Privacy Policy

Last updated: 17 August 2026. This policy explains what Vertowise (“we”) does with the information a physiotherapy clinic and its patients put into the service.

Who is responsible for what

The clinic is the data controller for its patient records: it decides what to record and why. Vertowise is the data processor: we store and process that data on the clinic’s instructions and do not use it for our own purposes. Clinics should have a Data Processing Agreement with us; ask and we will provide one.

What we store

Patients do not hold accounts. They reach intake forms, exercise programs and questionnaires through a single-use link. That link is the credential — anyone holding it can open the page, so clinics must send it only to the patient.

Where it lives

Data is stored in a PostgreSQL database hosted by Supabase in the United States (Ohio, us-east-2), and the application is served from the same region. If your clinic or patients are in the EU or UK, this is an international transfer and your Data Processing Agreement must cover it.

Who else processes it

ProcessorWhat it receives
Supabase (US)All application data
Netlify (US)Hosting; request logs
Google (Gmail SMTP)Transactional email — addresses and message content
PaddleBilling. Merchant of record; we never see full card details
Meta (WhatsApp Business Platform)WhatsApp reminders — patient phone number and message text, when the clinic enables it
Google Gemini, OpenRouter, GroqAI features only — dictation audio and the clinical text sent for transcription or summarising. See the warning below.

AI features and your patients’ data

Read this before switching on dictation or the AI assistant for real patients. When a clinic uses those features, the audio and clinical text involved are sent to a third-party AI provider for processing. On the free API tiers these providers generally reserve the right to retain that content, have humans review it, and use it to improve their models.

That is not appropriate for identifiable patient data. Until Vertowise runs these features on paid, zero-retention API terms, treat the AI features as suitable for non-identifiable use only, and do not dictate patient names or identifying details into them. Clinics with a legal duty of medical confidentiality should keep them switched off.

How long we keep it

Patient records are kept while the clinic’s account is active, because the clinic usually has its own legal retention period for medical records. When an account closes, the clinic can request export or deletion and we will action it within 30 days, except where we must retain billing records for tax purposes.

Security

No system is perfectly secure. If we discover a breach affecting patient data we will notify affected clinics without undue delay so they can meet their own notification duties.

Rights

Patients should contact their clinic, which controls the record and can correct, export or erase it. If you are a clinic and need help fulfilling such a request, contact us and we will assist within 30 days.

Cookies

We set only what the service needs: a session cookie to keep you signed in, and a preference cookie for language and theme. No advertising or third-party tracking cookies, which is why you are not being asked to accept any.

Contact

Questions, or to request a Data Processing Agreement: abdharespt@gmail.com.