Privacy policy
Recorvita holds medical records, which is about as sensitive as personal data gets. This policy says plainly what we collect, why we are allowed to, who else can ever see it, and how to take it back. It is written to be read, not to be survived.
1. Who is responsible for your data
The controller of your personal data — the person legally responsible for it — is:
- Controller
- Michał Glinka
- Address
- Zalipie 7a, 04-625 Warszawa, Poland
- NIP
- 952-196-48-57
- Data protection contact
- privacy@recorvita.com
Recorvita is built alongside the patient organization KidneyGlobal.org, but the controller of your records is the person named above. A human answers that address.
We have not appointed a Data Protection Officer, because the scale of the processing does not require one under Article 37 GDPR. Write to the address above and you reach the person actually responsible.
2. What this policy covers
This policy covers the Recorvita information pages at recorvita.com and the patient application at patient.recorvita.com.
These information pages collect nothing at all. recorvita.com sets no cookies, runs no analytics, embeds no trackers and makes no requests to any third party — not even for fonts, which are served from our own domain. There is no form on it. Reading it is not logged beyond the ordinary web server records described in section 3.
It does not cover other websites we link to, such as KidneyGlobal.org, which have their own policies.
3. What we collect
Only what the application actually stores. Almost all of it is entered by you, and most of it is optional — the only things required to have an account are an email address and a password.
Account data
- Your email address.
- Your password, stored only as a cryptographic hash. We never store, and cannot read, your actual password.
- If you turn on two-factor authentication, the secret needed to verify your codes.
- Whether your email is verified, whether the account is active, and the time of your last sign-in.
Profile data — all optional
- First and last name, date of birth.
- Nationality, country of residence, interface language, time zone.
- Height and weight.
- Occupation and family history, if you choose to record them.
- For people living with kidney disease: transplant date and organ, and dialysis start date.
Health records — special category data
- Documents you upload or photograph: PDF, JPG and PNG files.
- Laboratory values you enter, together with the reference range and flag printed on your own document.
- Medications, doses, schedules and who prescribed them.
- Conditions, including ICD-10 codes where you or your clinician record them.
- Doctors, appointments, procedures and allergies.
Sharing data
- Any share you create: what you shared, with whom, the scope you chose and the date it expires.
- If you ask a clinician a question through the application, the question text and the scope you proposed.
Security and technical data
- An access log recording each time a record is opened, by whom and when. This exists so that you can see who looked at your data — it is a feature, not surveillance of you.
- Session tokens, stored as hashes rather than in a form we could reuse, and their expiry.
- Ordinary server records generated by serving a web page — IP address, browser type, time of request — kept briefly for security and abuse prevention.
We do not collect: advertising identifiers, location data, contacts, your device's files beyond what you deliberately upload, or anything from tracking cookies. There are no advertising or analytics companies involved at any point.
4. Why, and on what legal basis
Health data is "special category" data under Article 9 GDPR, which means it may only be processed on a narrow set of grounds. Ours are:
- Your explicit consent
- Article 9(2)(a). This is the basis for everything in your health record. You give it by choosing to put a record into Recorvita, and you can withdraw it at any time by deleting the record or the account — see section 8. Withdrawal does not affect processing that already happened lawfully.
- Performing our agreement with you
- Article 6(1)(b). Running your account, authenticating you, storing and displaying what you entered, and letting you export it.
- Our legitimate interests
- Article 6(1)(f). Keeping the service secure, preventing abuse, and keeping the access log that lets you audit who saw your data. We have balanced this against your rights and think it favours you, because the same measures are what protect your record.
- Legal obligations
- Article 6(1)(c). Where the law requires us to keep or disclose something. To date we have received no such request.
We do not profile you, and we make no decisions about you. There is no automated decision-making within the meaning of Article 22, and Recorvita does not interpret your results — it displays what you and your documents say. See"Is Recorvita a medical device?".
5. Who else can see your records
By default, nobody but you.
- A clinician sees something only when you create a share or an invitation. You choose the scope and the expiry date. You can revoke it at any time, and every opening is written to your access log.
- A family caregiver gets access only on your explicit instruction, with a scope you set, and their actions appear in the same log.
- Administrators — the people who keep the service running — can see accounts, support requests and system health. They have no access to patient documents or results, and every administrative action is logged.
- We do not sell data, and we never will. We do not share it with advertisers, data brokers, insurers or employers. There is no investor who needs a return on it.
