Last revision Aug 5 2026
Effective date: Sep 5 2026
Konfidens is operated by Mindcare AS (org. no. 925 239 070), Oslo, Norway.
We use a limited number of third-party providers to deliver the Konfidens platform. This page lists all of them. It is maintained as the single authoritative list and is incorporated by reference into our Data Processing Agreement and our Privacy Policy.
We operate in two distinct roles, and the distinction determines which table a provider appears in:
- As data processor — for patient and client data entered into the platform by practitioners. The practitioner or clinic is the data controller; we process on their documented instructions. Providers we engage for this purpose are sub-processors under Article 28 GDPR / UK GDPR.
- As data controller — for data about practitioners, clinics, website visitors and prospective customers, which we process in our own right to operate and sell the service. Providers we engage for this purpose are our own processors, not sub-processors of our customers' data.
We require all providers to process data solely for their specified purpose, under a written data processing agreement, and in compliance with applicable data protection law.
1. Sub-processors — patient and client data
These providers may process personal data that practitioners enter into the platform about their patients, including special category health data under Article 9 GDPR / UK GDPR.
| Sub-processor |
Legal entity |
Purpose |
Categories of data |
Processing location |
| Amazon Web Services |
Amazon Web Services EMEA SARL (Luxembourg) |
Hosting, database and file storage for the entire platform |
All platform data, including health data, identity data, contact data, appointment data and technical logs |
Frankfurt, Germany (eu-central-1) |
| Microsoft Azure |
Microsoft Ireland Operations Limited |
AI Scribe — text processing and session summarisation |
Text transcripts of therapy sessions (health data). No audio. Deleted from Microsoft data centres within 48 hours |
Norway |
| Speechmatics |
Speechmatics Ltd (United Kingdom) |
AI Scribe — speech-to-text transcription |
Live session audio (health data). Transcribed in real time; no audio files are stored at any point |
United Kingdom |
| Whereby |
Whereby AS (Norway) |
Secure video consultations |
Video and audio stream (health data), plus connection metadata. Media is transmitted peer-to-peer where a direct connection is available; where it is not, media is relayed via Whereby's servers |
EU/EEA |
| Adyen |
Adyen N.V. (Netherlands) |
Processing of patient payments to the practitioner, and refunds |
Payment card data, transaction history, billing details |
Europe |
| GatewayAPI |
GatewayAPI A/S (Denmark) |
SMS for authentication and appointment reminders |
Phone number, message content |
Germany, Finland, Denmark |
| Brevo |
Brevo SAS (France) |
Transactional email sent from the platform |
Email address, recipient name, subject and content. No health information is sent by email |
Germany, Belgium, Ireland |
| Criipto |
Criipto ApS (Denmark) |
BankID identification and authentication (Norwegian users only) |
First name, last name, date of birth |
Norway |
| hCaptcha |
Intuition Machines, Inc. (United States) |
Bot detection and fraud prevention on login and registration |
Browser and operating system characteristics, IP address, interaction behaviour |
Primarily EU; may include the United States — see note 3 |
Notes
- Adyen is separately a licensed credit institution supervised by De Nederlandsche Bank. In relation to fraud screening, anti-money-laundering and regulatory reporting, Adyen acts as an independent data controller under its own legal obligations rather than as our sub-processor.
- Whereby does not store recordings of consultations. Media travels directly between participants where network conditions permit; where a direct connection cannot be established, it is relayed through Whereby's infrastructure within the EU/EEA. Connection metadata is processed in all cases.
- hCaptcha is operated by Intuition Machines, Inc., a United States company. Analytics data is stored in the EU by default and sessions are processed on equipment close to the end user; limited sampled log metadata, most often IP addresses, may be processed in either Europe or the United States and is retained only for a short period. Intuition Machines is certified under the EU–US, UK–US and Swiss–US Data Privacy Frameworks, and its standard Data Processing Addendum — incorporated into its Master Terms of Service — additionally puts the EU Standard Contractual Clauses and the UK International Data Transfer Addendum in place. hCaptcha holds ISO 27001, ISO 27701 and SOC 2 Type II certification.
