Restora Privacy Policy
Effective date: 29 April 2026 (version 1.2 changes take effect 12 August 2026) Last updated: 29 July 2026 Version: 1.2
This Privacy Policy explains how AnchorPoint Systems ("AnchorPoint", "we", "us", or "our") collects, uses, stores, and shares personal data when you use the Restora mobile application or related services (collectively, the "Service").
We comply with the Jamaica Data Protection Act, 2020 (the "JDPA") and follow recognised international data-protection standards where they exceed JDPA requirements.
If you have any questions about this Policy or how we handle your data, please contact our Data Protection Officer at [email protected] before using the Service. By creating an account, you confirm that you have read, understood, and agreed to this Policy.
1. Who we are
Data controller: AnchorPoint Systems Registered address: Shrewsbury Road, Petersfield P.O., Westmoreland, Jamaica Data Protection Officer: Lamar Haye Contact email: [email protected] Service: Restora — a multi-tenant practice-management application for physiotherapists and their clients.
We act as the data controller for the Restora platform itself (your account, app preferences, payments to AnchorPoint, anonymised usage analytics, and similar). Where you are a client of a physiotherapist using Restora, the physiotherapist is the data controller for their clinical records about you, and AnchorPoint acts as a data processor on their behalf for those records. This distinction matters for some of your rights — see Section 9.
2. Who this Policy applies to
This Policy applies to three groups of users:
- Physiotherapists (and clinic administrators in future versions) who register a practice on Restora and use it to manage their clients ("Practitioners").
- Clients of those Practitioners who use Restora to book appointments, access exercise plans, communicate with their Practitioner, and so on ("Clients").
- Visitors to any web pages we operate (currently the public privacy and terms pages).
Where this Policy says "you" without qualification, it refers to all three.
3. What personal data we collect
3.1 Data you provide directly
At account creation (Practitioners and Clients): - Email address - First and last name - Phone number (optional) - Password (stored only as a salted bcrypt hash; we never see it in plain text)
Practitioners only: - Practice name and brand details - Professional title - License number and issuing body (for verification) - Photo identification or license documentation (uploaded to support verification) - Bank details or payment credentials — when you connect a WiPay merchant account, or add your personal WiPay Scan2Pay link and/or bank-transfer details so clients can pay you manually (these are stored encrypted at rest)
Clients only (collected through your Practitioner's intake form): - Date of birth - Gender - Address - Occupation - Jamaica TRN (optional) - Medical history, current medications, allergies, primary complaint - Emergency contact details - General practitioner contact details - Photographs of body-chart annotations (clinical) - Voice recordings (transcribed for SOAP notes; the audio file is not retained after transcription completes) - Any other information your Practitioner asks for in their custom intake template
During a telehealth video session (Pro Practice feature): - Live audio and video between you and your Practitioner, carried over an encrypted, one-time video room. Restora does not record, store, or transcribe telehealth calls. The room is provisioned per appointment and expires after the session, so old join links can't be reused. Our video provider (Daily.co) transports the stream but does not retain the media.
When you pay through the app (Clients): - If your Practitioner takes payment manually, you may optionally upload a payment-confirmation screenshot (for example, of a WiPay Scan2Pay or bank-transfer receipt). Such a screenshot can contain financial information — like a transaction reference or a partial account number. It is shared only with your Practitioner so they can confirm your payment, stored under access control, and retained under the payment-records schedule in Section 8. You are never required to attach one unless your Practitioner asks for proof.
3.2 Data collected automatically
- Authentication tokens — stored locally on your device in secure platform storage (Apple Keychain / Android Keystore via
expo-secure-store) - Device identifiers — push notification tokens (for sending appointment and order reminders), device platform (iOS/Android), and app version. You can switch push notifications off entirely, or choose which categories you receive, under More → Notifications; turning them off stops the push but not the in-app notification list
- Usage data — when you log in, what screens you view, taps and basic interaction events (via PostHog; see Section 6)
- Crash and error reports — stack traces, device model, OS version, and the path you took before a crash (via Sentry; see Section 6)
- IP address — recorded transiently in server logs and access logs; not persisted alongside your user record
3.3 Data we do not collect
- We do not collect your real-time location.
- We do not access your contacts, photos library, or microphone except where you explicitly tap a record-audio button in a clinical note flow.
- We do not sell, rent, or trade your personal data to anyone, ever.
- We do not use your data to train AI models, and the AI processor we use is contractually barred from training on anything we send them. Where a feature genuinely needs AI processing — today that is voice-to-text for clinical notes, and AI-generated session summaries — it is opt-in and asks for your explicit consent first. See Section 6.