We would disclose data to a public authority only where a valid legal obligation required it, and only to the extent required.
6. Companies that process data for us
We use a small number of service providers ("processors"). Each acts only on our instructions, under a contract that requires confidentiality and appropriate security. The complete list:
- Railway Corp.
- Application and database hosting (PostgreSQL, Redis)
European Union — europe-west4, Amsterdam - Amazon Web Services EMEA SARL
- Encrypted storage of uploaded documents and images (S3)
European Union — eu-central-1, Frankfurt - Hostinger International Ltd.
- Hosting of the recorvita.com information pages only — these pages hold no personal data
European Union - GoDaddy.com, LLC
- Email for @recorvita.com addresses, used for correspondence and account messages
European Union and the United States
That is the whole list. There is no analytics provider, no advertising network, no customer tracking tool, and no artificial-intelligence service processing your records.
7. Where your data is stored
Your records — the database and the documents you upload — are stored in the European Union: the application and database in Amsterdam, uploaded files in Frankfurt.
Email is the one exception. Correspondence sent to or from an @recorvita.com address may be processed in the United States by our email provider. If you would rather not send health details by email, please don't — put them in your record instead, where they stay in the EU.
Should any transfer outside the European Economic Area become necessary in future, we will rely on a lawful transfer mechanism under Chapter V GDPR — Standard Contractual Clauses or an adequacy decision — and update this policy before it happens.
8. How long we keep it
- While your account exists. Your records stay until you delete them or delete your account. We do not expire your data or lock you out of your own history.
- Deletion is immediate. Deleting your account removes your documents and results from the database and from file storage straight away. There is no grace period and no support ticket — it is a real deletion.
- Backups. Our hosting provider keeps automated encrypted backups of the database. Deleted data may persist in those backups until they age out of the provider's rotation, after which it is gone from there too. Backups are never used to restore an account you deleted.
- Access log. Kept while your account exists, because its purpose is to let you audit access to your own record. It goes when the account goes.
- Server and security records. Kept briefly — a matter of weeks — then discarded.
Before you delete an account we offer you an export, so that "delete" does not have to mean "lose".
9. How we protect it
- Encrypted in transit (HTTPS everywhere) and encrypted at rest.
- Passwords stored as hashes; session tokens stored as hashes.
- Two-factor authentication available on your account — we recommend turning it on.
- Role-based access control, enforced by the server rather than by hiding buttons: a patient account cannot reach clinician data even by asking the API directly.
- Full event logging, so access is auditable.
- Automated encrypted backups managed by our hosting provider.
- Private by default. Nothing is shared unless you share it.
No system is perfectly secure, and we will not pretend otherwise. If we ever discover a breach likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours as Article 33 requires, and tell you directly where Article 34 requires it.
If you find a security problem, please write toprivacy@recorvita.com. We will not pursue anyone who reports a genuine vulnerability in good faith.
10. Your rights
Under the GDPR you have the right to:
- Access your data, and get a copy of it (Article 15).
- Correct anything inaccurate (Article 16).
- Erase it (Article 17). In the application this is one action.
- Restrict processing (Article 18).
- Port your data (Article 20) — take it elsewhere in a machine-readable form. Recorvita's export gives you a readable PDF and a machine-readable file. We treat this as a right, not a courtesy.
- Object to processing based on legitimate interests (Article 21).
- Withdraw your consent at any time (Article 7(3)), by deleting the record or the account.
Most of these you can exercise yourself, immediately, inside the application — which is faster than asking us. For anything else, write toprivacy@recorvita.com. We answer within one month, as Article 12(3) requires.
You also have the right to complain to a supervisory authority. In Poland that is:
- Supervisory authority
- Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office (UODO))
ul. Stawki 2, 00-193 Warszawa
https://uodo.gov.pl
You can complain to them without contacting us first, though we would rather have the chance to put something right.
11. Children
Recorvita is intended for adults. A parent or legal guardian may keep a record on behalf of a child, and is then responsible for the consent that makes that lawful. If you believe a child has created an account independently, write toprivacy@recorvita.com and we will remove it.
12. Changes to this policy
When this policy changes we update the version and date at the top. If a change materially affects how your health data is handled, we will tell you in the application or by email before it takes effect — not quietly.
13. Contact
- Data protection
- privacy@recorvita.com
- Anything else
- hello@recorvita.com
- By post
- Michał Glinka
Zalipie 7a
04-625 Warszawa, Poland