Who we are
Axistify is operated by IconicTek, LLC. We provide the software your healthcare provider uses to monitor and support your care between visits. Your provider decides which patients are enrolled and which clinicians can see your information.
In data protection terms, your healthcare provider is generally the controller of your health information and Axistify acts as a processor on their behalf. [confirm: whether this framing matches your contracts with providers]
Accounts are issued by your provider
You cannot sign up for Axistify yourself. Accounts are created by your healthcare provider, and your access ends when they end it. If you did not expect an Axistify account, contact your provider first — they control enrolment.
What we collect
We hold the following, and nothing beyond it:
- Who you are. Name, email address, phone number, date of birth, and a profile photo if you upload one. Clinicians additionally have a professional licence number.
- Readings from your devices. Blood pressure, pulse, blood oxygen, temperature and weight, along with when each reading was taken and which device produced it. Readings arrive over Bluetooth from devices supplied or approved by your provider.
- Messages. Messages you exchange with your care team, including any photos you attach.
- Video visits. The schedule, duration and attendance of visits. Where a visit is recorded, the recording and any whiteboard content are stored too. [confirm: whether visit recording is enabled for patients]
- Exercise activity. Which prescribed exercises you completed, how much of each video you watched, and the pain and effort ratings you choose to give. Those ratings are optional.
- Device assignments. Which monitoring devices your provider has issued to you, including their hardware identifiers.
We do not sell your information, we do not use it for advertising, and we do not build advertising profiles.
Why we hold it
Solely to deliver the service your provider has enrolled you in: to show your readings to you and to the clinicians on your care team, to carry your messages and video visits, to record whether prescribed exercises were completed, and to keep the service secure and working.
Who can see your information
Access is enforced by the database itself, not only by the app. Every record carries the organisation it belongs to, and access rules are applied on every query.
- You — all of your own information.
- Clinicians assigned to you — doctors and nurses on your care team. Removing a clinician from your care team removes their access.
- Your provider's administrators — limited oversight of their own organisation.
- Axistify staff — only where necessary to operate or support the service.
Patients of one provider can never see patients of another, and clinicians cannot see patients outside their own care team.
Services that process data for us
We use a small number of processors. Each one only receives what it needs to do its job:
- Supabase — the database, sign-in, and realtime updates. Your account and clinical records live here.
- Google Cloud Storage — profile photos, message attachments, exercise videos and visit recordings. Files are stored privately and served through short-lived links.
- Agora — the audio and video connection during a video visit.
- Google Maps — turning provider addresses into map locations for home visits.
- Vercel and Railway — hosting for the website and the application programming interface.
- Stripe — billing between Axistify and your provider. Patients are not billed through the app.
[confirm: list the countries these processors store data in, and whether Business Associate Agreements are in place with each]
How long we keep it
Clinical records are kept for as long as your provider requires them, because they form part of your medical record and your provider — not Axistify — decides that period. [confirm: state the retention period and deletion process]
How we protect it
Information is encrypted in transit and at rest. Access is restricted by role and enforced in the database on every request. Files are held in private storage and are never publicly readable. Sign-in uses industry-standard authentication, and sessions can be revoked.
No system is perfectly secure. If a breach affects your information we will notify your provider and, where required, you and the relevant regulator.
Your rights
You can ask for a copy of your information, ask us to correct it, or ask about deletion. Because your provider holds the clinical relationship, please contact them first — we will support them in responding. You may also contact us directly using the details below.
[confirm: add the specific rights and response times for your jurisdictions — for example HIPAA in the United States, or GDPR in the EU and UK]
Children
Axistify is intended for adults enrolled by a healthcare provider. Where a provider enrols a minor, the account is managed under that provider's own consent and safeguarding arrangements. [confirm: whether minors are enrolled, and the minimum age]
Changes to this policy
If we change this policy we will update the date at the top of this page and, where the change is significant, tell your provider so they can inform you.
Contact
IconicTek, LLC — info@axistify.com · +1 651 399 8282
[confirm: add the registered postal address]