zavisvisibility

Privacy notice

Public checks

Public checkers use clinic identifiers and information returned by configured public sources. Anyone with a shareable report link can read that report until it expires. Public reports exclude private clinic records and Google management credentials. Clinic search and current-hours requests send the search text or selected place ID to Google. Google handles information under its Privacy Policy.

Workspace records

The application stores account identifiers and names, user profiles, clinic records, team roles, confirmed care and exception calendars, and operational activity. Workspace permissions restrict private records to authorized members of the same account.

Signing in through Zavis

When you open this app inside Zavis, it verifies the session supplied by your dashboard to confirm your user and account. The app keeps its short-lived workspace credential in memory, without saving it in browser storage or a separate sign-in cookie. The server stores a hash of that credential. Switching accounts clears the previous account view and requires verification of the new account.

Standalone sign-in, when used, stores a password hash and uses an HTTP-only session cookie. Your Zavis password is not requested by the embedded app.

Optional Google management

Connecting Business Profile is optional. Access tokens and reviewed publishing content are encrypted. Disconnecting a clinic removes its stored Google access and related retained management content. Managed profile imports and reviewed content have a 24-hour availability limit; scheduled cleanup removes expired content. Transient category, service and attribute views expire after 15 minutes.

Public hours and source retention

Current Google Maps opening hours are displayed temporarily and cleared within 15 minutes or at the clinic-local date boundary, whichever comes first. The server does not cache their response or save it into reports, exports or score history. It retains request accounting and error metadata for budget control. Other public provider content follows the configured provider retention period, limited to seven days; derived historical summaries may remain.

Notifications

Configured email and WhatsApp providers process opted-in notifications and delivery receipts. You can manage workspace notification preferences and unsubscribe using the supplied links. Google Search Console is not integrated.

Service operator details

This hosted deployment is undergoing integration testing. The service operator’s legal identity, privacy contact, applicable data rights and deployment-specific retention details have not yet been configured. These details must be included in the final notice before accepting live client accounts.