Effective Date: Sept. 12, 2023 for UK customers
Effective Date: Jul. 1, 2024 for customers outside UK
Konfidens' Data Privacy Policy details how Konfidens collects, utilizes, and deletes your data. By using the Konfidens platform (the "Platform") and making use of your Konfidens account (the "Account") and all its related features, including session notes, appointments, payments, and video chat (the "Services"), you acknowledge that your data related to your use of our Services is processed in accordance with the following privacy policy. This privacy policy, along with any product-specific privacy policies (collectively, the "Privacy Policy"), outlines (i) the data we collect during your access and use of the Services; (ii) how we use this data; and (iii) the measures we have in place to safeguard your data. Please consider the Privacy Policy as a supplementary document to our terms and conditions.
Data Controller and Processor
The services are operated by Mindcare AS (Business Registration Number: 925 239 070), headquartered at Rathkes gate 5B, 0558 Oslo. You can reach us via email at hello@konfidens.com.
Mindcare acts as the data controller for information collected from its clients. This typically includes data necessary for service delivery and fulfilling our obligations to our customers.
Our customers utilize our services to manage their mental health care practices. As part of this process, data pertaining to their clients is stored and processed on our platform. For this data, Mindcare assumes the role of the data processor, while the account holder serves as the data controller.
We aim to provide you with transparent privacy policy. If you have any inquiries or concerns regarding any aspects of these terms not covered here, please don't hesitate to reach out to us at hello@konfidens.com.
We process information about you in the following situations:
The personal information collected is processed based on the following:
Legal Basis: The legal foundation we operate under for the information pertaining to platform users is established in accordance with § 1 of the Personal Data Act, in conjunction with Article 6(1)(b) of the General Data Protection Regulation (GDPR). This legal framework is anchored in the agreements entered into by platform users, as stipulated in our terms of use.
Data Processing Agreement: Regarding the information that our customers input into the platform, we assume the role of a data processor, governed by the provisions set forth in our data processing agreement. This agreement clearly outlines our responsibilities and obligations in managing this data.
The legal foundation for data processing relies on your consent to utilize our platform for the services we offer, in accordance with Article 9(2)(a) of the General Data Protection Regulation (GDPR). When using our platform as a patient, this consent is granted for the following purposes:
It's important to note that beyond these specified purposes, your healthcare provider assumes the role of the data controller for information related to you, while we act as the data processor for this information.
App includes the domain app.konfidens.com, app.konfidens.no and app.konfidens.uk
For security and privacy reasons, Konfidens does not use any third-party cookies on the website. Konfidens only uses its own cookies to provide functionality related to user-friendliness and security, but we strive to keep this number to a minimum.
You can read more about our cookies on this page.
Konfidens adheres to the information security and privacy standards set by the Norwegian Directorate of eHealth within the healthcare sector. Consequently, a majority of your actions as a healthcare professional are systematically recorded. These actions encompass, among others:
Each log entry comprises a user identifier, the date of the action, and specifics about your login method during that session. In cases involving particularly sensitive actions, such as printing notes from a patient's record, we also log your IP address for added security and accountability.
Konfidens uses a limited number of subcontractors to provide services on the platform. In cases where the processing of personal information is necessary, we require the data to be processed and stored in Europe, in compliance with the General Data Protection Regulation (GDPR).
To provide the Services, we rely on select data subprocessors, which process different categories of data. Processors never store data outside of the scope of their specific purpose. Subprocessors are as follows:
If you have created a user account but have not been active for a period of 4 years, we will send you a notice that your account will be archived and deactivated. Archiving involves anonymizing your data and occurs 6 months after the notice, unless you log in again in the meantime. Personal information processed under Konfidens' legitimate interests will be stored as long as we are required to keep them. For example, if you have made payments on the platform, information we are legally required to store according to Norwegian accounting regulations will be retained for 10 years after the end of the fiscal year.
You have the right to receive a response without undue delay, and no later than one month. Contact us at hello@konfidens.com if you wish to exercise any of these rights.
If you are a patient and require corrections or deletions of information entered into the platform by your healthcare provider, kindly reach out to the therapist or clinic responsible for your treatment. Please be aware that healthcare professionals may have legal obligations to maintain records of individuals who have received healthcare services and the nature of the care provided, as stipulated by national legislations.
We hope you will let us know if you believe we are not in compliance with the rules in the Personal Data Act. In that case, please contact us through the contact or channel you have already established with us.