Privacy policy

Last updated: 28 September 2026

1. Who processes the information

The identified service provider is Rayan Chelouati, self-employed professional, tax ID Y2655152T, Calle Mezquita, Edificio Velázquez, 11202 Algeciras (Cádiz), Spain. Any change of entity will be communicated and formalised as applicable.

The clinic or professional determines the care purpose and is the controller of clinical information. VRET processes it on documented instructions as processor. VRET is controller for its own professional accounts, contracting, billing, support, security and marketing activities.

2. Patient information and clinical use

The clinic holds the link between civil identity and the patient code. VRET uses codes and UUIDs and may process virtual reality sessions, biofeedback measurements, tasks, answers, drafts, clinical notes and associated files. These are pseudonymised personal health data: not requesting a name or identity document does not make them anonymous.

Professionals may enter clinical text. They should limit it to what is necessary and avoid unnecessary names, documents, addresses or other identifiers. Text can contain identifying information if a professional enters it; we therefore do not claim that storing identifying information is impossible. Access is restricted to authorised professional scope.

General session video recording has been withdrawn. Exercise audio delivered to the mobile app is not a recording of the patient’s voice. Available clinical snapshots and files remain part of the data inventory. A future voice dialogue feature requires its own information, assessment and safeguards before activation.

3. Purposes and lawful grounds

The clinic must determine and document the applicable Article 6 lawful basis and Article 9 condition for care, inform the patient and comply with relevant health rules. Care is not automatically based on accepting an app or giving generic consent. VRET uses clinical data only to provide, maintain and protect the service under documented instructions, not for advertising or model training.

For its own activities, VRET uses necessary information to perform contracts or requested pre-contract steps, comply with legal obligations and protect the service under assessed legitimate interests. Consent-based optional communications and technologies allow withdrawal without affecting earlier lawful processing. VRET does not make automated clinical decisions producing legal or similarly significant effects on patients.

PurposeInformation and useGround and necessityRetention criteria
Professional account and accessProfessional contact, organisation and credentials to provide access and administer the relationship.Contract or requested pre-contract steps. Necessary authentication and contact details are service requirements.For the relationship; on termination, delete or restrict only information needed for applicable obligations or claims.
Billing and paymentsProfessional tax and transaction details to issue invoices, collect payment and keep accounts.Contract and accounting/tax obligations. Required tax details are necessary for correct invoicing.Commercial records: six years where applicable; tax rules and interruptions are assessed separately. This does not extend clinical-record retention.
Support and incidentsContact and minimal technical description to resolve a request and maintain the service.Contract; assessed legitimate interests in abuse prevention and continuity. Do not send unnecessary clinical content.Until resolution and for justified related incident or liability periods, removing unnecessary content earlier.
Security and acceptance evidenceProfessional access, permission changes, versioned acceptance and rights decisions to demonstrate actions and prevent unauthorised access.Security/accountability obligations and assessed legitimate interests in fraud prevention and defence of claims.Only while necessary for identified investigations, obligations or claims, with category-specific review. Records must not contain complete clinical files.
Enquiries and communicationsContact details and the received request to reply or deliver requested resources; optional messages according to recorded preferences.Requested pre-contract steps where applicable; consent where required for messages. Optional fields and advertising do not condition clinical care.Until an enquiry is resolved; optional messages until withdrawal or unsubscribe, with inactive-contact review and minimal suppression records to avoid resending.
Booked callsName, email and date of the call you book through Calendly, and whether it took place; to hold it, remind you of it and, if it did not happen or you cancelled without rebooking, send you at most three emails offering another date, with no marketing content.Pre-contract steps you request by booking (Art. 6(1)(b) GDPR). This ground is not used for newsletters, resources or advertising, which require your consent. Every email lets you ask us to stop writing.For the pre-contract relationship; emails to recover the call are only sent during the following ten days. Afterwards, the enquiries and communications criterion applies.
Optional analytics and advertisingBrowser identifiers and public-site events authorised by the visitor to measure usage and campaigns.Consent where required; reject or withdraw through privacy settings. This does not authorise clinical tracking.According to cookie-panel periods and verified provider configuration. Optional data are not required to use clinical services.

