Privacy Policy
What we collect, where it is stored, who we share it with, and how we protect it.
Last updated:
What we collect, where it is stored, who we share it with, and how we protect it.
Last updated:
This policy covers personal data processed through the psisula marketing site (psisula.com) and the psisula application. For the formal disclosure under Turkish data protection law, see the KVKK Disclosure Notice.
When you give it: the name, email, phone, practice type, team size and optional message on the demo request form. Your name, email and role when you open an account. The content of emails you send us.
Generated in use: login and session records, technical logs consisting of a request id plus clinic and therapist ids, and error records.
What we don’t collect: the demo form asks for no tax id, budget, current software, password or card details. The marketing site runs no advertising or profiling tracker of any kind.
For the client data a clinic enters, the clinic is the controller and we are the processor. We access it only:
Both are logged. We do not use client data for product development, analytics, or AI model training.
The marketing site sets no cookies and runs no analytics. The application uses only the essential cookies that keep you signed in. See the Cookie Policy.
Servers, database and file storage are located in the European Union (Alkmaar, Netherlands). The providers we rely on, the data each receives and their locations are listed in the table in the KVKK Disclosure Notice: our hosting provider, OpenAI, Twilio, Resend, Sentry, Zoom and Google Meet.
When our sub-processor list changes, account holders are notified in advance under the Data Processing Agreement.
TLS in transit; AES-256-GCM field-level encryption at rest for session notes, treatment plans, diagnoses, telehealth credentials and assessment answers. Phone numbers do not sit in the database as searchable plaintext. Access is limited by role, and every request is checked against whether the record belongs to the clinic in session. The full list is on the Security page.
Data is not end-to-end encrypted: search, reporting and AI features require the server to read it. We write that down as a limitation.
If we identify a personal data breach we inform affected account holders without undue delay and within 72 hours at the latest. The notice covers the nature of the breach, the categories of data affected, the likely consequences and the measures we have taken. For data we process as controller, we notify the Personal Data Protection Board ourselves; where clinical data is involved the notification duty sits with the clinic, and we give them what they need to meet it.
The product is used by adult healthcare professionals with accounts. Data about child and adolescent clients is entered by the clinic under parental or guardian consent, and obtaining that consent is the clinic’s responsibility.
When we update this policy we change the date at the top of the page. For a material change we notify account holders by email.