Privacy Policy

Last updated: May 2026 GDPR compliant

This Privacy Policy explains how Optonet Ltd collects, uses, stores, and protects personal data in connection with the Optonet Chatbot platform (optonetchatbot.com), an AI-assisted pre-consultation anamnesis SaaS for healthcare centres.

1. Who We Are

Data Controller / Data Processor
CompanyOptonet Ltd
Companies House (UK)09744666
VAT numberGB232373724
Registered address81 North Park Brook Road, Callands, Warrington WA5 9ST, United Kingdom
General contactoptonet@optonetproject.com
GDPR / data requestsgdpr@euverify.com
DSAR portalSubmit a data request
Legal representativeGuillermo Bueno del Romo
Data Protection OfficerPending formal appointment — contact gdpr@euverify.com for all DPO matters in the interim
Our GDPR role depends on who the data belongs to:

2. What Personal Data We Collect

2.1 Healthcare centre account data

2.2 Patient data (processed on behalf of healthcare centres)

2.3 Technical and operational data

3. Legal Basis for Processing

Processing activityLegal basis
Centre account management and billingArt. 6.1.b GDPR — performance of contract
Patient health data during AI interviewArt. 9.2.a GDPR — explicit consent of the data subject, obtained before the interview begins
AI-assisted clinical report generationArt. 9.2.a + Art. 9.2.h (healthcare provision) + Art. 22.2.a (explicit consent for AI-assisted processing)
Consent records retentionArt. 7 GDPR — demonstrating compliance with consent requirements
Error monitoring and platform reliabilityArt. 6.1.f GDPR — legitimate interest in maintaining a secure and reliable service
Compliance with legal obligationsArt. 6.1.c GDPR

4. How We Use Your Data

⚠ AI processing disclosure (Art. 22 GDPR) The interview is conducted by an AI assistant. The AI structures patient responses and generates a clinical summary. It does not make clinical diagnoses or autonomous medical decisions. All output is reviewed by a qualified healthcare professional. Patients provide explicit consent to AI-assisted processing before the interview begins and may decline at any time.

5. Sub-processors and Third-party Services

We share personal data with the following sub-processors strictly for the purpose of delivering the Optonet Chatbot service. All sub-processors are bound by appropriate data protection agreements.

Sub-processorPurposeLocationSafeguard
Supabase Database, authentication, file storage, serverless functions EU (eu-central-1 Frankfurt, Germany) DPA signed; data stored exclusively in EU
OpenAI / Azure OpenAI AI language model for interview and report generation EU (Azure Sweden Central) / USA fallback DPA; EU-US Data Privacy Framework (2023); Zero Data Retention policy — data not used to train models
Brevo Transactional email delivery (Smart Link, notifications) EU DPA signed
Stripe Payment processing (billing data only — no patient data) EU / USA EU-US Data Privacy Framework (2023); Stripe DPA
Sentry Error monitoring and platform reliability EU (Sentry EU instance) Session replay disabled on clinical routes (/interview/*); maskAllText enabled; EU data residency

We do not sell personal data to third parties. We do not use patient data for advertising or marketing purposes.

6. International Data Transfers

Our primary data infrastructure (Supabase) is hosted in Germany (EU). Where data is transferred outside the EU/EEA, we rely on the following safeguards:

7. How Long We Keep Your Data

Data categoryRetention period
Patient health data and clinical reports (completed sessions)Minimum 5 years after last clinical contact (Spain: Ley 41/2002); deleted at the healthcare centre's instruction or upon erasure request
Conversation transcriptsSame as above; permanently deleted (hard delete) when a session is removed by the centre
Expired / incomplete sessionsAutomatically purged after Smart Link TTL expiry
Consent recordsDuration of patient relationship + 3 years (audit trail)
Centre account dataDuration of contract + 6 years (UK statutory limitation period)
Billing records6 years (legal obligation)
Error logs (Sentry)90 days rolling

8. Security Measures

9. Your Rights Under the GDPR

If you are a patient whose data has been processed through Optonet Chatbot, your primary point of contact for data rights is the healthcare centre that conducted your consultation, as they are the Data Controller for your patient data.

You may also contact Optonet Ltd directly via our DSAR portal. We will respond within 30 days.

RightWhat it means
Access (Art. 15)Request a copy of your personal data held by the platform
Rectification (Art. 16)Correct inaccurate or incomplete data
Erasure (Art. 17)Request deletion of your data ("right to be forgotten")
Restriction (Art. 18)Request that processing be limited in certain circumstances
Portability (Art. 20)Receive your data in a structured, machine-readable format (JSON)
Objection (Art. 21)Object to processing based on legitimate interest
Withdraw consent (Art. 7.3)Withdraw consent at any time without affecting the lawfulness of prior processing. You may do so via the link provided at the end of your interview.
Lodge a complaintYou have the right to lodge a complaint with a supervisory authority. In Spain: Agencia Española de Protección de Datos (AEPD). In Ireland: Data Protection Commission (DPC).

10. Cookies

Optonet Chatbot uses only strictly necessary cookies required for platform functionality (session management, authentication tokens). We do not use advertising cookies or cross-site tracking cookies. Functional cookies do not require consent under the ePrivacy Directive.

No third-party analytics cookies are placed on patient-facing interview pages (/interview/*).

11. Minors

Optonet Chatbot is a professional healthcare platform. Patient interviews involving minors under 16 must be conducted with verified parental or guardian consent, obtained by the healthcare centre prior to using the platform for that patient.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified to registered healthcare centres by email at least 30 days before taking effect. The "Last updated" date at the top of this page always reflects the current version.

EU/EEA GDPR Representative (Article 27)

If you are located in the EU/EEA and have questions or concerns regarding your personal data, you may contact our appointed GDPR representative:

EU Representative:
Euverify Ltd (Ireland)
Unit 3D North Point House
North Point Business Park
New Mallow Road, Cork
T23 AT2P, Ireland
Email: gdpr@euverify.com

To submit a Data Subject Access Request (DSAR), data deletion request, or any other GDPR-related enquiry, please use our secure DSAR portal. Requests submitted through this portal are logged and tracked to ensure a timely and compliant response.

13. How to Contact Us

For all GDPR and data protection matters: General enquiries: