What is GDPR
GDPR (General Data Protection Regulation, EU 2016/679) is the European Union's general regulation on the protection of personal data. It came into effect on May 25, 2018.
As a platform processing health data, Soveria complies with GDPR's heightened requirements for special categories of data.
Clinical data (assessment results, session records) are classified as health data (Art. 4(15) GDPR). We process them exclusively based on your explicit consent (Art. 9(2)(a)).
Legal basis
| Data type | Legal basis | GDPR Article |
|---|---|---|
| Registration data | Contract performance | Art. 6(1)(b) |
| Clinical data | Explicit consent | Art. 9(2)(a) |
| Technical logs | Legitimate interest | Art. 6(1)(f) |
| Financial data | Legal obligation | Art. 6(1)(c) |
You may withdraw consent for clinical data processing at any time by contacting dpo@soveria.co. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
Your rights
As a data subject under GDPR, you have the following rights:
Right to information (Art. 13–14)
Know what data is collected about you, why, and on what legal basis
Implemented on this pageRight of access (Art. 15)
Receive a copy of all your personal data within 30 days, free of charge
Request: dpo@soveria.coRight to rectification (Art. 16)
Correct inaccurate or supplement incomplete personal data
Dashboard → ProfileRight to erasure (Art. 17)
"Right to be forgotten" — deletion of your data within 30 days
Timeline: 30 daysRight to restriction (Art. 18)
Suspend data processing when disputing data accuracy
Request: dpo@soveria.coRight to portability (Art. 20)
Receive your data in a machine-readable format (JSON/CSV)
Profile → Data → ExportRight to object (Art. 21)
Object to processing based on legitimate interest
Request: dpo@soveria.coRight against automated decisions (Art. 22)
Soveria does not make automated clinical decisions. All decisions are made by the specialist
Implemented architecturallyHow to submit a request
Processing timelines
Notification of supervisory authority about data breach (Art. 33 GDPR)
Standard response time for data subject requests (Art. 12(3))
Extended timeline for complex or numerous requests (with notification)
Exercising your GDPR rights is free. Soveria may charge a reasonable fee only for manifestly unfounded or excessive requests (Art. 12(5)).
Data transfer outside EU
| Provider | Country | Safeguard |
|---|---|---|
| Hetzner Online GmbH | Germany (EU) | Within EU |
| Resend Inc. | USA | SCC |
| Stripe Inc. | USA | SCC |
Clinical data (assessment results, session records) are stored exclusively on Hetzner servers in Germany and are never transferred outside the EU.
Complaints to supervisory authority
If you believe your GDPR rights have been violated, you have the right to file a complaint with a supervisory authority.
Germany's data protection supervisory authority: bfdi.bund.de
You may also contact the supervisory authority in your country (Art. 77 GDPR).
Contact DPO
Our Data Protection Officer (DPO) is your primary contact for GDPR and privacy matters.