Privacy Policy
Version 2026-10-03 · updated 3 October 2026
1. Data controller
The controller is Andris Saulitis, [LEGAL FORM], reg. No. [REG. No.], address: [ADDRESS], Latvia. Data contact: [EMAIL] (also vitamodocourse@gmail.com). The service is created by psychiatrist Andris Saulitis (M.D.). Data Protection Officer: [to be appointed — verify].
2. What data we process
• Account: e-mail, password (stored only as a scrypt hash), language, settings. • Login log: time, IP address and browser of the last 20 logins (account security). • Health data (special category, Art. 9 GDPR): messages to VitaMind, voice queries (transcribed), Smart Check-Up and measurements, diaries and trackers (journal, nutrition, autism, PRN log), VitaPath progress, daily audits and personal brochures, watch data (Apple Health / Health Auto Export — only if you connect it), uploaded medical documents, the doctor's clinical notes, safety episodes (crisis/somatic). • “Money & state”, “Context”, “Questions”, “Memory folders” modules — your entries, may concern other people. Entries from the former “Addiction”, “Children”, “Partner search” and “Dating” modules (removed from the site) are kept only until you delete your account or health data and are not used by the service. • Purchases, subscription, consultations (via Stripe and Cal.com), support requests. • Technical data: session cookie, IP (rate limiting).
3. Purposes and legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Account, login, security | e-mail, password hash, login log, cookie | Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interest — account protection |
| VitaMind, check-ups, paths, diaries and trackers | health data | Art. 9(2)(a) your explicit consent + Art. 6(1)(b) contract |
| Doctor consultation and medical records | consultation records, doctor's messages/plan/prescriptions | Art. 9(2)(h) provision of health care; Art. 6(1)(c) legal duty to keep medical records [verify: Latvian law] |
| Alerting the doctor in a crisis (112 flow) | fact and level of crisis, episode id | Art. 9(2)(c) vital interests; Art. 9(2)(a) consent |
| Payments, accounting | purchases, amounts, Stripe data | Art. 6(1)(b) contract; Art. 6(1)(c) tax/accounting law |
| E-mails (service and newsletter) | Art. 6(1)(b) contract; newsletter — Art. 6(1)(a) consent (unsubscribe anytime) | |
| Abuse prevention | IP, request rate | Art. 6(1)(f) legitimate interest — service stability and security |
Automated processing: the safety layer automatically detects signs of a crisis, shows emergency contacts (112) and alerts the doctor. This is not a decision with legal effects (Art. 22 GDPR) — any further action is taken by a human.
4. Special category data (health)
We process health data only on the basis of your explicit consent, given at registration (the checkbox is unticked by default). We store the time of consent, the version of its text and a log of “given / withdrawn / renewed / data deleted”. If life is at risk we will still respond and point you to emergency help (Art. 9(2)(c) GDPR). Files with this data are encrypted on the server (AES-256-GCM). Only the doctor and the administrator can access them (staff login with password and second factor — [verify that staff MFA is enforced]).
5. Right to withdraw consent
You can withdraw consent at any time on the “My data & consent” page in your account without deleting it. Processing of health data pauses immediately; for 30 days you can restore consent or delete that data yourself, and without a decision it is deleted automatically. Purchases, books and subscription are not affected. Withdrawal does not affect the lawfulness of processing before it.
6. Who we share data with (processors)
| Processor | Purpose | Country | Transfer safeguard |
|---|---|---|---|
| Anthropic | AI answer generation (query text and context) | USA | EU-US DPF / SCC [verify] |
| ElevenLabs | speech-to-text (dictation) and voice answers | USA | SCC [verify] |
| Voyage AI | vector search over the knowledge base (embeddings) | USA | SCC [verify] |
| OpenAI | image generation in the admin panel (no client data sent) | USA | EU-US DPF [verify] |
| HeyGen | video creation in the admin panel (no client data sent) | USA | SCC [verify] |
| MongoDB Atlas | knowledge base / RAG storage [verify whether used in production] | EU/USA [verify] | SCC [verify] |
| Resend | sending e-mails | USA | EU-US DPF / SCC [verify] |
| Stripe | payments | Ireland/USA | EU-US DPF |
| Cal.com | consultation booking | USA | SCC [verify] |
| Zoom | video consultations | USA | EU-US DPF [verify] |
| Sign in with Google (OAuth) — only if you choose it | USA | EU-US DPF | |
| Telegram | doctor alerts — ONLY a non-personal signal (level, id, time, link), no name, e-mail or message text | UAE/other [verify] | no personal data transferred |
| Hetzner | server and backup hosting | Germany (EU) | not required (EU) |
We do not sell your data or use it for advertising.
7. Retention
| Data | Period |
|---|---|
| Account, chats, diaries, check-ups, paths, modules | while the account exists |
| Health data after consent is withdrawn | 30 days (you can restore consent or delete earlier), then deleted automatically |
| Deleted account | closed immediately (no sign-in, data no longer shown, newsletter off); a full snapshot is kept for 60 days in a closed encrypted archive so the account can be restored at your request or a claim handled, then erased automatically. Access — only the doctor and the administrator |
| Medical records of a paid consultation | [verify under Latvian law: a longer retention duty may apply] |
| Login session (cookie) | up to 60 days |
| Login log | last 20 logins |
| Safety episodes (for doctor reminders) | 7 days after the reminder (up to 90 days if the alert was not delivered) |
| Safety event log | while the account exists |
| Server backups | 14 days (then overwritten) |
| Payment records | at Stripe — as required by accounting/tax law |
8. Your rights and how to exercise them
You may: access your data and get a copy (“Download my data” in Settings), rectify it, delete your account (“Delete account” in Settings) or only your health data (the “My data & consent” page), restrict processing, object to processing based on legitimate interest, receive your data in a machine-readable format (portability), and withdraw consent. Requests: [EMAIL]; we reply within 1 month (Art. 12(3) GDPR).
9. Complaint to the supervisory authority
You may lodge a complaint with the Latvian Data State Inspectorate — Datu valsts inspekcija (dvi.gov.lv) — or with the authority of your country of residence.
10. Important
This service is not an emergency service. In a crisis or danger to life, call 112 or 113 (ambulance, Latvia); emotional support line 116 123 — free, 24/7.