Privacy Policy
Last updated: 19 July 2026
Version 1.0 · The English text is the binding version.
This is a product-facing privacy notice describing how Intuita, as a data processor, handles personal data on behalf of the treating practitioner. It is written to satisfy the transparency duties of GDPR Articles 13 and 14 (EU) and Information Privacy Principle 3 of the New Zealand Privacy Act 2020.
1. Who we are, and our role
Intuita is operated by Reza Labs, the sole proprietorship (eenmanszaak) of Mohammadreza Khosravivala, registered in the Dutch Business Register under KVK number 42116766, the Netherlands — acting as the data processor ("Intuita", "we", "us").
Contact: reza@intuita.health
It matters who decides and who acts:
- Your treating practitioner (the therapist or counsellor) is the data controller. They decide that Intuita is used in your sessions, what is recorded, and what happens to the resulting records.
- Intuita is the processor. We process session data only on the documented instructions of your practitioner, under a written Data Processing Agreement (GDPR Art. 28) that also incorporates New Zealand IPP 12 comparable-safeguards clauses for the cross-border arrangement.
Because we are the processor, most of your data-protection rights are exercised through your treating practitioner (see section 8). This notice tells you what we do with the data so you can give informed consent and understand your rights.
We have not appointed a Data Protection Officer; at our current scale we are not required to. We will appoint one if the service grows to require it.
2. What Intuita is — and is not
Intuita is a documentation tool for practitioners — a note-taking and observation assistant. It transcribes a session, then produces session notes, summaries, and observations to help the practitioner with their own documentation.
Intuita does not diagnose, does not recommend treatment, does not screen for or score clinical risk, and does not make any decision about your care. It is not a medical device. Every output is a documentation aid that your practitioner reviews; the clinical judgment, and the responsibility, remain entirely theirs.
3. What personal data we process
We process the following categories, all on behalf of your practitioner.
3.1 Account and identity data
- Patients/clients: first name, last name, email (optional), phone (optional), date of birth (optional), pronoun, and free-text intake notes authored by your practitioner; where your practitioner invites you to use Intuita's patient pages, also your sign-in credentials (password-based).
- Couples (where couple sessions are used): each partner's first name, last name, pronoun, and email.
- Practitioners (our direct users): name, email, password hash, role, clinic, language and interface preferences.
3.2 Special-category health data (GDPR Art. 9)
Therapy session content is special-category health data and is the most sensitive data Intuita handles:
- Session transcripts — the transcribed dialogue of the session, stored as structured text with anonymised speaker labels.
- AI-generated documentation aids — the notes, summaries, and observations (with supporting quotes) Intuita produces from the transcript for your practitioner to review — including, where your practitioner enables it, observations drawn across your own past sessions. These are aids for the practitioner, never clinical conclusions.
- People mentioned in sessions — names, relationships, and short summaries of third parties you mention. See section 9 on third-party data.
- Other clinical materials — materials your practitioner chooses to create or share through Intuita as part of working with you.
3.3 Audio
Your session audio is captured to produce the transcript.
For a session recorded live, the audio is processed only transiently: it is transcribed in flight and deleted the moment the transcript is produced — no live therapy audio is ever stored. Where your practitioner instead uploads a recording of a session, that uploaded file is kept securely in the EU with the same protections as your notes until it is deleted — and it is removed whenever your information is removed. Either way, what your practitioner works from is the written transcript.
3.4 Consent and audit records
- Consent records — when you accept this notice, we store the consent type, the version and a cryptographic fingerprint (hash) of the exact text you saw, the method (clickwrap), your IP address, your user agent, and the timestamp. This is our proof that consent was informed and freely given.
- Access logs — every access to or change of health data is logged (who, what, when, what action) for accountability.
3.5 What we deliberately do NOT send outside the system
When transcripts are sent for analysis, we do not send patient names, dates of birth, email, phone, session IDs, practitioner names, or clinic identifiers. Speaker turns are labelled generically (Patient: / Therapist:) before analysis. Names spoken aloud during a session form part of the transcript text itself and are not removed before analysis.
