← All policies

Privacy notice

What Vesyra collects, why it collects it, who else touches it, and how long it stays. The short version: account details, the business records a practice enters, and server logs — and nothing that identifies a practice's patients.

Effective 5 August 2026.

1Who this covers

Vesyra is operated by Amagi Solutions Group. This notice covers the Vesyra web application and the vesyra.app website.

Two different groups of people appear in it, and the distinction matters throughout. Practices are the businesses that license Vesyra. Usersare the individuals a practice gives an account to — owners, administrators, managers, clinicians and front-desk staff. A practice’s own patients are not users, do not have accounts, and are not identified anywhere in the system; see section 4.

2What we collect

We collect three things, and it is a short list on purpose.

  • Account information.A user’s email address, display name, optional professional title, the practice or practices they belong to, and their role in each. Passwords are stored only as a one-way hash by our authentication provider; nobody at Vesyra can read one, and the product has no screen that displays one.
  • Business records the practice enters. Products, vendors, deliveries and their prices, lot numbers and expiry dates, stock adjustments, service lines, and sales — what was sold, for how much, which product it drew down, and which user rang it and administered it.
  • Operational logs. Server and database logs generated by hosting: request timestamps, paths, response codes, and the IP address a request arrived from. These exist so that outages and abuse can be diagnosed.

We do not buy personal information from data brokers, and we do not enrich or append to what a practice gives us.

3Why we use it

Account information exists to authenticate a person and to decide what they may see and do. Business records exist because they are the product: they are what the practice reads back as inventory levels and margin. Logs exist to keep the service up and to investigate security events.

We also use a practice’s billing and contact details to invoice them and to send service notices — an outage, a security disclosure, a change to this notice. Those are not marketing and cannot be unsubscribed from while an account is active.

We do not use a practice’s business records to train machine learning models, and we do not sell or rent personal information to anyone, for any purpose.

4Patient information

Vesyra is built so that a practice’s patients are not identified in it. There is no field anywhere in the schema for a patient name, date of birth, address, telephone number, email address, insurance identifier, photograph or clinical note, and the application provides no way to attach a file.

A visit is recorded against a reference code that the practice assigns from its own clinical or practice-management system and keeps on its own side. Vesyra stores the code, the date, the service line, the products drawn and the amount charged. It cannot resolve the code to a person; only the practice can.

Free-text fields — notes on an adjustment, for instance — are for business context and must not be used to record anything about an identifiable patient. A practice that types a patient name into one has put information into Vesyra that Vesyra is not designed to hold.

This section describes how the software is built. It is not a legal conclusion about how any particular regulation applies to a particular practice’s use of it; that is a question for the practice and its counsel, and we will provide the data model in writing to help them answer it. Our data-handling posture is set out in more detail in the data protection statement.

5Who owns what a practice enters

The practice does. We hold its business records to provide the service to it, and for no independent purpose of our own. A practice may export its reporting data as CSV from inside the product at any time, without asking us.

Where a practice is subject to privacy laws that make it responsible for information it collects, Vesyra acts on the practice’s instructions with respect to that information rather than deciding for itself what to do with it.

6Who we share it with

We share personal information with service providers who run parts of the platform for us, under contracts that limit them to that purpose:

  • Vercel — application hosting and content delivery.
  • Supabase — the database and the authentication service, hosted in the United States.
  • Resend — delivery of transactional email such as account invitations.

We will also disclose information where we are legally required to, and to a successor entity if the business is sold — in which case this notice travels with the information and the successor is bound by it until it gives notice of a change.

One practice never sees another practice’s data. Isolation is enforced in the database by row-level security, evaluated on every query against the identity of the signed-in user, rather than by application code remembering to add a filter.

7Cookies and tracking

Vesyra sets one kind of cookie: the session cookie that keeps a user signed in. It is strictly necessary — without it there is no way to stay authenticated between page loads — and it is cleared when the user signs out.

There is no advertising network on this site, no third-party analytics, no session recording, no heat mapping and no cross-site tracking pixel. Typefaces are served from our own domain rather than from a font CDN, so loading a page does not announce the visit to anyone else. That is also why there is no consent banner: there is nothing to consent to beyond the cookie the service cannot run without.

8How long we keep it

Business records are kept for as long as the practice’s account is active, because inventory and margin history are the point of the product and a report that silently loses last year is worse than no report.

After an account is closed we keep its data for 30 days so that it can be restored if the closure was a mistake or a dispute, then delete it from live systems. Encrypted backups age out on their own schedule and are fully expired within 90 days of closure. A practice that wants its data deleted sooner than 30 days can ask, and we will do it.

Operational logs are retained for a shorter period, sufficient to investigate an incident, and are not used for any other purpose.

9Security

Traffic is encrypted in transit with TLS. Data is encrypted at rest by our database provider. Access is granted per practice and per role, and a user’s access to one practice grants nothing at another.

Accounts are created by an administrator, not by self-service signup, and the first sign-in is by an invitation link that expires. Vesyra staff access production data only when required to operate the service or to resolve a support request, and such access is logged.

No system is immune. If we become aware of a breach affecting a practice’s information we will notify that practice without undue delay, describe what we know, and say what we are doing about it.

10Your rights

Depending on where you live, you may have the right to ask what personal information we hold about you, to have it corrected, to have it deleted, to receive a copy of it, and not to be discriminated against for exercising any of these. We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing to opt out of on that front.

If you are a user of a practice’s workspace, the fastest route is usually your practice administrator, who can change or remove your account directly. You are also welcome to write to us at legal@vesyra.app, and we will respond within the period the applicable law requires. We may need to verify your identity before acting, and where the information belongs to a practice rather than to us we will refer the request to that practice and assist them with it.

11Children

Vesyra is a business tool licensed to practices. It is not directed at children, it has no consumer signup, and we do not knowingly collect personal information from anyone under 16. If you believe a child’s information has reached us, write to us and we will remove it.

12Changes to this notice

We will update this page when the product changes in a way that changes the answers, and the effective date at the top will move. If a change materially reduces the protections described here, we will tell account administrators by email before it takes effect rather than relying on anyone to notice a new date.

13Contact

Questions about this notice, or a request about your information: legal@vesyra.app.

This notice describes how the software is built and operated. It is not legal advice, and nothing in it is a determination about how a particular regulation applies to a particular practice.