Privacy Policy

Last revision Aug 16 2026

Konfidens' Data Privacy Policy details how Konfidens collects, utilizes, and deletes your data. By using the Konfidens platform (the "Platform" or "we") and making use of your Konfidens account (the "Account") and all its related features, including session notes, appointments, payments, and video chat (the "Services"), you acknowledge that your data related to your use of our Services is processed in accordance with the following privacy policy. This privacy policy, along with any product-specific privacy policies (collectively, the "Privacy Policy"), outlines (i) the data we collect during your access and use of the Services; (ii) how we use this data; and (iii) the measures we have in place to safeguard your data. Please consider the Privacy Policy as a supplementary document to our terms and conditions.

Data Controller and Processor
The services are operated by Mindcare AS (Business Registration Number: 925 239 070), headquartered at Rรธatoppen 11C, 0756 Oslo. You can reach us via email at hello@konfidens.com.

Mindcare acts as the data controller for information collected from its clients. This typically includes data necessary for service delivery and fulfilling our obligations to our customers.

Our customers utilize our services to manage their mental health care practices. As part of this process, data pertaining to their clients is stored and processed on our platform. For this data, Mindcare assumes the role of the data processor, while the account holder serves as the data controller.

UK GDPR Representative (Article 27)
We have appointed Euverify Ltd as our representative in the United Kingdom under Article 27 UK GDPR. Requests concerning personal data for which Mindcare is the data controller should be directed to hello@konfidens.com. Requests submitted directly are ordinarily resolved more quickly; requests received by the representative are forwarded to Mindcare for handling.

UK data subjects may alternatively contact the representative:
Euverify Ltd, 3rd Floor, 86โ€“90 Paul Street, London EC2A 4NE, United Kingdom.
โ€Email: gdpr@euverify.comSecure portal

We aim to provide you with transparent privacy policy. If you have any inquiries or concerns regarding any aspects of these terms not covered here, please don't hesitate to reach out to us at
hello@konfidens.com.

โ€

When is Personal Information Collected?

We process information about you in the following situations:

  1. You have registered as a user on the platform.
  2. You create an order or agreement on the platform.
  3. An order or agreement is made on your behalf.
  4. You are invited to the platform by a colleague or friend.
  5. You connect integrations, such as Google Calendar or Behandlernettverk.no.
  6. You subscribe to our newsletter.
  7. You have applied for a job with us.
  8. You contact us via chat, email, or other means.

โ€

Legal Basis for Processing Personal Information

The personal information collected is processed based on the following:

For platform users

Legal Basis: We process personal data about platform users in order to perform our contract with them, under Article 6(1)(b) GDPR (users in Norway and the EEA) or Article 6(1)(b) UK GDPR (users in the United Kingdom). This is anchored in the agreement entered into by platform users as set out in our terms of use. Where we process platform user data beyond what is necessary to perform the contract โ€” for example service communications, product analytics and platform security โ€” we rely on our legitimate interests under Article 6(1)(f).

For users in Norway, the GDPR applies as incorporated by personopplysningsloven (LOV-2018-06-15-38). For users in the United Kingdom, the UK GDPR applies as supplemented by the Data Protection Act 2018.

โ€
Data Processing Agreement: Regarding the information that our customers input into the platform, we assume the role of a data processor, governed by the provisions set forth in our data processing agreement. This agreement clearly outlines our responsibilities and obligations in managing this data.

โ€

For clients

Where your therapist is the data controller: Your therapist or clinic is the data controller for your patient record โ€” session notes, clinical information, appointment history. They determine the legal basis, which is normally Article 9(2)(h) read with Article 6(1)(c) (provision of health care), together with helsepersonelloven ยงยง39โ€“40 in Norway or Data Protection Act 2018, Schedule 1, Part 1, paragraph 2 in the United Kingdom. Requests concerning your patient record should be directed to your therapist or clinic.

Where Mindcare is the data controller: We process a limited set of your data in our own right to operate the account you use: secure login, appointment booking and changes, booking history, and facilitating payment to your provider. The legal basis is Article 6(1)(b) (performance of a contract with you).

โ€

Visits to app

App includes the domain app.konfidens.com, app.konfidens.no and app.konfidens.uk, booking.konfidens.com, booking.konfidens.uk, booking.konfidens.no and directory.konfidens.uk

For security and privacy reasons, Konfidens does not use third party cookies for marketing or tracking purposes, but has certain cookies to provide functionality related to user-friendliness and security. We strive to keep this number to a minimum.

