Skip to main content

Legal

Privacy Policy

Last Updated: September 15, 2026

1. Introduction

Psicosuite ("we," "our," or "us") is operated by Soto, a company registered in Ecuador. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. By using Psicosuite, you agree to the collection and use of information in accordance with this policy. Our servers are located in the United States, and this Privacy Policy is governed by the laws of Ecuador. Applicable privacy regimes include Ecuador’s Ley Orgánica de Protección de Datos Personales (LOPDP) and its Reglamento, GDPR-aligned controller/processor duties where they apply to our processing, and HIPAA-oriented safeguards for protected health information where that regime applies to your use of the platform. These obligations are cumulative: LOPDP is additional to, and does not replace, GDPR or HIPAA duties.

1.1. Roles (controller and processor)

For patient and clinical data you enter into Psicosuite, you (the professional or clinic) are the controller (and, where HIPAA applies, the covered entity or professional responsible party). Soto/PsicoSuite acts as your processor (and business-associate–style processor for that clinical data). Soto is the controller of account registration data, billing, support communications, and product security/telemetry. Patients typically exercise access, rectification, erasure, and related rights (ARCO / GDPR-style rights) primarily with you; we provide tools to help you respond and we handle account-holder privacy requests directed to us via our contact page.

2. Information We Collect

We collect several types of information from and about users of our platform:

  • Personal Information: Name, email address, phone number, profession, and other information you provide during registration
  • Patient Data: Information about your patients, including medical records, session notes, and clinical documentation
  • Usage Data: Information about how you access and use our platform, including IP addresses, browser type, and device information
  • Communication Data: Records of communications between you and our support team
  • Payment Information: Billing details and payment method information (processed securely through third-party payment processors)
  • Technical Data: Log files, error reports, and performance data

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, maintain, and improve our services, including optional calendar synchronization and third-party videoconferencing features you choose to enable
  • To process your registration and manage your account
  • To communicate with you about your account, services, and updates
  • To comply with legal obligations and protect our rights
  • To ensure the security and integrity of our platform

4. Data Storage and Security

Your data is stored on servers located in the United States. We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. This includes encryption of data in transit and at rest, regular security assessments, and access controls. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

5. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances: (a) with your explicit consent, (b) to comply with legal obligations, (c) to protect our rights and safety, (d) with service providers who assist us in operating our platform (under strict confidentiality agreements), or (e) in connection with a business transfer or merger.

6. Third-Party Services

Our platform may integrate with third-party services such as payment processors, email service providers, calendar synchronization (for example Google Calendar or Microsoft Outlook / Microsoft 365 calendar), and optional videoconferencing links or meetings created through providers such as Google Meet or Microsoft Teams when you choose those options. Those providers process information under their own terms and privacy policies, and we encourage you to review them. We are not responsible for the privacy practices of third-party services.

6.1. Google Calendar and Microsoft Outlook calendar integrations & data usage

Psicosuite can connect to Google Calendar and to Microsoft Outlook / Microsoft 365 calendar (including calendar data accessed through Microsoft’s APIs) to help you manage appointments and keep your schedule consistent between Psicosuite and the calendar you use. You decide whether to connect each integration.

Purpose of data access

When you connect a supported calendar, we use calendar-related data only for operational scheduling purposes, including:

  • To create, read, update, and delete calendar events associated with your Psicosuite appointments, where you have enabled sync
  • To synchronize appointment details between Psicosuite and your connected calendar so both stay aligned when you use the feature
  • To support notifications and workflows tied to your Psicosuite calendar (for example reminders or conflict avoidance, depending on your settings)
  • To reflect your availability when scheduling, where the product uses your connected calendar for that purpose
  • To reduce double-booking by reading existing events on the calendars you connect, within the scope you authorize

Data access scope

The exact permissions depend on the provider (Google or Microsoft) and what you approve during OAuth. In general, authorization may allow Psicosuite to:

  • Read calendar events needed to check availability and prevent conflicts, within the permissions you grant
  • Create calendar events for appointments you choose to sync
  • Update or remove calendar events when corresponding appointments change or are cancelled in Psicosuite, where sync is enabled
  • Use identifiers and metadata returned by the provider (such as event IDs) to maintain the link between Psicosuite appointments and external calendar items
  • Access limited profile information from the provider (such as name and email) as needed to complete sign-in and identify the connected account

Data security and privacy

Calendar data from connected providers is handled as follows:

