Last revision Aug 16 2026
Konfidens' Data Privacy Policy details how Konfidens collects, utilizes, and deletes your data. By using the Konfidens platform (the "Platform" or "we") and making use of your Konfidens account (the "Account") and all its related features, including session notes, appointments, payments, and video chat (the "Services"), you acknowledge that your data related to your use of our Services is processed in accordance with the following privacy policy. This privacy policy, along with any product-specific privacy policies (collectively, the "Privacy Policy"), outlines (i) the data we collect during your access and use of the Services; (ii) how we use this data; and (iii) the measures we have in place to safeguard your data. Please consider the Privacy Policy as a supplementary document to our terms and conditions.
Data Controller and Processor
The services are operated by Mindcare AS (Business Registration Number: 925 239 070), headquartered at Rรธatoppen 11C, 0756 Oslo. You can reach us via email at hello@konfidens.com.
Mindcare acts as the data controller for information collected from its clients. This typically includes data necessary for service delivery and fulfilling our obligations to our customers.
Our customers utilize our services to manage their mental health care practices. As part of this process, data pertaining to their clients is stored and processed on our platform. For this data, Mindcare assumes the role of the data processor, while the account holder serves as the data controller.
UK GDPR Representative (Article 27)
We have appointed Euverify Ltd as our representative in the United Kingdom under Article 27 UK GDPR. Requests concerning personal data for which Mindcare is the data controller should be directed to hello@konfidens.com. Requests submitted directly are ordinarily resolved more quickly; requests received by the representative are forwarded to Mindcare for handling.
UK data subjects may alternatively contact the representative:
Euverify Ltd, 3rd Floor, 86โ90 Paul Street, London EC2A 4NE, United Kingdom.
โEmail: gdpr@euverify.comSecure portal
We aim to provide you with transparent privacy policy. If you have any inquiries or concerns regarding any aspects of these terms not covered here, please don't hesitate to reach out to us at hello@konfidens.com.
โ
We process information about you in the following situations:
โ
The personal information collected is processed based on the following:
Legal Basis: We process personal data about platform users in order to perform our contract with them, under Article 6(1)(b) GDPR (users in Norway and the EEA) or Article 6(1)(b) UK GDPR (users in the United Kingdom). This is anchored in the agreement entered into by platform users as set out in our terms of use. Where we process platform user data beyond what is necessary to perform the contract โ for example service communications, product analytics and platform security โ we rely on our legitimate interests under Article 6(1)(f).
For users in Norway, the GDPR applies as incorporated by personopplysningsloven (LOV-2018-06-15-38). For users in the United Kingdom, the UK GDPR applies as supplemented by the Data Protection Act 2018.
โ
Data Processing Agreement: Regarding the information that our customers input into the platform, we assume the role of a data processor, governed by the provisions set forth in our data processing agreement. This agreement clearly outlines our responsibilities and obligations in managing this data.
โ
Where your therapist is the data controller: Your therapist or clinic is the data controller for your patient record โ session notes, clinical information, appointment history. They determine the legal basis, which is normally Article 9(2)(h) read with Article 6(1)(c) (provision of health care), together with helsepersonelloven ยงยง39โ40 in Norway or Data Protection Act 2018, Schedule 1, Part 1, paragraph 2 in the United Kingdom. Requests concerning your patient record should be directed to your therapist or clinic.
Where Mindcare is the data controller: We process a limited set of your data in our own right to operate the account you use: secure login, appointment booking and changes, booking history, and facilitating payment to your provider. The legal basis is Article 6(1)(b) (performance of a contract with you).
โ
App includes the domain app.konfidens.com, app.konfidens.no and app.konfidens.uk, booking.konfidens.com, booking.konfidens.uk, booking.konfidens.no and directory.konfidens.uk
For security and privacy reasons, Konfidens does not use third party cookies for marketing or tracking purposes, but has certain cookies to provide functionality related to user-friendliness and security. We strive to keep this number to a minimum.
You can read more about our cookies on this page.
l
Konfidens adheres to the information security and privacy standards set by the Norwegian Directorate of eHealth within the healthcare sector. Consequently, a majority of your actions as a healthcare professional are systematically recorded. These actions encompass, among others:
Each log entry comprises a user identifier, the date of the action, and specifics about your login method during that session. In cases involving particularly sensitive actions, such as printing notes from a patient's record, we also log your IP address for added security and accountability.
โ
We use a limited number of third-party providers to deliver the platform. Where personal data is processed, we require it to be processed and stored within the EEA or the United Kingdom, other than where stated otherwise.
The complete and current list โ including each provider's legal entity, purpose, categories of data processed and processing location โ is published at konfidens.com/sub-processors.
That page also sets out the safeguards we rely on for any transfer of personal data outside the EEA or the United Kingdom.
โ
If you have created a user account but have not been active for a period of 4 years, we will send you a notice that your account will be archived and deactivated. Archiving involves anonymizing your data and occurs 6 months after the notice, unless you log in again in the meantime. Personal information processed under Konfidens' legitimate interests will be stored as long as we are required to keep them. For example, if you have made payments on the platform, information we are legally required to store according to Norwegian accounting regulations will be retained for 10 years after the end of the fiscal year.
You have the right to receive a response without undue delay, and no later than one month. Contact us at hello@konfidens.com if you wish to exercise any of these rights.
โ
Konfidens offers an optional Google Calendar integration. This section covers Google user data obtained through Google APIs only.
When a practitioner connects their Google account, we access their email address and calendar events (title, description, location, times, status and event links). We also create a dedicated โKonfidensโ calendar and write events only to calendars created by the app. We do not access Gmail, Drive or Contacts.
We use this data solely to show Google events in Konfidens, avoid double bookings, and write Konfidens appointments back to Google Calendar (service name, time and a Konfidens link โ not patient names or clinical notes).
The use of information received from Google APIs and Google Workspace scopes will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, analytics, selling, or to develop, improve or train non-personalized AI or machine learning models. AI Scribe does not use Google user data.
We store copies on AWS in Frankfurt. OAuth tokens are encrypted at rest; data is encrypted in transit (TLS 1.2+) and at rest. Event titles, descriptions and locations are shown only to the practitioner who connected the account. We do not share Google user data with other vendors.
When the practitioner disconnects, we delete the Konfidens calendar in Google, delete locally stored copies, and stop accessing the account. Access can also be revoked at https://myaccount.google.com/permissions.
โ
If you are a patient and require corrections or deletions of information entered into the platform by your healthcare provider, kindly reach out to the therapist or clinic responsible for your treatment. Please be aware that healthcare professionals may have legal obligations to maintain records of individuals who have received healthcare services and the nature of the care provided, as stipulated by national legislations.
โ
We hope you will let us know if you believe we are not in compliance with the rules in the Personal Data Act. In that case, please contact us through the contact or channel you have already established with us. If you are in the United Kingdom, you also have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk). If you are in Norway, you may complain to Datatilsynet (datatilsynet.no).