Privacy Policy
Effective date: 3 July 2026 · Version 1.0
Public legal document
| Platform operator | Phai Tech LLC |
| Jurisdiction | New Jersey, USA |
| Registration number | 0451256721 |
| Registered office | 475 Wall St, Princeton, NJ 08540 USA |
| Website | https://phai.tech |
Contents
- Scope
- Who controls your personal data
- Health data and the Salventia advisor
- Personal data we collect
- How we obtain personal data
- Purposes and legal grounds
- Data about other travellers
- Providers and payment processing
- Who receives personal data
- AWS hosting and international processing
- Security
- Retention
- Service communications and no direct marketing
- Cookies and similar technologies
- Automated tools and ranking
- Children
- Your rights
- Complaints and supervisory authorities
- Changes to this Policy
- Contact
1. Scope
This Privacy Policy applies to personal data processed through the Salventia website, applications, booking interfaces, Account functions, the Salventia advisor, customer support, email and telephone channels, and other services that link to this Policy.
A Provider may process personal data independently when supplying its own services. The Provider’s privacy notice also applies to that processing.
2. Who controls your personal data
Phai Tech LLC, incorporated in New Jersey, USA, registration number 0451256721, with registered office at 475 Wall St, Princeton, NJ 08540 USA, operates Salventia and is the controller of personal data used to provide the Platform Services described in this Policy.
Privacy enquiries and rights requests may be sent to dpo@salventia.com.
3. Health data and the Salventia advisor
The Salventia advisor helps you find suitable recovery, rehabilitation and wellness programmes. To personalize its guidance, it stores and processes health data that you provide: health facts you enter — such as diagnoses, allergies, contraindications, requirements and care preferences — and information extracted from documents you upload, such as discharge summaries and lab reports.
Legal basis — your explicit consent. We process this health data only on the basis of your explicit consent. Before the advisor processes any health data, we ask for two consents — Health-data processing and Cross-border processing — recorded against this policy version. Publishing a new policy version re-requests your consent.
Review before effect. Health facts we extract from your documents are shown to you for review and have no effect on your guidance until you confirm them. Direct personal identifiers are redacted before any document text is sent to a language-model provider.
You stay in control. You can withdraw either consent at any time from your profile. Withdrawal stops new advisor sessions and processing of newly uploaded documents immediately, and previously produced advisor results are removed as described in Section 12. Withdrawing consent does not by itself delete your Account.
Outside the advisor. Provide health information only through the advisor and document-upload features designed for it, or directly to a Provider through a Provider-controlled channel. Do not enter health information in unrelated fields such as search filters, booking notes or general support messages, which are not intended for it.
4. Personal data we collect
| Category | Examples |
|---|---|
| Identity and contact data | Name, surname, email address, telephone number, country and preferred language. |
| Account data | Account identifier, login and security records, preferences and saved items. |
| Health data and documents | Health facts you provide to the advisor (diagnoses, allergies, contraindications, requirements and care preferences), medical documents you upload (for example discharge summaries and lab reports), and the health facts we extract from them. Processed only with your explicit consent (Section 3). |
| Search and preference data | Destination, dates, budget, accommodation type, language, diet, accessibility and other non-medical preferences. |
| Booking data | Provider, programme, dates, guests, price, status, requests and confirmation details. |
| Transaction data | Amount, currency, payment status, masked reference and transaction identifier. Salventia does not collect or store full card details or CVV/CVC. |
| Support and communications | Messages, complaint details, call metadata and call recording where you are notified before recording. |
| Review data | Rating, review text, display name, image and moderation history. |
| Device and usage data | IP address, browser, operating system, device identifiers, language, timestamps, pages viewed, referrals and error logs. |
| Security and fraud data | Login attempts, suspicious activity, technical logs and information required to protect Users, Providers and the Platform. |
5. How we obtain personal data
- Directly from you when you create an Account, search, submit a Booking Request, communicate with us or leave a review.
- Directly from you when you provide health facts to the advisor or upload documents to your profile (Section 3).
- From another person who makes a Booking for you.
- From a Provider or payment processor in connection with availability, confirmation, payment status, changes, cancellation or a complaint.
- Automatically from your device, browser and use of the Platform.
- From permitted business partners or referral channels where they direct you to Salventia and have a lawful basis to share the data.
