Who we are
Soveria Platform (hereinafter — "Soveria", "we", "our") is a clinical measurement-based care platform for mental health professionals and their clients.
We take the protection of your personal data seriously. This Privacy Policy describes what data we collect, how we use it, and what rights you have regarding your data.
Soveria Platform · Email: privacy@soveria.co · DPO: dpo@soveria.co
Data we collect
Data you provide
- Registration data: name, email, password (hashed)
- Professional data (for specialists): qualifications, specialization, license number
- Clinical data: assessment results, clinical notes, treatment protocols
- Session data: records of therapeutic sessions, notes
- Contact data: phone, address (optional)
- Booking data: when you request a session through a specialist's public booking page, the name, email and optional message you provide — used only to arrange that session and shared with that specialist
- Calendar data (for specialists who connect an external calendar): the start and end times of your events and all-day markers, used to show when you are busy. Event identifiers are stored only as a one-way hash. Event titles are shown to you only while you review a busy block and are never stored; event descriptions, guests and locations are never accessed.
Data we collect automatically
- Technical data: IP address, browser type, operating system
- Usage data: visit times, pages viewed, platform actions
- Cookies and similar technologies (see Cookie Policy)
- Session security data: sign-in session identifiers and a device/IP fingerprint, used to keep you signed in and to detect and block reuse of a stolen session
⚠️ Clinical health data belongs to a special category of personal data (Art. 9 GDPR). We process it exclusively based on your explicit consent.
Processing purposes
We process your data for the following purposes:
| Purpose | Legal basis | Data category |
|---|---|---|
| Service provision | Contract performance (Art. 6(1)(b)) | Registration, professional |
| Clinical data processing | Explicit consent (Art. 9(2)(a)) | Clinical, assessment data |
| Technical support | Legitimate interest (Art. 6(1)(f)) | Contact, technical |
| Platform security | Legitimate interest (Art. 6(1)(f)) | Technical, logs, session security |
| Legal compliance | Legal obligation (Art. 6(1)(c)) | All categories |
We use your data only for the stated purposes. Each purpose has a specific legal basis under GDPR.
Third-party sharing
We share your data only in the following cases:
- Your therapist (for clients) — within the therapeutic relationship
- Subcontractors (sub-processors) — for technical platform operations
- By legal requirement — if obligated by court order or regulator request
Data Sub-processors
| Provider | Purpose | Country |
|---|---|---|
| Timeweb Cloud (ООО «Таймвеб») | Server hosting, data storage | Russia (152-FZ) |
| Resend Inc. | Transactional email delivery | USA (SCC) |
| Stripe Inc. | Payment processing | USA (SCC) |
| Google LLC | Calendar synchronisation: reading your busy times and all-day markers. When you enable it: writing Soveria session times to your calendar | USA |
Calendar synchronisation is optional and is set up by the specialist. When a specialist connects an external calendar, the times and busy status of their own calendar events transit that provider's infrastructure (Google LLC, USA). This cross-border transfer takes place on the basis of the specialist's explicit authorisation given at connection. Soveria does not store any client health data through the calendar integration — only the specialist's busy-time blocks are saved; event titles, which the specialist controls, are shown to the specialist for review and are not stored. Writing Soveria session times back to a connected calendar is available only when the specialist enables it; these events contain only the session time and a neutral title (for example "Soveria: Therapy") and never include a client's name or any other client details.
Retention periods
| Data type | Retention period | Basis |
|---|---|---|
| Registration data | Until account deletion | Contract performance |
| Clinical data | 5 years after treatment ends | Professional standards |
| Technical logs | 90 days | Legitimate interest |
| Financial data | 7 years | Tax legislation |
| Consent records | 3 years after withdrawal | Consent verification |
| Session security tokens | Up to 30 days (sliding), plus 7 days forensic | Account security |
| Calendar busy data (imported) | Deleted when the calendar is disconnected; busy intervals refreshed on each sync | Legitimate interest (scheduling) |
When you delete your account, your registration data is removed within 30 days. Clinical data may be retained longer per professional standards.
Your rights
Right of access
Request a copy of all your personal data we process
Right to rectification
Correct inaccurate or incomplete personal data
Right to erasure
Right to be forgotten — request deletion of your data
Right to portability
Receive your data in a machine-readable format
Right to object
Object to the processing of your data
Right to restriction
Restrict the processing of your personal data
To exercise any of these rights, contact our DPO: dpo@soveria.co. We will process your request within 30 days.
