Privacy Policy

Version 1.3 – Effective: August 2026

This Privacy Policy explains how we process and protect your personal data when you use our website www.psynex.de or the services we offer through this website (together "our Services" or "the Platform").

The website and platform is operated by:

Intermac systems

Sendnicher Str. 58a

56072 Koblenz

Germany

Email: info@intermac.de

Phone: +49-151-2755-5942

VAT ID: DE178012433

(hereinafter "the Company", "we", "our" or "us")

Data Protection Contact:
For questions about data protection, contact us at: info@intermac.de

Important Notice: Our Role as Data Processor

Psynex is a B2B platform for healthcare professionals (psychotherapists, psychologists).

For the processing of patient data of your clients, you as the therapist are the Data Controller under GDPR. We (Intermac systems) act as a Data Processor pursuant to Article 28 GDPR. The terms of data processing are governed by our separate Data Processing Agreement (DPA), which you must accept during registration.

This Privacy Policy primarily concerns:

  1. Your own data as a user of the platform (therapist account)
  2. General information about data processing
  3. Technical and organizational measures

Your obligations towards your patients:

  • You must obtain valid consent from your patients for data processing under Articles 6, 9 GDPR
  • You must inform your patients about data processing (including use of AI services)
  • You are responsible for fulfilling your patients' data subject rights

1. Data We Process and Purposes

1.1 Therapist Data (our direct users)

When you register as a therapist and use the platform, we process the following data about you:

Data CategoryExamplesPurposeLegal Basis
Account DataName, email, password (hashed), phoneProvision and management of your accountArt. 6(1)(b) GDPR (contract performance)
Professional InformationLicense, specialty, practice addressVerification of authorization to useArt. 6(1)(b), (c) GDPR
Payment DataBilling address, payment methodProcessing subscription paymentsArt. 6(1)(b) GDPR
Usage DataLogin times, features used, IP addressProvision and improvement of servicesArt. 6(1)(f) GDPR (legitimate interest)
CommunicationsSupport requests, feedbackCustomer service, product improvementArt. 6(1)(b), (f) GDPR
Voice ProfileVoluntarily recorded or uploaded voice sample of at most eight seconds, stored as MP3Attributing your own contributions during speaker separation. For this purpose the voice sample is transmitted to OpenAI with every transcription that uses speaker separation (see Section 3.2)Art. 6(1)(a) GDPR (consent), as the feature is voluntary

1.2 Patient Data (processed on behalf of therapists)

When you as a therapist enter patient data into the platform, we process this exclusively on your behalf:

Data CategoryExamplesPurpose
Patient Master DataName, date of birth, contact details, insurance numberIdentification, insurance applications
Health Data (Art. 9 GDPR)Diagnoses, symptoms, treatment progress, therapy notesDocumentation, therapy report creation
Session DataAudio transcripts, session notes, treatment plansAI-assisted documentation and reporting
Insurance DataInsurance provider, coverage approval, application statusCreating reimbursement applications

Legal basis for patient data:

  • You as the therapist are responsible for the legal basis (typically: patient consent under Art. 9(2)(a) GDPR or legal authorization under Art. 9(3) GDPR)
  • We process this data only on your documented instructions (Art. 28 GDPR)

2. Data Sources

We collect data from the following sources:

Directly from you:

  • During registration and account management
  • When using the platform (entering patient data, session notes)
  • When contacting us (support, email)
  • During payment transactions

Automatically:

  • Through your use of the website/platform (log files, cookies)
  • Through audio transcription during session recordings

From third parties:

  • Payment service providers (transaction confirmations)
  • Licensing authorities (only for verification upon your request)

3. Recipients and Data Sharing

3.1 Internal Recipients

Access to data is limited to:

  • Authorized employees of Intermac systems (on a need-to-know basis)
  • Technical administrators (with 2FA-protected, logged access)

Patient data is stored encrypted in the database, and the encryption keys are managed separately in Azure Key Vault. There is no administrative interface through which plaintext patient data would be accessible. Access to decrypted content would only be possible through deliberate technical effort at the infrastructure level – for instance, in a specifically requested support or error case – and does not occur in regular operation. As a data processor, we are additionally bound by § 203 para. 4 StGB directly to the therapist's professional confidentiality obligation.

