1. Scope
This Privacy Policy applies to the Vantor Clinic staff mobile application and the Vantor APIs and account services used by the app. The app is intended for authorized clinic owners and staff members and is not a public patient, diagnostic, or emergency-care application.
2. Data the staff app collects
The app transmits data to Vantor only when it is needed to provide and secure clinic workflows. Depending on the features used and the user's permissions, this can include:
- Account and profile information: name, email address, phone number, user ID, password credentials, profile image, clinic or workspace name, role, branch assignments, address, date of birth, gender, nationality, and other profile details entered by authorized users.
- Client and clinic information: client names, contact details, profile information, clinic assignments, and other records entered by authorized clinic staff.
- Appointments and health information: appointment calendar entries, treatment and session history, clinical notes, incidents, before-and-after records, forms, and related health information that a clinic chooses to manage through Vantor.
- Communications: email, SMS, WhatsApp or other in-app message content, reminders, support requests, and communication status.
- Photos, recordings, files, and documents: profile or treatment photos, call voice recordings when the clinic enables recording, forms, attachments, exports, and documents uploaded or created for clinic workflows.
- App activity and security information: app interactions, in-app searches, user-created notes and content, authentication events, session changes, and security or audit records.
- Deletion-request information: name, account email, optional phone number, account type, clinic name, request details, IP address, and browser information when the public deletion form is submitted.
3. Data not collected by the current Vantor mobile release
The current Vantor staff app does not request precise or approximate location, read the device's contacts, inspect installed apps, collect web-browsing history, or use data for advertising. The Vantor Android release is currently built without the optional Firebase configuration, so Firebase push tokens, Crashlytics reports, and advertising or analytics identifiers are not collected by that release.
4. Why we use data
We use the collected data to:
- create and manage accounts and clinic workspaces;
- authenticate users and enforce role- and branch-based access;
- provide appointments, client records, treatment workflows, communications, media, forms, documents, and staff operations;
- respond to support and privacy requests;
- protect accounts, maintain auditability, prevent misuse, and comply with applicable legal obligations.
We do not use staff-app data for advertising or marketing profiles.
5. Required and optional data
A clinic owner must provide a name, email address, phone number, and password to create an account. Staff accounts require the identifiers assigned by the clinic. Health records, messages, photos, recordings, files, and other workflow content are optional and are collected only when an authorized user chooses to use the relevant feature.
6. Sharing and service providers
We do not sell personal data and do not share it for advertising. Data may be processed by contracted service providers acting on Vantor's behalf, such as hosting, infrastructure, email, SMS, WhatsApp, and telephony providers. These providers may process only the information needed to deliver the requested service. Authorized users within the clinic or organization that controls the workspace may access data according to their assigned permissions.
We may disclose information when required by law or when necessary to protect users, clinics, Vantor, or the public. If Vantor is involved in a merger, acquisition, or transfer, data will remain subject to appropriate safeguards.
7. Security
The mobile app uses HTTPS for data in transit. Vantor also uses access tokens, role- and branch-based permissions, access controls, and operational safeguards. Passwords are handled as authentication credentials and are not displayed to other clinic users. No security system can guarantee absolute protection, so we continually review and improve these safeguards.
8. Retention
Account and clinic data is kept only while needed to provide the service, protect the platform, or meet the clinic's and Vantor's legal obligations. When an approved deletion request is processed, eligible account and profile data is deleted or anonymized. Limited security, audit, clinical, or legal records may be retained for the period required by applicable law or by the clinic that controls those records, with access restricted to authorized purposes.
9. Access, correction, and choices
Users can update available account information in the app or contact Vantor to request access or correction. A clinic may control records created by its staff, including clinical records, and may need to authorize changes to those records. Privacy requests are reviewed according to the user's role, the clinic's instructions, and applicable law.
10. Account deletion
To request deletion of a Vantor Clinic account and the associated eligible personal data, use the public account deletion request form. Vantor verifies account ownership and, where necessary, the requester's authority before deleting or anonymizing eligible information. The deletion page explains what is deleted and what may need to be retained.
11. Children's privacy
The Vantor Clinic staff app is intended for professional clinic personnel aged 18 or older and is not directed to children.
12. Changes to this policy
We may update this policy when the app, its data practices, or legal requirements change. The effective date at the top of this page identifies the current version. Google Play Data safety disclosures will be updated when the mobile app's collection or handling changes.
13. Contact
- App and operator: Vantor CRM
- Privacy email: [email protected]
- Website: https://vantor-sd.com/