Privacy policy
Version 2.6 · in force since 1 October 2026
Detailed information on the processing of personal data at VinculAI, in accordance with article 13 of Regulation (EU) 2016/679.
This is a courtesy translation for information only. The service is provided in Spain, in Spanish, and the Spanish version of this document is the only one with legal effect. In the event of any discrepancy, the Spanish text prevails. The application interface is available in Spanish only.
1. First things first: VinculAI wears two hats
This is the distinction that orders everything else, and it is worth understanding before you read on.
For your account data, we are the Controller
Your sign-up, your email address, your practice’s details, your billing with us, the security logs and who visits our website. All of that we decide ourselves, and that is what this policy is about.
For your patients’ data, we are only the Processor
Appointments, the clinical record, session notes, messages and documents belong to your patients, and you are the Controller of that data —the professional or the practice—. We only process it following your instructions, and that is governed by the data processing agreement, not by this policy.
One practical consequence follows: if you are a patient and you want to exercise your rights, you have to contact your psychologist or your practice, not us. We explain it in more detail in the patient privacy notice.
We never use your patients’ data for our own purposes: not for product statistics, not for marketing, and not for training artificial intelligence models.
2. Who the Controller is
- Controller: Raúl Ríos Beiro (VinculAI)
- Registered address: Avenida Hermanos Machado 135, 46025 Valencia, España
- Contact: privacidad@vinculai.com · +34 680 476 385
No data protection officer has been appointed for the time being. If one is appointed, their contact details will be published here and notified to the Spanish Data Protection Agency (AEPD) within ten days, as required by article 34.3 of Spanish Organic Act 3/2018 (LOPDGDD).
3. What we process, what for and on what legal basis
Everything that follows refers to the data for which we are the Controller (section 1).
| What for | What data | Legal basis |
|---|---|---|
| Signing you up, maintaining your account, giving you support and providing you with the service | Name, email address, password (stored encrypted), telephone number, details of your practice and of your team | Performance of the contract (article 6.1.b GDPR) |
| Charging you for the subscription and keeping our accounts | Tax details, amounts, the transaction identifier at the payment gateway | Legal obligation (article 6.1.c GDPR; the Spanish Commercial Code and the Spanish General Tax Act) |
| Keeping the service secure: access logs, abuse detection, usage limits and backups | User identifier, IP address, timestamps, browser type | Legitimate interest (article 6.1.f GDPR): protecting the platform and the health data it holds against improper access and abuse |
| Telling you about service changes, incidents and relevant news | Name and email address | Performance of the contract (article 6.1.b GDPR) |
| Sending you commercial information about similar products, if you are already a client | Name and email address | Legitimate interest (article 6.1.f GDPR) under article 21.2 of Spanish Act 34/2002. You can object free of charge in every message |
| Giving you access to the demo, knowing who has tried it and writing to you once to ask how it went | Name, surname and email address | Pre-contractual measures at your request (article 6.1.b GDPR): you are the one asking to try the product, and that single message is the follow-up to what you asked for |
| Sending you commercial information if you are not a client yet | Name and email address | Your consent (article 6.1.a GDPR), which you can withdraw |
| Measuring use of the public websites with analytics | IP address, browsing, cookie identifier | Your consent (article 6.1.a GDPR and article 22.2 of Spanish Act 34/2002). See section 10 |
Providing the sign-up details is necessary in order for us to provide you with the service: without them we cannot create the account or issue you an invoice. The rest is voluntary, and not providing it has no consequence beyond not receiving that particular communication.
4. Patients’ health data
Data concerning health is special category data (article 9.1 GDPR) and its processing is prohibited unless an exception applies. In a psychology practice the usual exception is article 9.2.h —the provision of health care pursuant to a contract with a health professional— together with article 9.3, which requires the processing to be carried out by a professional subject to the obligation of professional secrecy, or by someone under their responsibility.
Establishing and documenting that exception is for the practice or the professional, who is the Controller. We do not need a legal basis of our own for that data: our legitimacy is derived and arises from the data processing agreement (article 28 GDPR).
What we do take on are the measures: clinical notes and messages are encrypted at application level with AES-256-GCM before being stored, session notes are accessible only to the treating professional, each practice is isolated from every other in the database itself, and no health data ever appears in technical logs.
5. Artificial intelligence
VinculAI uses artificial intelligence models to structure and format notes, for the management and booking assistant, and to read expense invoices. It is worth being precise about what that involves.
- Only what is asked for in each request is sent: the specific text to be formatted or the specific question put to the assistant. Neither the database nor the clinical record is sent across.
- The data is not used to train models. The provider’s commercial terms expressly prohibit it, and we pass that on as a contractual obligation.
- The output of the artificial intelligence is a draft. The professional reviews it, corrects it and signs it: authorship of and responsibility for the clinical record remain theirs.
- We take no automated decisions producing legal effects or significantly affecting anyone, within the meaning of article 22 GDPR. There is no profiling of patients and no scoring that shapes access to the service.