For these activities, exercise your rights directly with VRET at [email protected], including withdrawal of consent, objection to direct marketing and objection to processing based on legitimate interests. Verification is proportionate to the request; identity documents are not requested by default. If professional details come from public sources or a third party, VRET must provide the applicable source and indirect-collection notice within the statutory period; public availability does not itself authorise marketing.

4. Children and representatives

Clinical use with children remains the professional’s responsibility. The clinic assesses capacity, age-appropriate information, representation, confidentiality and authorisations according to age, treatment and applicable law. Digital-consent age does not replace healthcare-consent rules. VRET does not require copies of a child’s or representative’s identity documents for patient access.

5. IP addresses, devices and security

Cloudflare terminates request TLS and receives the IP address, path and time; it can access the traffic it decrypts. Keeping this provider means we cannot claim that nobody processes the IP address. Our mobile-route controls minimise logging and prevent forwarding IP headers to the application; coverage includes reviewing errors, rejected requests and general logs. This policy does not promise anonymity from network providers.

Controls include clinic separation, professional permissions, encryption and logging restrictions. New MFA and mobile privacy measures are being introduced in phases; availability depends on the deployed version. No ISO or ENS certification or complete compliance is claimed on the basis of a technical test.

The patient app processes patient and device identifiers, assignments, task answers, optional ratings and playback records (activity, dates, position and duration) so the clinic can provide follow-up. The app does not record the patient’s voice. Answers and local context are stored in an encrypted database; audio files and the technical playback journal have access controls and are excluded from backups.

If you enable reminders, we process the notification token and time zone. When configured, remote delivery uses Expo and Apple or Google notification services. Reminder text is generic, but the operating system may display the app name. You can disable reminders in Settings. These data are not used for advertising.

Deleting data from this phone removes the local copy, including unsynced records, but does not itself delete access or records held by the clinic. You can request deletion of your access and data through the clinic or [email protected]. The clinic must explain applicable legal retention and handle the request; immediate deletion of data subject to mandatory retention is not promised.

The mobile design limits offline authorisation to 48 hours after successful validation. Pending drafts have a seven-day limit from that validation and are removed when the app next runs if the device was off. Suspension locks access; authenticated revocation starts erasure. Changing patients requires removing the previous patient’s data. Remote erasure is not instantaneous on an offline device.

6. Retention

The clinic sets clinical-record retention and justifies exceptions to erasure. Healthcare periods depend on applicable rules and document type, separately from technical backup retention. At service termination, return, deletion and categories requiring legally mandated restricted retention are agreed.

Invoices and supporting records are retained for applicable accounting and tax periods. Security, acceptance and rights-request evidence is limited to its purpose and relevant liabilities; it does not justify retaining complete clinical content. The retention matrix distinguishes each category and its deletion mechanism.

The approved, not yet verified and non-guaranteed recovery objective is 30 days, with necessary auxiliary backup references retained for at most 37 days. Target maximum data loss is 15 minutes and target service recovery is under two hours; these are objectives subject to complete recovery drills.

Transition status, 14 September 2026: older backup copies still exist. The new retention ceiling has not yet been demonstrated across every location. Historical copies will be removed through a recorded inventory after a complete restoration has been verified. The previous seven-day statement was inaccurate.

Deletion from active systems, pending file deletion and backup expiry are separate stages. Backup data must remain unavailable for ordinary use; restoration must reapply subsequent erasures before any user access. A clinic’s justified clinical-record retention is a separate obligation and does not justify keeping every technical backup indefinitely.

7. Recipients, providers and transfers

This inventory distinguishes technical use from contractual evidence. A provider’s standard terms do not by themselves prove acceptance, a specific processing region or a transfer safeguard. The clinic may request the applicable supplier and contractual record at [email protected].

