing my phone number, I consent to being contacted via phone or SMS for appointment reminders, waitlist notifications, and reactivation outreach. I acknowledge that [Business Name] utilizes an automated AI assistant for scheduling, and my name and appointment preferences may be processed and securely stored by this AI’s service provider to facilitate my bookings.”

Requirements: the clause must be clearly visible (not buried in fine print); client acknowledgment must be recorded (checkbox, signature, or equivalent); and you must retain proof of consent for the duration of the client relationship and for a minimum of two (2) years thereafter.

3. Outbound Call & SMS Consent

If you enable the Service’s outbound calling and SMS features (reminders, waitlist harvesting, reactivation), you must ensure the following:

CASL Compliance (Canada): you have express or implied consent from each contact before the Service places an outbound call or sends an SMS on your behalf; your intake forms include a specific, informed opt-in mechanism; and you provide a clear unsubscribe/opt-out mechanism.

TCPA Compliance (United States): you have prior express written consent for automated calls and text messages, documented and retained.

Requirements: Moonlight AI™ acts solely as the executor of outbound communications. You are the originator and are solely responsible for consent. You agree to indemnify the Company against any regulatory action, fine, or complaint arising from communications sent without proper consent.

4. Privacy Notice Update

If you maintain a publicly available Privacy Policy (website, posted in-office, etc.), you should update it to disclose that you use an AI-powered automated scheduling service. This builds trust and satisfies transparency obligations under PIPEDA’s Principle 8 (Openness).

Suggested addition: “We use Moonlight AI™ (Agentic Front Desk), an AI-powered voice receptionist, to assist with appointment scheduling, reminders, and client communications. When you call our office, your call may be handled by this automated system. Your name, phone number, and appointment details are processed by the AI to facilitate your booking, and securely stored by our AI service provider (encrypted, hosted in Canada) on our behalf for as long as we use the service. We do not use this AI service to store health information.”

5. In-Room Clinical Transcription Consent

Applicable only if you enable the Service’s in-room clinical transcription add-on (tablet- or device-button-triggered recording during patient visits). If enabled, you must ensure the following:

Point-of-Care Notice: patients must be informed, before recording begins, that their conversation with the provider may be recorded and transcribed by an AI-assisted tool to help generate their clinical note. Acceptable notice methods: posted signage in the exam room, verbal notice from the provider at the start of the visit, or both.

Approved verbal notice example: “Today I’ll be using an AI tool to transcribe our conversation and help generate your visit notes. I’ll start it now — let me know if you’d like me to pause or turn it off at any point.”

Provider-Triggered Consent Model: recording is never automatic or ambient — it starts only when the provider actively triggers it after confirming the patient’s identity on screen. The provider may decline to record, or stop recording, for any portion of the visit. Patients may ask the provider to pause or stop the recording at any time, and the provider is responsible for honoring that request.

Jurisdiction-Specific Requirements:

  • Canada (PHIPA/PIPA): consent must be informed and voluntary; a provider-triggered recording with verbal notice satisfies this. Withdrawal must be honored immediately — if the provider cancels a session, nothing is transcribed, generated, or stored. If a session is stopped normally, it is processed into a clinical note as intended.
  • United States (HIPAA): recording for the purpose of generating clinical documentation falls under treatment operations; verbal notice is sufficient, but you must be able to demonstrate the notice was given if asked. The In-Room Clinical Transcription Add-On requires a signed Business Associate Agreement (Schedule B of the Data Processing Agreement) before it is enabled.

Requirements: you are responsible for training providers to give the point-of-care notice before starting a recording, and for posting exam-room signage if you rely on signage rather than (or in addition to) verbal notice. Moonlight AI™ is responsible for ensuring recording cannot start without the provider’s explicit trigger, and for discarding a session’s data if the provider cancels the session before it completes.

Where the completed clinical note and verbatim transcript are stored: in your own Google Workspace (Google Drive), which you own and control. Moonlight AI™ additionally retains a limited index record — patient name, phone number, visit date, treating provider, session duration, a link to the note document, and status — in its encrypted, per-client-isolated database in Canada for a retention period configured to match your own records-retention obligation (commonly several years; a 365-day default applies if none is set), after which it is automatically deleted — and you can also delete individual sessions earlier yourself (see below). Short-lived processing copies are described in Schedule B of the Data Processing Agreement. Real-time transcription and note generation use HIPAA-eligible Amazon Web Services that do not retain your data or use it to train AI models. Consultation audio is never stored.

Compliance Responsibility Matrix

ObligationResponsible Party
Playing AI disclosure during inbound callsBusiness (Subscriber)
Obtaining intake form consentBusiness (Subscriber)
Obtaining outbound calling/SMS consentBusiness (Subscriber)
Updating public Privacy PolicyBusiness (Subscriber)
Giving point-of-care recording notice for in-room transcriptionBusiness (Subscriber)
Posting exam-room signage (if used in lieu of / alongside verbal notice)Business (Subscriber)
Providing the AI disclosure technologyMoonlight AI™
Ensuring the AI does not suppress the disclosureMoonlight AI™
Ensuring recording only starts on explicit provider triggerMoonlight AI™
Discarding a session’s data when the provider cancels it before completionMoonlight AI™
Storing the completed clinical note + transcript (in the Business’s own Google Drive)Business (Subscriber) — Moonlight AI™ writes the files to the Business’s Workspace
Retaining the limited index record (patient name/phone/visit metadata) per Schedule BMoonlight AI™
Executing a Business Associate Agreement before the Add-On is enabledBoth parties
Storing and retaining patient consent / point-of-care notice recordsBusiness (Subscriber)
Responding to patient data access, amendment, and deletion requestsBusiness (Subscriber), with Moonlight AI™ assistance for the index record

Consequences of Non-Compliance

  • Material Breach: failure to implement required disclosures constitutes a material breach of the Terms of Service, which may result in immediate suspension or termination of the Service without refund.
  • Regulatory Liability: non-compliance with PIPEDA, CASL, or TCPA may result in regulatory fines, which are the sole responsibility of the Business.
  • Indemnification: per Section 8 of the Terms of Service, you agree to indemnify and hold harmless Moonlight AI™ from any claims arising from your failure to obtain proper consent.

Acknowledgment

By subscribing to and using the Service, the Subscriber acknowledges that it has read and understood this Client Disclosure Directive and is responsible for updating its business intake forms, phone greetings, outbound consent mechanisms, privacy notices, and (if applicable) in-room recording notices to satisfy the disclosure requirements of its local jurisdiction. Questions: support@moonlightai.ca.

← Back to Home