Privacy and data protection
The privacy policy for the RVer website and app, and what the GDPR means in our case. For any request about your data: [email protected].
01Privacy Policy
Last updated: September 2026
1. Data Controller
Amplified Creations, Lda., owner of the RVer brand, headquartered in Leiria, Portugal, is responsible for processing personal data collected through this website. Contact: [email protected]
2. Data Collected
We only collect data you voluntarily provide through the contact form: name, institution, email, phone and message. We do not collect data automatically, do not use tracking cookies and do not use third-party analytics.
3. Purpose and Legal Basis
Data is used exclusively to respond to your information request (legitimate interest / pre-contractual execution). We do not use data for marketing without express consent.
4. Your Rights
You have the right of access, rectification, erasure, restriction, portability and objection. Contact us at [email protected].
02General Data Protection Regulation (GDPR)
Last updated: September 2026
1. Data Controller
Amplified Creations, Lda., owner of the RVer brand, headquartered in Leiria, Portugal, is the data controller for personal data processed in the context of its B2B commercial activities. General contact: [email protected]
2. Data Protection Officer (DPO)
Pedro Thomaz · [email protected]
3. Scope — Data Processed by RVer
The RVer base product is a Class I medical device registered with Infarmed, I.P. under no. CDM 94571546, and bears the CE mark under Regulation (EU) 2017/745 (MDR). The device is supplied to healthcare institutions (hospitals, clinics), which act as data controllers for their patients' data. Amplified Creations, Lda. does not access, collect or process patient data under any circumstances.
Personal data processed directly by Amplified Creations, Lda. is limited to B2B contact information of clients and prospective clients: contact person name, professional email address, contract dates and healthcare institution. This data is used exclusively for managing the commercial relationship.
Usage statistics. The app sends usage statistics per device — which module and which content were opened, and for how long — linked to the device identifier and never to a person. These records contain no personal or clinical patient data and are used exclusively to improve the app and to help the institution manage its equipment.
Family video call. During a session, the institution can open a video call between the device and up to two family members, who join from a browser with a code (PIN). The call is live only: nothing is recorded. Camera audio and video travel directly between the participants over an encrypted connection. When a direct connection is not possible, they pass through a relay service that has no access to the content. To set up the connection, the devices query a public connection server (Google STUN), which sees only the network address. What the person sees in the headset is relayed in real time through our server to those on the call, and is not stored. To connect the call, the server temporarily keeps the room identifier, the PIN and the device identifier, deleted when the call ends or at most one hour later. A technical record that the room was created — by which device and when, with no names or content — is kept to prevent abuse and deleted after 90 days.
Patient assignment. In the Companion app, the team can link a session to a patient, by name or by a code of the institution's choosing — a name is not required. This information is stored only on the device itself and is never sent to RVer's servers. The institution is the data controller for it. When a device leaves an institution, at the end of a contract or to go to another client, it is factory reset and receives a fresh installation of the RVer app. All data it held, including patient names and codes, is erased, as if it were a new device.
4. Purpose and Legal Basis
Processing is carried out on the following bases:
- Performance of a contract (Art. 6(1)(b) GDPR) — to fulfil contractual obligations to clients;
- Legitimate interests (Art. 6(1)(f) GDPR) — to respond to information requests from prospective clients;
- Legal obligation (Art. 6(1)(c) GDPR) — where required by applicable legislation, including MDR 2017/745.
5. Cookies and Tracking
This website does not use tracking cookies, third-party analytics tools or any other mechanism for monitoring user behaviour.
6. Data Retention
Contact data of prospective clients is retained for the period necessary to handle the request, and for a maximum of 2 years after the last contact. Client data relating to active contracts is retained for the duration of the contract and for the legally required period thereafter.
7. Sharing with Third Parties
Data is not sold or shared with third parties for commercial purposes. It may be disclosed to subcontractors providing technological infrastructure services (e.g. hosting), who are contractually bound to comply with GDPR.
8. Data Subject Rights
Data subjects have the right to:
- Access their personal data;
- Rectification of inaccurate data;
- Erasure ("right to be forgotten"), where legally applicable;
- Restriction of processing;
- Data portability;
- Object to processing.
To exercise any of these rights, contact the DPO at [email protected].
You also have the right to lodge a complaint with the competent supervisory authority: Comissão Nacional de Proteção de Dados (CNPD) — www.cnpd.pt.
9. Security
We implement appropriate technical and organisational measures to protect data against unauthorised access, loss, alteration or destruction, in accordance with Art. 32 GDPR.
10. Regulatory Framework
Amplified Creations, Lda. operates in compliance with Regulation (EU) 2016/679 (GDPR), Regulation (EU) 2017/745 (MDR) and applicable national legislation.