3.2 External Service Providers (Sub-processors)

We use the following sub-processors under Article 28 GDPR:

Service ProviderServiceLocationData Protection Guarantees
Hetzner Online GmbHServer hosting, data centerGermany (Falkenstein, Nuremberg)DPA under Art. 28 GDPR, BSI C5 Type 2, ISO 27001:2022 certified
Microsoft Ireland Operations Ltd.Key management (Azure Key Vault)Germany (Frankfurt, Germany West Central)Microsoft Products and Services DPA per Art. 28 GDPR, ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, BSI C5
OpenAI Ireland Ltd.AI text processing (transcription, report generation)EU (EU data center, Data Residency, Zero Data Retention)DPA per Art. 28 GDPR, additional BAA, SOC 2, ISO 27001
Stripe Payments Europe Ltd.Payment processingIreland (EU)DPA per Art. 28 GDPR, PCI DSS Level 1 certified
ResendTransactional emailsEUDPA per Art. 28 GDPR, SOC 2

Our OpenAI setup in detail:

  • Contractual partner: OpenAI Ireland Ltd. (EU legal entity), not OpenAI LLC (USA)
  • Processing exclusively in the EU data center (EU Data Residency)
  • Zero Data Retention (ZDR) mode: Content is neither stored nor logged, not reviewed by humans, and discarded immediately after processing
  • Data Processing Agreement (DPA) per Art. 28 GDPR in place
  • Additional Business Associate Agreement (BAA) – a contractual framework OpenAI concludes with customers in the healthcare sector, establishing additional protection obligations
  • No use of data for training AI models – technically enforced at the project level and contractually fixed in the DPA
  • Transfer exclusively over TLS 1.3

This differs fundamentally from public ChatGPT, where inputs are stored by default for 30 days, logged for abuse monitoring, and potentially used for training unless the user actively opts out.

4. International Data Transfers

4.1 Principle: Data Processing in the EU

Your data (especially patient data) is primarily processed in Germany:

  • Main database: Hetzner data centers in Germany
  • Backups: Encrypted in German data centers

4.2 OpenAI – EU Data Processing

For AI text processing, we use OpenAI's EU-based infrastructure:

  • Server location: EU data center (EU Data Residency, Zero Data Retention)
  • Data transfer to USA: Does not occur for data processed via API
  • Legal basis: Art. 46 GDPR (Standard Contractual Clauses in BAA/DPA)

Transparency about our OpenAI usage:

Our contractual partner is OpenAI Ireland Ltd., an EU legal entity based in Ireland. Data processing takes place exclusively within the EU (EU Data Residency). In Zero Data Retention mode, content is discarded immediately after processing and not stored. No third-country transfer of your submitted content to the USA occurs; access by US authorities to your patient data is therefore contractually and technically excluded.

5. Data Retention

Data TypeRetention PeriodReason
Account DataUntil you delete the account, then immediately. Rolling backups expire after max. 90 daysContract performance. Ending a subscription deletes nothing; the account continues on the free plan
Patient DataAs long as you wish, at most until account deletion, then immediatelyData processing – you control deletion
Session Audio RecordingsDeleted immediately after complete transcription. If a recording is retained for error analysis, it is deleted automatically 24 hours after the transcription attemptData minimisation, short retention solely for troubleshooting
Voice ProfileUntil you delete it, at the latest upon account deletionVoluntary feature, deletable at any time in the settings
Billing Data10 years after year-endTax retention requirements
BackupsMax. 90 days (rolling system)IT security, then automatic deletion
Log Files30 days, IP addresses anonymized after 14 daysIT security, abuse prevention
Support Correspondence3 years after last messageTraceability, quality assurance

Once a retention period ends:

We delete the data from live operation and from object storage. It remains in the rolling backup copies for up to 90 days, after which those backups expire. We cannot promise that data becomes unreadable in backups that have already been written.

What you can control:

  • Delete individual patients or sessions: available at any time, and the deletion is immediate
  • Automatic deletion on a schedule: you can have session content, chat histories and AI documents deleted on their own after a period you choose, from one hour up to 30 days. The patient record can be kept. The setting is off by default
  • Full export: you can download your data as a ZIP archive at any time, regardless of plan or cancellation. This is your right to data portability under Art. 20 GDPR in a form you can actually use
  • Delete your account: deletes immediately, with no waiting period

Excluded from deletion are billing data, kept for ten years under § 147 of the German Fiscal Code (AO); access logs, which we strip of personal details rather than delete; and our support correspondence with you, which is deleted three years after the last message. Deleting your account does not shorten that period.

