OViz

Privacy & subprocessors

OViz is an educational consult aid for hearing-care providers. It is not a diagnostic or fitting tool. This page summarizes how information is handled in the product and which processors support delivery.

What we collect

Clinics enter consult context such as audiometric values, questionnaire responses, optional demographics, and—when consent and entitlement allow— ear-fit photos. Clinic staff accounts use email and password (with optional multi-factor authentication). Billing identifiers may be stored for subscription management.

Purposes

Information is used to generate educational consult visuals and reports for the treating clinic, to operate secure access and audit trails, to send patient intake links when requested, and to maintain the service (security, reliability, and billing).

Safeguards

  • Clinic-scoped row-level security in the database.
  • Session idle and absolute timeouts for clinic accounts.
  • Hashed public link tokens (intake, report share, partner, feedback).
  • PHI filtering on error monitoring payloads.
  • Ear-fit photos require stored consent and plan entitlement; revoke deletes objects.

Free OViz Scorecard

The public scorecard records pseudonymous completion events, the answers and results you submit, your work email, consent timestamp, landing path, referring site, and available UTM campaign values. We use this information to show your result, understand scorecard completion, and follow up about OViz. Raw IP addresses are not stored with scorecard records. You can request deletion through the contact channel below.

Subprocessors

The following processors may process service data on behalf of OViz. Regions can change with infrastructure updates; operators should confirm production project settings.

ProcessorRoleRegion note
SupabasePrimary application database, authentication, and private file storage.Project region is configured by the operator (prefer a Canadian region when available).
VercelApplication hosting, edge delivery, and preview deployments.Deployed on Vercel’s global edge network; runtime regions follow project settings.
UpstashDistributed rate limiting (Redis) for public and API abuse controls.OViz rate-limit Redis is provisioned in Montreal (yul1) when configured via Vercel Marketplace.
ResendTransactional email (intake invitations and clinic notices).Email delivery provider; recipient addresses are masked/hashed in application logs.
SentryError monitoring and performance diagnostics.US ingest endpoints may be used; application filters strip PHI/PII before events are sent.
StripeSubscription billing for clinic plans (owner console).Payment card data is handled by Stripe; OViz does not store full card numbers.

Contact

Privacy questions and data-subject requests for clinic-hosted records should go first to the treating clinic (the organization that entered the information). Platform operators can be reached via the contact channel published on oviz.ca.