Privacy & subprocessors
OViz is an educational consult aid for hearing-care providers. It is not a diagnostic or fitting tool. This page summarizes how information is handled in the product and which processors support delivery.
What we collect
Clinics enter consult context such as audiometric values, questionnaire responses, optional demographics, and—when consent and entitlement allow— ear-fit photos. Clinic staff accounts use email and password (with optional multi-factor authentication). Billing identifiers may be stored for subscription management.
Purposes
Information is used to generate educational consult visuals and reports for the treating clinic, to operate secure access and audit trails, to send patient intake links when requested, and to maintain the service (security, reliability, and billing).
Safeguards
- Clinic-scoped row-level security in the database.
- Session idle and absolute timeouts for clinic accounts.
- Hashed public link tokens (intake, report share, partner, feedback).
- PHI filtering on error monitoring payloads.
- Ear-fit photos require stored consent and plan entitlement; revoke deletes objects.
Free OViz Scorecard
The public scorecard records pseudonymous completion events, the answers and results you submit, your work email, consent timestamp, landing path, referring site, and available UTM campaign values. We use this information to show your result, understand scorecard completion, and follow up about OViz. Raw IP addresses are not stored with scorecard records. You can request deletion through the contact channel below.
Subprocessors
The following processors may process service data on behalf of OViz. Regions can change with infrastructure updates; operators should confirm production project settings.
| Processor | Role | Region note |
|---|---|---|
| Supabase | Primary application database, authentication, and private file storage. | Project region is configured by the operator (prefer a Canadian region when available). |
| Vercel | Application hosting, edge delivery, and preview deployments. | Deployed on Vercel’s global edge network; runtime regions follow project settings. |
| Upstash | Distributed rate limiting (Redis) for public and API abuse controls. | OViz rate-limit Redis is provisioned in Montreal (yul1) when configured via Vercel Marketplace. |
| Resend | Transactional email (intake invitations and clinic notices). | Email delivery provider; recipient addresses are masked/hashed in application logs. |
| Sentry | Error monitoring and performance diagnostics. | US ingest endpoints may be used; application filters strip PHI/PII before events are sent. |
| Stripe | Subscription billing for clinic plans (owner console). | Payment card data is handled by Stripe; OViz does not store full card numbers. |
Contact
Privacy questions and data-subject requests for clinic-hosted records should go first to the treating clinic (the organization that entered the information). Platform operators can be reached via the contact channel published on oviz.ca.