Who we are

Soveria Platform (hereinafter — "Soveria", "we", "our") is a clinical measurement-based care platform for mental health professionals and their clients.

We take the protection of your personal data seriously. This Privacy Policy describes what data we collect, how we use it, and what rights you have regarding your data.

Data Controller

Soveria Platform · Email: privacy@soveria.co · DPO: dpo@soveria.co

Data we collect

Data you provide

  • Registration data: name, email, password (hashed)
  • Professional data (for specialists): qualifications, specialization, license number
  • Clinical data: assessment results, clinical notes, treatment protocols
  • Session data: records of therapeutic sessions, notes
  • Contact data: phone, address (optional)
  • Booking data: when you request a session through a specialist's public booking page, the name, email and optional message you provide — used only to arrange that session and shared with that specialist
  • Calendar data (for specialists who connect an external calendar): the start and end times of your events and all-day markers, used to show when you are busy. Event identifiers are stored only as a one-way hash. Event titles are shown to you only while you review a busy block and are never stored; event descriptions, guests and locations are never accessed.

Data we collect automatically

  • Technical data: IP address, browser type, operating system
  • Usage data: visit times, pages viewed, platform actions
  • Cookies and similar technologies (see Cookie Policy)
  • Session security data: sign-in session identifiers and a device/IP fingerprint, used to keep you signed in and to detect and block reuse of a stolen session

⚠️ Clinical health data belongs to a special category of personal data (Art. 9 GDPR). We process it exclusively based on your explicit consent.

Processing purposes

We process your data for the following purposes:

PurposeLegal basisData category
Service provisionContract performance (Art. 6(1)(b))Registration, professional
Clinical data processingExplicit consent (Art. 9(2)(a))Clinical, assessment data
Technical supportLegitimate interest (Art. 6(1)(f))Contact, technical
Platform securityLegitimate interest (Art. 6(1)(f))Technical, logs, session security
Legal complianceLegal obligation (Art. 6(1)(c))All categories
What this means for you

We use your data only for the stated purposes. Each purpose has a specific legal basis under GDPR.

Third-party sharing

We share your data only in the following cases:

  • Your therapist (for clients) — within the therapeutic relationship
  • Subcontractors (sub-processors) — for technical platform operations
  • By legal requirement — if obligated by court order or regulator request

Data Sub-processors

ProviderPurposeCountry
Timeweb Cloud (ООО «Таймвеб»)Server hosting, data storageRussia (152-FZ)
Resend Inc.Transactional email deliveryUSA (SCC)
Stripe Inc.Payment processingUSA (SCC)
Google LLCCalendar synchronisation: reading your busy times and all-day markers. When you enable it: writing Soveria session times to your calendarUSA

Calendar synchronisation is optional and is set up by the specialist. When a specialist connects an external calendar, the times and busy status of their own calendar events transit that provider's infrastructure (Google LLC, USA). This cross-border transfer takes place on the basis of the specialist's explicit authorisation given at connection. Soveria does not store any client health data through the calendar integration — only the specialist's busy-time blocks are saved; event titles, which the specialist controls, are shown to the specialist for review and are not stored. Writing Soveria session times back to a connected calendar is available only when the specialist enables it; these events contain only the session time and a neutral title (for example "Soveria: Therapy") and never include a client's name or any other client details.

Retention periods

Data typeRetention periodBasis
Registration dataUntil account deletionContract performance
Clinical data5 years after treatment endsProfessional standards
Technical logs90 daysLegitimate interest
Financial data7 yearsTax legislation
Consent records3 years after withdrawalConsent verification
Session security tokensUp to 30 days (sliding), plus 7 days forensicAccount security
Calendar busy data (imported)Deleted when the calendar is disconnected; busy intervals refreshed on each syncLegitimate interest (scheduling)
Account deletion

When you delete your account, your registration data is removed within 30 days. Clinical data may be retained longer per professional standards.

Your rights

Right of access

Request a copy of all your personal data we process

Right to rectification

Correct inaccurate or incomplete personal data

Right to erasure

Right to be forgotten — request deletion of your data

Right to portability

Receive your data in a machine-readable format

Right to object

Object to the processing of your data

Right to restriction

Restrict the processing of your personal data

To exercise any of these rights, contact our DPO: dpo@soveria.co. We will process your request within 30 days.

