PsyLab
Privacy Policy
1. Data Controller
The Data Controller of personal data collected through the PsyLab platform (psylab.cloud) is PsyLab.
2.1 Data provided directly by the user
- Name, surname and email address (account registration)
- Billing data (name, address, tax code / VAT number) for the management of subscriptions
- Contents inserted in the platform (messages sent to the AI, texts, notes)
- Information on the profession (specialization, type of activity)
2.2 Data collected automatically
- IP address and device information
- Browser, operating system, language
- Pages visited, features used, duration of sessions
- Technical logs and performance data
2.3 Payment data
Credit card and payment instrument data are managed exclusively by third-party payment providers. PsyLab does not access or store complete data of payment instruments.
4. Sensitive data and clinical content
PsyLab is a tool intended for mental health professionals. The user is responsible for the contents he inserts into the platform. It is expressly recommended not to enter identifying data of real patients (name, surname, tax code, date of birth or any information that allows direct or indirect identification).
If the user enters data relating to the health of third parties (data belonging to the special categories referred to in Article 9 GDPR), he does so under his own exclusive responsibility as independent data controller. In this case, the user is required to have an adequate legal basis for such processing (e.g. patient consent) and to inform PsyLab via a specific request to evaluate the stipulation of a co-owner responsibility agreement or appointment as data controller.
5. How we use content fed into the AI
Messages and content sent to the PsyLab AI assistant are processed to generate the requested responses. PsyLab undertakes to:
- not use the contents inserted by users to train third-party AI models without explicit consent;
- keep the contents of the sessions for the time strictly necessary to provide the Service;
- apply technical measures of pseudonymisation and encryption on data in transit and at rest.
7. Sharing data with third parties
PsyLab does not sell your personal data. The data can be shared with:
- Cloud infrastructure providers (e.g. AWS) for hosting the Service, appointed as Data Processors
- Payment providers for managing subscriptions
- Analysis providers (e.g. Google Analytics) for aggregate usage statistics
- AI model providers (e.g. OpenAI) for processing requests, exclusively via APIs with data processing agreements (DPA) in compliance with GDPR
- Competent authorities in the cases provided for by the law
All third-party suppliers are selected from among subjects who guarantee adequate security measures and compliance with the GDPR.
8. Non-EU data transfer
Some of the third-party providers mentioned (e.g. OpenAI, AWS) may process data in countries outside the European Economic Area. In such cases, PsyLab guarantees that the transfers take place in compliance with the guarantees provided by the GDPR (Standard Contractual Clauses or adequacy decisions of the European Commission).
9. Rights of the interested party
Pursuant to Articles 15-22 of the GDPR, the user has the right to:
- Access - obtain a copy of their personal data processed
- Rectification - correct inaccurate or incomplete data
- Deletion ("right to be forgotten") - request the deletion of their data
- Limitation - limit the processing in certain cases
- Portability - receive your data in a structured and machine-readable format
- Objection - object to processing based on legitimate interest
- Revocation of consent - at any time, without prejudice to previous processing
To exercise any right, simply send a request to: info@psylab.cloud
PsyLab will respond within 30 days of receiving the request.
11. Data security
PsyLab takes appropriate technical and organizational measures to protect personal data from unauthorized access, alteration, disclosure or destruction, including: TLS encryption in transit, encryption at rest, access control with two-factor authentication, continuous infrastructure monitoring.
In the event of a data breach resulting in a risk to user rights, PsyLab will notify the incident to the Guarantor Authority for the protection of personal data within 72 hours and will promptly inform the users involved, pursuant to Art. 33-34 GDPR.
12. Minors
The Service is not intended for persons under the age of 18. PsyLab does not knowingly collect personal data from minors. In case of unauthorized use by minors, parents or guardians may request deletion by writing to info@psylab.cloud.
13. Complaints
The user has the right to lodge a complaint with the Guarantor for the protection of personal data (www.garanteprivacy.it) if he believes that the processing of his personal data is in violation of the GDPR.
14. Changes to the Privacy Policy
PsyLab reserves the right to update this Privacy Policy. Substantial changes will be communicated via email at least 15 days in advance. The updated version will always be available at psylab.cloud/privacy-policy.
15. Contacts
For any questions regarding the processing of your personal data: info@psylab.cloud
