INTRODUCTION AND SCOPE
Purpose and commitment of privacy
In Majily LLC (hereinafter: THE COMPANY), privacy and information security are fundamental pillars of our operation. This Privacy Policy (hereinafter: PP) is intended to inform mental health professionals, clinics or health institutions (hereinafter: THE USER) in a transparent manner about the practices of collection, use, storage, processing and protection of personal data and health information managed through our platform.
Scope of application
This PP governs all information collected or processed by THE COMPANY through its website, mobile applications, third-party integrations, Artificial Intelligence systems and any other tool or digital service that is part of the company's technological offer (hereinafter, and as a whole, THE SOFTWARE or SERVICES).
Relationship with the Terms and Conditions
This PP is an integral and inseparable part of the Terms and Conditions (T&C) of THE COMPANY. The terms defined in the T&C will maintain the same meaning in this document to ensure consistency and harmony of the legal framework that binds THE PARTIES.
Legal standards and compliance
This policy has been drafted to comply simultaneously with the regulations of the State of Wyoming and the federal laws of the United States, as well as with the Law No. 25.326 on Protection of Personal Data of the Argentine Republic and its regulations. In case of conflict between regulations, THE COMPANY will apply the technical and legal standard that is most favorable for the protection of the privacy of the data holder.
Acceptance and consent
By ticking the acceptance box during the registration, as well as by means of access, navigation or continued use of the SERVICES, THE USER declares that he has read, understood and granted his express and unequivocal consent for the treatment of his data and those of his patients in accordance with the terms described herein. If THE USER does not agree with these provisions, he shall refrain from using THE SOFTWARE immediately.
2. Identification of the controller
Identity of the person responsible
The legal person responsible for the processing, storage and protection of personal and clinical data managed through the platform is MAJILY LLC, a limited liability company duly constituted and in force under the laws of the State of Wyoming, United States of America.
Operating address and head office
For purposes of this PP and any official communication, the principal headquarters and management address of THE COMPANY are located at 1000 Brickell Avenue Suite #715 PMB 153 Miami, Florida 33131, United States of America.
Registration agent in jurisdiction of origin
In compliance with Wyoming corporate regulations, Registered Agents Inc is identified as a registration agent, domiciled at 30 N Gould St Ste R Sheridan, WY 82801, United States of America.
Privacy Communication Channel
THE USER may direct any inquiry, request for exercise of rights or report of incidents related to the privacy of the data exclusively to the email address: soporte@brauni.io.
Role in data management
In accordance with the data protection regulations, it is confirmed that THE COMPANY acts as Data Processor with respect to the patient information charged by the professional, and as Data Controller with respect to the registration and invoicing information of THE USER.
3. Legal basis for treatment
Consent of the holder
The processing of the personal data of THE USER is based on his free, express and informed consent, given unequivocally at the time of the identification of the acceptance box and the creation of his account on the platform. This consent gives THE COMPANY the legal basis necessary to process the information in accordance with the purposes described herein.
Contract performance
Much of the data processing is strictly necessary for the fulfilment of the contractual obligations assumed by THE COMPANY, specifically to grant the right of use over THE SOFTWARE and to provide clinical management, storage and assistance services through AI requested by THE USER.
Compliance with legal obligations
THE COMPANY may treat and, where appropriate, disclose information when necessary to comply with binding laws, regulations, legal processes or governmental requests, both in the United States and in the jurisdictions where the USER operates. This includes detection of fraud and protection of user safety.
Legitimate interest
THE COMPANY bases the processing of anonymized metadata and statistical diagnostic data on its legitimate interest in improving the operation of EL SOFTWARE, conducting benchmarking studies and ensuring the safety and resilience of the technological infrastructure. This treatment is carried out by ensuring that natural persons holding the data are not identified.
Revocation of consent
THE USER retains the right to withdraw his consent at any time. However, the revocation of his consent may imply the technical impossibility of continuing to make use of the SERVICES, resulting in the cancellation of the account under the terms established in the Sixteenth T&C Clause.
4. Types of data collected
THE COMPANY collects personally identifiable information provided directly by THE USER at the time of creating its account or contracting the SERVICES, which may include name, email address, telephone number, professional position, rating credentials and invoicing data. With respect to invoicing, it is clarified that THE COMPANY does not collect or store credit card numbers or security codes, as such management is carried out entirely by the PAYMENT PROVEER.
In relation to PATIENT DATA, SOFTWARE collects and processes the information that THE USER loads, stores or transmits, including personal data, medical records, session notes, diagnostics and other health records. The processing of this data is strictly confidential and is done under the exclusive direction of THE USER as controller.
THE COMPANY collects information automatically through the use of THE SOFTWARE, such as IP addresses, browser types, device identifiers, system logs (logs), approximate geolocation data and usage patterns of platform tools. This information is used primarily to ensure security, identify preferences and improve technical expertise.