6. Purposes and legal grounds
The exact legal ground depends on the applicable law. We rely on performance of a contract or steps requested before a contract, consent where the law requires it, compliance with legal obligations, protection of legal rights, and legitimate business interests where those interests are permitted and do not override your rights. Health data is processed only on the basis of your explicit consent (Section 3).
| Purpose | Why we process |
|---|---|
| Operate Accounts and Platform functions | Provide requested services; protect Account security. |
| Provide the Salventia advisor and personalize recommendations | Your explicit consent to store and process the health data you provide (Section 3). |
| Read and extract facts from documents you upload | Your explicit consent; suggested facts take effect only after you confirm them. |
| Search, compare and process Booking Requests | Take steps at your request and perform Platform Services. |
| Confirm and administer Bookings | Perform contractual and pre-contractual obligations. |
| Arrange or verify payments | Perform the Booking, maintain financial records and prevent fraud. |
| Customer support and complaints | Perform Platform Services, resolve disputes and protect legal rights. |
| Platform security and fraud prevention | Legal obligation or permitted legitimate interest in security and abuse prevention. |
| Analytics and service improvement | Consent where required; otherwise permitted operational interests using proportionate data. |
| Reviews and moderation | Provide review functionality, protect content integrity and comply with law. |
| Legal and regulatory compliance | Comply with accounting, tax, consumer, court and regulatory obligations. |
Where applicable law requires consent, we will request it before the relevant processing begins. You may withdraw consent for future processing, but withdrawal does not affect processing that was lawful before withdrawal.
7. Data about other travellers
If you provide personal data about another traveller, you confirm that you are authorised to do so, that the information is accurate and that you have informed the person about this Privacy Policy.
Provide health information about another person only where you are authorised to act for them. A parent or legal guardian must provide information for a person under 18.
8. Providers and payment processing
We share the personal data needed to request, confirm and administer a Booking with the selected Provider. A Provider normally acts as an independent controller for its use of that data to supply the Provider Service, comply with law and manage its relationship with you.
Where payment details are required, they are entered directly into an interface controlled by the Provider or its payment processor. Salventia does not collect or store the full card number, CVV/CVC or other sensitive authentication data. We may receive limited transaction information needed to confirm payment and manage the Booking.
9. Who receives personal data
- The Provider selected for your Booking and, where necessary, its authorised booking or operational partners.
- Language-model and AI processing providers used to extract facts from documents you upload and to generate advisor guidance. Direct personal identifiers are redacted before document text is sent to a language-model provider.
- Payment processors and banks involved in a transaction.
- Amazon Web Services and other hosting, database, security and backup providers.
- Customer-support, email-delivery, communications and CRM providers.
- Analytics and performance providers, but only in accordance with the Cookie and Similar Technologies Policy and applicable consent requirements.
- Professional advisers, auditors and insurers under confidentiality obligations.
- Courts, regulators, law-enforcement bodies and public authorities where disclosure is legally required or necessary to protect rights and safety.
- A buyer, investor or successor in a genuine corporate transaction, subject to appropriate confidentiality and legal safeguards.
We do not sell personal data, and we do not use your health data for advertising. At this stage, we do not use contact information for direct marketing by Salventia or allow Providers to use Booking data for their unrelated marketing unless you separately agree directly with the Provider.
10. AWS hosting and international processing
Salventia uses Amazon Web Services (“AWS”) and maintains segregated, country-specific data environments for GCC markets. The underlying AWS deployment may use an AWS Region, Local Zone or other AWS infrastructure serving the relevant country, depending on service availability and the technical architecture implemented for that market.
Where the advisor processes your health data, that processing — including any cross-border transfer needed to deliver it — is covered by your Cross-border processing consent (Section 3). Where intra-GCC adequacy applies, processing remains within the region.
Personal data is not routinely combined across country environments. Limited remote access or processing from another country may occur for security, maintenance, customer support, disaster recovery, legal compliance or use of an authorised service provider.
Where personal data is transferred or remotely accessed across borders, we apply the mechanisms required by applicable law, which may include a transfer assessment, contractual safeguards, consent, regulatory approval or another legally recognised basis. We also limit data to what is necessary and restrict access by role.
Further details about the applicable hosting location and key subprocessors may be provided through the Platform or on request, subject to security and confidentiality constraints.
11. Security
We use technical and organisational measures appropriate to the nature of the data and the risks, including access controls, role-based permissions, encryption in transit and where appropriate at rest, logging, secure development practices, backup controls, vulnerability management and staff confidentiality obligations. Uploaded documents and health data are stored encrypted.
No online service can guarantee absolute security. You should use a strong unique password and promptly report suspected unauthorised access.
If a personal-data breach creates a risk requiring notification, we will notify the competent authority and affected persons within the period required by applicable law.
