Legal
How Talvos collects, uses, protects and discloses personal data — written to meet our obligations under Singapore's Personal Data Protection Act 2012.
Last updated 19 September 2026 · Effective 26 July 2026
This policy is issued by Talvos ("Talvos", "we", "us"), a company incorporated in Singapore (UEN: 202615434K), with its registered office at 60 Paya Lebar Road, #6-28, Paya Lebar Square, Singapore 409051. Talvos develops and operates Vera, an AI-powered voice and messaging reception service for healthcare clinics.
This policy explains how we handle personal data in connection with our website at talvos.co, our sales and support activities, and the Vera service itself.
The Personal Data Protection Act 2012 ("PDPA") distinguishes between an organisation that decides how personal data is used and a data intermediary that processes it on another organisation's behalf. Talvos operates in both roles, and which one applies changes your rights and who you should contact.
| As an organisation | For people who visit talvos.co, request a demo, or correspond with us, Talvos determines how that personal data is used. This policy governs it directly. |
|---|---|
| As a data intermediary | For patients of a clinic that uses Vera, the clinic is the organisation responsible for the personal data. Talvos processes it only on that clinic's documented instructions, under a written agreement. The clinic's own privacy policy governs how patient data is used, and patient requests should be directed to the clinic in the first instance. |
When a clinic engages Vera, we process personal data about that clinic's patients and staff, strictly as needed to answer and route enquiries and to schedule appointments. Depending on how the clinic configures the service, this may include:
The reason a patient gives for an enquiry may amount to health information. We treat all such data as confidential and restrict access to what the reception function requires. Vera does not provide diagnosis, triage or clinical advice, and is not designed to build a clinical record.
We use personal data for the following purposes, and no others without your consent:
We do not sell personal data, and we do not use patient data to advertise to patients.
Where we rely on your consent, you may withdraw it at any time by contacting us using the details in section 14. We will act on a withdrawal request within a reasonable period and tell you the likely consequences — for example, we cannot continue responding to a demo request once you withdraw consent to be contacted.
For patients of a clinic that uses Vera, consent for the handling of patient data is obtained and managed by that clinic as part of its own privacy practices. Withdrawal requests should be sent to the clinic, which may instruct us accordingly.
Patient data processed through Vera is hosted entirely in Singapore. It is not transferred out of Singapore in the ordinary course of providing the service.
Each clinic is provisioned with a dedicated, logically isolated database. One clinic's data is not commingled with another's, and access is governed by role-based controls.
If a transfer of personal data outside Singapore ever becomes necessary, we will comply with the Transfer Limitation Obligation under the PDPA, ensuring the recipient is bound to a standard of protection comparable to that under the Act, and we will inform affected customers in advance.
We cease to retain personal data, or remove the means by which it can be associated with an individual, as soon as it is reasonable to assume that the purpose for collecting it no longer applies and retention is no longer necessary for legal or business purposes.
We make reasonable security arrangements to protect personal data in our possession or under our control against unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks. These include:
No method of transmission or storage is completely secure. If a data breach occurs that results in, or is likely to result in, significant harm to affected individuals or is of a significant scale, we will notify the Personal Data Protection Commission and affected parties as required under the PDPA, and we will support our clinic customers in meeting their own notification obligations.
Under the PDPA you may:
Send requests to our Data Protection Officer using the details in section 14. We will respond within 30 days where reasonably possible, and will tell you if we need longer. We may need to verify your identity first, and a reasonable fee may apply to an access request as permitted under the PDPA.
If you are a patient of a clinic that uses Vera, please direct your request to that clinic. As a data intermediary we are required to act on the clinic's instructions, and the clinic is best placed to identify your records across its systems. We will support the clinic in responding to you.
Our website and the Vera service are directed at clinics and healthcare organisations, not at children. Where a clinic uses Vera in connection with the care of a patient under 13, the clinic is responsible for obtaining consent from a parent or guardian in accordance with the PDPA and its own policies.
We may update this policy from time to time to reflect changes in our services, our practices, or the law. The date at the top of this page shows when it was last revised. Where a change materially affects how we handle your personal data, we will take reasonable steps to notify you — for our clinic customers, through the contact details on the account.
We have appointed a Data Protection Officer responsible for overseeing our compliance with the PDPA. For any question, request or complaint about personal data:
If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission of Singapore at pdpc.gov.sg.