Use metadata and statistical diagnostic data that have been stripped of any personal identifier are collected in order to make operational improvements to THE SOFTWARE and optimize Artificial Intelligence tools without compromising privacy.
THE USER is solely responsible for the veracity of the information provided and for ensuring that he has the legal consents and authorizations of his patients for the entry and processing of his information in EL SOFTWARE.
5. Purposes of treatment
THE COMPANY treats the data collected for the main purpose of providing, operating and maintaining the functionalities of THE SOFTWARE and THE SERVICE, including the management of clinical records, the management of agendas and the provision of the artificial intelligence assistant for clinical use. This processing is essential to comply with the purpose of the platform’s concession contract.
The contact and invoicing information of THE USER is used to manage the subscription model, process recurring charges through the PAYMENT PROVIDER and issue the corresponding tax vouchers for the services and ADD-ONS contracted.
THE COMPANY uses the data to provide technical support, diagnose and resolve operational incidents and respond to queries sent by THE USER to the official support channel. Likewise, the information is used to send critical notifications about the security of the account, updates of the terms or alerts to possible security gaps that affect the integrity of the data.
In order to ensure the stability of the system, THE COMPANY processes usage data to periodically audit the volume of resources consumed and ensure that the use of the account is in line with the patient limits, AI tokens and storage defined in the USER's subscription plan.
PATIENTS DATA are processed by integrated AI tools exclusively to generate real-time suggestions, reports and analysis according to the direct instructions of THE USER, without such information being used for training machine learning models or third-party algorithms.
THE COMPANY uses strictly anonymized usage metadata and diagnostic data to conduct benchmarking studies, generate public statistical reports and develop technical improvements in the operation and efficiency of EL SOFTWARE.
6. Sensitive data processing and artificial intelligence
Nature of health data
EL USUARIO reconoce que la información procesada a través de EL SOFTWARE referente a la salud mental de los pacientes constituye la categoría de “Datos Sensibles” bajo la normativa argentina y de “Información de Salud Protegida” (PHI) bajo estándares estadounidenses. LA EMPRESA se compromete a otorgar a estos datos el nivel más elevado de seguridad y confidencialidad, procesándolos únicamente para la prestación del servicio médico-asistencial solicitado por el profesional.
Guarantee of non-training models
THE COMPANY expressly guarantees that PATIENTS DATA entered into the platform are not, under any circumstances, used for the training, improvement or development of models of Artificial Intelligence (IA), machine learning or algorithms of its own or of third parties. Clinical processing is limited to the execution of functions in real time for the exclusive benefit of the consultation of THE USER.
Security in the processing of AI
All AI tools integrated into SOFTWARE operate under strict end-to-end encryption protocols. AI infrastructure providers (such as Google or AWS) are contractually prohibited from accessing patient identifiable information for purposes other than the technical execution of processing requested by THE COMPANY.
Ownership of results
Any report, clinical summary or diagnostic suggestion generated by AI tools is the exclusive property of THE USER and is privately integrated into the patient’s medical records. THE COMPANY does not retain rights to the clinical content generated by the assistant.
Use of anonymised data
Without prejudice to the above prohibitions, THE USER authorises THE COMPANY to process technical metadata and diagnostic data in a strictly anonymised manner (deidentification process that prevents linking information to a particular or identifiable natural person) for technical improvement purposes, global statistics or benchmarking studies.
Need for human review
In compliance with the principle of professional responsibility, THE USER recognizes that AI results may contain inaccuracies and is required to perform a critical human validation of all information prior to its official clinical use.
7. International data transfer
Accommodation in the United States
THE USER acknowledges and accepts that all information processed through SOFTWARE, including PATIENT DATA, is hosted and stored exclusively on servers located within the territory of the United States of America.
Consent to transfer
By using the SERVICES, THE USER grants his free, express and informed consent for the international transfer of his personal data and those of his patients to the United States of America for processing and storage. In the case of users residing in the Argentine Republic, this transfer is carried out under Act No. 25.326, guaranteeing adequate levels of protection through the use of world class suppliers.
Third party infrastructure
The company uses AWS services for the operational execution and storage of databases. This infrastructure has international security and compliance certifications that ensure the resilience and availability of information.
Multiregion configuration
In order to ensure continuity of service and protection against systemic failures, THE COMPANY maintains a multi-region storage configuration within the AWS infrastructure in the United States. This architecture ensures the redundancy of the data without the latter leaving US jurisdiction.
Security guarantees in transit
THE COMPANY implements industrial level encryption protocols to protect information during its transfer from the USER's devices to storage servers, mitigating the risks of interception by unauthorized third parties.
8. DISCLOSURE TO THIRD PARTIES
THE COMPANY does not sell, rent or market the personal or clinical data of its users or patients under any circumstances. The information is only shared with third-party service providers that are strictly necessary for the operation of EL SOFTWARE.