- Voice dictation does not store the audio at any point. That feature is currently switched off.
If we ever introduced something that did fall within article 22 —an automated prediction that shaped a booking, for example—, we would say so here expressly, we would explain the logic applied and its consequences, and we would offer the right to human intervention and to contest it.
6. Who we share data with
We do not sell data and we do not disclose it to third parties. We do rely on providers that process it on our behalf —sub-processors—, with a processing agreement and the same obligations we take on ourselves. This is the complete and current list:
| Provider | What for | What it receives | Where |
|---|---|---|---|
| Supabase | Database, authentication and file storage | All application data. Clinical notes, messages and file names travel and are stored encrypted at application level; the provider cannot read them. | Database in Paris (France). Contracting entity: Supabase Pte. Ltd (Singapore)Outside the EEA, with safeguards |
| Hetzner Online GmbH | Servers on which the application and the video consultation run | Everything that passes through the application, in transit and in memory. For the video consultation: the participant's first name, the room identifier and connection metadata. Audio and video travel encrypted, in two-person sessions they go straight from one browser to the other without passing through the server, and they are NEVER recorded under any circumstances. | GermanyEuropean Economic Area |
| Anthropic PBC | Artificial intelligence models | The text the professional chooses to send with each request (a note to be formatted, a query to the management assistant, a supplier invoice to be read) and the messages the patient writes in the booking assistant. The database is not sent, and none of this is used to train models. | United StatesOutside the EEA, with safeguards |
| Microsoft (Azure OpenAI)feature currently switched off | OpenAI artificial intelligence models, hosted by Microsoft | The text the professional chooses to send with each request (a note to be structured, a query to the management assistant, a supplier invoice to be read) and the messages the patient writes in the booking assistant. The database is not sent, and none of this is used to train models. Microsoft may keep that text for up to 30 days for the sole purpose of detecting abuse of the service. | European Union (resource in Spain; processing does not leave Microsoft's EU Data Boundary)European Economic Area |
| Brevo (Sendinblue SAS) | Transactional email | Name, email address, the content of the notice and any documents attached to it (a receipt, for example). Its open and click tracking cannot be switched off. | FranceEuropean Economic Area |
| Stripe | Card payments | The payer’s email address and the amount. The description is always generic («Session», «Session deposit», «Balance of the session»): the name of the service booked never leaves the platform. | Ireland, with processing in the United States by its groupOutside the EEA, with safeguards |
| PayPal | PayPal payments | The payer’s email address and the amount, with the same generic description as above. | Luxembourg, with processing in the United States by its groupOutside the EEA, with safeguards |
| Bilbabit, S.L. (Verifacti)feature currently switched off | Submission of billing records to the Spanish Tax Agency (VERI*FACTU), as a social collaborator authorised by the AEAT | The invoice data: tax ID and business name of the issuer, number and date, amounts and description. Where the invoice identifies the recipient —only if they provided their tax ID—, their name and tax ID as well. The description states the service («Session»), so together with a tax ID it may be inferred that the person received psychological care. It receives no clinical records, notes, messages or documents. In addition, and only from the professional or practice signing the authorisation to file on their behalf —never from patients—, their identity document and a photograph of their face to verify who is signing. | Spain (Getxo, Bizkaia), with processing on European Union servers. For the signing of that authorisation it relies on Namirial, S.p.A. (Senigallia, Italy)European Economic Area |
| Sign-in with Google (for the team and, if they choose it, for the patient) and optional Google Calendar synchronisation | The email address of the account used to sign in. Only the patient’s INITIALS and the time are written to the calendar: no full name, no reason for the visit, no description and no guests. | European Union and United StatesOutside the EEA, with safeguards | |
| Proveedores de notificaciones push | Delivery of notices to the browser or the phone (Google, Mozilla, Apple) | The technical address of the browser and the time of sending. The content of the notice travels end-to-end encrypted: the provider cannot read it. | GlobalOutside the EEA, with safeguards |
| WhatsApp (Meta Platforms Ireland Limited) | Sending appointment reminders over WhatsApp | The patient’s phone number, first name, the clinic’s name, the date and time of the appointment and a personal link to manage it. Never the reason for the consultation or any clinical data. | Ireland, with processing by Meta Platforms, Inc. (USA)Outside the EEA, with safeguards |
| Microsoft (Azure Speech) | Transcription of dictated notes | Only the audio the professional records when they choose to dictate a note, which may contain the patient’s clinical information. The audio is never stored. | European UnionEuropean Economic Area |
Providers that receive no personal data
- Europe PMC (EMBL-EBI, United Kingdom). Scientific literature search. Only abstract clinical terms are sent, never patient identifiers. The United Kingdom benefits from a European Commission adequacy decision, renewed on 19 December 2025.
