Back to home

Privacy Policy (Professional Portal)

Draft under legal review · June 2026

1. Controller

[Operator], Republic of Chile. Contact: contacto@sanemos.ai. This policy covers the Therapist's own data. Processing of patient data is governed by the Data Processing Agreement (DPA).

2. Legal framework

Law No. 19,628 on the Protection of Private Life and Law No. 21,719 modernizing it, together with applicable complementary regulations of the Republic of Chile.

3. Therapist data we process

Account data (name, email, encrypted password); professional profile (license number, bio, training, credentials, specialties); billing and subscription data (handled with the payment processor); usage and technical data (IP, browser, timestamps).

4. Purposes

Provide and manage the professional portal; process subscription and payments; display the Therapist's directory profile; service communications; comply with legal obligations. We do not use this data for third-party advertising and do not sell it.

5. Providers (Sub-processors)

As applicable, we share data with: Supabase (database, auth, files); Vercel (hosting); Flow (subscription payments); LiveKit (video calls); Resend (transactional email); and, for AI features, one of OpenAI / Anthropic / Google (Gemini) per the active configuration. All act under confidentiality and security obligations.

6. Patient data

Regarding patient clinical data, the Operator acts as Processor on behalf of the Therapist (Controller); such processing is governed by the DPA.

7. International transfers

Some providers are outside Chile (mainly the USA). By accepting, you acknowledge data may be processed in those countries, requiring providers to apply measures equivalent to Chilean law (encryption in transit and at rest, access control, confidentiality).

8. Retention

We retain Therapist data while the account is active and delete it within 30 days of cancellation, except for legal obligations (e.g., accounting/tax records of payments).

9. Rights

Access, rectification, cancellation, and objection per law. Exercise at contacto@sanemos.ai; response within 15 business days.

10. Security

TLS encryption in transit; role-based access control (RLS); encrypted passwords; encryption of patient intake forms. No system is completely secure; we will notify breaches as required by law.

11. Changes and contact

We will post changes with 15 days' notice if significant. contacto@sanemos.ai.