Muveya Privacy Policy
Effective date: · Version: 1.0
This Policy is written in English. The Spanish and Portuguese versions are translations; if they differ, the English version governs.
Last updated: September 21, 2026.
This Privacy Policy explains how Woku SpA processes personal data when providing Muveya. Muveya is a product of Woku, operated by Woku SpA, that lets dental clinics and dental networks manage their supply catalog, stock, internal orders and approvals, and the custody of deliveries between their sites, with a record of who did what.
1. Who we are and how to contact us
The controller for Muveya is Woku SpA, a company incorporated in Chile, domiciled at Calle 120 39 Dp 14 B, Hualpén, Chile 4600150 (in this Policy, "Woku", "we", or "our"). "Muveya" refers to the product and the services described in this Policy, not to a separate company. Terms such as Customer, Tenant, Clinic, Warehouse, User, and Plan are used here with the meaning given in the Terms of Service.
- General inquiries and support: [email protected]
- Privacy, data rights, and security: [email protected]
When a Customer uses Muveya to run its operations, that Customer determines the purposes for which the personal data in its Tenant is collected and used, such as the attribution of its staff in operational records and the patient references it enters. In that case, the Customer is the controller and Woku processes that data on the Customer's behalf as a processor, under the Data Processing Agreement. When we process data to administer accounts, authentication, security, support, or our own site, Woku acts as controller.
2. To whom and to which services it applies
This Policy applies to:
- people who visit
muveya.com; - owners, administrators, and members of a Muveya Tenant, and people invited to join one;
- people who request access, information, support, or a demonstration;
- people whose data appears in the records a Customer keeps in Muveya, such as staff named in orders, approvals, deliveries, or stock movements.
The organizations that use Muveya may have their own privacy policies. If you work for, or receive care from, an organization that uses Muveya, also review that organization's privacy notice.
3. Personal data we process
3.1 Account, identity, and Tenant membership
We may process:
- name, email address, and the language of account emails;
- email verification status, sign-in method (password or Google), and identity provider;
- memberships, roles, permissions, access to Clinics and Warehouses, invitations, and active Tenant;
- date of last sign-in.
We do not store your password or a hash of it in Muveya: authentication is managed by our identity provider, Stytch.
Information we receive from Google. If you choose Sign in with Google, we receive from Google, through Stytch, your email address, whether Google has verified it, and your name if your Google account provides one. Muveya requests only the basic openid, email, and profile permissions. We use this information only to authenticate you and to identify or create your Muveya account; if Google provides no name, we use the part of your email address before the "@" as your name. We do not receive or store Google access or refresh tokens, we do not call other Google APIs, and we do not use your profile photo or any other information from your Google account. Section 7 explains how this information is used and shared.
3.2 Security and technical data
We may process IP address, user agent, session identifiers, timestamps, access logs, administrative actions, errors, requests, and signals for the prevention of fraud or abuse.
Each console session record keeps the IP address and user agent from which the session was started, so that sessions can be recognized and revoked, until the session expires. To limit sign-in attempts, we store a hash that combines your email address with the network range of your IP address, not the address itself. Sensitive actions in a Tenant are recorded in audit records that identify who acted, the action, the resource, and the outcome.
The IP address may also be processed temporarily by our network and hosting providers, in security systems, in operational logs, or in rate limiting.
3.3 Operational data and Customer Data
A Customer and its Users may create or upload:
- photos of supply packaging that Users choose to send for assisted catalog entry, and the proposed fields they review;
- names of the Tenant and of its Clinics, Warehouses, and consumption destinations;
- catalog items, presentations, commercial codes and their issuers, categories, and costs;
- stock boxes with their lot, serial numbers, and expiry dates;
- stock movements, such as receipts, consumptions, transfers, adjustments, and counts, with the User who recorded them and, for corrections, the reason;
- internal orders, approval decisions, and their comments;
- dispatch, delivery, and receipt confirmations and their notes;
- catalog files imported in CSV format.
The Customer decides what data to include. It must not include personal or sensitive data that it is not authorized to process. Costs, order values, and patient references are removed on our servers before data reaches Users who lack the corresponding permission.
