Privacy Policy
How Revitics Enterprises handles personal information on this website and, separately, how it handles the data a customer entrusts to the platform.
1.Two very different roles
Revitics Enterprises handles data in two capacities, and conflating them is how privacy policies become misleading. This document keeps them apart throughout.
| Capacity | What it covers |
|---|---|
| Controller | Information you give us — this website, an email to our team, a job application, a sales enquiry. We decide why it is held. |
| Processor / business associate | Data inside the platform, including protected health information, which belongs to the customer. We handle it only on that customer's documented instructions under an executed business associate agreement. |
Where the two conflict, the customer agreement and the business associate agreement govern the platform data. This policy never overrides them.
2.What this website collects
This site collects nothing automatically. There is no analytics script, no advertising pixel, no session recording and no cookie set by these pages. That is verifiable — view the source of any page.
You give us information only when you choose to:
- Email. If you write to us, we hold the message and your address so we can reply and keep a record of the conversation.
- Job applications. Applications currently arrive by email. What you send — your CV, your history, anything else you include — is held for recruiting.
Our hosting provider keeps ordinary server logs, which include IP addresses, for operational and security purposes. See Subprocessors.
3.Data inside the platform
The platform ingests healthcare claims and remittance data — X12 837 claims, 835 remittance advice, 277 acknowledgments — along with payer contracts and documents a provider chooses to attach. This data belongs to the customer.
Deliberate identity minimisation
The platform stores a minimal patient reference by design: a last name and a first initial. It does not store dates of birth. Where a payer's remittance supplies a full first name or a member identifier, those values are retained only for matching a payment to a claim, and are never disclosed outside the platform.
Anything a provider sends to a payer — an appeal package, a claim status request — carries the last name and first initial and nothing more. Uploaded documents are checked before they are enclosed, and an upload whose filename or description carries a fuller identifier is refused rather than accepted with a warning.
What we do not do
- We do not sell data. There is no circumstance in which customer data or personal information is sold, rented or traded.
- We do not use customer data for advertising.
- We do not use customer data to train generalised external AI models. See AI Governance.
- We do not use one customer's data to serve another. Tenant isolation is enforced on the server for every request and is covered by automated tests.
4.Why we are allowed to hold it
For website and business contacts, we rely on legitimate interests — running a business, answering people who contact us, and recruiting — and on consent where the law requires it.
For platform data we act on the customer's instructions under the services agreement and the business associate agreement. We do not determine the purposes for which protected health information is processed.
NEEDS DECISION Whether this policy needs to address GDPR or UK GDPR depends on whether the company takes non-US customers or employs anyone in those jurisdictions. Counsel should decide before this is published.
6.How it is protected
Set out in full on Security & trust. In summary: encryption in transit and at rest, multi-factor authentication, role-based access with least privilege, server-enforced tenant isolation, and an audit trail covering authentication, privileged actions, exports and every financial decision.
One honest limit, because it matters: encryption at rest defends stolen storage — a disk image, a backup, a detached volume. It does not defend against a compromised application, which must hold the key in order to function.
7.How long it is kept
Set out on Data retention & deletion, including what happens when a customer leaves.
8.Your rights
If we hold personal information about you as a controller — you emailed us, or you applied for a job — you may ask us to give you a copy, correct it, or delete it. Write to the address at the foot of this page and we will respond within thirty days.
If your information is in the platform because a healthcare provider put it there, we cannot act on your request directly. That data belongs to the provider, and the law gives you your access and amendment rights against them, not against us. Tell us and we will route your request to the right customer and support them in answering it.
NEEDS DECISION State-specific rights — California, Colorado, Virginia, Texas and others — turn on where the company is registered and where its customers are. Counsel should determine which apply and add the required disclosures.
9.Children
This website is not directed at children and we do not knowingly collect information from them through it. Platform data may relate to patients of any age, because a healthcare claim may; it is handled under the business associate agreement in every case.
10.Changes to this policy
Material changes will be posted here with a new effective date, and customers will be told directly rather than left to notice. Prior versions will be kept and made available on request — a policy you cannot see the history of is not much of a commitment.
Questions about this document: · All policies