Controlled access
A record is accessible within an authorized care relationship. AI does not have unrestricted access to the database.
Behind every record is a person who trusts you. Protecting their story is part of how we build Recodex.
Privacy is more than a padlock. It concerns the information collected, who can access it, how AI is used and the choices available to patients.
A record is accessible within an authorized care relationship. AI does not have unrestricted access to the database.
Relevant context is selected, and identifying details in supported text are pseudonymized.
Patients have privacy choices. Psychologists remain responsible for their clinical decisions.
Psychologists, patients and clinical assistants have different roles. Bringing treatment together in one place does not give everyone the same permissions.
Recodex includes controls for care relationships and separation between records. Patients also have a privacy centre where they can review recent AI access and manage their authorizations.
Clinical access checks the professional’s identity and active relationship with the patient. A clinical AI conversation stays linked to a single patient.
Role illustration · No real records
To help prepare a session or find information, AI needs clinical context. It does not need unrestricted access to the entire platform.
Recodex selects relevant sources and pseudonymizes supported text: certain identifiers are replaced or masked before calling the model. Clinical information nevertheless remains sensitive and must be protected.
Pseudonymization is not complete anonymization. Images, attachments and audio require precautions specific to their format.
Difficulties related to work stress. Active goal: recognize her needs and set boundaries.
Information relevant to the requestA summary, hypothesis or draft note can be useful. It can also be incomplete or incorrect. The professional reviews suggestions, puts them in context and decides what belongs in the record and treatment.
These mechanisms are present in the platform. Validation under real conditions and operational commitments are part of the work to complete before launch.
The server checks the care relationship before using a patient’s context in clinical AI.
A clinical conversation can be linked to only one patient, maintaining a clear boundary between records.
Supported text has detected identifiers replaced or masked before the model uses it.
Controls let patients pause AI access or withdraw their consent.
The log records the purpose of access and the categories of sources used, without copying clinical messages into it.
AI suggestions are aids to be reviewed. On their own, they do not constitute a clinical decision or validation.
Recodex is in development. We distinguish built-in mechanisms from measures, contracts and validations that still need to be confirmed before use with real clinical data.
Document storage and processing regions, encryption measures, backups, administrative access and restoration procedures.
Complete privacy assessments and contracts, identify subprocessors and processing locations, then confirm data retention and model training restrictions.
Finalize notices and verify that required authorizations, refusals, pauses and withdrawals are respected across all relevant workflows, including audio and transcription.
Define retention periods for each data category, access, correction and deletion procedures, and exceptions related to maintaining clinical records.
Check permissions, arrange the necessary security reviews and test procedures for detecting, handling and communicating about incidents.
Publish the responsible person’s contact details, approved policies and information needed to understand data processing before accepting real clinical data.
Clinical records, AI conversations, audio and transcription serve different purposes. Each must have a clear purpose, an authorization framework and its own retention rules.
A transcription or AI service may process some information needed for its function. Providers, processing locations and confidentiality commitments must be documented and communicated before launch.
Viewing, correcting or requesting deletion of information must follow a clear procedure. Removing AI access does not automatically delete clinical documents or the professional’s retention obligations.
Access depends on the person’s role and the authorized care context. For clinical AI linked to a patient, Recodex checks the active relationship between the professional and that patient. Administrative and support access must also be documented and limited before launch.
Context is prepared from sources relevant to the request. It may include clinical information, questionnaires or selected note excerpts. The model has no key to connect freely to the database. Clinical context remains sensitive, even when pseudonymized.
No. Pseudonymization replaces or masks certain identifiers, but a clinical history may still allow someone to be recognized. It reduces exposure of identity without eliminating all possibilities of reidentification. Images and scanned documents may also contain visible details that text masking does not cover.
The privacy centre provides both controls, along with a view of recent access. Withdrawal or pausing concerns AI access to the record. It does not automatically delete the clinical record or documents the professional must retain. The full consent process is among the validations to complete before launch.
The planned provider framework requires confirmation that transmitted clinical data will not be used for training. Contracts, settings and any exceptions must be checked before launch. We do not present this requirement as a contractual guarantee already confirmed for every service.
The exact locations for storage, backups and provider processing are among the details still to be confirmed. They must be distinguished: where a record is hosted does not necessarily determine where AI processing or transcription takes place. This information must be published before real clinical data is used.
Recording, transcription and assisted writing are separate uses. They must be explained to the patient, together with required authorizations, the providers involved and retention rules. Text masking does not automatically make an audio recording or attachment anonymous.
The rules must distinguish clinical records, AI conversations, audio files, documents and access logs. The final policy will specify retention periods and deletion procedures for each category. Withdrawing AI authorization does not mean erasing information already incorporated into the clinical record.
This page does not claim SOC 2, ISO 27001 or any other independent certification. If a certification or audit is obtained, its scope and corresponding verifiable information may be published here.
Use the Contact page for general privacy questions or to report a concern. Avoid including clinical notes, identity documents or information that could identify a patient. Official contact details for the person responsible for protecting personal information must be published before launch.
Want to understand a data use, an access permission or a safeguard? Let’s talk.
For an initial contact, do not send clinical information or details that could identify a patient.