4. How we use your data (lawful purposes)
Under the JDPA, every use of your data must have a lawful basis. Here is what we do and the basis we rely on:
| Purpose | Lawful basis |
|---|---|
| Creating and maintaining your account | Contract (you signed up for an account) |
| Allowing you to book / accept appointments, send messages, manage exercise plans | Contract (the Service you signed up for) |
| Allowing your Practitioner to maintain clinical records about your treatment | Vital interests + Contract (you and your Practitioner have a clinical relationship) |
| Sending you appointment reminders, payment receipts, transactional notifications | Contract (necessary to deliver the Service) |
| Anonymised, aggregated analytics about how the Service is used | Legitimate interests (improving the product) |
| Crash reports to fix bugs | Legitimate interests (keeping the Service reliable) |
| Verifying Practitioner licenses before they can take public bookings | Legal obligation + Legitimate interests (preventing harm) |
| Complying with anti-fraud / payment-network rules | Legal obligation |
| Responding to lawful requests from regulators or law enforcement | Legal obligation |
We will never use your data for direct marketing without your separate, opt-in consent. Restora does not send marketing emails today.
5. How clinical data is handled (Clients — read this)
If you are a Client connecting to a Practitioner, you should understand that:
-
Your Practitioner is the data controller for your clinical records. This includes your intake answers, SOAP notes, body-chart annotations, exercise plans, progress entries, and treatment history. AnchorPoint stores this information on your Practitioner's behalf as a data processor — we do not look at it, mine it, or share it.
-
Clinical records stay with the Practitioner who created them — unless that Practitioner chooses to send a copy with a referral. Retaining the record is a regulatory requirement under Jamaica clinical-records norms (typically 7 years). By default, accepting a transfer of care moves only your forward-looking relationship to the new Practitioner; the historical record stays with the original one.
When referring you on, however, your Practitioner may tick "Transfer patient info". If they do, Restora takes a read-only text snapshot of your record as it stands at their practice — your profile details, intake answers, finalised clinical notes, and progress entries — for the receiving Practitioner's reference. Where that happens:
- The snapshot is frozen at the moment of referral and never changes afterwards.
- It is released to the receiving practice only after you accept the transfer of care. If you decline, or the referral is never accepted, they never see it.
- It is a copy, not a move — your original records still remain with your previous Practitioner.
- It sits separately from anything your new Practitioner goes on to record, as reference only.
The decision to include your record is your Practitioner's to make, as controller of those records and in line with their professional obligations. The transfer-of-care screen tells you when a copy is being shared, before you accept.
-
A referral shares clinical context with the receiving practice before you are asked. When your Practitioner refers you on, the referral carries the clinical detail they write for the receiving Practitioner — typically a working diagnosis, your current status, and any precautions — so that Practitioner can judge whether they are the right fit for you. They see this when the referral arrives, which is before you are notified: you are asked to decide only once they have accepted, so you are not drawn into a decision that may never happen. This is ordinary clinical referral practice, relied on for continuity of care. If you would rather not be referred, tell your Practitioner before they send it.
-
AnchorPoint may access clinical data only for these specific reasons:
- To fix a bug you have reported (with your case-by-case consent)
- To respond to a lawful court order or regulator request
- To migrate data when changing infrastructure (in encrypted form, by senior engineering staff only)
-
Tenant isolation, and its limits. Every database query the platform makes is scoped to a single tenant (your Practitioner's workspace), so Practitioners cannot browse one another's records. The only ways your data crosses a practice boundary are deliberate ones, each requiring your Practitioner to have acted:
- A referral they send (item 3), and any record snapshot attached to it (item 2).
- Connected practices sharing a store. Practitioners can connect and opt to list each other's products. If you order an item that another practice supplies, that practice sees the order — what was ordered, the amount, and an internal reference identifying you — so they can fulfil it. If one of the two practices takes on delivery, the other is told your name, so the handover can be arranged.
- Practice-to-practice messaging. Connected Practitioners can message each other, for example to coordinate a referral or a delivery, and may mention you by name. What they write is their professional judgment and their responsibility.