6. Data Security and Encryption

We take the security of your and your patients' data very seriously. The following measures are implemented:

🔒 Encryption At Rest

  • AES-256 encryption
  • Encryption keys derived per user
  • Patient names, diagnoses, notes encrypted

🔐 Encryption In Transit

  • TLS 1.3 for all connections
  • HTTPS-only
  • HSTS enabled

👤 Access Control

  • Password required (min. 8 characters)
  • Optional: 2FA
  • Automatic sign-out after 30 min without interaction
  • Role-based permissions

🛡️ Infrastructure Security

  • Firewall-protected servers
  • DDoS protection
  • Regular security updates
  • Daily encrypted backups

Tenant Separation:

  • Strict data separation between therapists
  • One therapist can never see another therapist's data
  • Encryption keys derived per user

7. Your Rights as a Therapist (User)

You have the following data protection rights regarding your own data:

✓ Right of Access (Art. 15 GDPR)

You can request a copy of all data stored about you at any time. You can view your profile data through your account dashboard.

✓ Right to Rectification (Art. 16 GDPR)

You can request corrections if your data is inaccurate or incomplete. You can edit profile data yourself in your account.

✓ Right to Erasure (Art. 17 GDPR)

You can request deletion of your data when:

  • The data is no longer necessary
  • You withdraw your consent
  • You object to processing
  • The data was unlawfully processed

Practical: Use the "Delete Account" function in your profile. Deletion happens immediately, with no waiting period. Individual patients and sessions can be deleted one at a time, also immediately. See section 5 for the exceptions and for what happens in backups.

✓ Right to Data Portability (Art. 20 GDPR)

You can receive your data in a structured, commonly used format. Practical: Export function for all your data (JSON/CSV format).

✓ Right to Object (Art. 21 GDPR)

For processing based on legitimate interests, you can object. For direct marketing, you can object at any time (opt-out in every marketing email).

✓ Right to Complain (Art. 77 GDPR)

You have the right to lodge a complaint with a data protection supervisory authority.

For Rhineland-Palatinate:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz

Hintere Bleiche 34, 55116 Mainz

poststelle@datenschutz.rlp.de

Contact to exercise your rights:

Email: info@intermac.de
We respond to requests within 30 days.

8. Cookies and Tracking

We use only technically necessary cookies for platform operation:

Cookie NamePurposeDuration
session_tokenAuthentication (login session)30 days or until logout
csrf_tokenProtection against CSRF attacks1 day

✓ No tracking or marketing cookies

We do not use Google Analytics, social media tracking pixels (Facebook, LinkedIn), advertising cookies, or third-party cookies.

9. Newsletter and Marketing

For newsletter signup, we use double opt-in. You can unsubscribe at any time (link in every email). Legal basis: Art. 6(1)(a) GDPR (consent).

10. Social Media and External Links

Our website may contain links to external websites. We have no control over their privacy practices. When you click, you leave our area of responsibility.

11. Minors

Our platform is intended for adult professionals. We do not knowingly collect data from persons under 18.

12. Automated Decisions and Profiling

We use AI (OpenAI) only as assistance (transcription, report generation). All final decisions are made exclusively by the therapist. There is no automated decision-making within the meaning of Art. 22 GDPR.

No profiling: We do not create profiles for marketing or creditworthiness purposes.

13. Data Breaches and Incident Response

In case of a data breach:

  • To therapists: We will notify you within 24 hours by email
  • To supervisory authority: Notification within 72 hours (Art. 33 GDPR)
  • To patients: You as the therapist are responsible for notifying your patients (Art. 34 GDPR)

14. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy. We will notify you of material changes by email (at least 14 days in advance).

Current version: Always available at www.psynex.de/privacy-policy

15. Contact and Questions

For questions, requests, or complaints about data protection, contact us:

Intermac systems

Norbert Doetsch

Sendnicher Str. 58a

56072 Koblenz, Germany

Email: info@intermac.de

Phone: +49-151-2755-5942

Response time: We respond to requests within 30 days.

Effective: August 2026 | Version: 1.3

This Privacy Policy was prepared with the utmost care. It does not constitute legal advice. For specific questions, please consult a data protection expert or attorney.

Privacy Policy | Psynex | Psynex