psisula

Privacy Policy

What we collect, where it is stored, who we share it with, and how we protect it.

Scope

This policy covers personal data processed through the psisula marketing site (psisula.com) and the psisula application. For the formal disclosure under Turkish data protection law, see the KVKK Disclosure Notice.

What we collect

When you give it: the name, email, phone, practice type, team size and optional message on the demo request form. Your name, email and role when you open an account. The content of emails you send us.

Generated in use: login and session records, technical logs consisting of a request id plus clinic and therapist ids, and error records.

What we don’t collect: the demo form asks for no tax id, budget, current software, password or card details. The marketing site runs no advertising or profiling tracker of any kind.

Client data

For the client data a clinic enters, the clinic is the controller and we are the processor. We access it only:

  • at the customer’s explicit request, to resolve a problem they have reported;
  • during technical maintenance strictly necessary to keep the service running.

Both are logged. We do not use client data for product development, analytics, or AI model training.

Cookies

The marketing site sets no cookies and runs no analytics. The application uses only the essential cookies that keep you signed in. See the Cookie Policy.

Hosting and sub-processors

Servers, database and file storage are located in the European Union (Alkmaar, Netherlands). The providers we rely on, the data each receives and their locations are listed in the table in the KVKK Disclosure Notice: our hosting provider, OpenAI, Twilio, Resend, Sentry, Zoom and Google Meet.

When our sub-processor list changes, account holders are notified in advance under the Data Processing Agreement.

AI and session audio

  • Drafting a note from session audio requires recording consent to be captured in the system; without it, the request never reaches any provider.
  • Audio is not retained. Once transcribed, the audio is discarded; the transcript text is stored encrypted.
  • No AI-generated content is ever published, attached to a record or sent to a client automatically. Every draft waits for therapist review.

How we protect data

TLS in transit; AES-256-GCM field-level encryption at rest for session notes, treatment plans, diagnoses, telehealth credentials and assessment answers. Phone numbers do not sit in the database as searchable plaintext. Access is limited by role, and every request is checked against whether the record belongs to the clinic in session. The full list is on the Security page.

Data is not end-to-end encrypted: search, reporting and AI features require the server to read it. We write that down as a limitation.

Data breach

If we identify a personal data breach we inform affected account holders without undue delay and within 72 hours at the latest. The notice covers the nature of the breach, the categories of data affected, the likely consequences and the measures we have taken. For data we process as controller, we notify the Personal Data Protection Board ourselves; where clinical data is involved the notification duty sits with the clinic, and we give them what they need to meet it.

Children’s data

The product is used by adult healthcare professionals with accounts. Data about child and adolescent clients is entered by the clinic under parental or guardian consent, and obtaining that consent is the clinic’s responsibility.

Changes

When we update this policy we change the date at the top of the page. For a material change we notify account holders by email.

Contact

[email protected]