Skip to content

Privacy

Last updated 8 September 2026

This text has not been reviewed by a lawyer. It is a working draft written by the Talven team and needs professional review before this product handles real patient data. We would rather say so than imply otherwise.

Who holds the data

When a clinic uses Talven, the clinic decides what patient information is collected and why. Talven processes those records to provide the clinic workspace. Patients should direct requests about their records to their clinic in the first instance.

The software is not presented as a regulatory certification. The clinic and the service provider must assess their own responsibilities with qualified advisers before handling real patient data.

What we store

  • Clinic and staff account details: name, email address, role.
  • Patient records the clinic enters: demographics, contact details, visit notes, prescriptions, observations, invoices and payments.
  • Files uploaded by the clinic or a patient, held in private storage and served only through authenticated, expiring links.
  • An audit trail of who did what, and delivery records for messages we send.

Where it is stored

The current deployment uses a database hosted in Singapore and private Cloudflare R2 object storage for uploaded files. We do not claim India-only storage. Confirm hosting, contractual and data-transfer requirements with the team before using real patient data.

Who can see a record

Access is checked on the server for every request. Clinic staff see only their own clinic’s records. A patient sees only their own chart, and only after accepting an invitation sent to a verified address — never because a name, phone number or email happened to match. Platform administrators see account and operational information; they have no route into a patient chart.

Messages

We send appointment and follow-up email where a patient has opted in, and we record that consent with the wording shown at the time. Opting out stops it. Message content is kept deliberately sparse and links are authenticated.

Retention and deletion

A clinic retention setting is stored with a default of three years. That setting is not a statement of the legally required retention period and does not mean records are automatically deleted after three years. Authorised staff can export patient charts. Contact the clinic and the Talven team about access, retention or deletion requirements.

Contact

Questions about this notice: hello@supernetrix.com.