Security

  • TLS 1.3 for all connections
  • JWT authentication with short-lived tokens
  • Password hashing (bcrypt, 12 rounds)
  • Rate limiting on sensitive endpoints
  • Role-based access control (RBAC)
  • Regular encrypted backups
  • Servers in Timeweb Moscow, Russia (152-FZ)
Incident notification

In case of a data breach, we will notify the supervisory authority within 72 hours (Art. 33 GDPR) and affected individuals without undue delay (Art. 34 GDPR).

Cookies

We use a limited set of cookies for platform operation. For detailed information about the cookies we use and how to manage your preferences, please see our Cookie Policy.

Policy changes

We may update this Privacy Policy. We will notify you of material changes via email or through a platform notification.

By continuing to use the platform after changes are published, you accept the updated policy.

Version history

v1.6 (Jun 2026) — Google Calendar integration & Limited Use disclosure; calendar sub-processor (Google LLC), event time/all-day data · v1.5 (Jun 2026) — Refresh-token rotation & session-security data · v1.3 (Mar 2026) — Updated sub-processors · v1.2 (Jan 2026) — Added retention periods · v1.0 (Oct 2025) — First version

Contact DPO

If you have questions about our Privacy Policy or wish to exercise your rights, contact our Data Protection Officer (DPO).

Data Protection Officer
We are always ready to answer your questions
dpo@soveria.co
Primary communication channel
30 days
Maximum response time for requests
BfDI
Supervisory authority: Bundesbeauftragter für den Datenschutz

Google Calendar integration

When you connect a Google account, Soveria accesses the following Google data — only to provide the calendar-sync feature you turn on:

  • Availability (busy/free): to block your Soveria public-booking slots when you are already busy, we work out your busy and free intervals from the start and end times of the events in the calendars you select — read as described under Calendar events below.
  • Calendar list: we read the names and identifiers of your calendars (read-only) so you can choose which ones to use.
  • Calendar events: we read the start and end times and all-day markers of your events to keep your availability current; the title of an all-day event is shown to you only while you review it and is never stored. Event descriptions, guests and locations are never read. When you turn on adding sessions, Soveria writes, updates and deletes only the session events it creates in the calendar you choose — marked as ours — and never changes your other events.

Storage. OAuth tokens are encrypted at rest (AES-256-GCM) on our servers in Russia. From your calendar we store only anonymised busy intervals (start and end times and an all-day marker) and a one-way hash of each event identifier — never event content.

Sharing. We do not sell or share this data. Google LLC (USA) acts as a sub-processor for this feature, and the cross-border transfer takes place on the basis of your explicit authorisation when you connect.

Retention and deletion. Disconnecting a calendar revokes Soveria's access, deletes the imported busy data and removes any future Soveria-created events; deleting your account does the same automatically.

Limited Use

Soveria's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Referral program

If you join Soveria through another specialist's referral link, or invite colleagues with your own link, we process a small amount of billing-class data to operate the program. This is not clinical data and is never linked to your clients or their records.

Referral cookie. Opening a referral link stores a first-party cookie named sov_ref in your browser for up to 90 days. It holds only the opaque referral token — no name, email or clinical data — and lets us record who referred you when you register. It is not used for advertising or cross-site tracking, and you can remove it at any time through your browser.

  • Attribution — which specialist referred you, recorded once at registration and never changed.
  • Rewards ledger — the free months or commission a referrer earns from referred subscriptions, and how they are settled.
  • Fraud-prevention check — when a referred specialist first pays, we compare the masked card number already held for billing (the referred's and the referrer's) to detect self-referral and abuse. We collect and store no additional card data for this; if they match, the reward is placed on hold for a member of our team to review.

Legal basis. For the referrer, processing is necessary to perform the referral agreement (GDPR Art. 6(1)(b)). For the referred specialist, and for fraud prevention, we rely on our legitimate interest in operating and protecting the program (Art. 6(1)(f); fraud prevention is a recognised legitimate interest under Recital 47). Under Federal Law 152-FZ this corresponds to processing necessary to perform a contract and for the operator's legitimate interests (Art. 6(1) items 5 and 7). No separate consent is required and we do not add a consent step.

Your choices. A referred specialist can object to the referral program at any time by emailing dpo@soveria.co; we will then stop earning new rewards from your activity. We may continue limited fraud-prevention processing where we have compelling legitimate grounds or need it to establish or defend a legal claim. If a reward is ever placed on hold, you can ask us to review the decision at the same address.

A hold is always reviewed by a person

A referral reward is never refused automatically. A fraud-prevention hold only pauses the reward until a member of our team reviews it, and a hold applied by mistake — for example, colleagues who genuinely share one payment card — is released.