4. Why we process it (purposes)
We process session data solely to provide the documentation service to your practitioner:
- Transcribing your session into text.
- Producing documentation aids — notes, summaries, and observations — for your practitioner to review.
- Where enabled by your practitioner, drawing on your own past sessions to support the continuity of their notes.
We do not use your data for advertising, for profiling you for any purpose other than your practitioner's documentation, or to make automated decisions about your care. We do not use your data to train AI models, and our sub-processors are contractually bound not to train on it either.
5. Legal basis
Session health data is special-category data under GDPR Art. 9, which requires both a lawful basis (Art. 6) and an Art. 9 condition.
- Our basis is your explicit consent — Art. 6(1)(a) together with Art. 9(2)(a) — captured as clickwrap before your session data is processed.
For practitioner account data (not health data), our basis is performance of the contract for the service (Art. 6(1)(b)).
New Zealand: for clients of a New Zealand practitioner, this processing also operates under the NZ Privacy Act 2020 and the Health Information Privacy Code 2020. Your practitioner collects your health information under those rules and remains accountable for it; Intuita processes it under contractual comparable safeguards (IPP 12), with the entire session-content data path resident in the European Union under the GDPR — which the New Zealand Privacy Commissioner treats as providing safeguards comparable to the NZ Privacy Act.
6. Where your data goes — sub-processors and cross-border processing
Intuita uses a small number of carefully chosen sub-processors. Your session content never leaves the European Union.
| Sub-processor | Role | Data processed | Location | Safeguard |
|---|---|---|---|---|
| AssemblyAI | Speech-to-text transcription | Session audio (transient) | EU — Dublin endpoint | Data Processing Addendum; training excluded on the EU endpoint |
| Google LLC (Google Cloud) — Vertex AI | Transcript analysis | Pseudonymised transcript text (Patient:/Therapist:) | EU-resident — Netherlands | Google Cloud Data Processing Addendum; no training on customer data; DPF/SCCs cover any residual US-parent access |
| Hetzner Online GmbH | Hosting / storage | All data at rest and in transit | Germany (EU) | Hetzner data-processing agreement (AVV); EU hosting |
| Resend, Inc. | Email delivery (invitations, notices) | Contact details only (name, email) — never session content | United States | EU–U.S. Data Privacy Framework |
Cross-border note (NZ pilot): the practitioner is in New Zealand; Intuita and its processing sub-processors are in the European Union. The transfer of NZ client data to the EU is governed by the practitioner's IPP 12 obligation, met by the EU/GDPR comparable-safeguards arrangement in our DPA. The only data that leaves the EU is basic contact details for email delivery (see the table above), under the EU–U.S. Data Privacy Framework; session content is never transferred outside the EU.
7. How long we keep your data (retention)
Intuita is a processing layer, not your system of record. We hold your data only as a working copy to provide the service. The keeper of the clinical record is your practitioner (the controller), who retains it in their own systems for as long as their professional and legal duties require (in New Zealand, clinical records are commonly kept for 10 years; in the Netherlands, 20 years under the WGBO).
- Working-copy retention: Intuita keeps a patient's data for 2 years after their most recent active session (a couple is treated as one unit), then automatically and permanently deletes it.
- Advance notice (we do not delete silently): Intuita warns the practitioner 30 days before deletion, so they can export or move out anything they want to keep. Export is available to the practitioner at any time before then.
- Audio: live-session audio is never stored; an uploaded recording is kept until deleted, and is removed whenever your information is removed (see section 3.3).
- Consent and access-log records: retained as evidence of lawful processing and accountability, and may survive deletion of the clinical data for that purpose.
Because your practitioner — not Intuita — keeps the clinical record, the 2-year working-copy window does not shorten how long your record exists; it only means Intuita does not act as the long-term archive. Your practitioner can also ask us to delete your data sooner at any time.