3.4 Patient and care references
An internal order may carry a patient reference, and a stock exit may carry a care reference. Both are opaque codes that the Customer takes from its own clinical or practice management systems; Muveya is not a clinical record. We protect them as follows:
- they are encrypted field by field (AES-256-GCM) before they are stored;
- they are shown only to Users with the permission to read patient references;
- they are excluded from application logs, exports, the public API, and MCP access.
The Customer must not enter patient names, national identification numbers (such as the Chilean RUT), diagnoses, clinical histories, or other identifying or clinical data in these references or in any free-text field. The free-text justification of an order is automatically checked against common identifier patterns; other free-text fields, such as comments and notes, are not checked.
3.5 Access requests
If you write to us to request access to Muveya, information, or a demonstration, we process the information you include in your message, such as your name, email address, and organization, to respond to you and follow up on your request. muveya.com has no contact or lead-capture forms.
3.6 No payment data during the pilot
During the pilot, the Service is free of charge. Muveya has no checkout, does not collect payment methods, and does not receive card or billing data. If paid Plans are introduced, we will announce them in advance and update this Policy before collecting any payment data.
3.7 Support and communications
We process the content of emails, requests, meetings, survey responses, and other messages you send us, together with the data necessary to respond and keep a record of the request.
We also send the account emails needed to use the Service: verification of your email address, including when you accept an invitation, setup of your first password, and invitations to join a Tenant. They are sent from [email protected] through Amazon SES, in the language of your account, and do not include costs or patient references.
These emails are operational communications, not marketing. Promotional communications not tied to your use of the Service require a separate legal basis and preferences.
3.8 Analytics
We do not use product analytics, advertising pixels, or third-party tracking tools in the Muveya console or on muveya.com. If we introduce analytics, we will update this Policy first and, where the law requires it, load it only after your consent.
The Android app uses Google ML Kit to read barcodes on the device. Google collects technical information about the device, app, installation, scanner events, errors, configuration, and performance for diagnostics and usage analytics. Barcode camera frames are processed on the phone; packaging photos deliberately sent for assisted entry follow section 6. See ML Kit data disclosure.
4. Where we obtain the data
We obtain data:
- directly from you or from the Customer that administers the Tenant, including when it invites you;
- from other Users of the Tenant, when they record operations in which you take part;
- automatically from browsers, devices, security systems, and technical logs;
- from Google, through Stytch, when you choose to sign in with Google;
- from the Customer's own systems, when it enters references or imports files, and from other sources that a Customer instructs us to process and for which it declares that it has authorization.
5. For what purposes and why we process data
The exact legal basis depends on the country and the relationship. When applicable law requires identifying it, we use the following:
| Purpose | Typical data | Typical legal basis |
|---|---|---|
| Create and administer accounts, Tenants, and access | Account, identity, membership, session | Performance of the contract and pre-contractual measures |
| Authenticate you with Google when you choose it | Email address, verification status, and name received from Google | Performance of the contract |
| Provide the catalog, stock ledger, orders, approvals, custody, counts, reports, CSV imports and exports, and read-only API access | Customer Data, operational records, configuration | Performance of the contract; Customer instructions when we act as processor |
| Protect the Service and prevent abuse or fraud | IP, hash values, session, device, logs, audit | Legitimate interest in security; legal obligations |
| Operate, diagnose, and improve reliability | Errors, technical metrics, logs | Legitimate interest, minimized and subject to objection where applicable |
| Respond to access requests, support, privacy, and incidents | Contact and communications | Performance of the contract, legitimate interest, and legal obligations |
| Comply with the law and defend rights | Data relevant to the obligation or claim | Legal obligation and the establishment, exercise, or defense of legal claims |
When we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out beforehand.
6. Artificial intelligence
Muveya can read photos of a supply's packaging to propose catalog fields, such as its name, brand, presentation, lot, and dates. When you choose this feature, we send the photos, the scanned barcode if present, and your interface language to OpenAI to produce the proposal. We do not add your account profile, other Tenant records, or patient references to this request. Photograph only the packaging, without people, prescriptions, patient labels, or other personal or clinical information.
- We do not use Customer Data to train or fine-tune models. OpenAI does not use API data for training by default; see its API data controls.
- The proposal can contain errors. You review and confirm the fields before saving; the model cannot approve orders or change stock.
- We store submitted packaging photos privately for traceability, including photos submitted before you finish creating the item. They are not automatically deleted after the response or if you cancel. Retention and deletion follow section 10 and the DPA.
