Privacy Policy: Euneo console
Version 1.0 · 10 October 2026
Effective date: 10 October 2026
1. Welcome! Who we are and what this policy covers
Euneo Health ehf. (reg. no. 461101-2590), Laufrima 31, 112 Reykjavík, Iceland ("Euneo", "we", "us") provides the Euneo console. For any questions about your personal data or privacy rights, write to us at privacy@euneohealth.com. This address also connects directly to our Data Protection Officer.
This policy applies to you if you use the Euneo console as a physiotherapist or other clinician, or as a clinic admin. It covers only the personal data about you that Euneo controls (Section 2). It does not cover your patients' data or our public website. Patients are covered by our separate app privacy policy: https://euneohealth.com/privacy-policy.
You confirm that you have read this policy when you create your console account and accept our General Terms of Service. We record which version you confirmed and when. Confirming it is not consent to any processing of your personal data.
2. Who is in charge of your personal data?
Euneo is the data controller for the data described in Section 3. This means we decide how it is used and are responsible for it.
Console account data. Your name, professional email address, login credentials, and profile information used to access and manage your console account.
Why we can use this data: Needed to fulfil our contract with you to provide and maintain your account. How long we keep it: As long as your account exists.
Euneo is the data controller for your console account (including your login credentials, name, email, and profile details). Your clinic is the data controller for the treatment records you work on, your name attached to changes you make, and any Quality Suite figures about you. If you work on your own, you are the data controller for your workspace and treatment records. Euneo processes treatment record data only on the data controller's behalf under our data processing agreement. Your clinic tells you how it uses that data; send requests about it to the clinic. If you send them to us, we pass them on.
3. What data we collect, why we use it, and how long we keep it
Access log. A record of who opened or changed which treatment records, when, and from which IP address (the internet address of the device). It includes what you do in the console, but never the content of a record. Euneo and the data controller of each workspace use it to check that records are only opened when needed.
Why we can use this data: Legitimate interest, meaning a necessary reason that does not override your rights. Here, the reason is keeping the console secure and preventing unauthorised access. How long we keep it: 400 days, stored in the EU. We keep it for this period even if you close your account.
Product analytics. We only analyse data that cannot identify you, such as which features are used and device and browser information.
Why we can use this data: It cannot identify you, and we only use it to understand how the console is used and to improve it. How long we keep it: 25 months.
Error monitoring. Error details, device and browser information, and a code that replaces your name (a pseudonymised ID).
Why we can use this data: Legitimate interest: keeping the console safe, reliable and working. How long we keep it: Up to 90 days.
Service logs. Errors and requests to our servers, with your user ID or IP address.
Why we can use this data: Legitimate interest: keeping our servers secure and working properly. How long we keep it: 30 days.
Support and feedback. What you send us and your contact details, including any screenshots or videos you upload with feedback. Please leave out patient data unless we need it to help you. If you include patient data, we use it only to answer you, on behalf of the data controller of the workspace.
Why we can use this data: Needed to fulfil our contract with you, or legitimate interest (answering your questions). How long we keep it: 24 months after your question is resolved, or until you close your account, whichever comes first.
Service emails. We email you about your account, security and changes to our terms or this policy.
Why we can use this data: Needed to fulfil our contract with you. How long we keep it: As long as your account exists.
Agreements. We record which versions of our terms and this policy you accepted or confirmed, and when. If you accept our terms or data processing agreement on behalf of a clinic, we also record your name, Icelandic ID number (kennitala), job title, and the date and version you accepted.
Why we can use this data: Legitimate interest: being able to show what the clinic agreed to. How long we keep it: As long as the agreement applies, and for four years after it ends.
4. Who gets to see your information?
- Authorities, only where the law requires it.
- The service providers in the table below. They act on our instructions.
| Provider | Purpose | Location and safeguard |
|---|---|---|
| Firestore and Cloud Storage | Main database and file storage | Belgium and the Netherlands (EU) |
| Google Cloud BigQuery | Summaries and Quality Suite reports | EU |
| Railway | Web service hosting | Amsterdam (EU) |
| Vercel | Console hosting | Frankfurt (EU) |
| Vercel Blob | Screenshots and videos uploaded with feedback | Dublin (EU) |
| Resend | Service emails, including invitations that include your name | Stored in the US (company registered in Ireland). Safeguards: Standard Contractual Clauses and Data Privacy Framework |
| Twilio | Text message invitations with your name and a connection code | Dublin (EU) |
| Google Workspace | Support questions | EU |
5. Transferring information outside of Europe
Your data is stored in the European Economic Area (EEA), except where the table in Section 4 shows the US. For transfers to the US we use safeguards approved by the European Commission: the EU–US Data Privacy Framework or Standard Contractual Clauses (standard contract terms). Some providers that store data in the EEA are owned by US companies. Their technical staff in the US may access the data remotely, under the same safeguards.
6. Your privacy rights and controls
Under privacy law, you have rights over your personal data. You can:
- Ask to see your data or get a copy of it
- Ask us to correct data that is wrong
- Ask us to delete your data or limit how we use it
- Get the data you gave us in a format you can move to another service
Your right to object. Where we rely on legitimate interest (Section 3), you can object at any time for reasons relating to your situation. Write to privacy@euneohealth.com.
Closing your account. You can close your account by writing to us. As the controller of your console account, Euneo deletes your account credentials and profile data upon closure. Treatment records, your name on recorded changes, and Quality Suite figures are held on behalf of your clinic (or you, if operating independently) as data controller, and their deletion or retention follows the controller's instructions. Access-log entries are retained for 400 days, and records of agreements are kept as described in Section 3. Error and service logs are deleted automatically within 90 days. Deleted data is removed from our backups within 180 days.
We answer requests within one month. For complex requests we may need up to two more months; if so, we tell you why within the first month.
You can complain to Persónuvernd (the Icelandic Data Protection Authority), Laugavegur 166, 4. hæð, 105 Reykjavík, postur@personuvernd.is, www.personuvernd.is. You can also complain to the data protection authority in the EEA country where you live or work, or where you think the problem happened.
7. Cookies and browser storage
The console uses cookies and similar browser storage only where they are needed to sign you in and keep the console secure. It does not use advertising cookies and does not track you on other websites.
8. Keeping your data safe
We protect your data with encryption, both when it is sent and when it is stored. Only staff who need access have it, we log access, we test our backups, and our staff are bound by confidentiality and trained in data protection.
If a security breach is likely to put you at high risk, we tell you without undue delay.
9. Policy updates and contact details
We update this policy when our processing changes. We tell you before important changes take effect, in the console or by email.
Questions: privacy@euneohealth.com, or Euneo Health ehf., Laufrima 31, 112 Reykjavík. To report a security weakness: security@euneohealth.com.
Last updated: 10 October 2026