← Back to the English overview

Privacy policy

Version 1.5 · in force since 5 August 2026

Detailed information on the processing of personal data at VinculAI, in accordance with article 13 of Regulation (EU) 2016/679.

This is a courtesy translation for information only. The service is provided in Spain, in Spanish, and the Spanish version of this document is the only one with legal effect. In the event of any discrepancy, the Spanish text prevails. The application interface is available in Spanish only.

1. First things first: VinculAI wears two hats

This is the distinction that orders everything else, and it is worth understanding before you read on.

For your account data, we are the Controller

Your sign-up, your email address, your practice’s details, your billing with us, the security logs and who visits our website. All of that we decide ourselves, and that is what this policy is about.

For your patients’ data, we are only the Processor

Appointments, the clinical record, session notes, messages and documents belong to your patients, and you are the Controller of that data —the professional or the practice—. We only process it following your instructions, and that is governed by the data processing agreement, not by this policy.

One practical consequence follows: if you are a patient and you want to exercise your rights, you have to contact your psychologist or your practice, not us. We explain it in more detail in the patient privacy notice.

We never use your patients’ data for our own purposes: not for product statistics, not for marketing, and not for training artificial intelligence models.

2. Who the Controller is

  • Controller: Raúl Ríos Beiro (VinculAI)
  • Registered address: Avenida Hermanos Machado 135, 46025 Valencia, España
  • Contact: privacidad@vinculai.com · +34 680 476 385

No data protection officer has been appointed for the time being. If one is appointed, their contact details will be published here and notified to the Spanish Data Protection Agency (AEPD) within ten days, as required by article 34.3 of Spanish Organic Act 3/2018 (LOPDGDD).

3. What we process, what for and on what legal basis

Everything that follows refers to the data for which we are the Controller (section 1).

What forWhat dataLegal basis
Signing you up, maintaining your account, giving you support and providing you with the serviceName, email address, password (stored encrypted), telephone number, details of your practice and of your teamPerformance of the contract (article 6.1.b GDPR)
Charging you for the subscription and keeping our accountsTax details, amounts, the transaction identifier at the payment gatewayLegal obligation (article 6.1.c GDPR; the Spanish Commercial Code and the Spanish General Tax Act)
Keeping the service secure: access logs, abuse detection, usage limits and backupsUser identifier, IP address, timestamps, browser typeLegitimate interest (article 6.1.f GDPR): protecting the platform and the health data it holds against improper access and abuse
Telling you about service changes, incidents and relevant newsName and email addressPerformance of the contract (article 6.1.b GDPR)
Sending you commercial information about similar products, if you are already a clientName and email addressLegitimate interest (article 6.1.f GDPR) under article 21.2 of Spanish Act 34/2002. You can object free of charge in every message
Sending you commercial information if you are not a client yetName and email addressYour consent (article 6.1.a GDPR), which you can withdraw
Measuring use of the public websites with analyticsIP address, browsing, cookie identifierYour consent (article 6.1.a GDPR and article 22.2 of Spanish Act 34/2002). See section 10

Providing the sign-up details is necessary in order for us to provide you with the service: without them we cannot create the account or issue you an invoice. The rest is voluntary, and not providing it has no consequence beyond not receiving that particular communication.

4. Patients’ health data

Data concerning health is special category data (article 9.1 GDPR) and its processing is prohibited unless an exception applies. In a psychology practice the usual exception is article 9.2.h —the provision of health care pursuant to a contract with a health professional— together with article 9.3, which requires the processing to be carried out by a professional subject to the obligation of professional secrecy, or by someone under their responsibility.

Establishing and documenting that exception is for the practice or the professional, who is the Controller. We do not need a legal basis of our own for that data: our legitimacy is derived and arises from the data processing agreement (article 28 GDPR).

What we do take on are the measures: clinical notes and messages are encrypted at application level with AES-256-GCM before being stored, session notes are accessible only to the treating professional, each practice is isolated from every other in the database itself, and no health data ever appears in technical logs.

5. Artificial intelligence

VinculAI uses artificial intelligence models to structure and format notes, for the management and booking assistant, and to read expense invoices. It is worth being precise about what that involves.