2. Vendors — practitioner, customer and website data
These providers process data about practitioners, clinics, prospective customers and website visitors, where Mindcare AS is the data controller. They do not have access to patient records.
| Vendor |
Legal entity |
Purpose |
Categories of data |
Processing location |
| Chargebee |
Chargebee Inc. |
Subscription billing, invoicing and revenue management |
Name, email address, billing address, payment details, subscription history |
Frankfurt, Germany (AWS eu-central-1, EU hosting region) |
| Google Calendar (optional) |
Google Ireland Limited |
Calendar sync: read busy time from the users’s Google Calendar; write anonymized Konfidens appointments onto a dedicated “Konfidens” calendar |
Google account email; calendar event metadata (title, description, location, start/end time); OAuth tokens. Events written from Konfidens contain service name and time only — not patient names or clinical notes |
Google’s infrastructure. Transfers from the EEA/UK to the United States, where they occur, rely on Google’s EU–US / UK–US Data Privacy Framework certification and Standard Contractual Clauses as described in section 3 |
| Google Workspace |
Google Ireland Limited |
Business email, documents and internal collaboration |
Name, email address, correspondence content |
EU/EEA |
| Google Calendar |
Google Ireland Limited |
Optional calendar sync for preventing double bookings |
Google account email; title, description, location, start/end time of calendar events |
Google’s infrastructure. Transfers from the EEA/UK to the United States, where they occur, rely on Google’s EU–US / UK–US Data Privacy Framework certification and Standard Contractual Clauses as described in section 3 |
| Intercom |
Intercom, Inc. (United States) |
Customer support chat and support email |
Name, email address, support conversation content |
United States — see section 3 |
| Bunny.net |
BunnyWay d.o.o. (Slovenia) |
Video hosting and content delivery for konfidens.com marketing pages only |
IP address, browser and device information of website visitors |
EU/EEA |
Note on support conversations
Support conversations are handled in Intercom and Google Workspace. Practitioners should not include patient-identifying information in support requests.
Note on Google Calendar
Connecting Google Calendar is optional and is initiated by the practitioner. Google processes the practitioner’s own Google account as an independent controller. Copies of event metadata that we store in order to operate the sync are hosted on AWS in Frankfurt (see Amazon Web Services in section 1). Patient names and session notes are not written to Google Calendar.
3. International transfers
The Konfidens platform is designed so that patient data is stored and processed within the EEA and the United Kingdom.
- Between the EEA and the United Kingdom. The European Commission has adopted an adequacy decision for the United Kingdom under Article 45 GDPR, and the United Kingdom has adopted corresponding adequacy regulations for the EEA. Transfers in both directions therefore require no additional safeguards. Both decisions are subject to periodic review.
- Norway. Norway is a member of the EEA. The GDPR applies as incorporated by personopplysningsloven (LOV-2018-06-15-38).
- Transfers to the United States. Where a provider processes data in the United States, we rely on that provider's certification under the EU–US Data Privacy Framework for transfers from the EEA, and under the UK Extension to the EU–US Data Privacy Framework for transfers from the United Kingdom. Where a provider is not certified under both, we put in place the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by a transfer risk assessment.
Current certification status can be verified at dataprivacyframework.gov.
4. Changes to this list
We will inform controllers of any intended addition or replacement of a sub-processor listed in section 1, so that they have an opportunity to object.
Notice period: We notify by email at least 14 days before a new sub-processor begins processing patient data. Notice is given once we have decided to engage a provider; it does not depend on when integration or development work is completed.
Objections: If you object on reasonable data protection grounds, tell us within the notice period and we will work with you to resolve it, including by offering an alternative configuration where one is available. If we cannot resolve the objection, you may terminate the affected Services on written notice, without penalty, before the change takes effect. Continued use of the Services after the notice period constitutes acceptance.
Changes that do not require advance notice:
- Replacing a sub-processor with an affiliate or corporate successor of that same sub-processor, where the purpose, categories of data and processing location are unchanged.
- Changes to the vendors listed in section 2, which do not process patient data.
- Changes required urgently to maintain the security, integrity or continuity of the Services, or to comply with a legal obligation. Where this applies, we notify controllers as soon as reasonably practicable after the change, and the right to object and terminate set out above applies from the date of that notice.
Notifications are sent via email to all admin users with an active subscription. Controllers are responsible for ensuring they can receive email from us.
5. Supervisory authorities
@
6. Contact
Questions about this list, or requests for the underlying data processing agreements, can be sent to hello@konfidens.com.
Representative in the United Kingdom (Article 27 UK GDPR)
Euverify Ltd, 3rd Floor, 86–90 Paul Street, London EC2A 4NE, United Kingdom
Email: gdpr@euverify.com