Security
- TLS 1.3 for all connections
- JWT authentication with short-lived tokens
- Password hashing (bcrypt, 12 rounds)
- Rate limiting on sensitive endpoints
- Role-based access control (RBAC)
- Regular encrypted backups
- Servers in Timeweb Moscow, Russia (152-FZ)
In case of a data breach, we will notify the supervisory authority within 72 hours (Art. 33 GDPR) and affected individuals without undue delay (Art. 34 GDPR).
Cookies
We use a limited set of cookies for platform operation. For detailed information about the cookies we use and how to manage your preferences, please see our Cookie Policy.
Policy changes
We may update this Privacy Policy. We will notify you of material changes via email or through a platform notification.
By continuing to use the platform after changes are published, you accept the updated policy.
v1.6 (Jun 2026) — Google Calendar integration & Limited Use disclosure; calendar sub-processor (Google LLC), event time/all-day data · v1.5 (Jun 2026) — Refresh-token rotation & session-security data · v1.3 (Mar 2026) — Updated sub-processors · v1.2 (Jan 2026) — Added retention periods · v1.0 (Oct 2025) — First version
Contact DPO
If you have questions about our Privacy Policy or wish to exercise your rights, contact our Data Protection Officer (DPO).
Google Calendar integration
When you connect a Google account, Soveria accesses the following Google data — only to provide the calendar-sync feature you turn on:
- Availability (busy/free): to block your Soveria public-booking slots when you are already busy, we work out your busy and free intervals from the start and end times of the events in the calendars you select — read as described under Calendar events below.
- Calendar list: we read the names and identifiers of your calendars (read-only) so you can choose which ones to use.
- Calendar events: we read the start and end times and all-day markers of your events to keep your availability current; the title of an all-day event is shown to you only while you review it and is never stored. Event descriptions, guests and locations are never read. When you turn on adding sessions, Soveria writes, updates and deletes only the session events it creates in the calendar you choose — marked as ours — and never changes your other events.
Storage. OAuth tokens are encrypted at rest (AES-256-GCM) on our servers in Russia. From your calendar we store only anonymised busy intervals (start and end times and an all-day marker) and a one-way hash of each event identifier — never event content.
Sharing. We do not sell or share this data. Google LLC (USA) acts as a sub-processor for this feature, and the cross-border transfer takes place on the basis of your explicit authorisation when you connect.
Retention and deletion. Disconnecting a calendar revokes Soveria's access, deletes the imported busy data and removes any future Soveria-created events; deleting your account does the same automatically.
Soveria's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Referral program
If you join Soveria through another specialist's referral link, or invite colleagues with your own link, we process a small amount of billing-class data to operate the program. This is not clinical data and is never linked to your clients or their records.
Referral cookie. Opening a referral link stores a first-party cookie named sov_ref in your browser for up to 90 days. It holds only the opaque referral token — no name, email or clinical data — and lets us record who referred you when you register. It is not used for advertising or cross-site tracking, and you can remove it at any time through your browser.
- Attribution — which specialist referred you, recorded once at registration and never changed.
- Rewards ledger — the free months or commission a referrer earns from referred subscriptions, and how they are settled.
- Fraud-prevention check — when a referred specialist first pays, we compare the masked card number already held for billing (the referred's and the referrer's) to detect self-referral and abuse. We collect and store no additional card data for this; if they match, the reward is placed on hold for a member of our team to review.
Legal basis. For the referrer, processing is necessary to perform the referral agreement (GDPR Art. 6(1)(b)). For the referred specialist, and for fraud prevention, we rely on our legitimate interest in operating and protecting the program (Art. 6(1)(f); fraud prevention is a recognised legitimate interest under Recital 47). Under Federal Law 152-FZ this corresponds to processing necessary to perform a contract and for the operator's legitimate interests (Art. 6(1) items 5 and 7). No separate consent is required and we do not add a consent step.
Your choices. A referred specialist can object to the referral program at any time by emailing dpo@soveria.co; we will then stop earning new rewards from your activity. We may continue limited fraud-prevention processing where we have compelling legitimate grounds or need it to establish or defend a legal claim. If a reward is ever placed on hold, you can ask us to review the decision at the same address.
A referral reward is never refused automatically. A fraud-prevention hold only pauses the reward until a member of our team reviews it, and a hold applied by mistake — for example, colleagues who genuinely share one payment card — is released.