6. Third-party processors we use
We rely on a small set of external services to operate Restora. Each of these is bound by a written processing agreement requiring them to meet at least the same standards of confidentiality and security that we hold ourselves to.
| Processor | What they do | What they receive | Where they're located |
|---|---|---|---|
| MongoDB Atlas | Database hosting | All application data (encrypted at rest) | United States (us-east-1, Virginia) |
| Railway | Application hosting | Server-side logs, transient request bodies | United States |
| Cloudflare | DNS, traffic security, possibly content delivery | IP addresses (transiently) | Global edge, primarily United States |
| WiPay | Card payment processing — your subscription to AnchorPoint, and card payments for Practitioners who connect a WiPay merchant account | Order/subscription amount, currency, your payment method (no card numbers ever touch our servers) | Trinidad & Tobago |
| Daily.co | Telehealth video rooms (Pro Practice tier) | Live audio/video during a session — not recorded, stored, or transcribed | United States |
| Sentry | Crash reporting | Stack traces, device + app metadata, your user id (no clinical data) | United States |
| PostHog | Product analytics | Anonymous device id, screen views, button taps (no personal data, no clinical data) | United States or EU (we use the EU region where available) |
| Apple / Google | Push notifications via APNs and FCM | A device-specific notification token + the notification text | United States |
| OpenAI (opt-in only) | Voice-to-text transcription, AI-generated plain-English session summaries for SOAP notes, and reading a practitioner's registration card to pre-fill their verification form | A short audio clip; for summaries the relevant clinical-note text; for card reading, the photograph of the practitioner's own registration card | United States — under a data-processing addendum. API data is not used to train OpenAI's models. OpenAI may hold it briefly (up to 30 days) for abuse monitoring before deleting it, unless zero-retention is in force for our account — see below |
AI processing, precisely. Both AI features are opt-in: they run only for Clients who have given a specific consent to AI processing, and the treating Practitioner reviews an AI summary before sharing it with you. To be exact about what happens to the data:
- Restora keeps no copy of what is sent. The audio clip for a transcription is discarded once the transcript returns — we never write it to storage. For a summary, we send the note text and store only the summary that comes back.
- OpenAI does not train on it. Data sent through OpenAI's API is excluded from model training under their API terms.
- OpenAI may hold it briefly. By default OpenAI retains API inputs and outputs for up to 30 days for abuse and misuse monitoring, then deletes them. This is OpenAI's retention, not ours, and it applies unless a zero-data-retention arrangement is in force for our account.
- You can avoid it entirely. Declining AI-processing consent means no clinical text or audio of yours is ever sent to OpenAI; every other part of the Service works as normal.
- Practitioner registration cards. When a physiotherapist uploads their registration card, we can read it automatically so the verification form is filled in for them to check. This applies only to the practitioner's own professional card — never to a client's data — and it is a convenience, not a decision: a person at AnchorPoint still reviews the card itself, and the physiotherapist can skip the automatic reading and type the details in by hand. The image is sent directly in the request rather than published to a link, and is excluded from OpenAI's model training on the same terms as everything else above.
Manual payments. Many Practitioners take payment manually via their personal WiPay Scan2Pay link or a bank transfer rather than through a connected merchant account. In that case the payment happens directly between you and your Practitioner — through WiPay's own hosted page or your bank — and neither Restora nor AnchorPoint receives, processes, or holds those funds. We only record that you reported the payment, the method, and any confirmation screenshot you chose to attach, so your Practitioner can reconcile it.
We do not share data with anyone outside this list without notifying you first via this Policy.
7. Cross-border data transfers
Most of our processors are based in the United States. The JDPA permits cross-border transfers where the destination country provides adequate protection or where we have implemented appropriate safeguards.
The United States does not have blanket adequacy under the JDPA, so for every US-based processor we rely on:
- Standard Contractual Clauses (SCCs) — contractual terms binding the processor to JDPA-equivalent protections, including the obligation to respect your data-subject rights and notify us promptly of any unauthorised access.
- Encryption in transit (TLS 1.2+) and encryption at rest (AES-256 or equivalent).
- Restricted access — only the minimum number of personnel can decrypt data, and access is logged.
Where a processor offers EU-region or UK-region hosting, we use it (currently PostHog). We may revisit cross-border arrangements as Caribbean cloud-hosting options mature.
By using the Service, you acknowledge and consent to these transfers.
8. How long we keep your data
| Data | Retention period |
|---|---|
| Active account data (auth, profile, app preferences) | Until you close your account, then 30 days for backup expiry, then deleted |
| Clinical records | 7 years from the date of your last appointment (matches Jamaica clinical-records practice). This is the Practitioner's retention obligation, not ours; if a Practitioner closes their Restora practice, we offer them a data export and then delete after 90 days. |
| Referral records, including any record snapshot attached to a referral (Section 5.2) | 7 years, alongside the clinical records they form part of |
| Payment records | 7 years (Jamaica accounting / tax requirement) |
| Server logs | 30 days |
| Crash and error reports | 90 days |
| Analytics events | 365 days, then aggregated and individually anonymised |
| Push notification tokens | Until the device unregisters or the token expires (~7 days of inactivity) |
When the retention period ends, data is permanently deleted from primary storage and removed from rolling backups within a further 90 days.
