Privacy Policy
Effective since 7 September 2026 · Version 2.1
This policy explains how Delta Labs processes the personal data of users of the Delta Service. It distinguishes processing carried out by Delta Labs for its own purposes from the processing of patient data carried out on behalf of professional users.
1. Data controller and contact details
Delta Labs SAS, a French simplified joint-stock company with share capital of EUR 1,000, registered with the Niort Trade and Companies Register under number 102 094 448, SIRET 102 094 448 00010, with its registered office at 11 BIS Allée du Muguet, 79200 Parthenay, France, is the controller of the processing activities it determines for managing the Service, accounts, security, billing, communications and its legal obligations.
For any question relating to data protection: admin@mydelta.app.
2. Respective roles for patient data
The professional user determines the purposes and essential means of processing their patients' data. In principle, the professional acts as a controller, or as an initial processor when acting on behalf of another organisation.
For this entrusted data, Delta Labs acts on the professional's instructions and acts as a processor or sub-processor, depending on the applicable relationship. The corresponding obligations are set out in the Data Processing Agreement (DPA).
Delta Labs does not determine, in place of the professional, the legal basis applicable to health data, the information to be provided to patients, whether their consent is required or the retention periods specific to the professional's practice.
3. Data processed
3.1 Data relating to the user
- account and identity data, including first name, last name and email address;
- professional and configuration data, including declared professions, practice preferences, practice language, countries of practice and, where requested, administrative subdivisions;
- security and authentication data, including passwords stored in hashed form, email verification status, authentication factors, sessions, IP address, user agent and technical logs;
- subscription and billing data, including Stripe customer and subscription identifiers, plan, billing interval, payment status, promotions, invoices, billing address and tax information;
- legal evidence, including the documents and versions presented, language, content fingerprint, date and context of acceptance;
- usage data, preferences, support requests and communications with Delta Labs.
3.2 Data entrusted by the user
Depending on the features used, the Service may process:
- patient identity, contact details, administrative information and care information;
- information relating to appointments, sessions and consultations;
- free-form notes, observations and other content entered by the professional;
- optional audio recordings and their metadata;
- transcripts, draft reports, summaries, context and other generated documents;
- health data and other sensitive data that such content may reveal;
- technical identifiers, statuses, dates and durations required for the operation, security and diagnosis of the Service.
3.3 Sources of data
Data is provided directly by the user, produced when they use the Service, received from services they choose to connect, or generated technically by Delta and its providers. Patient data is provided or recorded under the responsibility of the professional user.
4. Purposes and legal bases for Delta Labs' own processing
| Purpose | Main legal basis | Data concerned |
|---|---|---|
| Create and manage the account, provide the Service and deliver support | Performance of the contract or steps taken before entering into a contract | Account, profile, preferences, usage and support communications |
| Manage subscriptions, payments, taxes, invoices and accounting obligations | Performance of the contract and legal obligations | Identity, contact details, subscription, billing and tax data |
| Secure the Service, prevent abuse, diagnose incidents and ensure continuity | Legitimate interests and applicable legal obligations | Authentication, IP address, user agent, technical identifiers, logs and minimised error context |
| Manage legal documents and demonstrate notices and acceptances | Performance of the contract, legal obligation and legitimate interest in retaining evidence | Version, language, fingerprint, audience, date, IP address and user agent |
| Send communications relating to the account, Service or applicable obligations | Performance of the contract, legal obligation or legitimate interest, depending on the message | Identity, email address, language and technical delivery history |
Where an optional communication requires consent, the user may withdraw it at any time. Messages essential to account operation, security, billing or compliance with a legal obligation are not marketing communications.
5. Recipients and service providers
Data is accessible to authorised members of Delta Labs within the limits of their duties and to providers required for the Service, including:
- Amazon Web Services for application hosting, storage, databases, networking, logs, monitoring and technical email delivery through Amazon SES;
- Google Cloud for transcription, the temporary storage required for that transcription and artificial intelligence processing enabled by the user;
- Sentry for detecting and analysing technical errors, with a configuration intended to exclude known clinical content and sensitive fields;
- Stripe for creating and managing customers, subscriptions, payments, invoices, taxes and payment methods. Delta Labs neither receives nor stores full card numbers or security codes;
- advisers, authorities, courts or third parties to whom disclosure is necessary to comply with the law, establish or defend rights, or protect the Service.
