Privacy Policy
Last updated: June 28, 2026
1. Introduction
RbDevOps ("we," "our," or "us") operates the rb-devops.com website and related digital solutions. This Privacy Policy explains what information we collect, how we use it, and the choices you have. HM Praxis is a record-keeping tool for licensed professionals; RbDevOps is not a healthcare provider and does not access the patient records you keep in the software.
Local-first by design
Your business data lives on your device. We collect the minimum information needed to run your account and enforce your license. If you enable Pro sync, your devices share data directly with each other over your own local network; it does not pass through us.
2. Information we collect
2.1 Account information
When you create an account, we collect:
- Email address
- First and last name
- Password (stored as a secure hash, never in plain text)
- Organization or business name (if provided)
2.2 Billing information
Payments are processed by third-party payment processors. We store transaction references and subscription status. We do not store credit card numbers or bank account details.
2.3 License and device information
We collect:
- License activation records
- Device identifiers for license enforcement
- Application version information
2.4 Device-to-device sync (optional, Pro plan)
HM Praxis stores your business data, including all patient records, locally on your own device. We do not upload, store, or relay your business data on our servers. If you enable sync on a Pro plan, your devices exchange data directly with each other over your own local network (LAN); there is no cloud relay and nothing is sent to us.
Sync is opt-in and stays entirely on your local network. If you do not enable it, your data simply remains on the single device where it was entered. Either way, your business data does not leave your control.
3. How we use your information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process transactions and manage subscriptions
- Enforce license terms and prevent abuse
- Send service-related communications
- Respond to support requests
We do not sell your personal information to third parties.
4. Data security
We apply industry-standard security measures to protect the account, license, and billing information we hold. Your business data is not transmitted to or held by us. However, you acknowledge that:
- No method of transmission over the Internet is 100% secure
- You are responsible for maintaining the security of your account credentials
- We are not liable for unauthorized access resulting from the compromise of your credentials
5. Data retention
We retain your account information for as long as your account is active. Upon account deletion:
- Account data is anonymized or deleted within 30 days
- License activation and device records tied to your account are deactivated and unlinked
- Billing records may be retained as required by law
6. Your rights
You have the right to:
- Access your account information
- Update or correct your information
- Delete your account and the account records we hold
- Export your data
7. Third-party services
Our services may integrate with:
- PayPal: Payment processing for subscriptions, billed in US dollars and subject to its own privacy policy
- Google OAuth: Optional sign-in (subject to Google's privacy policy)
- Cloudflare: Content delivery and security services
- Resend: Transactional email delivery for account, billing, and support notifications (subject to its privacy policy)
8. Cookies and tracking
We use essential cookies for authentication and session management. We do not use third-party advertising or tracking cookies.
9. Children's privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.
11. Privacy notice for Mexico (LFPDPPP)
This section is the privacy notice (aviso de privacidad) required by Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares, "LFPDPPP"). It complements, and does not replace, the rest of this Privacy Policy.
Data controller (responsable)
The party responsible for the personal data we process is Reynaldo Barrera, persona física con actividad empresarial, operating as RbDevOps, with a domicile in the United Mexican States. For any privacy matter you may contact us at [email protected].
Data we process and purposes
We process your account data (name and email), your password as a secure hash, billing references and subscription status, and license and device records. We use this data to create and operate your account, to process payments and manage your subscription, to enforce your license and prevent abuse, and to provide support. Your patient and business records are stored locally on your own device and are never transmitted to or held by us.
Your ARCO rights
Under the LFPDPPP you have the following rights over your personal data, known as ARCO rights:
- Access - to know what personal data we hold about you and how we use it
- Rectification - to correct your data when it is inaccurate or incomplete
- Cancellation - to request that we delete your data when it is no longer needed
- Opposition - to object to our processing of your data for specific purposes
To exercise any ARCO right, email [email protected] from the address registered on your account and describe the right you wish to exercise and the data involved. We will respond within the timeframes set by the LFPDPPP. You may also withdraw your consent or limit the use of your data, and you may file a complaint with the National Institute for Transparency, Access to Information and Personal Data Protection (INAI).
Security measures and breach notification
We apply administrative, technical, and physical security measures designed to protect the account, license, and billing data we hold against loss, misuse, and unauthorized access. If a security breach materially affects your personal data, we will notify you without undue delay so that you can take steps to protect your interests.
Third parties and transfers
We rely on the following processors to operate the service: PayPal (payments), Google (optional sign-in), Cloudflare (content delivery and security), and Resend (transactional email). Each processes only the data needed for its function and under its own privacy commitments. We do not sell your personal data.
12. International users: GDPR and CCPA
If you access our services from the European Economic Area or the United Kingdom, the General Data Protection Regulation (GDPR) may apply to the limited account, license, and billing data we process, and we handle that data consistently with its principles. If you are a California resident, the California Consumer Privacy Act (CCPA) gives you rights to know, delete, and opt out of the sale of personal information; we do not sell personal information. Because your patient and business records are stored on your own device and never reach us, you act as the data controller for that information, and you remain responsible for your organization's own compliance obligations, including under the GDPR, the CCPA, and any health-data or privacy law that applies to your practice and the people you serve.
13. Contact us
If you have questions about this Privacy Policy, please contact us at:
Email: [email protected]
We use analytics cookies to understand how the site is used and improve the product. They stay off until you accept. Privacy notice