Privacy Policy (Professional Portal)
Draft under legal review · June 2026
1. Controller
[Operator], Republic of Chile. Contact: contacto@sanemos.ai. This policy covers the Therapist's own data. Processing of patient data is governed by the Data Processing Agreement (DPA).
2. Legal framework
Law No. 19,628 on the Protection of Private Life and Law No. 21,719 modernizing it, together with applicable complementary regulations of the Republic of Chile.
3. Therapist data we process
Account data (name, email, encrypted password); professional profile (license number, bio, training, credentials, specialties); billing and subscription data (handled with the payment processor); usage and technical data (IP, browser, timestamps).
4. Purposes
Provide and manage the professional portal; process subscription and payments; display the Therapist's directory profile; service communications; comply with legal obligations. We do not use this data for third-party advertising and do not sell it.
5. Providers (Sub-processors)
As applicable, we share data with: Supabase (database, auth, files); Vercel (hosting); Flow (subscription payments); LiveKit (video calls); Resend (transactional email); and, for AI features, one of OpenAI / Anthropic / Google (Gemini) per the active configuration. All act under confidentiality and security obligations.
6. Patient data
Regarding patient clinical data, the Operator acts as Processor on behalf of the Therapist (Controller); such processing is governed by the DPA.
7. International transfers
Some providers are outside Chile (mainly the USA). By accepting, you acknowledge data may be processed in those countries, requiring providers to apply measures equivalent to Chilean law (encryption in transit and at rest, access control, confidentiality).
8. Retention
We retain Therapist data while the account is active and delete it within 30 days of cancellation, except for legal obligations (e.g., accounting/tax records of payments).
9. Rights
Access, rectification, cancellation, and objection per law. Exercise at contacto@sanemos.ai; response within 15 business days.
10. Security
TLS encryption in transit; role-based access control (RLS); encrypted passwords; encryption of patient intake forms. No system is completely secure; we will notify breaches as required by law.
11. Changes and contact
We will post changes with 15 days' notice if significant. contacto@sanemos.ai.