Privacy Policy

Last updated: 19 July 2026

Version 1.0 · The English text is the binding version.

This is a product-facing privacy notice describing how Intuita, as a data processor, handles personal data on behalf of the treating practitioner. It is written to satisfy the transparency duties of GDPR Articles 13 and 14 (EU) and Information Privacy Principle 3 of the New Zealand Privacy Act 2020.


1. Who we are, and our role

Intuita is operated by Reza Labs, the sole proprietorship (eenmanszaak) of Mohammadreza Khosravivala, registered in the Dutch Business Register under KVK number 42116766, the Netherlands — acting as the data processor ("Intuita", "we", "us").

Contact: reza@intuita.health

It matters who decides and who acts:

Because we are the processor, most of your data-protection rights are exercised through your treating practitioner (see section 8). This notice tells you what we do with the data so you can give informed consent and understand your rights.

We have not appointed a Data Protection Officer; at our current scale we are not required to. We will appoint one if the service grows to require it.


2. What Intuita is — and is not

Intuita is a documentation tool for practitioners — a note-taking and observation assistant. It transcribes a session, then produces session notes, summaries, and observations to help the practitioner with their own documentation.

Intuita does not diagnose, does not recommend treatment, does not screen for or score clinical risk, and does not make any decision about your care. It is not a medical device. Every output is a documentation aid that your practitioner reviews; the clinical judgment, and the responsibility, remain entirely theirs.


3. What personal data we process

We process the following categories, all on behalf of your practitioner.

3.1 Account and identity data

3.2 Special-category health data (GDPR Art. 9)

Therapy session content is special-category health data and is the most sensitive data Intuita handles:

3.3 Audio

Your session audio is captured to produce the transcript.

For a session recorded live, the audio is processed only transiently: it is transcribed in flight and deleted the moment the transcript is produced — no live therapy audio is ever stored. Where your practitioner instead uploads a recording of a session, that uploaded file is kept securely in the EU with the same protections as your notes until it is deleted — and it is removed whenever your information is removed. Either way, what your practitioner works from is the written transcript.

3.4 Consent and audit records

3.5 What we deliberately do NOT send outside the system

When transcripts are sent for analysis, we do not send patient names, dates of birth, email, phone, session IDs, practitioner names, or clinic identifiers. Speaker turns are labelled generically (Patient: / Therapist:) before analysis. Names spoken aloud during a session form part of the transcript text itself and are not removed before analysis.


4. Why we process it (purposes)

We process session data solely to provide the documentation service to your practitioner:

  1. Transcribing your session into text.
  2. Producing documentation aids — notes, summaries, and observations — for your practitioner to review.
  3. Where enabled by your practitioner, drawing on your own past sessions to support the continuity of their notes.

We do not use your data for advertising, for profiling you for any purpose other than your practitioner's documentation, or to make automated decisions about your care. We do not use your data to train AI models, and our sub-processors are contractually bound not to train on it either.


5. Legal basis

Session health data is special-category data under GDPR Art. 9, which requires both a lawful basis (Art. 6) and an Art. 9 condition.

For practitioner account data (not health data), our basis is performance of the contract for the service (Art. 6(1)(b)).

New Zealand: for clients of a New Zealand practitioner, this processing also operates under the NZ Privacy Act 2020 and the Health Information Privacy Code 2020. Your practitioner collects your health information under those rules and remains accountable for it; Intuita processes it under contractual comparable safeguards (IPP 12), with the entire session-content data path resident in the European Union under the GDPR — which the New Zealand Privacy Commissioner treats as providing safeguards comparable to the NZ Privacy Act.


6. Where your data goes — sub-processors and cross-border processing

Intuita uses a small number of carefully chosen sub-processors. Your session content never leaves the European Union.

