1. Who the controller is
Psynthia is a service of [RAZÓN SOCIAL DEL TITULAR DE PSYNTHIA], with tax ID (NIF) [NIF] and registered address at [DOMICILIO SOCIAL] (“Psynthia”, “we”). For any privacy matter you can write to us at privacy@psynthia.app.
Psynthia is a tool for psychology professionals: practice management, session recording and transcription, artificial intelligence assistance, reports, scheduling and bookings. This policy explains what data we process, for what purposes, on what legal basis, with whom we share it, how long we keep it and how to exercise your rights.
2. Two different roles: controller and processor
We are the controller of the data of the people who register on Psynthia (professionals and members of their practice) and of visitors to our website: account, billing, support and use of the service. This policy governs that processing.
Patient data (record, sessions, audio, transcripts, notes, reports, appointments, consents and reviews) is processed by each professional or practice as controller. Psynthia only processes it on their behalf, as processor, following their instructions and the data processing agreement (art. 28 GDPR) published at /legal/dpa. If you are a patient and wish to exercise your rights, contact your professional; if you write to us, we will forward your request to them.
3. What data we process as controller
Depending on how you use Psynthia, we process:
- Account data: name, email address, password (encrypted; we never see it), language, time zone, professional details you add to your profile and, if you enable two-step verification, its configuration.
- Practice data: practice name, members, roles and invitations.
- Billing data: plan, subscription, credits and invoices. Card details are collected and stored by Stripe; we do not see them.
- Usage data: technical access and error logs, consumption of AI and transcription credits, and product usage milestones (for example, completing registration, creating the first patient or the first recording) that we measure in our own database to improve the service.
- Communications: the messages you send to support.
- Website browsing data: as described in the cookie policy (/legal/cookies).
4. Purposes and legal bases
We process that data to:
- Provide the service to you, manage your account and your practice and handle support: performance of the contract (art. 6.1.b GDPR).
- Charge the subscription and credits and issue invoices: performance of the contract and compliance with legal tax and accounting obligations (art. 6.1.c GDPR).
- Maintain the security of the service, prevent abuse and fix errors: legitimate interest (art. 6.1.f GDPR).
- Measure, in aggregate, how the product is used in order to improve it: legitimate interest. The figures we analyse are counts by registration cohort, without clinical data.
- Send you operational communications about the service (changes to the terms, security notices, billing): performance of the contract. We do not send advertising without your consent.
- Set non-technical cookies: only with your consent, which you may withdraw at any time.
5. Patient health data
Patient data are special categories of data (art. 9 GDPR). The professional, as controller, is the one who decides to process them and who must have a legal basis for doing so (normally, the provision of health care, art. 9.2.h GDPR) and, to record sessions, the patient's consent, which Psynthia helps them collect and record.
Psynthia only uses that data to provide the service to the practice: it does not sell it, does not use it for advertising or to train artificial intelligence models, and does not combine it with data from other practices. Artificial intelligence processes clinical text only when the professional requests it (assistant, summaries, notes, reports) and always on servers in the European Union.
6. With whom we share data
We do not sell personal data. To provide the service we rely on providers acting as processors (or sub-processors), under contract and with appropriate safeguards. The complete list, with the function of each one, the data it receives and where it processes it, is published and kept up to date at /legal/subprocessors. In summary:
- Supabase (database, authentication and files): European Union (Ireland).
- Google Cloud Vertex AI (artificial intelligence models): European Union.
- Stripe (payments): European Union, with possible transfers to the US.
- ElevenLabs and Deepgram (transcription of session audio), Resend (email), Netlify (website hosting) and Sentry (error logging): United States.
- Google Calendar: only if the professional enables synchronisation.
7. International transfers
Some providers process data outside the European Economic Area, in the United States. Those transfers are covered by the EU-US Data Privacy Framework, where the provider has signed up to it, or by the standard contractual clauses approved by the European Commission, with the supplementary measures that apply. You can ask us for a copy of those safeguards by writing to privacy@psynthia.app.
Artificial intelligence processing of clinical text (assistant, summaries, notes and reports) takes place exclusively in the European Union. Audio transcription is currently carried out by United States providers with the safeguards indicated.
8. How long we keep data
We keep each item of data only for as long as necessary:
- Account and practice data: while the account is active. When you close it, they are permanently deleted together with all the practice's patient data; anything remaining in the service's systems is erased within a maximum of 30 days from the end of the contract.
- Session audio: according to each practice's retention settings (keep it, delete it after a number of days or delete it when the report is generated). Deleting a session or a patient deletes its audio.
- Invoices and billing data: the period required by tax and commercial law (generally, 4 to 6 years).
- Deletion log: when a patient, a session or an account is deleted we keep a record that the deletion took place, who requested it and when, without names or clinical content (only internal identifiers and counts), for 5 years, in order to be able to demonstrate compliance (art. 5.2 GDPR).
- Technical and error logs: for the period each provider keeps them, at most a few months.
9. Backups
Psynthia does not currently make its own scheduled backups of the database or files, beyond the redundancy of the provider's infrastructure. We therefore recommend that you regularly export the data you need to keep: Psynthia lets you download a ZIP per patient with their record, sessions, transcripts, audio and reports. We will update this policy when we introduce managed backups.
10. Security
We apply technical and organisational measures appropriate to health data: encryption in transit (HTTPS) and at rest, isolation of each practice's data in the database through row-level security policies, two-step verification for accounts, role-based permissions within the practice, temporary links for downloading files and error logging without request bodies, cookies, IP addresses or on-screen text. If a security breach affecting your data were to occur, we will notify the supervisory authority and, where appropriate, the affected individuals, within the time limits set by the GDPR.
11. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw at any time any consent you have given, by writing to privacy@psynthia.app. We will respond within one month. You can exercise many of them yourself from the application: editing your profile, exporting your patients' data or closing your account.
If you believe we have not handled your request properly, you can lodge a complaint with the Agencia Española de Protección de Datos (Spanish Data Protection Agency) (www.aepd.es).
12. Minors
Psynthia is intended for professionals and does not allow minors to register. Data of minor patients is processed by the professional as controller, with the consent of their legal representatives where necessary.
13. Changes to this policy
If we change this policy in a material way we will notify you by email or in the application before the change takes effect. The date of the last update appears at the beginning of the document.