Skip to main content

Privacy Policy

Last updated: April 26, 2026

Compliant with GDPR + Moldovan Law 133/2011

Mental-health data is a special category under GDPR Art. 9. At Seempathy we process it only with explicit consent, store it encrypted, and give you full control. This policy describes exactly what we collect, why, with whom we share it, and how to exercise your rights.

1. Categories of data we collect

**Identity**: name, date of birth, photo, ID/passport (therapists only, for verification). **Contact**: email, phone, address (optional). **Account**: hashed password, encrypted 2FA secret, locale preferences, active sessions. **Health (special category)**: clinical notes, assessment scores (PHQ-9, GAD-7), mood journal, chat messages with therapist, session transcripts. **Payment**: MAIB transaction id, partial card metadata (NOT the full PAN), invoices. **Behavioural**: page visits, UTM events, A/B-test bucket — only if you accepted „Analytics”. **Communications**: email send logs, notification preferences. **Crisis indicators**: anonymised audit log of detected crisis-keyword events (keywords + timestamp, NOT the message body).

2. Legal basis for each category

Each category has an explicit legal basis: - **Identity, contact, account, payment** — contract performance (GDPR Art. 6(1)(b), Law 133 art. 5). - **Health data** — explicit consent (GDPR Art. 9(2)(a)) + processing for medical purposes (Art. 9(2)(h)). - **Behavioural** — consent (toggleable in the cookie banner & account settings). - **Marketing communications** — consent (with opt-out anytime). - **Crisis indicators** — vital interest (GDPR Art. 6(1)(d)) + professional ethical obligation.

3. Who receives your data

We share personal data only with: - **Your therapist** (joint controller with Seempathy) — for therapy delivery. DPA signed at onboarding. - **MAIB** — payment processor (card data does not pass through our servers). - **Hetzner Online GmbH** (DE/FI) — infrastructure. Standard Contractual Clauses on file. - **Resend** — transactional email (EU routing). - **SMS.MD** — SMS notifications, MD-domestic only. - **Supabase** (self-hosted on our Hetzner servers) — auth + storage + DB. We do NOT sell, rent, or share data with marketing third parties. We do NOT use Google Analytics or similar — behavioural events live only in our own database.

4. International transfers

Your data is stored on servers in the European Union (Hetzner Helsinki, Finland). We do not transfer data outside the EEA. The MAIB integration is MD-domestic — transactions never leave Moldova or the EU. If we ever introduce a non-EU subprocessor, we will re-prompt your consent.

5. How long we keep data

Per Moldovan Health Code (Law 411/1995) and tax law: - **Account profile**: as long as active + 30-day soft delete after deletion request. - **Therapy session records (notes, transcripts, assessments, chat)**: **5 years** from last session. - **Payment records**: 10 years (Moldovan tax code art. 134). - **Marketing consent**: until withdrawn + 2 years (proof of consent under GDPR Art. 7). - **Behavioural / analytics**: 13 months. - **Audit log + crisis indicator log**: 5 years. A cron job runs nightly to honour these retention windows.

6. Your rights (GDPR Art. 15-22, Law 133 art. 12-15)

You have the right to: - **Access** — see what data we hold. „Download my data” button in settings. - **Rectification** — correct inaccurate data. Directly in settings or via the form below. - **Erasure** („right to be forgotten”) — request account deletion. 30-day soft delete, then hard delete via cron. Session notes remain anonymised for 5 years per the Moldovan Health Code. - **Portability** — receive your data in machine-readable JSON. - **Objection** — to marketing, profiling, analytics cookies. - **Restriction** — temporarily disable processing of certain data. - **Withdraw consent** — anytime, without affecting prior lawful processing. **Response time**: 30 calendar days (extendable once by 60 days for complex requests, with notice). **DPO contact**: dpo@seempathy.md. If you are not satisfied with our response, you can lodge a complaint with **CNPDCP** (Moldovan National Centre for Personal Data Protection, www.datepersonale.md) or your local EU supervisory authority.

7. Security

**In transit**: TLS 1.3 for all connections. Video sessions use WebRTC with DTLS-SRTP. **At rest**: disk encryption (Hetzner) + column-level AES-256-GCM for clinical notes, assessments, chat messages, 2FA secrets, OAuth calendar tokens. **Access**: immutable audit log for every admin access to patient PHI, kept 5 years. 2FA strongly recommended for admin/therapist accounts. **Key rotation**: annual + immediately on suspected compromise.

8. Cookies

We use 3 categories (CMP banner on first visit): - **Necessary** (always on): auth, CSRF, locale. - **Analytics** (optional): page-usage measurement — our database only, no Google Analytics. - **Marketing** (optional): newsletter, drip campaigns. „Accept all” and „Reject all” buttons have equal prominence — no dark patterns. Your choice is stored for 12 months, then we ask again.

9. Data Protection Officer (DPO)

For any question about our processing of your data: **Email**: dpo@seempathy.md **Address**: Seempathy SRL, Chișinău, Republic of Moldova Supervisory authority: **CNPDCP** — www.datepersonale.md, 48 Serghei Lazo St., MD-2004 Chișinău.

Manage cookies

Reset your cookie preferences and reopen the banner.

Exercise your GDPR rights
Fill the form below to exercise any of your data rights. We respond within 30 days.

We will verify you are the data subject before responding.

You'll receive a complete export of your data.

Response guaranteed within 30 calendar days. For complex requests we may extend once by 60 days (with notice).