top of page

Privacy policy 

Effective Date: 16 August 20256

Welcome to CVDapp.com (“we”, “our”, or “us”). Your privacy is important to us. This Privacy Policy outlines how we handle information when you use our website.

1. Overview

CVDapp.com provides two distinct types of services, and this policy covers both:

  1. Clinical Reference Tools — calculators, drug references, and decision-support tools intended solely to assist healthcare professionals. These run locally in your browser.

  2. Patient Transfer Chat System ("PTCS") — a hospital-to-hospital coordination tool that lets sending and receiving hospitals communicate about a specific patient transfer, including status updates, messages, and file attachments (e.g., images, scans, PDFs).

PTCS is a workplace tool issued to hospital staff by their institution. It is not intended for use by patients or the general public, and patients do not create accounts or interact with it directly.

2. Information We Collect

2.1 Clinical Reference Tools

Calculations occur locally in your browser and are not transmitted to our servers. No personally identifiable information, patient names, medical records, or health data entered into calculators are retained by us.

2.2 Patient Transfer Chat System

 

Because PTCS exists to coordinate real patient transfers, it necessarily collects and processes:

  • Staff account data — staff code, hashed password, name, role (e.g., staff / room admin / group admin / regional admin), and the hospital, group, and room the staff member belongs to. Staff accounts are issued by the hospital administrator; there is no public self-registration.

  • Hospital and room data — hospital, unit, or room/department codes used to route transfers.

 

  • Case data — for each transfer: patient name, diagnosis, transfer status (pending, accepted, traveling, arrived, canceled), and timestamps for each stage. Only the sending and receiving staff assigned to that specific case can see it.

  • Messages — chat content exchanged between sender and receiver staff about a case, and general room-to-room messages.

  • Attachments — images, video, or PDF files uploaded to support a transfer (e.g., photos of a patient, scans, reports).

  • Security and audit logs — login attempts, IP addresses, timestamps, and a record of sensitive actions taken in the system (including who viewed a given attachment and when).

We collect only what is needed to coordinate the transfer and to secure the system — PTCS does not collect data for advertising, profiling, or any purpose unrelated to patient transfer and hospital operations.

3. How We Use Information

We use PTCS data to:

  • Route and coordinate a patient transfer between the sending and receiving hospitals.

  • Authenticate hospital staff and enforce that each person can only see cases and messages belonging to their own hospital, group, or room.

  • Maintain an audit trail of sensitive actions (for hospital oversight, incident review, and legal compliance).

  • Operate security features such as rate-limiting logins and expiring file access.

We do not sell PTCS data, use it to train AI models, or share it with advertisers.

5. Who Can Access Your Data

Access to case data, messages, and attachments is restricted at the system level:

  • Only staff assigned to the sending or receiving hospital/room for a specific case can view that case's messages and attachments. This is enforced on every request, not just in the interface.

  • Hospital, group, and regional administrators have management visibility appropriate to their role (e.g., a room admin manages their room's staff; a regional admin has broader oversight), but access to sensitive actions is logged.

  • CVDapp does not share PTCS data with third parties for marketing or unrelated purposes. Data is only accessible to the infrastructure providers described in Section 6, who process it strictly as data processors under agreement, and to hospital staff/administrators as described above.

6. Data Storage, Security, and International Transfers

  • Infrastructure: PTCS runs on Wix's platform (Business tier, with HIPAA-mode enabled and a Business Associate Agreement in place) with file attachments stored separately on Amazon Web Services (AWS) S3, in the Bangkok (ap-southeast-7) region — meaning attachment data is kept within Thailand. AWS is also covered by a Business Associate Agreement.

  • Encryption: Data is encrypted in transit (TLS/HTTPS) and at rest (server-side encryption on stored files). We use server-side encryption rather than end-to-end encryption by design, so that hospitals retain the ability to audit and, where legally required, retrieve records — a tradeoff we disclose openly.

  • Attachment access controls: Uploaded files are private by default. Viewing a file requires a short-lived, signed access link (typically valid for a few minutes) rather than a permanent public URL, and viewing an attachment is logged (including a watermark identifying who viewed it and when).

  • Account security: Passwords are stored as salted cryptographic hashes (never in plain text); login attempts are rate-limited to deter brute-force attacks; staff accounts are provisioned and can be deactivated centrally by hospital administrators.

7. Data Retention & Deletion

  • Attachments are automatically deleted approximately 24 hours after upload, or immediately if the associated case is canceled. Short-lived access links expire within minutes, regardless of the underlying file's retention period.

  • Messages and case records are retained only for as long as necessary to support the transfer and any immediate follow-up. We are finalizing a firm retention window (targeted at up to 90 days) for these records, after which they will be deleted or archived in a de-identified form; this policy will be updated once that window is finalized.

  • Audit and security logs are retained separately for longer periods, as necessary, to meet legal, security, and incident-investigation obligations.

8. Data Breach Notification

In the event of a data breach involving personal data processed through PTCS, we will notify Thailand's Personal Data Protection Committee (PDPC) within 72 hours as required by the PDPA, and will notify affected hospitals so they can meet their own notification obligations to patients where applicable.

9. Your Rights

Hospital staff and, where applicable, patients whose data is processed through PTCS may have rights under the PDPA to access, correct, or request deletion of personal data, subject to hospitals' independent medical record-keeping obligations under Thai healthcare law (which may require certain records to be retained regardless of a deletion request). Requests should generally be directed to the hospital administering the relevant case, who can coordinate with us as needed. You may also lodge a complaint with the PDPC.

10. Compliance Status

PTCS is designed to align with PDPA requirements and operates under Business Associate Agreements with its infrastructure providers (Wix and AWS). It has not yet obtained independent certifications such as ISO 27001 or SOC 2; formal certification is on our roadmap. We do not claim certifications we do not currently hold.

11. Children's Data

PTCS is a workplace tool for licensed hospital staff, not a consumer product, and is not directed at or knowingly used by children. Any patient information (including that of a minor) is entered by healthcare professionals solely for treatment-coordination purposes.

12. Cookies & Analytics

The CVDapp.com marketing site and clinical calculators may use analytics tools (such as Google Analytics), which you can disable through your browser settings. PTCS itself does not use tracking cookies for advertising; it uses session tokens solely to keep you securely logged in.

13. Changes to This Policy

We may update this policy as PTCS evolves (for example, once the message/case retention window in Section 7 is finalized, or if new infrastructure or certifications are added). Material changes will be posted here with a revised effective date.

14. Contact

Questions about this policy, or requests related to your personal data, can be directed through our feedback/contact form at cvdapp.com.

Medical disclaimer: CVDapp.com's clinical reference tools should be used alongside clinical expertise and applicable guidelines. We assume no responsibility for how users apply the information provided.

.

bottom of page