Sub-processorRoleData processedLocationSafeguard
AssemblyAISpeech-to-text transcriptionSession audio (transient)EU — Dublin endpointData Processing Addendum; training excluded on the EU endpoint
Google LLC (Google Cloud) — Vertex AITranscript analysisPseudonymised transcript text (Patient:/Therapist:)EU-resident — NetherlandsGoogle Cloud Data Processing Addendum; no training on customer data; DPF/SCCs cover any residual US-parent access
Hetzner Online GmbHHosting / storageAll data at rest and in transitGermany (EU)Hetzner data-processing agreement (AVV); EU hosting
Resend, Inc.Email delivery (invitations, notices)Contact details only (name, email) — never session contentUnited StatesEU–U.S. Data Privacy Framework

Cross-border note (NZ pilot): the practitioner is in New Zealand; Intuita and its processing sub-processors are in the European Union. The transfer of NZ client data to the EU is governed by the practitioner's IPP 12 obligation, met by the EU/GDPR comparable-safeguards arrangement in our DPA. The only data that leaves the EU is basic contact details for email delivery (see the table above), under the EU–U.S. Data Privacy Framework; session content is never transferred outside the EU.


7. How long we keep your data (retention)

Intuita is a processing layer, not your system of record. We hold your data only as a working copy to provide the service. The keeper of the clinical record is your practitioner (the controller), who retains it in their own systems for as long as their professional and legal duties require (in New Zealand, clinical records are commonly kept for 10 years; in the Netherlands, 20 years under the WGBO).

Because your practitioner — not Intuita — keeps the clinical record, the 2-year working-copy window does not shorten how long your record exists; it only means Intuita does not act as the long-term archive. Your practitioner can also ask us to delete your data sooner at any time.


8. Your rights, and how to exercise them

Under the GDPR (and, in New Zealand, the Privacy Act 2020 / Health Information Privacy Code), you have rights over your personal data:

RightGDPRNZ equivalent
To be informedArt. 13–14IPP 3
Access / a copyArt. 15IPP 6 / HIPC Rule 6
Rectification / correctionArt. 16IPP 7 / HIPC Rule 7
ErasureArt. 17
Restriction of processingArt. 18
Data portabilityArt. 20
To objectArt. 21
To withdraw consent (prospective)Art. 7(3)
Not to be subject to solely automated decisionsArt. 22
To complain to a supervisory authorityArt. 77Privacy Act complaint to the Privacy Commissioner

How rights are exercised — through your practitioner. Because Intuita is the processor and your practitioner is the controller, you exercise these rights by asking your treating practitioner, who instructs us to act. Where your practitioner invites you to use Intuita's patient pages, those pages support your work with your practitioner — they are not a self-service records portal; your clinical relationship stays the single point of contact for your records.

Automated processing (Art. 22). Intuita generates observations using AI, but these are documentation aids reviewed by your practitioner — they are not decisions made about you without human involvement. Your practitioner always remains in control. You can ask your practitioner to explain or disregard any AI-generated observation.

Complaints. You may complain to a supervisory authority: in the EU/Netherlands, the Autoriteit Persoonsgegevens (AP); in New Zealand, the Office of the Privacy Commissioner. You can also raise any concern directly with your practitioner or with us at the contact above.


9. People you mention in sessions (third-party data)

When you talk about other people in a session, Intuita records their name, your relationship to them, and a short summary, to help your practitioner's notes. Those people are not Intuita users and have not been separately notified. We rely on the GDPR Art. 14(5)(b) exemption (notifying each mentioned person would involve disproportionate effort), and we apply the same security and deletion standards to their data as to yours.


10. How we protect your data (security)

We state our security measures honestly — what is actually in place today:

No system is perfectly secure, but therapy data is the most sensitive data we handle and we treat it accordingly. In the event of a personal-data breach, we will notify your practitioner without undue delay so they can meet their notification duties; for serious breaches we support dual notification to both the Dutch AP (GDPR Art. 33) and the New Zealand Privacy Commissioner.


11. Adults only

Intuita is for adult clients. By consenting to its use, a client confirms they are 18 or older; the service is not offered for sessions with minors.


12. Changes to this policy

If we materially change how we process data — for example by adding a sub-processor, a new data category, or a new transfer destination — we will update this policy and, where required, ask for renewed consent. The version and date at the top of this document always reflect the current version.


13. Contact

With your permission, we load our self-hosted Pulse analytics script to understand site use. Choose "Accept" to allow analytics or "Necessary only" to keep it off. Your choice is stored in this browser. Privacy Policy