Infrastructure and computing providers
The company uses the services of Amazon Web Services (AWS) and Google for the hosting of databases, file storage and execution of Artificial Intelligence processes. These providers act as infrastructure subprocessors and are not authorized to use the data for their own purposes or training external models.
Processing of payments
All financial transactions and subscription management are done through Stripe LLC (and its affiliates). THE COMPANY does not store credit card data; such information is managed directly by this provider under its own security standards and privacy policies.
Communication providers
For the delivery of operational notifications, support emails and messages via WhatsApp integrated into SOFTWARE, THE COMPANY may use third party services specialized in electronic communications.
Legal requirements
THE COMPANY may disclose personal information if it believes in good faith that it is reasonably necessary to comply with a binding law, regulation, legal process or governmental request. It may also do so to protect the safety of its users, detect fraud or safeguard their intellectual property rights.
Obligations of subprocessors
THE COMPANY contractually requires that all its SUBPROCESSORS implement technical and organisational security measures equivalent to those established in this PP to protect the confidentiality of information.
9. Information security
Security commitment
THE COMPANY has implemented technical, physical and administrative safeguards specifically designed to protect the integrity and confidentiality of personal data and managed health information. These measures are aimed at preventing unauthorized access, accidental loss or destruction of information.
Encryption and technical protocols
All information processing processes, especially those related to Artificial Intelligence tools and the transmission of clinical data, are executed under strict encryption protocols. Also, access to the platform is made through secure connections that protect data in transit.
Infrastructure security
SOFTWARE operates on the infrastructure of Amazon Web Services (AWS), which ensures optimal levels of security, resilience and availability for clinical information management. To mitigate risks of data loss and ensure operational continuity in the event of systemic failures, THE COMPANY maintains a multi-region storage architecture that allows for redundancy and efficient retrieval of information.
Monitoring of accesses and protection actions
As part of its security measures, THE COMPANY registers and monitors the access metadata, sessions and activity of the account, and implements mechanisms for detecting abnormal access to clinical information, without accessing clinical content for such purposes. Faced with indications of unauthorized access, commitment of credentials or risk to data integrity, THE COMPANY may automatically or manually adopt containment measures such as revocation of active sessions, temporary blocking of the account and forced re-establishment of the password or authentication factors (2FA), notifying THE USER where appropriate, as provided for in the Terms and Conditions.
User-sharing responsibility
Information security is a shared responsibility. THE USER is solely responsible for maintaining the strict confidentiality of your access credentials (username and password). To strengthen the security of your account, the use of passwords that meet minimum requirements of complexity is required and the activation of two-factor (2FA) authentication mechanisms is strongly recommended when available.
Safe use practices
It is essential for THE USER to effectively close his session at the end of his working day or when the access device is beyond his direct control. The breach of these basic safety practices by the professional exempts THE COMPANY from liability for unauthorized access resulting from such negligence.
Technical limitations
Although THE COMPANY makes its best commercial efforts to protect the data, THE USER recognizes that no method of storage or electronic transmission is absolutely impregnable. Consequently, the use of the service is made at its own risk regarding vulnerabilities that are beyond the reasonable control of THE COMPANY.
10. Rights of data subjects
Both THE USER and the patients whose data is processed in EL SOFTWARE have the following rights:
- ACCESS: Right to request information on whether your data is being processed and to obtain a copy thereof.
- Rectification: Right to update or correct inaccurate or incomplete data.
- CANCELLATION (Abolishment): Right to request data deletion when no longer necessary for the purposes that were collected, subject to legal obligations for the preservation of clinical records.
- Opposition: Right to object to the processing of your data for legitimate reasons.
Exercise of rights by THE USER
The professional may exercise his rights to update, correct or delete his own registration data directly through the configuration interface of EL SOFTWARE or by sending a request to soporte@brauni.io.
Exercise of rights by the patient
In a commitment to total transparency, THE COMPANY enables a direct contact channel for patients of THE USER to consult about the treatment of their personal information. Patients may address their requests to the address soporte@brauni.io.
Identity procedure and validation
To protect the confidentiality of sensitive health data, any request (either from THE USER or the patient) will require rigorous identity validation. THE COMPANY may request official documentation or additional authentication methods before processing any access or modification request.
Coordination with the professional
Since THE COMPANY acts as a Data Processor, upon a direct request from a patient, THE COMPANY shall immediately notify THE USER (the controlling psychologist) to coordinate the response. This ensures that neither the course of clinical treatment nor the duty of custody of the file is affected by the professional.
Time limits for response
THE COMPANY undertakes to respond to requests for access within ten (10) days of proof of identity, and to requests for rectification or deletion within five (5) working days, in accordance with the deadlines established in the Argentine legislation.