One exception, and it is worth understanding it properly: paying for your subscription. When you pay for your own VinculAI subscription, Stripe does not act on our behalf: it processes your payment data as an independent Controller, in order to meet its own legal obligations (payment services and the prevention of money laundering). That is your data as the Client —never your patients’ data— and that part is governed by Stripe’s privacy policy, not by this one. It is a different thing from charging your patients, where Stripe does appear above as a sub-processor.
We also disclose data where the law requires it: to the tax authorities, to judges and courts, to the public prosecutor and to any competent authorities that request it.
Assistants you connect yourself. If you connect an external assistant to your account through our MCP server, that assistant will receive the data you ask it for. That connection is your decision, and whatever processing the assistant carries out is beyond our control; that is why we only accept clients from expressly authorised origins, and you can revoke access at any time.
7. Transfers outside the European Union
The database, the servers and the email are in the European Union. Some of the providers in the table above process data outside the European Economic Area (EEA); in those cases the transfer relies on the safeguards in article 46 GDPR:
- Supabase. European Commission standard contractual clauses (Decision 2021/914), modules two and three, under Irish law and jurisdiction. The database is hosted in the European Union; support, monitoring and account communications may involve group providers outside the European Economic Area.
- Anthropic PBC. European Commission standard contractual clauses (Decision 2021/914), modules two and three, incorporated into its data processing agreement.
- Stripe. Article 46 GDPR safeguards provided for in its data processing agreement.
- PayPal. Article 46 GDPR safeguards provided for in its data processing agreement.
- Google. Listed here for transparency, although Google does NOT act on the Processor’s behalf: when signing in it is the user who authenticates with Google, and in the calendar it is the professional’s own Google account —authorised by them, and revocable by them— that receives the data. In both cases the processing is governed by that user’s relationship with Google and by the Google API terms the Processor accepted when registering the application. Calendar synchronisation is OPTIONAL: until the professional switches it on, no data leaves for Google by this route.
- Proveedores de notificaciones push. The content is end-to-end encrypted (VAPID / aes128gcm), so the provider has no access to readable personal data.
- WhatsApp (Meta Platforms Ireland Limited). European Commission Standard Contractual Clauses and Meta’s certification under the EU-U.S. Data Privacy Framework. Messages are carried by Meta’s infrastructure, which can access their content: that is why only logistical information is sent.
You can request a copy of those safeguards by writing to privacidad@vinculai.com. The United Kingdom, where the scientific literature search engine is hosted, benefits from a European Commission adequacy decision, so no additional safeguards are required.
8. How long we keep data
| What | How long |
|---|---|
| Your account data | For as long as the account is active. After that it is erased, except for whatever has to remain blocked under the next row |
| Data blocked after the account is closed | For the limitation period of the liabilities arising from the contract, available only to judges, courts, the public prosecutor and the competent authorities (articles 32 and 33.4 of Spanish Organic Act 3/2018, the LOPDGDD) |
| Invoices and accounting records | Six years from the last entry (article 30 of the Spanish Commercial Code) and four years for tax purposes (article 66 of the Spanish General Tax Act) |
| Data of people who try the demo | The trial clinic and everything in it are deleted automatically after 24 hours. We keep your name and email address as a contact for two years from the last time you tried it, or until you ask us to delete them |
| Technical and security logs | For as long as is needed to investigate incidents, with a maximum of twelve months |
| Patients’ clinical records | The practice decides, as the Controller. Spanish Act 41/2002 on patient autonomy requires it to keep them for at least five years from the discharge of each episode of care, plus any longer periods laid down by the rules of its autonomous region. We do not keep them on our own account |
9. Your rights
You can exercise the rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw at any time any consent you have given, without that affecting the lawfulness of the processing carried out beforehand.
Write to privacidad@vinculai.com stating which right you are exercising. We will reply within one month, extendable by a further two months if the request is complex, in which case we will tell you. We may ask you to prove your identity if we have reasonable doubts about who you are.
If you believe we have not dealt with your request properly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD), without prejudice to going to court.
If you are a patient, contact your psychologist or your practice: they are the Controller of your data. If a request of yours reaches us, we will pass it on to them and tell you so, but we cannot deal with it on our own account. You have the detail in the patient privacy notice.
10. Cookies and storage in your browser
In the management panel and in the patient portal we use only technical and necessary storage: the user session, protection against attacks and your interface preferences. It is exempt from consent under article 22.2 of Spanish Act 34/2002, because without it the service you have asked for cannot work.
On the public websites each practice publishes with VinculAI, the practice can switch on its own analytics (Google Analytics or Google Tag Manager). When it has them switched on, the visitor sees a notice before anything loads, with two buttons of the same size: accept and reject. If they reject, absolutely nothing is written to their browser and the site works just the same. The decision is stored in the browser itself and can be changed at any time from the ‘Cookies’ link in the footer.
If the practice does not set up analytics, there is no notice, because there is nothing to consent to.
11. Changes to this policy
If we change anything material —a new purpose, a new sub-processor— we will tell you in advance by email and in the platform itself, and we will publish the new version here with its date. For the addition of sub-processors, the notice period and your right to object are in the data processing agreement.