9. Your rights under the JDPA
You have the following rights with respect to data we control:
- Right of access. Ask us what personal data we hold about you. We will respond within 30 days.
- Right to rectification. Ask us to correct inaccurate data.
- Right to erasure ("right to be forgotten"). Ask us to delete data we control. However, clinical records held by your Practitioner are their records, not ours — for those, your erasure request must go to your Practitioner directly, who will assess it against their professional and legal obligations.
- Right to restrict processing. Ask us to pause certain uses of your data while you contest accuracy or our lawful basis.
- Right to data portability. Receive your data in a structured, commonly-used, machine-readable format. Email us and we will provide a JSON export.
- Right to object. Object to processing based on our legitimate interests; we will reassess and either justify continued processing or stop.
- Right to withdraw consent. Where we rely on your consent (for example, opt-in features), you can withdraw it at any time.
- Right to lodge a complaint. With us, in the first instance — we take complaints seriously and aim to resolve them within 30 days. If you remain unsatisfied, you may complain to the Office of the Information Commissioner (OIC) of Jamaica.
To exercise any of these rights, email [email protected] with your full name, the email address on your Restora account, and a description of your request. We may need to verify your identity before fulfilling certain requests; this is to protect you, not to obstruct the request.
We do not charge a fee for handling reasonable requests. We may charge a reasonable administrative fee for repeat or excessive requests, as permitted by the JDPA.
10. Security
We take security seriously. Our key controls include:
- Encryption in transit — all client-server traffic is TLS 1.2 or higher.
- Encryption at rest — database storage and backups are encrypted with AES-256.
- Sensitive field encryption — bank account numbers and payment processor credentials are individually encrypted using Fernet symmetric encryption with rotated keys, on top of the database-level encryption.
- Authentication — passwords are hashed with bcrypt; access tokens are short-lived (15 minutes); refresh tokens are stored only in the device's secure enclave (Apple Keychain / Android Keystore).
- Tenant isolation — every authenticated request is scoped to a single tenant; no Practitioner can access another Practitioner's data.
- Audit logging — sensitive operations (payouts, identity verification decisions, account deletion) are recorded in an append-only audit log.
- Least privilege — internal AnchorPoint access to production data is limited to a small number of senior engineers, requires multi-factor authentication, and is logged.
- Vulnerability disclosure — if you discover a security issue, please email [email protected] rather than disclosing publicly. We aim to respond within 48 hours.
No system is perfectly secure. In the event of a personal-data breach that is likely to result in risk to your rights, we will notify you and the OIC within 72 hours of becoming aware, in line with JDPA §22.
11. Children
Restora is intended for adult use only (17 and older). The App Store age rating is 17+ and the Play Store rating is the local equivalent.
If a Practitioner treats a minor, the Practitioner is responsible for obtaining parental or guardian consent in line with their professional obligations. We do not knowingly collect personal data from anyone under the age of 17 directly.
If you believe a minor has used Restora to register a Client account, please contact us at [email protected] and we will delete the account.
12. Cookies and similar technologies
The Restora mobile app does not use cookies. We use the device's secure storage (Apple Keychain / Android Keystore) to keep you logged in.
The Restora privacy and terms web pages use only essential, non-tracking technology (a minimal session cookie if you choose to use any contact form). We do not load advertising trackers or third-party social-media widgets on these pages.
13. Changes to this Policy
We may update this Policy from time to time. When we do, we will:
- Update the "Effective date" and "Version" at the top.
- For material changes, send you an in-app notice at least 14 days before the new version takes effect.
- Keep previous versions of this Policy archived at restoraja.app/legal/privacy/history.
Continued use of the Service after the effective date of a new version constitutes acceptance of the updated Policy.
14. Contact
If you have any questions, requests, or concerns:
- Email: [email protected]
- Mail: AnchorPoint Systems Shrewsbury Road Petersfield P.O. Westmoreland, Jamaica
- Data Protection Officer: Lamar Haye
If you are not satisfied with our response, you may lodge a complaint with the Office of the Information Commissioner (Jamaica) at oic.gov.jm.