Security
Nothing to store, nothing to lose
The session exists only during the session. The rest comes down to a few technical metadata fields, kept for twelve months.
The guarantees
End-to-end encryption
The audio and video stream is encrypted between participants. Our servers relay it without being able to read it.
No session recorded
Recording is neither offered nor possible to switch on. There is no session file, and therefore no possible leak.
Hosting in the European Union
Servers and backups stay in European Union regions.
Minimal metadata
Timestamp, duration, session identifier. No content, no clinical note, no patient record.
Restricted, logged access
Access to the systems is named, logged, and limited to the people who need it.
Waiting room and code
The patient enters with a single-use code. You open the door, nobody else.
Processors
We only have two. The list is kept up to date on this page.
| Processor | Role | Location |
|---|---|---|
| Amazon Web Services | Hosting of the application and the databases | European Union regions |
| Stripe | Subscription payments and invoicing | European Union, standard contractual clauses for any processing outside the Union |
Retention periods
Session metadata is kept for twelve months, then deleted automatically.
Account data is kept for the duration of the subscription, then twelve months. Invoices are kept for seven years, a period required by Belgian accounting law.
Your rights
The General Data Protection Regulation grants you rights, which we apply free of charge.
- Access to your data
- Rectification
- Erasure
- Restriction of processing
- Objection
- Portability
- Complaint to the Data Protection Authority
A precise question about security
Write to us. We answer with the technical detail, not with a brochure.
Create my account