- OpenAI may retain inputs and outputs under its standard API data controls. Muveya does not promise zero retention or processing exclusively in your country.
- Material changes to this feature or its providers follow the notice process in section 15 and the DPA.
7. With whom we share data
We may share data only when necessary with:
- Infrastructure and operations providers. These include, depending on the active service and the applicable role, Amazon Web Services (including Amazon SES for account email), MongoDB Atlas, Cloudflare, Stytch, and OpenAI for the photo feature in section 6. Annex III of the DPA identifies which of these act as subprocessors of Customer Data and their roles.
- Google sign-in and the Android scanner. If you choose to sign in with Google, Google receives the authentication request and shares with Stytch and Woku the data described in section 3.1. Google also receives the Android scanner diagnostics described in section 3.8 when the app uses ML Kit.
- The Customer and its Users. Within a Tenant, data is shown to its Users according to their roles, permissions, and access to Clinics. If the Customer creates API keys, its own systems can read its Tenant's data through the read-only API, limited to the permissions of each key.
- Authorities and advisors. When reasonably necessary to comply with a legal obligation, protect rights, investigate abuse, or establish, exercise, or defend legal claims.
- Corporate transactions. In a merger, acquisition, financing, reorganization, or sale, subject to confidentiality and applicable law.
Woku does not sell personal data, and it does not use personal data for behavioral advertising.
Use of information received from Google. We use the information we receive from Google only to authenticate you and to identify or create your Muveya account. We do not use it for advertising, we do not sell it, and we do not transfer it to others except to the service providers that help us provide the Service (Stytch and our hosting and database providers), when necessary to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you. People at Woku do not read it except when you ask us for support, for security purposes, or to comply with the law. We keep it while your account exists, and you can ask us to delete it as described in section 12. Muveya's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Cookies, local storage, and similar technologies
We use different technologies depending on the surface:
- Console: cookies strictly necessary for an opaque session (
__Host-muveya_session, not readable by JavaScript) and for CSRF protection (__Host-muveya_csrf), plus a temporary cookie (__Host-muveya_google, up to 10 minutes) while you sign in with Google. All of them areSecureandSameSite=Strict. The session has an absolute maximum of 30 days from sign-in and does not expire because of inactivity. The console also usessessionStorageto continue a sign-in or invitation and return you to the page you requested, andlocalStorageto remember your interface language. - muveya.com: no analytics, advertising, or tracking cookies. The site may set a functional
NEXT_LOCALEcookie to remember your language. - Sign in with Google: during the redirect, our identity provider and Google may set their own cookies under their policies.
This section is our cookie information; there is no separate cookie policy. You may delete cookies and site data at any time in your browser; without the strictly necessary cookies you will not be able to sign in to the console.
9. International transfers
Woku is located in Chile and uses providers that operate in the United States and other jurisdictions. As a result, data may be processed outside the country where you reside.
When applicable law requires it, we use recognized mechanisms, such as adequacy decisions, standard contractual clauses, transfer addenda, and technical or organizational supplementary measures. The public list of providers in Annex III of the DPA identifies the relevant locations for each service; network and security services may process traffic on a global network.
10. How long we retain data
We retain data only for as long as necessary for the purposes described, to comply with the law, resolve disputes, and enforce our agreements.
| Data | Period or criterion |
|---|---|
| Packaging photos | Stored privately for catalog traceability; no automatic expiration is configured, including for photos of an item whose creation was not completed. A valid deletion request follows the DPA |
| OpenAI inputs and outputs | Standard API retention applies, including abuse monitoring and any response storage; see the API data controls linked in section 6 |
| Console session, including the IP address and user agent it records | Up to 30 days from sign-in, without an inactivity timeout; expired records are deleted automatically |
| Android session records | No automatic expiration is configured. Sign-out or revocation ends access, and a disabled account cannot authenticate. Record deletion follows the applicable requests described in section 12 |
| Sign-in attempts | 24 hours after the last attempt, stored as a hash |
| Sign in with Google in progress | Up to 10 minutes, encrypted |
| Account, including the information received from Google | While the account exists; removing a member from a Tenant ends their access but does not delete their account |
| Memberships and roles | While the Tenant remains active or until the Customer changes them |
| Customer Data, including catalog, stock, orders, approvals, custody, and counts | While the Tenant remains active or until a valid deletion instruction, subject to the deletion process in the DPA; stock movements, approval decisions, and custody confirmations are not edited, and corrections are recorded as new compensating entries |
| Patient and care references | Encrypted, for the same period as the record that contains them |
| Security audit records | While the Tenant remains active; no automatic expiration is configured |
| Analytics export records | 7 days; their download links expire after 5 minutes |
| Catalog export download links | 5 minutes |
| Application logs | Configured retention: 30 days for Core and 14 days for the public site and console |
| Database backups | Retention depends on the active MongoDB Atlas backup configuration; contact us for the applicable schedule and rotation period |
When a piece of data must be retained due to a legal obligation or the defense of claims, it will be restricted to that purpose. Ending the pilot or ceasing to use the Service does not by itself delete a Tenant or an account; to request it, write to us as described in section 12.
