Privacy policy
This policy explains which personal data OPALEVI stores, why, who else processes it, how long it is kept and what you can ask of us. It covers the OPALEVI website and the application clinics use.
Who is responsible
The practice that uses OPALEVI — a clinic, hospital, laboratory, dental lab, care service or veterinary practice — is the controller of the records it keeps about its patients, clients and staff: it decides what is recorded and why. OPALEVI processes those records on the practice's behalf and only on its instructions, to provide the service. Anyone who wants to see, correct or delete their record should ask the practice that keeps it.
OPALEVI is the controller of the data needed to run the service itself: the practice's account, its users' sign-in details, billing records and messages sent to us through this website.
What we store
- Account and user details: names, email addresses, telephone numbers, roles, and a hash of each password (never the password itself).
- What the practice records about its patients, which can include health data (visits, diagnoses, results, images and documents), along with appointments, invoices, payments and stock.
- Subscription details: the plan, the number of staff seats and the payment status. For a card payment, Paddle reports the status to us; card details are entered with Paddle and never reach OPALEVI. For a payment in EURC or USDC, we keep the address of the wallet that paid, the message it signed, the signature and the on-chain transaction.
- Technical records needed to keep the service safe: sign-in attempts, when important actions were taken in the application, and the emails the service sends.
- Your country, for your language: when you open the site without having chosen a language, our server looks up which country your IP address belongs to, in a database kept on the server itself, and opens the site in that country's language. The address is not stored and is not sent anywhere. IP geolocation by DB-IP (db-ip.com), licensed under CC BY 4.0.
- Messages sent through the contact form: your name, email address and what you wrote.
Why we use it
We use this data to provide and protect the service, to manage subscriptions and billing, to answer messages and to send the emails the service needs, such as password-reset links. We do not sell personal data, and we do not use patient records for advertising or for any purpose of our own.
Who else processes it
- Paddle.com, our merchant of record for card payments, processes those payments and the billing details it needs.
- Privy provides the wallet connection used for payments in EURC or USDC.
- The hosting provider that runs our servers and database stores the data on our behalf.
- Supabase stores the sign-in credentials (each password only as a hash) and checks them when you sign in.
- Cloudflare delivers this website and runs the security check on its public forms, which looks at your browser and connection to tell people from automated programs.
- PostHog (PostHog Inc., United States) measures how our public website is used: which pages are opened, where people click and how far they scroll, how fast pages load, and whether a registration or a contact message is completed. It also keeps screen recordings of visits to the public pages, with everything typed into a form hidden, and may ask a one-question survey. It sets no cookies, stores nothing in your browser, never sees the application itself, and receives page addresses without their query strings. The registration form and the payment receipt are counted but not recorded. This data is processed in the United States, under the European Commission's standard contractual clauses.
- For each clinic, identified only by its number, PostHog also receives how the service is used: when the clinic registered, when it added its first patient and its first visit, changes to its subscription and the payments made, and for each day of use, counts such as how many staff worked in it and which parts of the service were opened. No names, no e-mail addresses and no patient data are included.
- Sentry (Functional Software, Inc., data stored in the EU, Frankfurt) receives technical reports when the service fails or is slow: the kind of error, where in our code it happened, which part of the service was in use, the affected clinic's number and how long pages and requests took. Names, e-mail addresses, record numbers, anything typed and the query strings of addresses are removed before a report is sent, and screens are never recorded.
- Brevo (Sendinblue SAS, France) delivers the service's emails, such as invitations, password resets, account confirmations and reminders, to their recipients.
We have a data processing agreement with each of these providers, as Article 28 of the GDPR requires. It binds them to process the data only on our instructions, to keep it confidential and secure, and to help us respond when you exercise your rights.
Each of them processes the data only to provide their part of the service. The current list of providers, with where they process the data, is available from support on request.
How long we keep it
A practice's data is kept for as long as its account exists. Cancelling the subscription does not delete it, so the practice can come back or ask for a copy.
When the account owner asks for deletion, we delete the practice's data within 30 days of the request. Records the practice must keep by law should be taken out first; keeping them is the practice's responsibility.
Database backups are kept for up to 30 days, so deleted data also leaves the backups within that time.
Messages sent through the contact form are kept for as long as it takes to answer them and follow up.
How we protect it
- Each practice's data is kept apart: every request is limited to the practice the signed-in user belongs to.
- Staff see only what their role allows, and the account owner decides each person's role.
- Passwords are stored only as a salted hash, repeated failed sign-ins are limited, and a password-reset link expires after 30 minutes.
- The service runs over encrypted HTTPS connections, and the session cookie is only sent over them.
Your rights
You can ask us for a copy of the personal data we hold about you, and ask us to correct it, delete it, restrict its use or give it to you in a portable format, and you can object to how we use it. Write to support; we answer within 30 days. If your request concerns a patient record, we pass it to the practice that controls it.
If you think we have handled your data wrongly, you can complain to the data protection authority in your country.
Changes to this policy
When this policy changes, we update the date at the top of this page and, for an important change, tell account owners by email or in the application.
Contact
For any question about this document, or to make a request about your data, write to us at [email protected]. We answer within 30 days.