Privacy Policy

Last updated: March 2026 | Effective: March 2026

1. Introduction

Dyagnosys Wellbeing FZCO ("we," "our," or "us") is committed to protecting your privacy and the confidentiality of your mental health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our mental health assessment platform (the "Service").

We comply with: GDPR (EU), LGPD (Brazil), UAE PDPL, and other applicable data protection regulations.

Data Controller: Dyagnosys Wellbeing FZCO, registered in the United Arab Emirates with offices in Brasília, Brazil and Ras Al Khaimah, UAE.

2. Information We Collect

Assessment Data

Responses to GAD-7, PHQ-9, and other clinically-validated mental health questionnaires. This includes your answers, calculated scores, clinical interpretations, and historical assessment records.

Biometric Data

On-device only: Facial expression analysis via MediaPipe, voice tone analysis via Web Audio API. Raw biometric data is processed locally on your device and never transmitted to our servers.

Account Information

Name, email address, organization (for B2B users), profile preferences, and authentication credentials. Passwords are hashed using bcrypt and never stored in plain text.

Usage & Device Data

Browser type, device type, IP address, access times, features used, and interaction patterns. Used for service improvement and security monitoring.

Payment Information

Billing address and payment history. Full card details are processed by Stripe and never stored on our servers.

3. How We Use Your Information

We process your data for the following purposes:

Service Delivery

Provide personalized mental health assessments and AI-powered insights

Progress Tracking

Monitor your wellbeing trends over time with historical data

Account Management

Create and maintain your account, process payments, send notifications

Service Improvement

Analyze usage patterns to improve features and develop new capabilities

Security & Fraud Prevention

Detect and prevent unauthorized access, abuse, and security threats

Legal Compliance

Comply with applicable laws, regulations, and legal processes

4. Biometric Data Processing

Privacy by Design: All biometric analysis happens on YOUR device.

On-Device Processing: Facial expression recognition (via MediaPipe) and voice analysis (via Web Audio API) run entirely in your browser. Raw video and audio are processed locally and never leave your device.

Derived Insights Only: We store only anonymized, aggregated insights (e.g., "elevated stress indicators detected on March 15") rather than raw biometric data, video recordings, or audio files.

Your Control: Biometric analysis is optional. You can disable it in your Account Settings at any time.

5. Data Sharing & Third Parties

We do not sell your personal data. We share data only as follows:

Service Providers (Sub-processors)

  • Vercel — Application hosting and edge functions
  • Neon — PostgreSQL database hosting
  • Paddle — Merchant of Record for payment processing (EU/UK)
  • Stripe — Payment processing (other regions)
  • Resend — Transactional email delivery
  • Sentry — Error monitoring (PII filtered)

B2B/Employer Access

If you access the Service through your employer, they receive only aggregated, anonymized reports. Your individual assessment results are never shared with employers.

Legal Requirements

We may disclose data if required by law, court order, or government request, or to protect our rights and safety.

6. International Data Transfers

Your data may be transferred to and processed in countries outside your residence, including the United Arab Emirates, Brazil, and the United States (for sub-processors).

We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) for EU data subjects and equivalent legal mechanisms for other jurisdictions.

7. Data Security

We implement industry-standard security measures:

  • Encryption: AES-256 at rest, TLS 1.3 in transit
  • Authentication: JWT tokens with httpOnly cookies, bcrypt password hashing
  • Access Control: Role-based access, audit logging
  • Infrastructure: SOC 2 compliant cloud providers
  • Regular Audits: Security assessments and penetration testing

No method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

8. Data Retention

Data TypeRetention Period
Assessment DataDuration of account + 2 years, then anonymized
Biometric Insights2 years, then permanently deleted
Account InformationDuration of account + 30 days after deletion request
Payment Records7 years (legal/tax requirements)
Security Logs1 year

You can request immediate deletion at any time via Account Settings or by contactingprivacy@dyagnosys.com.

9. Your Rights (Data Subject Rights)

Right to Access

Request a complete copy of your personal data

Right to Rectification

Correct inaccurate or incomplete data

Right to Erasure

Request permanent deletion of your data ("right to be forgotten")

Right to Portability

Export your data in JSON or CSV format

Right to Restrict Processing

Limit how we process your data

Right to Object

Object to processing for direct marketing

Right to Withdraw Consent

Withdraw consent at any time

Right to Lodge a Complaint

File a complaint with your local DPA

To exercise these rights, visit your Account Settings or contact us at privacy@dyagnosys.com. We respond within 30 days.

10. Cookies & Tracking Technologies

We use the following technologies:

  • Essential Cookies: Required for authentication and basic functionality
  • Preference Cookies: Remember your settings and preferences
  • Analytics Cookies: Understand how users interact with the Service

You can manage cookie preferences through your browser settings. Disabling essential cookies may affect Service functionality.

11. Children's Privacy

The Service is not intended for children under 13. We do not knowingly collect personal data from children under 13.

Users aged 13-17 may use the Service only with verifiable parental or guardian consent. Parents/guardians must create and supervise these accounts.

12. B2B/Employer Users

If you access the Service through your employer or organization:

  • Your employer is the data controller for employment-related data
  • Employers receive only aggregated, anonymized reports
  • Individual assessment results are never shared with employers
  • Your participation is confidential and voluntary

13. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email and in-app notification with at least 30 days notice. Your continued use after changes constitutes acceptance.

14. Contact Information

For privacy inquiries, data requests, or to exercise your rights:

Data Protection Officer

Email: privacy@dyagnosys.com

Response time: Within 30 days

Regional Offices

Brasília, Federal District, Brazil

Ras Al Khaimah, United Arab Emirates

Additional Resources