Privacy for provider organisations.

How Empaithy processes clinical data on behalf of clinics, hospitals and platforms. For the Empaithy journal app, see the consumer privacy policy.

Scope and roles

This notice covers the Empaithy clinical platform and API used by provider organisations. For the Empaithy journal app, see the main privacy policy.

Data we process on behalf of clinics

Intake responses, session-derived structured notes, screening scores, check-in responses, and review items, together with the clinician and account records needed to operate the workspace.

Purposes and instructions

We process clinical data only to provide the service on the documented instructions of the provider organisation.

Hosting and data residency

Hosting locations are confirmed per engagement.

Retention of clinical records

Clinical records are retained for the period the provider organisation is required to keep them, and deleted or returned on termination.

Subprocessors

We maintain a current list of subprocessors and notify provider organisations before adding a new one.

Security

Encryption in transit and at rest, encrypted identities, scoped role-based access, and audit logging. The measures are described in more detail on our safety page.

Clinician and patient rights

Requests from patients are handled through the provider organisation as controller. We support the organisation in responding within statutory timelines.

DPA and BAA

A Data Processing Agreement is available for GDPR-regulated engagements and a Business Associate Agreement for HIPAA-regulated workflows.

Questions about any of this? Talk to us.