1. Scope
This policy applies to the Ayada website and practice-management application. Ayada is intended for professional practice workflows; it is not an emergency or crisis service.
2. Information processed
The application can process account and clinic identifiers, profile details, appointments, patient details, clinical documentation, assessments, prescriptions, lab and dental records, emergency contacts, billing and payment records, reminders, lifecycle requests, and selected account activity.
3. How information is used
Information is used to authenticate users, provide clinic workflows, enforce roles and clinic assignments, synchronize authorized records, generate reports and exports, maintain account settings, support multi-factor authentication, and record selected activity for accountability and troubleshooting.
4. Storage on the device
Ayada stores limited interface preferences in browser storage. Clinical records and new clinical changes are not available offline and are not intentionally cached for offline use. A service worker may cache static application files. A legacy recovery queue may remain temporarily only if an older release already held unsynchronized changes; reconnect and resolve it before clearing browser data.
5. Hosting and service providers
The application connects to Supabase for authentication, database, and file-storage services. The Supabase browser library is served with Ayada, and the public website loads brand fonts from Google Fonts. If you choose Google sign-in, Google also processes the authentication request. These providers may receive ordinary network and device information needed to deliver their services.
6. Sharing
Ayada does not contain an advertising integration or a feature that sells personal information. Information is transmitted to service providers needed to operate the functions described above and may be disclosed when required by applicable law. No broader disclosure promise is made without verified operating policies.
7. Retention, export, and deletion
Ayada does not assume a fixed legal retention period. Authorized users can export defined information, and owners can record retention decisions, legal holds, and reviewed archive or deletion requests. Submitting a lifecycle request does not delete information automatically. Account closure and deletion require an authorized review through Ayada Support. Device-side browser data may remain until cleared from the browser profile.
8. Security
Ayada defines authenticated sessions, optional authenticator-app MFA, HTTPS production connections, organization and clinic-scoped database policies, role permissions, patient assignment controls, and selected activity logging. These controls depend on correct production deployment and reduce risk without guaranteeing absolute security. See the Security page for boundaries.
9. Requests and changes
Requests to access, correct, export, archive, or delete information can be raised through the application’s governance controls or the Contact page. Availability depends on authorization, applicable law, and verified operating procedures. Material policy changes will be published with a new effective date.