Legal

Privacy Policy

How Revitics Enterprises handles personal information on this website and, separately, how it handles the data a customer entrusts to the platform.

EffectiveNot yet in force — draft
Last updated20 August 2026
Applies toThis website and the Revitics platform
Draft — not yet reviewed by counsel. It states accurately what the platform does today, but it has not been reviewed by healthcare counsel and is not yet in force. Do not rely on it, and do not publish it, until that review is complete.

1.Two very different roles

Revitics Enterprises handles data in two capacities, and conflating them is how privacy policies become misleading. This document keeps them apart throughout.

CapacityWhat it covers
ControllerInformation you give us — this website, an email to our team, a job application, a sales enquiry. We decide why it is held.
Processor / business associateData inside the platform, including protected health information, which belongs to the customer. We handle it only on that customer's documented instructions under an executed business associate agreement.

Where the two conflict, the customer agreement and the business associate agreement govern the platform data. This policy never overrides them.

2.What this website collects

This site collects nothing automatically. There is no analytics script, no advertising pixel, no session recording and no cookie set by these pages. That is verifiable — view the source of any page.

You give us information only when you choose to:

  • Email. If you write to us, we hold the message and your address so we can reply and keep a record of the conversation.
  • Job applications. Applications currently arrive by email. What you send — your CV, your history, anything else you include — is held for recruiting.

Our hosting provider keeps ordinary server logs, which include IP addresses, for operational and security purposes. See Subprocessors.

3.Data inside the platform

The platform ingests healthcare claims and remittance data — X12 837 claims, 835 remittance advice, 277 acknowledgments — along with payer contracts and documents a provider chooses to attach. This data belongs to the customer.

Deliberate identity minimisation

The platform stores a minimal patient reference by design: a last name and a first initial. It does not store dates of birth. Where a payer's remittance supplies a full first name or a member identifier, those values are retained only for matching a payment to a claim, and are never disclosed outside the platform.

Anything a provider sends to a payer — an appeal package, a claim status request — carries the last name and first initial and nothing more. Uploaded documents are checked before they are enclosed, and an upload whose filename or description carries a fuller identifier is refused rather than accepted with a warning.

What we do not do

  • We do not sell data. There is no circumstance in which customer data or personal information is sold, rented or traded.
  • We do not use customer data for advertising.
  • We do not use customer data to train generalised external AI models. See AI Governance.
  • We do not use one customer's data to serve another. Tenant isolation is enforced on the server for every request and is covered by automated tests.

5.Who else sees it

A short list, kept short deliberately.

  • Subprocessors that host or support the platform. Each is named on the Subprocessors page, and any subprocessor that can access protected health information is under a business associate agreement before it does.
  • Payers, when a customer's authorised user sends an appeal or a status request. That disclosure is initiated by the customer, contains what is described above, and is recorded in the audit trail.
  • Legal compulsion. If we are compelled to disclose data by law, we will tell the affected customer unless we are legally prohibited from doing so.

We do not share data with anyone else, including for analytics or benchmarking, without a customer's written instruction.

6.How it is protected

Set out in full on Security & trust. In summary: encryption in transit and at rest, multi-factor authentication, role-based access with least privilege, server-enforced tenant isolation, and an audit trail covering authentication, privileged actions, exports and every financial decision.

One honest limit, because it matters: encryption at rest defends stolen storage — a disk image, a backup, a detached volume. It does not defend against a compromised application, which must hold the key in order to function.

7.How long it is kept

Set out on Data retention & deletion, including what happens when a customer leaves.

8.Your rights

If we hold personal information about you as a controller — you emailed us, or you applied for a job — you may ask us to give you a copy, correct it, or delete it. Write to the address at the foot of this page and we will respond within thirty days.

If your information is in the platform because a healthcare provider put it there, we cannot act on your request directly. That data belongs to the provider, and the law gives you your access and amendment rights against them, not against us. Tell us and we will route your request to the right customer and support them in answering it.

NEEDS DECISION State-specific rights — California, Colorado, Virginia, Texas and others — turn on where the company is registered and where its customers are. Counsel should determine which apply and add the required disclosures.

9.Children

This website is not directed at children and we do not knowingly collect information from them through it. Platform data may relate to patients of any age, because a healthcare claim may; it is handled under the business associate agreement in every case.

10.Changes to this policy

Material changes will be posted here with a new effective date, and customers will be told directly rather than left to notice. Prior versions will be kept and made available on request — a policy you cannot see the history of is not much of a commitment.

Questions about this document: · All policies