You can read more about our cookies on this page.

l

Event Logging

Konfidens adheres to the information security and privacy standards set by the Norwegian Directorate of eHealth within the healthcare sector. Consequently, a majority of your actions as a healthcare professional are systematically recorded. These actions encompass, among others:

  • Initiating a session from an unfamiliar device.
  • Accessing a patient's record.
  • Writing session notes.
  • Electronically signing a note.
  • Revising an already signed note.
  • Granting access to a patient's record to a supervisor or colleague (subject to patient consent).

Each log entry comprises a user identifier, the date of the action, and specifics about your login method during that session. In cases involving particularly sensitive actions, such as printing notes from a patient's record, we also log your IP address for added security and accountability.

โ€

Who is Your Personal Information Shared With?

We use a limited number of third-party providers to deliver the platform. Where personal data is processed, we require it to be processed and stored within the EEA or the United Kingdom, other than where stated otherwise.

The complete and current list โ€” including each provider's legal entity, purpose, categories of data processed and processing location โ€” is published at konfidens.com/sub-processors.

That page also sets out the safeguards we rely on for any transfer of personal data outside the EEA or the United Kingdom.

โ€

How Long Do We Store Your Information?

If you have created a user account but have not been active for a period of 4 years, we will send you a notice that your account will be archived and deactivated. Archiving involves anonymizing your data and occurs 6 months after the notice, unless you log in again in the meantime. Personal information processed under Konfidens' legitimate interests will be stored as long as we are required to keep them. For example, if you have made payments on the platform, information we are legally required to store according to Norwegian accounting regulations will be retained for 10 years after the end of the fiscal year.

Your Rights

You have the right to receive a response without undue delay, and no later than one month. Contact us at hello@konfidens.com if you wish to exercise any of these rights.

  • Access to Your Data
    You have the right to access the data we have about you. If we hold healthcare information about you, we will require identification to provide you with this information. Learn more about the right to access.
  • Correction of Personal Information
    You can ask us to correct or supplement inaccurate or misleading information. Learn more about the right to correct or supplement information.
  • Right to Be Forgotten
    You have the right to be forgotten if our information about you is inadequate, irrelevant, or no longer necessary for the purpose it was processed. Learn more about the right to erasure.
  • Data Portability
    If we process information about you based on consent or a contract, you can request that we transfer information about you to you or to another data controller.

โ€

Google Calendar and Google user data

Konfidens offers an optional Google Calendar integration. This section covers Google user data obtained through Google APIs only.

When a practitioner connects their Google account, we access their email address and calendar events (title, description, location, times, status and event links). We also create a dedicated โ€œKonfidensโ€ calendar and write events only to calendars created by the app. We do not access Gmail, Drive or Contacts.

We use this data solely to show Google events in Konfidens, avoid double bookings, and write Konfidens appointments back to Google Calendar (service name, time and a Konfidens link โ€” not patient names or clinical notes).

The use of information received from Google APIs and Google Workspace scopes will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, analytics, selling, or to develop, improve or train non-personalized AI or machine learning models. AI Scribe does not use Google user data.

We store copies on AWS in Frankfurt. OAuth tokens are encrypted at rest; data is encrypted in transit (TLS 1.2+) and at rest. Event titles, descriptions and locations are shown only to the practitioner who connected the account. We do not share Google user data with other vendors.

When the practitioner disconnects, we delete the Konfidens calendar in Google, delete locally stored copies, and stop accessing the account. Access can also be revoked at https://myaccount.google.com/permissions.

โ€

Information in Patient Records

If you are a patient and require corrections or deletions of information entered into the platform by your healthcare provider, kindly reach out to the therapist or clinic responsible for your treatment. Please be aware that healthcare professionals may have legal obligations to maintain records of individuals who have received healthcare services and the nature of the care provided, as stipulated by national legislations.

โ€

Complaints About Processing

We hope you will let us know if you believe we are not in compliance with the rules in the Personal Data Act. In that case, please contact us through the contact or channel you have already established with us. If you are in the United Kingdom, you also have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk). If you are in Norway, you may complain to Datatilsynet (datatilsynet.no).