Restora

Restora Privacy Policy

Restora Privacy Policy

Effective date: 29 April 2026 (version 1.2 changes take effect 12 August 2026) Last updated: 29 July 2026 Version: 1.2

This Privacy Policy explains how AnchorPoint Systems ("AnchorPoint", "we", "us", or "our") collects, uses, stores, and shares personal data when you use the Restora mobile application or related services (collectively, the "Service").

We comply with the Jamaica Data Protection Act, 2020 (the "JDPA") and follow recognised international data-protection standards where they exceed JDPA requirements.

If you have any questions about this Policy or how we handle your data, please contact our Data Protection Officer at [email protected] before using the Service. By creating an account, you confirm that you have read, understood, and agreed to this Policy.


1. Who we are

Data controller: AnchorPoint Systems Registered address: Shrewsbury Road, Petersfield P.O., Westmoreland, Jamaica Data Protection Officer: Lamar Haye Contact email: [email protected] Service: Restora — a multi-tenant practice-management application for physiotherapists and their clients.

We act as the data controller for the Restora platform itself (your account, app preferences, payments to AnchorPoint, anonymised usage analytics, and similar). Where you are a client of a physiotherapist using Restora, the physiotherapist is the data controller for their clinical records about you, and AnchorPoint acts as a data processor on their behalf for those records. This distinction matters for some of your rights — see Section 9.


2. Who this Policy applies to

This Policy applies to three groups of users:

Where this Policy says "you" without qualification, it refers to all three.


3. What personal data we collect

3.1 Data you provide directly

At account creation (Practitioners and Clients): - Email address - First and last name - Phone number (optional) - Password (stored only as a salted bcrypt hash; we never see it in plain text)

Practitioners only: - Practice name and brand details - Professional title - License number and issuing body (for verification) - Photo identification or license documentation (uploaded to support verification) - Bank details or payment credentials — when you connect a WiPay merchant account, or add your personal WiPay Scan2Pay link and/or bank-transfer details so clients can pay you manually (these are stored encrypted at rest)

Clients only (collected through your Practitioner's intake form): - Date of birth - Gender - Address - Occupation - Jamaica TRN (optional) - Medical history, current medications, allergies, primary complaint - Emergency contact details - General practitioner contact details - Photographs of body-chart annotations (clinical) - Voice recordings (transcribed for SOAP notes; the audio file is not retained after transcription completes) - Any other information your Practitioner asks for in their custom intake template

During a telehealth video session (Pro Practice feature): - Live audio and video between you and your Practitioner, carried over an encrypted, one-time video room. Restora does not record, store, or transcribe telehealth calls. The room is provisioned per appointment and expires after the session, so old join links can't be reused. Our video provider (Daily.co) transports the stream but does not retain the media.

When you pay through the app (Clients): - If your Practitioner takes payment manually, you may optionally upload a payment-confirmation screenshot (for example, of a WiPay Scan2Pay or bank-transfer receipt). Such a screenshot can contain financial information — like a transaction reference or a partial account number. It is shared only with your Practitioner so they can confirm your payment, stored under access control, and retained under the payment-records schedule in Section 8. You are never required to attach one unless your Practitioner asks for proof.

3.2 Data collected automatically

3.3 Data we do not collect


4. How we use your data (lawful purposes)

Under the JDPA, every use of your data must have a lawful basis. Here is what we do and the basis we rely on:

Purpose Lawful basis
Creating and maintaining your account Contract (you signed up for an account)
Allowing you to book / accept appointments, send messages, manage exercise plans Contract (the Service you signed up for)
Allowing your Practitioner to maintain clinical records about your treatment Vital interests + Contract (you and your Practitioner have a clinical relationship)
Sending you appointment reminders, payment receipts, transactional notifications Contract (necessary to deliver the Service)
Anonymised, aggregated analytics about how the Service is used Legitimate interests (improving the product)
Crash reports to fix bugs Legitimate interests (keeping the Service reliable)
Verifying Practitioner licenses before they can take public bookings Legal obligation + Legitimate interests (preventing harm)
Complying with anti-fraud / payment-network rules Legal obligation
Responding to lawful requests from regulators or law enforcement Legal obligation

We will never use your data for direct marketing without your separate, opt-in consent. Restora does not send marketing emails today.


5. How clinical data is handled (Clients — read this)

If you are a Client connecting to a Practitioner, you should understand that:

  1. Your Practitioner is the data controller for your clinical records. This includes your intake answers, SOAP notes, body-chart annotations, exercise plans, progress entries, and treatment history. AnchorPoint stores this information on your Practitioner's behalf as a data processor — we do not look at it, mine it, or share it.