8. Your rights, and how to exercise them
Under the GDPR (and, in New Zealand, the Privacy Act 2020 / Health Information Privacy Code), you have rights over your personal data:
| Right | GDPR | NZ equivalent |
|---|---|---|
| To be informed | Art. 13–14 | IPP 3 |
| Access / a copy | Art. 15 | IPP 6 / HIPC Rule 6 |
| Rectification / correction | Art. 16 | IPP 7 / HIPC Rule 7 |
| Erasure | Art. 17 | — |
| Restriction of processing | Art. 18 | — |
| Data portability | Art. 20 | — |
| To object | Art. 21 | — |
| To withdraw consent (prospective) | Art. 7(3) | — |
| Not to be subject to solely automated decisions | Art. 22 | — |
| To complain to a supervisory authority | Art. 77 | Privacy Act complaint to the Privacy Commissioner |
How rights are exercised — through your practitioner. Because Intuita is the processor and your practitioner is the controller, you exercise these rights by asking your treating practitioner, who instructs us to act. Where your practitioner invites you to use Intuita's patient pages, those pages support your work with your practitioner — they are not a self-service records portal; your clinical relationship stays the single point of contact for your records.
- Erasure: your practitioner can have all of your data deleted from Intuita — your record, every session, all derived analysis, and any stored audio; access logs are anonymised and a receipt of the erasure is kept.
- Access / a copy: your practitioner can export your session records.
- Consent withdrawal: you can ask your practitioner to withdraw your consent at any time. Withdrawal is prospective (Art. 7(3)) — it stops all future recording and analysis of your sessions, but it does not by itself delete records already created (that is a separate erasure request). Withdrawal is reversible: re-consent restarts processing.
Automated processing (Art. 22). Intuita generates observations using AI, but these are documentation aids reviewed by your practitioner — they are not decisions made about you without human involvement. Your practitioner always remains in control. You can ask your practitioner to explain or disregard any AI-generated observation.
Complaints. You may complain to a supervisory authority: in the EU/Netherlands, the Autoriteit Persoonsgegevens (AP); in New Zealand, the Office of the Privacy Commissioner. You can also raise any concern directly with your practitioner or with us at the contact above.
9. People you mention in sessions (third-party data)
When you talk about other people in a session, Intuita records their name, your relationship to them, and a short summary, to help your practitioner's notes. Those people are not Intuita users and have not been separately notified. We rely on the GDPR Art. 14(5)(b) exemption (notifying each mentioned person would involve disproportionate effort), and we apply the same security and deletion standards to their data as to yours.
10. How we protect your data (security)
We state our security measures honestly — what is actually in place today:
- Encryption in transit: all traffic between your practitioner's device and our servers — including streamed session audio — is encrypted in transit.
- Encryption at rest: data is protected by disk/volume-level encryption on our EU host.
- Access control: authentication is required on every data access; practitioners see only their own patients; clinics are isolated from one another. Practitioner sign-in supports multi-factor authentication (password plus a one-time code from an authenticator app); patient sign-in, where used, is password-based. Sessions are short-lived and cannot be reused once expired.
- Access logging: every access to health data is recorded for accountability.
- Data minimisation in AI calls: patient identifiers are excluded from analysis requests; speaker labels are anonymised.
No system is perfectly secure, but therapy data is the most sensitive data we handle and we treat it accordingly. In the event of a personal-data breach, we will notify your practitioner without undue delay so they can meet their notification duties; for serious breaches we support dual notification to both the Dutch AP (GDPR Art. 33) and the New Zealand Privacy Commissioner.
11. Adults only
Intuita is for adult clients. By consenting to its use, a client confirms they are 18 or older; the service is not offered for sessions with minors.
12. Changes to this policy
If we materially change how we process data — for example by adding a sub-processor, a new data category, or a new transfer destination — we will update this policy and, where required, ask for renewed consent. The version and date at the top of this document always reflect the current version.
13. Contact
- Intuita (processor): Reza Labs (KVK 42116766), the Netherlands — reza@intuita.health
- Your data controller: your treating practitioner / clinic, who is your first point of contact for any request about your data.
- Supervisory authorities: Autoriteit Persoonsgegevens (Netherlands, EU) · Office of the Privacy Commissioner (New Zealand).