Who we are
Soveria Platform (hereinafter — "Soveria", "we", "our") is a clinical measurement-based care platform for mental health professionals and their clients.
We take the protection of your personal data seriously. This Privacy Policy describes what data we collect, how we use it, and what rights you have regarding your data.
Soveria Platform · Email: privacy@soveria.co · DPO: dpo@soveria.co
Data we collect
Data you provide
- Registration data: name, email, password (hashed)
- Professional data (for specialists): qualifications, specialization, license number
- Clinical data: assessment results, clinical notes, treatment protocols
- Session data: records of therapeutic sessions, notes
- Contact data: phone, address (optional)
Data we collect automatically
- Technical data: IP address, browser type, operating system
- Usage data: visit times, pages viewed, platform actions
- Cookies and similar technologies (see Cookie Policy)
⚠️ Clinical health data belongs to a special category of personal data (Art. 9 GDPR). We process it exclusively based on your explicit consent.
Processing purposes
We process your data for the following purposes:
| Purpose | Legal basis | Data category |
|---|---|---|
| Service provision | Contract performance (Art. 6(1)(b)) | Registration, professional |
| Clinical data processing | Explicit consent (Art. 9(2)(a)) | Clinical, assessment data |
| Technical support | Legitimate interest (Art. 6(1)(f)) | Contact, technical |
| Platform security | Legitimate interest (Art. 6(1)(f)) | Technical, logs |
| Legal compliance | Legal obligation (Art. 6(1)(c)) | All categories |
We use your data only for the stated purposes. Each purpose has a specific legal basis under GDPR.
Third-party sharing
We share your data only in the following cases:
- Your therapist (for clients) — within the therapeutic relationship
- Subcontractors (sub-processors) — for technical platform operations
- By legal requirement — if obligated by court order or regulator request
Data Sub-processors
| Provider | Purpose | Country |
|---|---|---|
| Hetzner Online GmbH | Server hosting, data storage | Germany (EU) |
| Resend Inc. | Transactional email delivery | USA (SCC) |
| Stripe Inc. | Payment processing | USA (SCC) |
Retention periods
| Data type | Retention period | Basis |
|---|---|---|
| Registration data | Until account deletion | Contract performance |
| Clinical data | 5 years after treatment ends | Professional standards |
| Technical logs | 90 days | Legitimate interest |
| Financial data | 7 years | Tax legislation |
| Consent records | 3 years after withdrawal | Consent verification |
When you delete your account, your registration data is removed within 30 days. Clinical data may be retained longer per professional standards.
Your rights
Right of access
Request a copy of all your personal data we process
Right to rectification
Correct inaccurate or incomplete personal data
Right to erasure
Right to be forgotten — request deletion of your data
Right to portability
Receive your data in a machine-readable format
Right to object
Object to the processing of your data
Right to restriction
Restrict the processing of your personal data
To exercise any of these rights, contact our DPO: dpo@soveria.co. We will process your request within 30 days.
Security
- TLS 1.3 for all connections
- JWT authentication with short-lived tokens
- Password hashing (bcrypt, 12 rounds)
- Rate limiting on sensitive endpoints
- Role-based access control (RBAC)
- Regular encrypted backups
- Servers in Hetzner Frankfurt, Germany (EU)
In case of a data breach, we will notify the supervisory authority within 72 hours (Art. 33 GDPR) and affected individuals without undue delay (Art. 34 GDPR).
Cookies
We use a limited set of cookies for platform operation. For detailed information about the cookies we use and how to manage your preferences, please see our Cookie Policy.
Policy changes
We may update this Privacy Policy. We will notify you of material changes via email or through a platform notification.
By continuing to use the platform after changes are published, you accept the updated policy.
v1.3 (Mar 2026) — Updated sub-processors · v1.2 (Jan 2026) — Added retention periods · v1.0 (Oct 2025) — First version
Contact DPO
If you have questions about our Privacy Policy or wish to exercise your rights, contact our Data Protection Officer (DPO).