Privacy for provider organisations.
How Empaithy processes clinical data on behalf of clinics, hospitals and platforms. For the Empaithy journal app, see the consumer privacy policy.
Last updated 3 September 2026
Scope and roles
This notice covers the Empaithy clinical platform and API used by provider organisations. For the Empaithy journal app, see the main privacy policy.
Data we process on behalf of clinics
Intake responses, session-derived structured notes, screening scores, check-in responses, and review items, together with the clinician and account records needed to operate the workspace.
Purposes and instructions
We process clinical data only to provide the service on the documented instructions of the provider organisation.
Hosting and data residency
Hosting locations are confirmed per engagement.
Retention of clinical records
Clinical records are retained for the period the provider organisation is required to keep them, and deleted or returned on termination.
Subprocessors
We maintain a current list of subprocessors and notify provider organisations before adding a new one.
Security
Encryption in transit and at rest, encrypted identities, scoped role-based access, and audit logging. The measures are described in more detail on our safety page.
Clinician and patient rights
Requests from patients are handled through the provider organisation as controller. We support the organisation in responding within statutory timelines.
DPA and BAA
A Data Processing Agreement is available for GDPR-regulated engagements and a Business Associate Agreement for HIPAA-regulated workflows.
Questions about any of this? Talk to us.