Skip to content

Privacy,
at the heart of your practice.

Behind every record is a person who trusts you. Protecting their story is part of how we build Recodex.

Connect your practice.
Respect what is entrusted to you.

Privacy is more than a padlock. It concerns the information collected, who can access it, how AI is used and the choices available to patients.

01

Controlled access

A record is accessible within an authorized care relationship. AI does not have unrestricted access to the database.

02

Less information exposed

Relevant context is selected, and identifying details in supported text are pseudonymized.

03

Oversight stays human

Patients have privacy choices. Psychologists remain responsible for their clinical decisions.

Every role has its place.
Every access has a framework.

Psychologists, patients and clinical assistants have different roles. Bringing treatment together in one place does not give everyone the same permissions.

Recodex includes controls for care relationships and separation between records. Patients also have a privacy centre where they can review recent AI access and manage their authorizations.

The right record, in the right context.

Clinical access checks the professional’s identity and active relationship with the patient. A clinical AI conversation stays linked to a single patient.

  • Authenticated professional
  • Active care relationship
  • One patient per conversation

Role illustration · No real records

Relevant context.
Less exposure of identity.

To help prepare a session or find information, AI needs clinical context. It does not need unrestricted access to the entire platform.

Recodex selects relevant sources and pseudonymizes supported text: certain identifiers are replaced or masked before calling the model. Clinical information nevertheless remains sensitive and must be protected.

Pseudonymization is not complete anonymization. Images, attachments and audio require precautions specific to their format.

In the clinical record
CD
Camille DuboisPatient record
Selection and pseudonymization
Context prepared for AI
Patient A

Difficulties related to work stress. Active goal: recognize her needs and set boundaries.

Information relevant to the request
Simplified fictional example. Even when pseudonymized, clinical context remains sensitive.

AI supports you.
You retain clinical responsibility.

A summary, hypothesis or draft note can be useful. It can also be incomplete or incorrect. The professional reviews suggestions, puts them in context and decides what belongs in the record and treatment.

Safeguards already
built into Recodex’s design.

These mechanisms are present in the platform. Validation under real conditions and operational commitments are part of the work to complete before launch.

Access verification

The server checks the care relationship before using a patient’s context in clinical AI.

Separation between records

A clinical conversation can be linked to only one patient, maintaining a clear boundary between records.

Text pseudonymization

Supported text has detected identifiers replaced or masked before the model uses it.

Privacy choices

Controls let patients pause AI access or withdraw their consent.

AI access logging

The log records the purpose of access and the categories of sources used, without copying clinical messages into it.

Professional review

AI suggestions are aids to be reviewed. On their own, they do not constitute a clinical decision or validation.

Trust is built
on verifiable commitments.

Recodex is in development. We distinguish built-in mechanisms from measures, contracts and validations that still need to be confirmed before use with real clinical data.

  1. 01

    Confirm hosting and technical safeguards

    Document storage and processing regions, encryption measures, backups, administrative access and restoration procedures.

    To finalize
  2. 02

    Establish terms with every provider

    Complete privacy assessments and contracts, identify subprocessors and processing locations, then confirm data retention and model training restrictions.

    To finalize
  3. 03

    Validate consent from end to end

    Finalize notices and verify that required authorizations, refusals, pauses and withdrawals are respected across all relevant workflows, including audio and transcription.

    To finalize
  4. 04

    Publish clear retention rules

    Define retention periods for each data category, access, correction and deletion procedures, and exceptions related to maintaining clinical records.

    To finalize
  5. 05

    Test security and incident response

    Check permissions, arrange the necessary security reviews and test procedures for detecting, handling and communicating about incidents.

    To finalize
  6. 06

    Formalize privacy governance

    Publish the responsible person’s contact details, approved policies and information needed to understand data processing before accepting real clinical data.

    To finalize

Know what is used.
And what is retained.

Separate uses, explained clearly

Clinical records, AI conversations, audio and transcription serve different purposes. Each must have a clear purpose, an authorization framework and its own retention rules.

Providers to identify

A transcription or AI service may process some information needed for its function. Providers, processing locations and confidentiality commitments must be documented and communicated before launch.

Requests handled in context

Viewing, correcting or requesting deletion of information must follow a clear procedure. Removing AI access does not automatically delete clinical documents or the professional’s retention obligations.

Your questions.
Straightforward answers.

We can discuss your specific situation with you.

Contact us
Who can view a patient’s record?

Access depends on the person’s role and the authorized care context. For clinical AI linked to a patient, Recodex checks the active relationship between the professional and that patient. Administrative and support access must also be documented and limited before launch.

Does AI receive the entire record?

Context is prepared from sources relevant to the request. It may include clinical information, questionnaires or selected note excerpts. The model has no key to connect freely to the database. Clinical context remains sensitive, even when pseudonymized.

Does pseudonymized mean anonymous?

No. Pseudonymization replaces or masks certain identifiers, but a clinical history may still allow someone to be recognized. It reduces exposure of identity without eliminating all possibilities of reidentification. Images and scanned documents may also contain visible details that text masking does not cover.

Can I pause AI or withdraw my consent?

The privacy centre provides both controls, along with a view of recent access. Withdrawal or pausing concerns AI access to the record. It does not automatically delete the clinical record or documents the professional must retain. The full consent process is among the validations to complete before launch.

Is the data used to train AI models?

The planned provider framework requires confirmation that transmitted clinical data will not be used for training. Contracts, settings and any exceptions must be checked before launch. We do not present this requirement as a contractual guarantee already confirmed for every service.

Where will data be hosted and processed?

The exact locations for storage, backups and provider processing are among the details still to be confirmed. They must be distinguished: where a record is hosted does not necessarily determine where AI processing or transcription takes place. This information must be published before real clinical data is used.

How are audio and transcription governed?

Recording, transcription and assisted writing are separate uses. They must be explained to the patient, together with required authorizations, the providers involved and retention rules. Text masking does not automatically make an audio recording or attachment anonymous.

How long is information retained?

The rules must distinguish clinical records, AI conversations, audio files, documents and access logs. The final policy will specify retention periods and deletion procedures for each category. Withdrawing AI authorization does not mean erasing information already incorporated into the clinical record.

Does Recodex have security certifications?

This page does not claim SOC 2, ISO 27001 or any other independent certification. If a certification or audit is obtained, its scope and corresponding verifiable information may be published here.

How can I ask a question or report a concern?

Use the Contact page for general privacy questions or to report a concern. Avoid including clinical notes, identity documents or information that could identify a patient. Official contact details for the person responsible for protecting personal information must be published before launch.

Every question deserves
a real answer.

Want to understand a data use, an access permission or a safeguard? Let’s talk.

For an initial contact, do not send clinical information or details that could identify a patient.