Privacy Policy
How we collect, use, and protect your data on Clynevia
This policy details how Clynevia collects, processes, and protects personal and clinical data when you access or use the platform.
Who We Are
Clynevia is a clinical workspace platform (SaaS) built for independent nutrition practitioners and private dietetics clinics to build personalized meal plans, manage patient health records, coordinate appointments, and publish patient guidance.
Platform Operator: Clynevia Team
Contact Email: clynevia@gmail.com
In the Current Early Access Phase: Clynevia is in active private rollout. Formal registered corporate details will be updated here as registration milestones conclude.
Information We Collect
Clinic & Practitioner Data
When onboarding your clinic on Clynevia, we collect:
- Clinic name and contact information (Email, phone number)
- Account credentials (Username, encrypted passwords)
- Subscription, billing tier, and payment status
- Clinic profile settings (Logos, branding colors, print templates, regional preferences)
Patient & Clinical Data
The practitioner inputs client health files into the workspace, including:
- Personal details (Name, age, gender, contact number)
- Anthropometric and health metrics (Weight, height, body composition, medical history, dietary allergies)
- Customized nutrition plans (Meals, portions, calories, macronutrient targets)
- Consultation schedules, attendance, and clinical follow-up notes
Important Clinical Notice: Patients do not create logins or direct accounts on Clynevia. All records are entered directly by the clinic. The clinic remains the designated Data Controller responsible for data accuracy and client consent.
Usage & Telemetry Data Upcoming Feature
- Access logs, authentication events, and feature interactions
- IP addresses, browser client, and operating system info
In the Current Early Access Phase: We do not run invasive behavioral trackers or commercial analytics within practitioner accounts. General telemetry will be documented prior to any public release.
How We Use Collected Information
We use stored data strictly for legitimate clinical workspace operations:
- Core Provisioning: Enabling dietitians to author meal plans, monitor metrics, and manage visit schedules.
- Secure Client Sharing: Generating private, unguessable mobile links for patients to view their assigned nutrition programs without app installation.
- Support & Updates: Sending critical account alerts, platform notices, and direct support.
- Security & Tenant Isolation: Ensuring robust data integrity and preventing unauthorized cross-tenant access.
- Regulatory Compliance: Complying with applicable statutory accounting and record-keeping mandates.
Data Storage, Security & Isolation
We apply rigorous security measures to protect sensitive clinical records:
- PostgreSQL Database: All workspace records are hosted on hardened relational databases featuring strict tenant-level isolation (Row-Level Security).
- Encryption in Transit: All communications enforce modern TLS 1.3 / HTTPS encryption.
- Authentication: Secure JSON Web Token (JWT) architecture with salted and hashed credentials.
- Automated Backups: Systematic database backup regimes Upcoming Feature.
- Restricted Access: Only authenticated clinic operators have access to their private patient roster.
In the Current Early Access Phase: Automated cross-region disaster recovery backups are in rollout. We advise keeping offline copies of historical files during the private preview.
Third-Party Disclosures
We do not sell, monetize, or lease your clinic or patient data to third parties. Data is processed only with reputable technical providers necessary for operations:
- Infrastructure Providers: Secure cloud hosting, database nodes, and transactional messaging.
- Statutory Compliance: When strictly mandated under lawful judicial court orders.
Data Retention & Deletion
Your clinic data is preserved for as long as your subscription is active. Upon account termination:
- Patient files and custom meal plans are queued for permanent deletion within 30 days.
- Immediate erasure can be requested via our Data Deletion process.
- Invoices and transaction metadata may be retained up to 7 years to fulfill tax and fiscal obligations.
Your Privacy Rights
In accordance with global privacy principles (such as GDPR and regional equivalents), practitioners retain full rights to:
- Access: Obtain a verifiable copy of stored personal records.
- Rectification: Correct or modify inaccurate clinic information.
- Erasure: Request permanent removal of clinic records.
- Portability: Receive clinic data in machine-readable formats (Excel / CSV).
- Objection: Restrict processing under qualified circumstances.
The Clinic as Data Controller
Legal Framework: With respect to patient and client health files, the clinic acts as the Data Controller, while Clynevia functions strictly as the Data Processor. Consequently:
- The clinic obtains patient authorization for record storage.
- The clinic dictates clinical record retention rules.
- Patients wishing to modify or erase records should coordinate directly with their treating practitioner.
Changes to this Policy
We may periodically update this policy to reflect operational improvements. Notice will be published here with an updated revision date.
Contact Privacy Support
For questions or privacy requests, please reach out directly:
Email: clynevia@gmail.com