Skip to main content

Privacy notice

Effective from . We will give notice before this changes materially.

Which document applies to you

If you are a patient asking about your medical record, the clinic that treats you decides how that record is used — not us. Contact them, and they can produce it. This notice covers people who visit carevault.app, sign up for an account, or contact us. Our handling of patient data on a clinic’s behalf is governed by the Data Processing Agreement and, where applicable, the Business Associate Agreement we sign with them.

Who we are

CareVault provides hospital and clinic management software. For personal data processed on this website and in your CareVault account, we are the controller. For patient data held inside a customer's workspace, the customer is the controller and we act only on their documented instructions.

What we collect, and why

Account data — your name, work email, and the workspace you belong to — because an account cannot exist without it. Legal basis: performance of a contract.

Security telemetry — IP address, user agent, session times, and a record of security-relevant actions — because a system holding health records must be able to show who did what. Legal basis: legitimate interests, and in most jurisdictions a legal obligation.

Contact enquiries — what you type into our contact form, plus your email and IP address — so we can reply and so we can rate-limit abuse. Legal basis: legitimate interests. Please do not send patient information through that form; it is not a secure channel.

Billing data — company details and the payment token returned by our payment processor. We never see or store your full card number. Legal basis: performance of a contract.

What we do not do

We do not sell personal data, and we do not share it with advertisers or data brokers.

We do not use patient data to train machine learning models, ours or anyone else's. The AI features send text to a model provider under an agreement with zero data retention, which means it is not retained for training or for abuse monitoring.

We do not run third-party advertising or analytics trackers on this website. There is no cookie banner because there is nothing to consent to beyond the session cookie that keeps you signed in.

Where it is held

In the region the workspace chose at sign-up: the United States, the European Union, India, or the Gulf. Database, document storage and error telemetry all follow that choice. Where data does leave the EEA or the UK, Standard Contractual Clauses and the UK addendum apply.

Our subprocessors are listed publicly, last updated 2026-07-21: see the register.

How long we keep it

Account data: for as long as the account exists, then 90 days.

Security and audit records: 7 years by default, which is the floor most healthcare regulators expect and which a customer can extend but not shorten.

Contact enquiries: 24 months.

Patient data: governed by the customer's own retention policy and by the statutory medical-record retention period that applies to them, which typically runs between 6 and 30 years. Erasure of a medical record is a documented disposition lifecycle, not a deletion on request.

Your rights

You can ask for a copy of the personal data we hold about you as a controller, ask us to correct it, ask us to delete it where no retention obligation applies, object to processing based on legitimate interests, and receive it in a portable format.

Email privacy@carevault.app. We respond within 30 days, which is the deadline under both GDPR Art. 12(3) and HIPAA §164.524, and we will tell you if we need to verify your identity first.

If you are unhappy with our response you may complain to your supervisory authority. In the EU that is the authority for your country of residence; in the UK it is the Information Commissioner's Office.

Cookies

One essential cookie holds your signed-in session. It is httpOnly, marked Secure in production, and scoped to the host you signed in on. There is no advertising, profiling or cross-site tracking cookie on any CareVault surface.

Your light or dark theme preference is stored in your browser's local storage and never leaves the device.

Security incidents

If we confirm a breach affecting a customer's data we notify that customer without undue delay and within 72 hours — the GDPR clock, which we apply everywhere rather than only where it is legally required. Where we are a processor, notification goes to the controller, who owns the decision to notify individuals.

To report a vulnerability, email security@carevault.app. We acknowledge within one business day and will not take action against good-faith research.

Contact

privacy@carevault.app for data protection matters, security@carevault.app for vulnerabilities, and the contact form for everything else.