Last updated: May 2026 GDPR compliant
This Privacy Policy explains how Optonet Ltd collects, uses, stores, and protects personal data in connection with the Optonet Chatbot platform (optonetchatbot.com), an AI-assisted pre-consultation anamnesis SaaS for healthcare centres.
| Data Controller / Data Processor | |
|---|---|
| Company | Optonet Ltd |
| Companies House (UK) | 09744666 |
| VAT number | GB232373724 |
| Registered address | 81 North Park Brook Road, Callands, Warrington WA5 9ST, United Kingdom |
| General contact | optonet@optonetproject.com |
| GDPR / data requests | gdpr@euverify.com |
| DSAR portal | Submit a data request |
| Legal representative | Guillermo Bueno del Romo |
| Data Protection Officer | Pending formal appointment — contact gdpr@euverify.com for all DPO matters in the interim |
| Processing activity | Legal basis |
|---|---|
| Centre account management and billing | Art. 6.1.b GDPR — performance of contract |
| Patient health data during AI interview | Art. 9.2.a GDPR — explicit consent of the data subject, obtained before the interview begins |
| AI-assisted clinical report generation | Art. 9.2.a + Art. 9.2.h (healthcare provision) + Art. 22.2.a (explicit consent for AI-assisted processing) |
| Consent records retention | Art. 7 GDPR — demonstrating compliance with consent requirements |
| Error monitoring and platform reliability | Art. 6.1.f GDPR — legitimate interest in maintaining a secure and reliable service |
| Compliance with legal obligations | Art. 6.1.c GDPR |
We share personal data with the following sub-processors strictly for the purpose of delivering the Optonet Chatbot service. All sub-processors are bound by appropriate data protection agreements.
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Supabase | Database, authentication, file storage, serverless functions | EU (eu-central-1 Frankfurt, Germany) | DPA signed; data stored exclusively in EU |
| OpenAI / Azure OpenAI | AI language model for interview and report generation | EU (Azure Sweden Central) / USA fallback | DPA; EU-US Data Privacy Framework (2023); Zero Data Retention policy — data not used to train models |
| Brevo | Transactional email delivery (Smart Link, notifications) | EU | DPA signed |
| Stripe | Payment processing (billing data only — no patient data) | EU / USA | EU-US Data Privacy Framework (2023); Stripe DPA |
| Sentry | Error monitoring and platform reliability | EU (Sentry EU instance) | Session replay disabled on clinical routes (/interview/*); maskAllText enabled; EU data residency |
We do not sell personal data to third parties. We do not use patient data for advertising or marketing purposes.
Our primary data infrastructure (Supabase) is hosted in Germany (EU). Where data is transferred outside the EU/EEA, we rely on the following safeguards:
| Data category | Retention period |
|---|---|
| Patient health data and clinical reports (completed sessions) | Minimum 5 years after last clinical contact (Spain: Ley 41/2002); deleted at the healthcare centre's instruction or upon erasure request |
| Conversation transcripts | Same as above; permanently deleted (hard delete) when a session is removed by the centre |
| Expired / incomplete sessions | Automatically purged after Smart Link TTL expiry |
| Consent records | Duration of patient relationship + 3 years (audit trail) |
| Centre account data | Duration of contract + 6 years (UK statutory limitation period) |
| Billing records | 6 years (legal obligation) |
| Error logs (Sentry) | 90 days rolling |
If you are a patient whose data has been processed through Optonet Chatbot, your primary point of contact for data rights is the healthcare centre that conducted your consultation, as they are the Data Controller for your patient data.
You may also contact Optonet Ltd directly via our DSAR portal. We will respond within 30 days.
| Right | What it means |
|---|---|
| Access (Art. 15) | Request a copy of your personal data held by the platform |
| Rectification (Art. 16) | Correct inaccurate or incomplete data |
| Erasure (Art. 17) | Request deletion of your data ("right to be forgotten") |
| Restriction (Art. 18) | Request that processing be limited in certain circumstances |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format (JSON) |
| Objection (Art. 21) | Object to processing based on legitimate interest |
| Withdraw consent (Art. 7.3) | Withdraw consent at any time without affecting the lawfulness of prior processing. You may do so via the link provided at the end of your interview. |
| Lodge a complaint | You have the right to lodge a complaint with a supervisory authority. In Spain: Agencia Española de Protección de Datos (AEPD). In Ireland: Data Protection Commission (DPC). |
Optonet Chatbot uses only strictly necessary cookies required for platform functionality (session management, authentication tokens). We do not use advertising cookies or cross-site tracking cookies. Functional cookies do not require consent under the ePrivacy Directive.
No third-party analytics cookies are placed on patient-facing interview pages (/interview/*).
Optonet Chatbot is a professional healthcare platform. Patient interviews involving minors under 16 must be conducted with verified parental or guardian consent, obtained by the healthcare centre prior to using the platform for that patient.
We may update this Privacy Policy from time to time. Material changes will be notified to registered healthcare centres by email at least 30 days before taking effect. The "Last updated" date at the top of this page always reflects the current version.
If you are located in the EU/EEA and have questions or concerns regarding your personal data, you may contact our appointed GDPR representative:
EU Representative:To submit a Data Subject Access Request (DSAR), data deletion request, or any other GDPR-related enquiry, please use our secure DSAR portal. Requests submitted through this portal are logged and tracked to ensure a timely and compliant response.