  • Only what is asked for in each request is sent: the specific text to be formatted or the specific question put to the assistant. Neither the database nor the clinical record is sent across.
  • The data is not used to train models. The provider’s commercial terms expressly prohibit it, and we pass that on as a contractual obligation.
  • The output of the artificial intelligence is a draft. The professional reviews it, corrects it and signs it: authorship of and responsibility for the clinical record remain theirs.
  • We take no automated decisions producing legal effects or significantly affecting anyone, within the meaning of article 22 GDPR. There is no profiling of patients and no scoring that shapes access to the service.
  • Voice dictation does not store the audio at any point. That feature is currently switched off.

If we ever introduced something that did fall within article 22 —an automated prediction that shaped a booking, for example—, we would say so here expressly, we would explain the logic applied and its consequences, and we would offer the right to human intervention and to contest it.

6. Who we share data with

We do not sell data and we do not disclose it to third parties. We do rely on providers that process it on our behalf —sub-processors—, with a processing agreement and the same obligations we take on ourselves. This is the complete and current list:

ProviderWhat forWhat it receivesWhere
SupabaseDatabase, authentication and file storageAll application data. Clinical notes, messages and file names travel and are stored encrypted at application level; the provider cannot read them.Database in Paris (France). Contracting entity: Supabase Pte. Ltd (Singapore)Outside the EEA, with safeguards
Hetzner Online GmbHServers on which the application runsEverything that passes through the application, in transit and in memory.GermanyEuropean Economic Area
Anthropic PBCArtificial intelligence modelsOnly the text the professional chooses to send with each request (a note to be formatted, a query to the management assistant, a supplier invoice to be read). The database is not sent, and none of this is used to train models.United StatesOutside the EEA, with safeguards
8x8 (Jitsi as a Service)Video consultationThe participant's first name, room identifier, IP address and connection metadata. Audio and video travel encrypted and are NEVER recorded under any circumstances.European Union (Frankfurt) by preferenceOutside the EEA, with safeguards
Brevo (Sendinblue SAS)Transactional emailName, email address, the content of the notice and any documents attached to it (a receipt, for example). Its open and click tracking cannot be switched off.FranceEuropean Economic Area
StripeCard paymentsThe payer’s email address and the amount. The description is always generic («Session», «Session deposit», «Balance of the session»): the name of the service booked never leaves the platform.Ireland, with processing in the United States by its groupOutside the EEA, with safeguards
PayPalPayPal paymentsThe payer’s email address and the amount, with the same generic description as above.Luxembourg, with processing in the United States by its groupOutside the EEA, with safeguards
GoogleSign-in with Google (for the team and, if they choose it, for the patient) and optional Google Calendar synchronisationThe email address of the account used to sign in. Only the patient’s INITIALS and the time are written to the calendar: no full name, no reason for the visit, no description and no guests.European Union and United StatesOutside the EEA, with safeguards
Proveedores de notificaciones pushDelivery of notices to the browser or the phone (Google, Mozilla, Apple)The technical address of the browser and the time of sending. The content of the notice travels end-to-end encrypted: the provider cannot read it.GlobalOutside the EEA, with safeguards
Microsoft (Azure Speech)feature currently switched offTranscription of dictated notesAudio of the professional’s voice. The audio is never stored.European UnionEuropean Economic Area

Providers that receive no personal data

  • Europe PMC (EMBL-EBI, United Kingdom). Scientific literature search. Only abstract clinical terms are sent, never patient identifiers. The United Kingdom benefits from a European Commission adequacy decision, renewed on 19 December 2025.

One exception, and it is worth understanding it properly: paying for your subscription. When you pay for your own VinculAI subscription, Stripe does not act on our behalf: it processes your payment data as an independent Controller, in order to meet its own legal obligations (payment services and the prevention of money laundering). That is your data as the Client —never your patients’ data— and that part is governed by Stripe’s privacy policy, not by this one. It is a different thing from charging your patients, where Stripe does appear above as a sub-processor.

We also disclose data where the law requires it: to the tax authorities, to judges and courts, to the public prosecutor and to any competent authorities that request it.

Assistants you connect yourself. If you connect an external assistant to your account through our MCP server, that assistant will receive the data you ask it for. That connection is your decision, and whatever processing the assistant carries out is beyond our control; that is why we only accept clients from expressly authorised origins, and you can revoke access at any time.

7. Transfers outside the European Union

The database, the servers and the email are in the European Union. Some of the providers in the table above process data outside the European Economic Area (EEA); in those cases the transfer relies on the safeguards in article 46 GDPR:

  • Supabase. European Commission standard contractual clauses (Decision 2021/914), modules two and three, under Irish law and jurisdiction. The database is hosted in the European Union; support, monitoring and account communications may involve group providers outside the European Economic Area.
  • Anthropic PBC. European Commission standard contractual clauses (Decision 2021/914), modules two and three, incorporated into its data processing agreement.
  • 8x8 (Jitsi as a Service). Standard contractual clauses incorporated into the European supplement to its terms. Routing is requested within the European Union, but in the event of a network incident the connection may be established through another region.
  • Stripe. Article 46 GDPR safeguards provided for in its data processing agreement.
  • PayPal. Article 46 GDPR safeguards provided for in its data processing agreement.
  • Google. Listed here for transparency, although Google does NOT act on the Processor’s behalf: when signing in it is the user who authenticates with Google, and in the calendar it is the professional’s own Google account —authorised by them, and revocable by them— that receives the data. In both cases the processing is governed by that user’s relationship with Google and by the Google API terms the Processor accepted when registering the application. Calendar synchronisation is OPTIONAL: until the professional switches it on, no data leaves for Google by this route.
  • Proveedores de notificaciones push. The content is end-to-end encrypted (VAPID / aes128gcm), so the provider has no access to readable personal data.

You can request a copy of those safeguards by writing to privacidad@vinculai.com. The United Kingdom, where the scientific literature search engine is hosted, benefits from a European Commission adequacy decision, so no additional safeguards are required.

8. How long we keep data

WhatHow long
Your account dataFor as long as the account is active. After that it is erased, except for whatever has to remain blocked under the next row
Data blocked after the account is closedFor the limitation period of the liabilities arising from the contract, available only to judges, courts, the public prosecutor and the competent authorities (articles 32 and 33.4 of Spanish Organic Act 3/2018, the LOPDGDD)
Invoices and accounting recordsSix years from the last entry (article 30 of the Spanish Commercial Code) and four years for tax purposes (article 66 of the Spanish General Tax Act)
Technical and security logsFor as long as is needed to investigate incidents, with a maximum of twelve months
Patients’ clinical recordsThe practice decides, as the Controller. Spanish Act 41/2002 on patient autonomy requires it to keep them for at least five years from the discharge of each episode of care, plus any longer periods laid down by the rules of its autonomous region. We do not keep them on our own account

9. Your rights

You can exercise the rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw at any time any consent you have given, without that affecting the lawfulness of the processing carried out beforehand.

Write to privacidad@vinculai.com stating which right you are exercising. We will reply within one month, extendable by a further two months if the request is complex, in which case we will tell you. We may ask you to prove your identity if we have reasonable doubts about who you are.

If you believe we have not dealt with your request properly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD), without prejudice to going to court.

If you are a patient, contact your psychologist or your practice: they are the Controller of your data. If a request of yours reaches us, we will pass it on to them and tell you so, but we cannot deal with it on our own account. You have the detail in the patient privacy notice.

10. Cookies and storage in your browser

In the management panel and in the patient portal we use only technical and necessary storage: the user session, protection against attacks and your interface preferences. It is exempt from consent under article 22.2 of Spanish Act 34/2002, because without it the service you have asked for cannot work.

On the public websites each practice publishes with VinculAI, the practice can switch on its own analytics (Google Analytics or Google Tag Manager). When it has them switched on, the visitor sees a notice before anything loads, with two buttons of the same size: accept and reject. If they reject, absolutely nothing is written to their browser and the site works just the same. The decision is stored in the browser itself and can be changed at any time from the ‘Cookies’ link in the footer.

If the practice does not set up analytics, there is no notice, because there is nothing to consent to.

11. Changes to this policy

If we change anything material —a new purpose, a new sub-processor— we will tell you in advance by email and in the platform itself, and we will publish the new version here with its date. For the addition of sub-processors, the notice period and your right to object are in the data processing agreement.