Skip to main content
Privacy

What we collect, and what we don’t

Written to be read rather than skimmed past. If anything here is vaguer than you need it to be, tell us and we will make it specific.

Last reviewed 3 October 2026

Who we are

Vision Digital Lab is the controller of the personal data described here. You can reach us at hello@visiondigitallab.com about anything on this page, including a request to see, correct or delete what we hold about you.

This policy covers two things: this website, and the VisionOne client portal at app.visiondigitallab.com. They hold different data and are described separately below.

This website runs no analytics

We do not load Google Analytics, advertising pixels, session recorders or any other third-party tracking script. We set no cookies for advertising or analytics. Nothing on this site builds a profile of you or follows you to another site.

That is a statement about today, and it is the kind of statement that quietly stops being true. If we add anything that tracks visitors, this page changes first and the date above changes with it.

If you contact us

Our contact form asks for your name, email address, and optionally your company, phone number, budget, the service you are interested in, and whatever you want to tell us. We use it to answer you and to work out whether we can help.

We do not sell it, rent it, or pass it to anyone for their own marketing. We keep it for as long as we are in conversation with you and for a reasonable period afterwards, and you can ask us to delete it at any time.

The VisionOne portal, and whose data is in it

VisionOne is the dashboard our clinic clients sign in to. For their staff it holds a name, an email address and a role — enough to sign in and to know who may change what.

The rest of what it holds is marketing performance data: what was spent on which channel, how many enquiries arrived, how many became appointments, and which work we completed. That is information about a clinic’s marketing, not about its patients.

Where an appointment appears on a clinic’s calendar, VisionOne stores a reference to it — the time, how long it runs, whether it happened, and a short label such as a first name and a last initial so a front desk can recognise the booking. It holds no diagnosis, no notes, no medications, no lab results and no reason for the visit. Those stay in the clinic’s own systems, and VisionOne has no way to request them.

Where it is held, and who can reach it

This website is hosted on Vercel. The VisionOne portal and its database run on a server in the United States. Access is role-based and signed in through a dedicated identity provider; each clinic can only reach its own data, enforced in the application and in the database rather than only in the browser.

Our engineering and support teams work from India. We say so here rather than leave you to find out later, because it appears on nearly every healthcare security questionnaire. Everyone working on a client account is bound by the same obligations that flow down from the Business Associate Agreement we sign with that clinic.

Third parties

We use third-party services to run the business — hosting, email, and the advertising and scheduling platforms a clinic already uses. Any third party involved in delivering your work is disclosed by name on request, along with what it is used for.

Where we connect VisionOne to a platform a clinic already uses, we read what we need to report on and no more. We do not take a copy of a clinic’s patient records into our systems in order to show a chart.

Your rights

You can ask us what we hold about you, ask us to correct it, ask us to delete it, or object to what we are doing with it. Email hello@visiondigitallab.com and we will respond within 30 days.

If you are a patient of one of our clients, your records belong to that clinic rather than to us. Ask them directly — they are the ones who hold your chart, and they are obliged to answer. We will help them answer if the question touches anything we handle.

Changes to this policy

When this changes, the review date at the top changes with it. We do not quietly revise a privacy policy and leave the date alone.