12. Retention
We retain personal data only for as long as necessary for the purpose for which it was collected and for applicable legal, accounting, security and claims periods. We then delete, anonymise or securely isolate it.
| Data type | Retention approach |
|---|---|
| Health data and advisor results | Kept while your Account is active and your consent is maintained. When you withdraw consent, new processing stops immediately and previously produced advisor results are removed through our erasure process; uploaded documents are retained only as long as needed for the purposes above or as required by law. |
| Unconfirmed Booking Requests | Normally up to 12 months, unless needed for a complaint, fraud review or legal obligation. |
| Account data | While the Account is active and for a limited period after closure to complete deletion, prevent fraud and resolve claims. |
| Confirmed Booking and transaction records | For the period required by applicable tax, accounting, consumer and limitation laws. |
| Support communications | For the period needed to resolve the matter and manage potential claims; longer where a dispute is active. |
| Call recordings | For a limited quality and evidence period disclosed when recording, unless needed for an active complaint or legal matter. |
| Security logs | For a proportionate security period based on the risk and the purpose of the log. |
| Backups | Until overwritten under the applicable backup-rotation schedule, with access restricted to recovery and security purposes. |
13. Service communications and no direct marketing
We use contact details to send communications necessary to provide the Platform Services, such as verification, Booking status, payment notices, changes, reminders, security alerts and responses to support requests.
Salventia does not currently send promotional newsletters, direct-marketing messages, promotional SMS or marketing calls. Creating an Account or making a Booking does not subscribe you to marketing.
If direct marketing is introduced later, we will update this Policy and implement any separate notice, consent and opt-out mechanism required by applicable law before using your details for that purpose.
14. Cookies and similar technologies
The Platform uses cookies and similar technologies as described in the Cookie and Similar Technologies Policy. Strictly necessary technologies may operate without optional consent where permitted. Optional analytics, functional or advertising technologies are used only when activated and where any legally required consent has been obtained.
15. Automated tools and ranking
We use algorithms and automated tools to organise search results, detect fraud, improve the Platform and — with your explicit consent — to process the health data and preferences you provide so the advisor can suggest suitable Provider Services. These tools do not diagnose, prescribe treatment, provide medical advice or assess medical suitability.
Salventia does not currently make solely automated decisions through the Platform that produce legal or similarly significant effects on Users. If such functionality is introduced, we will provide the disclosures and review rights required by applicable law.
16. Children
The Platform is intended for adults aged 18 or over. We do not knowingly allow a person under 18 to create an independent Account or enter into a Booking.
A parent or legal guardian may include a child in a Booking and provide the limited information needed for that Booking. If we learn that personal data was collected from a child without appropriate authority, we will take reasonable steps to delete or regularise it.
17. Your rights
Depending on the law that applies to you, you may have the right to:
- Obtain information about processing and request access to personal data.
- Correct inaccurate or incomplete personal data.
- Request deletion where there is no overriding legal reason to retain the data.
- Request restriction or suspension of certain processing.
- Object to processing in circumstances recognised by applicable law.
- Receive certain data in a portable format where the law provides that right.
- Withdraw consent for future processing where processing is based on consent, including the Health-data processing and Cross-border processing consents.
- Request human review of a qualifying automated decision if such decisions are introduced.
- Complain to the competent supervisory or regulatory authority.
You can withdraw your Health-data processing or Cross-border processing consent yourself at any time from your profile; you can also contact dpo@salventia.com to exercise any right. Include your country of residence and enough information to identify the relevant Account or Booking. We may request proportionate identity verification. We will respond within the period required by applicable law.
A request may be limited or refused where the law permits, for example to protect another person’s rights, preserve legal privilege, prevent fraud or comply with a retention obligation. We will explain the reason where legally required.
18. Complaints and supervisory authorities
Please contact dpo@salventia.com first so that we can investigate a privacy concern. You may also complain to the competent authority in the country whose data-protection rules apply to the processing, including the relevant authority in the United Arab Emirates, Saudi Arabia, Qatar, Bahrain, Kuwait or Oman.
Nothing in this Policy limits your right to use a court, consumer-protection process or regulatory procedure available under mandatory law.
19. Changes to this Policy
We may update this Privacy Policy to reflect changes in law, technology, Providers or Platform operations. The updated version will show its effective date. We will provide additional notice before a material change takes effect where required by law.
20. Contact
The Salventia platform is operated by Phai Tech LLC, incorporated in New Jersey, USA, registration number 0451256721, with registered office at 475 Wall St, Princeton, NJ 08540 USA.
Privacy and data protection enquiries: dpo@salventia.com.
Customer support: support@salventia.com.
Home · Terms & Conditions · Cookie Policy · Cancellation & Refund Policy · Cookie Settings