11. Security
We apply technical and organizational measures proportionate to the risk in the operating production service. These measures include:
- encryption in transit on interfaces controlled by Woku and encryption at rest managed by the providers;
- opaque, revocable sessions stored as a hash;
- access control by role and permission, with access that can be limited to specific Clinics, and isolation between Tenants that denies access by default;
- field-level encryption of patient and care references;
- server-side removal of costs, order values, and patient references for Users without permission;
- private file storage and short-lived signed download links;
- secrets managed outside the code;
- limits on sign-in attempts and on the rate of requests to the public API;
- an optional second authentication factor with an authenticator app;
- application logs that redact credentials, cookies, request bodies, costs, and patient references.
No system is infallible. If you detect a vulnerability or possible incident, write to [email protected] and avoid including unnecessary personal data in the first message.
When Woku acts as controller and a security breach represents a risk that must be communicated, we will notify the affected people and the relevant authorities without undue delay and within the deadlines of applicable law. The communication will describe the known nature, the likely consequences, the measures taken, and the contact channel, and it may be delivered in phases if the investigation continues.
12. Your rights
Depending on your jurisdiction, you may have the right to:
- know whether we process your data and access it;
- correct inaccurate or incomplete data;
- request deletion, blocking, or restriction;
- object to certain processing;
- withdraw consent;
- receive data in a portable format where applicable;
- not be subject to a decision based solely on automated processing with legal or similar effects where the law limits it;
- file a complaint with the competent authority.
To exercise a right regarding your account or muveya.com, including the deletion of your account and of the information received from Google, write to [email protected]. We may request reasonable information to verify your identity and protect other people. We will acknowledge receipt and communicate the expected timeframe without undue delay; we will respond within the period that applies to your jurisdiction. Muveya has no self-service export or deletion of accounts: a person at Woku carries out each request by hand on the underlying systems, so when a request requires extracting or removing records we will tell you what that manual work involves and keep you informed until it is complete.
If your request concerns data held in a Customer's Tenant, such as your records as a member of a clinic's staff or a patient reference, contact that Customer first. If you write to us, we will forward or assist with the request according to the instructions and obligations of the responsible Customer, without disclosing data from another Tenant.
Chile's Law No. 19.628 currently governs. The amendments of Law No. 21.719, including new rules and rights, take effect on December 1, 2026; we have drafted this Policy with a view to that strengthened framework.
13. Minors and high-risk data
Muveya is a business service and is not directed at minors under 18. Customers must not enter identifying or clinical data about patients of any age beyond the opaque references described in section 3.4, nor deliberately collect data from minors or sensitive categories without an appropriate legal basis, controls, and specific agreement. If you believe we received a minor's data without authorization, write to [email protected].
14. Third-party links and services
muveya.com and the console may contain links to or integrations with third-party services, such as Sign in with Google. Their policies and practices belong to those third parties. Review their information before giving them data.
15. Changes to this Policy
We may modify this Policy to reflect changes in the Service, providers, or legislation. We will publish the updated version and date. When a material change adversely affects your rights, we will give at least 30 days' notice by email or within the Service, unless a legal, security, or emergency obligation requires acting sooner. We will request additional consent when the law requires it.
16. Contact and complaints
- Privacy and exercise of rights: [email protected]
- General inquiries: [email protected]
- Postal mail: Woku SpA, Calle 120 39 Dp 14 B, Hualpén, Chile 4600150
If you are not satisfied with our response, you may turn to the data protection authority or competent court of your jurisdiction.