Privacy
This is Version 3, kept as it was published. It has been replaced by Version 4. Read the version in force.
What Medvetta holds, what it structurally cannot hold, who can see a record, and what deletion reaches. The absent capabilities beside this are the argument; everything else is detail.
What Medvetta does not hold
Medvetta holds no patient records, no treatment records and no clinical notes. Not restricted, not permissioned, not gated behind a support process — absent. There is no field, no import path and no permission that would allow it, which means there is nothing for anybody at Medvetta to look at and nothing for a subpoena to reach here.
A compliance finding therefore carries a category and never a diagnosis: it can say that a treatment class was performed without a current standing order, and it cannot say who was treated or what was done to them.
- No patient identity, contact detail, chart, image or consent form.
- No treatment performed, product administered, dose or lot given to a person.
- No clinical note, no assessment, no outcome.
- No schedule and no appointment. Two such surfaces are listed in the navigation and marked withheld, so their absence is visible rather than assumed; the navigation engine refuses to make either reachable for any role, on any plan, and building the page would not change that.
- No path by which a Medvetta employee reads a tenant’s clinical record. Support answers account questions; for anything inside a treatment room, the tenant shows us.
- No ratings, reviews, prices or booking, for anyone, at any tier.
The public resolver is anonymous
The public verification page records no identity for the person asking. Not an account, not an IP address retained against the query, not a cookie that survives the visit. A locum agency, a board investigator and a patient’s daughter all get the same answer and none of them leaves a trace on the record they looked at.
What deletion can and cannot reach
These are the other party’s records as much as yours, and a compliance product whose audit trail can be edited by one of its parties is worth nothing to either. Stating it here is the honest version; a retention table that quietly omits it is not.
- A signature. You signed something and another party relies on it; a signature one party can delete is not a signature.
- A countersigned agreement. It is the other party’s record too, and they did not ask for it to go.
- An append-only audit entry. Its whole value is that nobody, including Medvetta, can edit it after the fact.
If you join the company waitlist
The company waitlist is for practices, training organizations and vendors who want to hear when Medvetta opens access for their kind of company. Joining it records your interest and nothing else: it creates no account, issues no MVID, and establishes no verification status.
When you join, Medvetta keeps what you entered on the form and the page you joined from:
- Your name, work email and role.
- Your company’s name, website, address, state, number of employees and specialty, and the company types you selected.
- Anything you wrote in the optional note.
- The page you joined from, including any campaign label in its address. The click identifiers an advertising platform adds to a link are removed before anything is stored.
Medvetta uses these details to email you about access and onboarding for your company type, and to understand which kinds of companies are asking. You receive one confirmation when you join. Medvetta does not sell these details, does not publish them, does not add them to any professional’s record, and shares them with no other company except the services that host Medvetta and deliver its email, which handle them only to do that.
Inside Medvetta they are readable only by the Platform Owner.
They are kept until you unsubscribe or ask for them to be deleted. Every waitlist email carries an unsubscribe link; unsubscribing deletes your signup at once and stops waitlist email to that address. To have your details deleted without an email to hand, write to support@medvetta.com. Medvetta keeps a count of the people who have left the waitlist, with no name or address attached.
Counting visits to the public website
Medvetta counts how many people read its public website at medvetta.com — the home page, the company landing pages and these documents — so it can tell whether they are being read. It sets no cookie for this, stores nothing on your device, and uses no outside analytics service.
When one of those pages opens, your browser tells Medvetta which page it is. To count a visitor once a day rather than once a page, Medvetta combines your IP address and your browser’s description of itself with a secret that exists for that day only, and keeps the resulting code instead of either. Your IP address and your browser’s description are not stored.
- The secret is replaced every day, and the previous day’s secret and codes are deleted the next day. After that no visit can be linked to anybody, by Medvetta or anyone else.
- What is kept is a count for each day and each page: how many page views, and how many visitors. It says nothing about who they were.
- Nothing is counted in the Medvetta product, where people sign in, and nothing is counted on the public verification page, which records nothing about the person asking. Signing in to the product does not stop a visit to the public website being counted, because the website cannot see that you are signed in.
- Programs that say they are crawlers, link previews or automated browsers are not counted.
Inside Medvetta the counts are readable only by the Platform Owner.
Changes to this policy
These documents are versioned rather than edited. A change publishes a new version with a date, and the previous version stays readable at its own address — a document that silently changes cannot be relied on by anyone who read it yesterday. Material changes are notified at least thirty days before they take effect.