  • Accessed only after you explicitly connect the integration through the provider’s authorization flow (for example Google or Microsoft sign-in and consent)
  • Used for the scheduling and appointment-management purposes described in this section, not sold to third parties
  • Protected with appropriate technical and organizational measures consistent with the rest of this Privacy Policy
  • Subject to the same general commitments in this Privacy Policy regarding confidentiality and security, in addition to the provider’s own safeguards
  • Disconnectable by you in Psicosuite settings and revocable in your Google or Microsoft account security or app permissions, which stops further access by Psicosuite going forward

Your control

You can disconnect Google Calendar or Microsoft calendar integrations in Psicosuite at any time, and you can revoke Psicosuite’s access in your Google or Microsoft account settings. After revocation, we stop requesting new data from that connection; items already written to your external calendar may remain there unless you delete them in the calendar app.

6.2. Sub-processors

We use carefully selected service providers (sub-processors) to operate the platform. Categories include:

  • Hosting and databases (for example cloud infrastructure and MongoDB hosting in the United States)
  • Object storage for documents and media (for example Amazon S3 with server-side encryption)
  • Email delivery providers for transactional and account messages
  • Payment processors (for example Lemon Squeezy and other providers you choose)
  • Realtime video infrastructure (for example LiveKit) when you use in-platform sessions
  • Optional calendar or meeting providers (Google or Microsoft) only after you connect them

Sub-processors process data under our instructions and contractual confidentiality/security commitments. A signed HIPAA Business Associate Agreement, where required, remains a separate legal track from this Privacy Policy and from the in-app Data Processing Addendum.

7. Your Rights

Depending on applicable law (including LOPDP ARCO-style rights and GDPR rights where they apply), you may have the right to access, correct, update, delete, restrict, or object to certain processing of your personal information, and to receive a copy of your data. Account holders may exercise rights via Settings → Data privacy and our contact page. Patients should contact their therapist (the controller) first; therapists can export or erase patient records using platform tools. We will respond to requests directed to us within a reasonable timeframe consistent with applicable law.

Contact us

7.1. Cookies and similar technologies

We use essential cookies required for authentication, security, and basic site operation. On marketing pages we may also use a first-party acquisition cookie to understand how professionals find Psicosuite. Non-essential acquisition cookies are set only after you accept cookies via our notice. You can choose essential-only mode. Session and security cookies remain necessary for the product to function.

8. Data Retention

We retain your personal information for as long as necessary to provide our services and comply with legal obligations. When you delete your account, we will delete or anonymize your personal information, except where we are required to retain it for legal, regulatory, or legitimate business purposes.

9. Children's Privacy

Our platform is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately via our contact page.

Contact us

10. International Data Transfers

Your information may be transferred to and stored on servers located in the United States. Transfers occur so we can provide the service under the controller/processor roles described above, with appropriate technical and organizational measures (including encryption). Data protection laws in the United States may differ from those in your jurisdiction. For patient/clinical data, you as controller remain responsible for ensuring your use of a US-hosted processor is lawful under LOPDP, GDPR, HIPAA, and other laws that apply to your practice.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. Your continued use of our platform after such changes constitutes acceptance of the updated policy.

12. Contact Information

If you have any questions about this Privacy Policy or our data practices, please contact us via our contact page. Soto is the parent company responsible for Psicosuite.

Contact us

Data Processing Addendum (summary)

Last Updated: September 15, 2026

This summary describes how Soto/Psicosuite processes patient and clinical personal data on your behalf. Accepting it in Settings creates a record of your instructions as controller. It supports GDPR Article 28 processor terms and LOPDP processor duties. A signed HIPAA Business Associate Agreement, where required, remains a separate legal document.

Roles: You are the controller of patient/clinical data. Psicosuite is the processor and will process that data only to provide the Platform, on your documented instructions, and not for unrelated commercial profiling.

Your duties as controller: You remain responsible for lawful bases and patient consent under LOPDP (including health-data rules), GDPR special-category rules where applicable, and HIPAA authorization/consent duties where applicable; for responding to patient rights requests; and for configuring access for your staff.

Our security measures: We apply encryption in transit and at rest for applicable fields, access controls, audit logging, and organizational safeguards described in our Privacy Policy. We use sub-processors listed in the Privacy Policy under confidentiality and security commitments.

13. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of Ecuador, including the Ley Orgánica de Protección de Datos Personales. Where GDPR or HIPAA also applies to a processing activity, those obligations apply in addition. Any disputes arising from or relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of Ecuador.

Privacy Policy — How PsicoSuite Handles Your Data | PsicoSuite