  2. Clinical records stay with the Practitioner who created them — unless that Practitioner chooses to send a copy with a referral. Retaining the record is a regulatory requirement under Jamaica clinical-records norms (typically 7 years). By default, accepting a transfer of care moves only your forward-looking relationship to the new Practitioner; the historical record stays with the original one.

    When referring you on, however, your Practitioner may tick "Transfer patient info". If they do, Restora takes a read-only text snapshot of your record as it stands at their practice — your profile details, intake answers, finalised clinical notes, and progress entries — for the receiving Practitioner's reference. Where that happens:

    • The snapshot is frozen at the moment of referral and never changes afterwards.
    • It is released to the receiving practice only after you accept the transfer of care. If you decline, or the referral is never accepted, they never see it.
    • It is a copy, not a move — your original records still remain with your previous Practitioner.
    • It sits separately from anything your new Practitioner goes on to record, as reference only.

    The decision to include your record is your Practitioner's to make, as controller of those records and in line with their professional obligations. The transfer-of-care screen tells you when a copy is being shared, before you accept.

  3. A referral shares clinical context with the receiving practice before you are asked. When your Practitioner refers you on, the referral carries the clinical detail they write for the receiving Practitioner — typically a working diagnosis, your current status, and any precautions — so that Practitioner can judge whether they are the right fit for you. They see this when the referral arrives, which is before you are notified: you are asked to decide only once they have accepted, so you are not drawn into a decision that may never happen. This is ordinary clinical referral practice, relied on for continuity of care. If you would rather not be referred, tell your Practitioner before they send it.

  4. AnchorPoint may access clinical data only for these specific reasons:

    • To fix a bug you have reported (with your case-by-case consent)
    • To respond to a lawful court order or regulator request
    • To migrate data when changing infrastructure (in encrypted form, by senior engineering staff only)
  5. Tenant isolation, and its limits. Every database query the platform makes is scoped to a single tenant (your Practitioner's workspace), so Practitioners cannot browse one another's records. The only ways your data crosses a practice boundary are deliberate ones, each requiring your Practitioner to have acted:

    • A referral they send (item 3), and any record snapshot attached to it (item 2).
    • Connected practices sharing a store. Practitioners can connect and opt to list each other's products. If you order an item that another practice supplies, that practice sees the order — what was ordered, the amount, and an internal reference identifying you — so they can fulfil it. If one of the two practices takes on delivery, the other is told your name, so the handover can be arranged.
    • Practice-to-practice messaging. Connected Practitioners can message each other, for example to coordinate a referral or a delivery, and may mention you by name. What they write is their professional judgment and their responsibility.

6. Third-party processors we use

We rely on a small set of external services to operate Restora. Each of these is bound by a written processing agreement requiring them to meet at least the same standards of confidentiality and security that we hold ourselves to.

Processor What they do What they receive Where they're located
MongoDB Atlas Database hosting All application data (encrypted at rest) United States (us-east-1, Virginia)
Railway Application hosting Server-side logs, transient request bodies United States
Cloudflare DNS, traffic security, possibly content delivery IP addresses (transiently) Global edge, primarily United States
WiPay Card payment processing — your subscription to AnchorPoint, and card payments for Practitioners who connect a WiPay merchant account Order/subscription amount, currency, your payment method (no card numbers ever touch our servers) Trinidad & Tobago
Daily.co Telehealth video rooms (Pro Practice tier) Live audio/video during a session — not recorded, stored, or transcribed United States
Sentry Crash reporting Stack traces, device + app metadata, your user id (no clinical data) United States
PostHog Product analytics Anonymous device id, screen views, button taps (no personal data, no clinical data) United States or EU (we use the EU region where available)
Apple / Google Push notifications via APNs and FCM A device-specific notification token + the notification text United States
OpenAI (opt-in only) Voice-to-text transcription, AI-generated plain-English session summaries for SOAP notes, and reading a practitioner's registration card to pre-fill their verification form A short audio clip; for summaries the relevant clinical-note text; for card reading, the photograph of the practitioner's own registration card United States — under a data-processing addendum. API data is not used to train OpenAI's models. OpenAI may hold it briefly (up to 30 days) for abuse monitoring before deleting it, unless zero-retention is in force for our account — see below

AI processing, precisely. Both AI features are opt-in: they run only for Clients who have given a specific consent to AI processing, and the treating Practitioner reviews an AI summary before sharing it with you. To be exact about what happens to the data:

Manual payments. Many Practitioners take payment manually via their personal WiPay Scan2Pay link or a bank transfer rather than through a connected merchant account. In that case the payment happens directly between you and your Practitioner — through WiPay's own hosted page or your bank — and neither Restora nor AnchorPoint receives, processes, or holds those funds. We only record that you reported the payment, the method, and any confirmation screenshot you chose to attach, so your Practitioner can reconcile it.