Providers processing patient data on the user's behalf are also described in the DPA. Delta Labs does not sell personal data or patient data.
6. Location and international transfers
Delta's primary production infrastructure is configured in the AWS eu-west-3 region in Paris. Specialised transcription and artificial intelligence processing is configured in European Google Cloud locations compatible with the services used.
Some providers or their own sub-processors may nevertheless process data from other countries, particularly for support, security, billing or observability. Delta Labs therefore does not present the absence of any transfer outside the European Economic Area as an absolute guarantee.
Where a transfer requires a particular safeguard, Delta Labs relies on a mechanism recognised by applicable law, such as an adequacy decision or the European Commission's standard contractual clauses, supplemented where necessary by appropriate measures.
7. Retention periods
Delta Labs retains data for a period proportionate to the relevant purpose, the user's instructions, technical cycles and legal obligations:
- account and profile data is retained for the lifetime of the account, then for the time required to close it, establish or defend rights and comply with applicable obligations;
- billing data and accounting records are retained for the applicable statutory periods, which may be up to ten years for accounting records;
- legal evidence is retained for the contractual relationship and then for the period required to demonstrate the parties' rights and obligations;
- the main cloud infrastructure technical logs are currently configured with a ninety-day retention period; other security or deliverability records may follow a different cycle where necessary and proportionate;
- the body of emails placed in the delivery queue is deleted after handover to the provider; metadata strictly required to track delivery may be retained for longer;
- patient data is retained according to the professional's instructions and use, subject to technical deletion periods, backups and applicable legal obligations.
8. Security
Delta Labs implements technical and organisational measures appropriate to the risks, including:
- encryption of exposed communications using secure protocols and encryption at rest for the main production storage systems;
- individual authentication, enhanced authentication mechanisms, server-side authorisation controls and logical data isolation;
- private networks and storage, restricted internal access and controlled secret management;
- backups, logs, monitoring tools and deployment procedures appropriate to the architecture;
- minimisation of information sent to diagnostic tools.
As no measure eliminates every risk, users must also protect their access credentials, use appropriate equipment and promptly report any suspicious use.
9. Personal data breaches
Delta Labs analyses security incidents and takes appropriate measures to contain and remedy them. Where a personal data breach concerns Delta Labs as controller, it makes the required notifications within the statutory time limits. Where it concerns data entrusted by a professional, Delta Labs informs the professional without undue delay after becoming aware of it and provides the available information needed for the professional to meet their own obligations.
10. Data subject rights
Subject to the conditions provided by applicable law, users may request access to, rectification or erasure of their data, data portability or restriction of processing, and may object to certain processing or withdraw consent.
Requests may be sent to admin@mydelta.app or by post to Delta Labs SAS, 11 BIS Allée du Muguet, 79200 Parthenay, France. Delta Labs may request information reasonably necessary to verify identity and respond to the request.
For patient data processed in Delta on a professional's behalf, the request should generally be addressed to that professional. Delta Labs assists the professional under the conditions set out in the DPA.
The data subject may also lodge a complaint with the competent supervisory authority. In France, this is the CNIL: www.cnil.fr.
11. Artificial intelligence and automated decisions
Artificial intelligence features help the professional produce transcripts, drafts, summaries or documents. The professional must review, correct and validate the content before using it.
Delta does not use these features to make, in place of the professional, a decision producing legal effects or similarly significantly affecting a person based solely on automated processing.
12. Cookies and local storage
The Service uses cookies or storage mechanisms required for authentication, security, preferences and interface operation. If Delta Labs introduces trackers that are not strictly necessary, the corresponding information and, where required by law, consent mechanism will be implemented before they are used.
13. Required data
Fields marked as required are necessary to create the account, describe the professional context, determine the applicable documents, provide the Service or issue bills. Without them, certain steps or features may not be available. Other information is optional unless it becomes necessary for a feature expressly requested by the user.
14. Changes to this policy
Each change results in an identifiable, dated version. Depending on the nature of the change, the new version may be published without specific notice, be the subject of a notice, or require renewed explicit acceptance.
The version and language presented upon acceptance are retained as part of the corresponding evidence. The French version is the reference version; translations are provided to facilitate understanding, subject to any applicable mandatory rules.
15. Contact
Delta Labs SAS
11 BIS Allée du Muguet
79200 Parthenay, France
+33 7 66 80 89 66