RReva
PrivacyTermsLog in

Privacy Policy

Last updated September 2026

Reva (“Reva”, “we”) provides appointment-reminder software to medical and dental practices. This policy explains what data we handle and how. For any personal data that a practice enters about its own patients, the practice is the data controller and Reva acts as a data processor on its behalf.

Data we handle

  • Practice account data: the name, email and password (hashed) of the people who log in, and practice settings (name, timezone, language).
  • Patient data entered by the practice: patient name, phone number and/or messaging handle, appointment times and reasons, and a log of the reminder messages sent.
  • Channel credentials: the practice’s own WhatsApp or Telegram API keys, stored encrypted at rest and used only to send that practice’s reminders.

How we use it

Solely to operate the service: to schedule and send appointment reminders through the practice’s own WhatsApp/Telegram account, to show the practice its own schedule and message history, and to keep the account secure. We do not sell personal data or use it for advertising.

Where messages go

Reminder messages are delivered through the practice’s own WhatsApp (Meta) or Telegram account. Those providers process the message under their own terms; Reva does not control their handling.

Sub-processors

  • Hosting & compute: our cloud hosting provider.
  • Database: our managed database provider.
  • Licensing/payments: our checkout provider, for the one-time purchase.

Security

Encryption in transit (HTTPS) and at rest for sensitive credentials, per-practice data isolation, hashed passwords, rate-limited login, and authenticated webhooks. No system is perfectly secure, but we work to protect your data and will notify affected practices of a material breach.

Retention

We keep account and patient data for as long as the practice’s account is active. A practice can delete a patient at any time, which removes their record, appointments and reminders. On account closure we delete or anonymize practice and patient data within a reasonable period, except where law requires retention.

Your rights

Depending on your location (e.g. GDPR), patients may have rights to access, correct, or delete their data. Because the practice is the controller, such requests should be directed to the practice; Reva will assist the practice in fulfilling them.

Contact

Questions about this policy: privacy@[your-domain].

R Reva
PrivacyTerms