ServiceProcessingVerified scope
IONOS / self-managed infrastructureApplication server, PostgreSQL and MinIO objects (including the patient app exercise audio). Daily encrypted backup on operator-managed equipment at a separate physical location.Infrastructure observed and both locations in the EU. The specific physical region of the server and of the backup equipment are NOT documented: pending verification against the provider contract. No public surface names a country.
CloudflareProxy, TLS, network protection and delivery. Receives IP addresses and metadata and can access the traffic it decrypts.In use. Global network; account terms, subprocessors and transfers require review.
SentryTechnical errors with clinical-data and credential filters; client session replay disabled. From headset version 1.42.0, also headset errors and crashes (errors only: no sessions, traces or screenshots), without clinical data or patient identifiers. Prepared but not enabled in the patient app.Configured for web, API and headsets (from 1.42.0). EU region for events; the provider’s accounts, organisation settings and integrations may reside in the US. Project region, retention and contract evidence pending.
Resend / operational emailProfessional communications and alerts. Clinical information must not be included in email.Resend configured; verify every relay and mailbox in use, its terms and retention.
StripeProfessional subscriptions, payments and billing; not a recipient of clinical records.Configured for contracting; establish the roles and safeguards of the service used.
Auth0 / Okta (OIDC)Professional identity and access when the configured issuer is used; not patient records.OIDC support present; issuer, actual use, region and contract awaiting verification.
CalendlyCall scheduling: professional contact, calendar information and the originating campaign name (only with advertising-measurement consent).Public-site integration; activation and terms require verification. Do not use for clinical appointment content.
Google Analytics (GA4)Optional public-site analytics under VRET’s controllership and applicable consent.Integration conditional on configuration and consent; account region, transfers and retention require verification.
Microsoft ClarityOptional public-site visual analytics, with controls excluding the clinical area.Consent-gated integration; account configuration and safeguards require verification.
LinkedInOptional commercial-site advertising measurement; no authorised clinical content.Consent-gated integration; activation and transfer terms awaiting verification.
ProtonHuman contact, privacy and security mailboxes; avoid clinical attachments.Listed in the internal inventory; contract, retention and configuration require verification.
Grafana Cloud / Better StackTechnical metrics and availability, using an allowlist and no authorised clinical content.Configuration documented; review destinations, labels, retention and whether metrics can identify individuals.

Public-site analytics, scheduling, human mailboxes and identity-provider services require a separate inventory according to their actual activation. They are not authorised to receive clinical content. Optional analytics require the applicable consent controls. Conversational AI is disabled in the reviewed production configuration; new AI or cloud services require prior assessment and contractual approval.

Before using a subprocessor, authorisation, contractual obligations, support access and applicable transfer safeguards must be established. Selecting a European region does not prove exclusive EU processing. AWS and Google Cloud are future migration alternatives; this review does not activate them as contracted clinical infrastructure.

8. Exercising your rights

For access, copies, correction, restriction, objection or erasure of clinical information, contact your clinic first. The clinic verifies identity and decides legal exceptions; VRET assists it and provides operation status. Portability applies where its legal conditions are met. You may also contact [email protected] without emailing unnecessary identity documents or clinical information.

Requests are handled within the applicable statutory period. Under EU GDPR this is normally one month, with justified extensions communicated as required. You may complain to the AEPD or your competent supervisory authority, or to the ICO for processing subject to UK rules.

AEPD · ICO

9. Spain, the European Union and the United Kingdom

The intended scope covers Spain, the EU and the UK. Regular processing subject to UK rules requires completion of the specific obligations, including representation where required. DPO assessment and UK representative designation are recorded separately and are not treated as completed because a template exists. Clinics established in the United States are outside this customer scope; this does not mean that no provider or support access can involve a transfer to that country.

10. Contact and incidents

Privacy requests and security incidents can be raised through the channels below. Incidents are assessed and reported to the clinic without undue delay; the clinic decides the notifications for which it is responsible. This update describes reviewed processing and does not itself establish completion of pending contracts or appointments.

privacidad [arroba] vret.es · seguridad [arroba] vret.es

Privacy Policy · VRET