We do not share data with anyone outside this list without notifying you first via this Policy.


7. Cross-border data transfers

Most of our processors are based in the United States. The JDPA permits cross-border transfers where the destination country provides adequate protection or where we have implemented appropriate safeguards.

The United States does not have blanket adequacy under the JDPA, so for every US-based processor we rely on:

Where a processor offers EU-region or UK-region hosting, we use it (currently PostHog). We may revisit cross-border arrangements as Caribbean cloud-hosting options mature.

By using the Service, you acknowledge and consent to these transfers.


8. How long we keep your data

Data Retention period
Active account data (auth, profile, app preferences) Until you close your account, then 30 days for backup expiry, then deleted
Clinical records 7 years from the date of your last appointment (matches Jamaica clinical-records practice). This is the Practitioner's retention obligation, not ours; if a Practitioner closes their Restora practice, we offer them a data export and then delete after 90 days.
Referral records, including any record snapshot attached to a referral (Section 5.2) 7 years, alongside the clinical records they form part of
Payment records 7 years (Jamaica accounting / tax requirement)
Server logs 30 days
Crash and error reports 90 days
Analytics events 365 days, then aggregated and individually anonymised
Push notification tokens Until the device unregisters or the token expires (~7 days of inactivity)

When the retention period ends, data is permanently deleted from primary storage and removed from rolling backups within a further 90 days.


9. Your rights under the JDPA

You have the following rights with respect to data we control:

  1. Right of access. Ask us what personal data we hold about you. We will respond within 30 days.
  2. Right to rectification. Ask us to correct inaccurate data.
  3. Right to erasure ("right to be forgotten"). Ask us to delete data we control. However, clinical records held by your Practitioner are their records, not ours — for those, your erasure request must go to your Practitioner directly, who will assess it against their professional and legal obligations.
  4. Right to restrict processing. Ask us to pause certain uses of your data while you contest accuracy or our lawful basis.
  5. Right to data portability. Receive your data in a structured, commonly-used, machine-readable format. Email us and we will provide a JSON export.
  6. Right to object. Object to processing based on our legitimate interests; we will reassess and either justify continued processing or stop.
  7. Right to withdraw consent. Where we rely on your consent (for example, opt-in features), you can withdraw it at any time.
  8. Right to lodge a complaint. With us, in the first instance — we take complaints seriously and aim to resolve them within 30 days. If you remain unsatisfied, you may complain to the Office of the Information Commissioner (OIC) of Jamaica.

To exercise any of these rights, email [email protected] with your full name, the email address on your Restora account, and a description of your request. We may need to verify your identity before fulfilling certain requests; this is to protect you, not to obstruct the request.

We do not charge a fee for handling reasonable requests. We may charge a reasonable administrative fee for repeat or excessive requests, as permitted by the JDPA.


10. Security

We take security seriously. Our key controls include:

No system is perfectly secure. In the event of a personal-data breach that is likely to result in risk to your rights, we will notify you and the OIC within 72 hours of becoming aware, in line with JDPA §22.


11. Children

Restora is intended for adult use only (17 and older). The App Store age rating is 17+ and the Play Store rating is the local equivalent.

If a Practitioner treats a minor, the Practitioner is responsible for obtaining parental or guardian consent in line with their professional obligations. We do not knowingly collect personal data from anyone under the age of 17 directly.

If you believe a minor has used Restora to register a Client account, please contact us at [email protected] and we will delete the account.


12. Cookies and similar technologies

The Restora mobile app does not use cookies. We use the device's secure storage (Apple Keychain / Android Keystore) to keep you logged in.

The Restora privacy and terms web pages use only essential, non-tracking technology (a minimal session cookie if you choose to use any contact form). We do not load advertising trackers or third-party social-media widgets on these pages.


13. Changes to this Policy

We may update this Policy from time to time. When we do, we will:

Continued use of the Service after the effective date of a new version constitutes acceptance of the updated Policy.


14. Contact

If you have any questions, requests, or concerns:

If you are not satisfied with our response, you may lodge a complaint with the Office of the Information Commissioner (Jamaica) at oic.gov.jm.