11. Data retention and deletion
Active retention period
THE COMPANY shall retain the personal data and PATIENT DATA only for as long as the USER's account remains active and is necessary for the provision of the SERVICES.
Discharge of service and recovery period
In case of voluntary cancellation of the subscription, access to the operating functions of EL SOFTWARE will cease at the end of the paid period (monthly or annual, according to the contracted modality). From that date, a grace period of ninety (90) days running during which the information will remain stored on the servers to allow its export and recovery by THE USER will begin.
Retention for non-payment
Faced with a default event, THE COMPANY will grant a period of ninety (90) days counted from the first failed attempt to collect. During this period, THE USER will maintain restricted access exclusively for the consultation and export of existing data.
Definitive and irreversible elimination
Once the period of 90 (90) days mentioned in the preceding paragraphs has elapsed, THE COMPANY shall proceed to the technical, safe and irreversible removal of all information from its active servers. THE USER recognizes that, after this deletion, it will be technically impossible to recover any data or clinical record.
Custody responsibility
THE USER recognizes that SOFTWARE is not a perpetual filing service or a backup service. The legal obligation to keep the medical records for the deadlines required by the applicable health regulations rests exclusively with the professional. THE COMPANY shall not be liable for the loss of data resulting from the failure of THE USER to export its information during the grace periods established.
Derogations by legal obligation
Without prejudice to the above, THE COMPANY may retain certain registration and financial transactions (invoicing) data for additional periods when necessary to comply with fiscal, accounting or legal obligations, or for defence against possible judicial claims.
System Logs and Backups
THE USER accepts that the complete removal of interaction records and the purge of data in disaster backups may not be immediate due to technical limitations, although such data will remain inaccessible for the ordinary use of the system.
12. PRIVACY OF MINORS
Restriction of use for users
In accordance with the Terms and Conditions THE COMPANY, the access and use of THE SOFTWARE is strictly prohibited for persons under eighteen (18) years of age. Upon registration, THE USER guarantees that he or she has legal majority in his or her jurisdiction of residence. THE COMPANY does not intentionally collect personal identification information from professionals who know they are minors.
Treatment of minor patient data
THE COMPANY acknowledges that, due to the nature of the SERVICES, THE USER can charge and process PATIENTS' DATA that are minor. In these cases, the processing of such information is carried out exclusively within the framework of the professional relationship between the psychologist and the patient, where THE COMPANY acts only as a technical processor.
Professional responsibility
It is the sole and exclusive responsibility of THE USER to ensure that he has the informed consents, parental authorizations or legal guardians necessary to process information about minors in EL SOFTWARE. The professional must comply with:
- Local regulations for the protection of children and adolescents (such as Law 26.061 in Argentina).
- The consent requirements for children under 13 or 16 years of age according to the applicable jurisdiction (such as COPPA in the United States or the progressive autonomy standard in Argentina).
Special protection
THE COMPANY applies the same high-level encryption and security standards to all clinical data, regardless of the age of the holder, ensuring that juvenile data receive the most rigorous technical protection available on the platform.
Detection of unauthorized use
If THE COMPANY becomes aware that a minor has created a user account directly or that data of minors has been uploaded without due legal basis, THE COMPANY reserves the right to delete such information and suspend the account immediately to protect the privacy of the minor.
13. Reporting of security gaps
THE COMPANY implements robust technical and organisational measures (such as encryption and access controls) to safeguard information. However, THE USER recognizes that no security or encryption system is infallible, and that the software may be subject to attacks or human errors outside the control of THE COMPANY.
Notification protocol
In the event that THE COMPANY has confirmed knowledge of a security gap affecting the integrity, availability or confidentiality of PATIENTS' DATA, personal information or Protected Health Information (PHI), it undertakes to notify the affected USER as soon as possible.
Communication channels
Such notification will be formally sent to the email address linked to the USER's account. It is the responsibility of the professional to keep that communication channel up to date to ensure the receipt of critical alerts.
Content of the communication
The breach notification shall include, to the extent technically possible:
- The nature of the security incident.
- The categories of data that could have been compromised.
- Recommended measures to mitigate potential risks.
- The information necessary for THE USER, in his capacity as data controller, to make the relevant assessments and reports to the competent authorities if the law so requires.
Technical cooperation
THE COMPANY shall make reasonable commercial efforts to investigate the incident and restore the safety of the service as soon as possible. However, the liability of THE COMPANY shall not extend to indemnities for damages arising from events that constitute Case fortuitous or faults in the infrastructure of third-party suppliers (AWS/Google).
14. Enforcement authority and complaints
United States Authority
THE COMPANY is subject to the powers of investigation and enforcement of the Federal Trade Commission (FTC) of the United States. Users and third parties may address their inquiries or claims about privacy practices to that body if they consider that their rights have been violated under U. S. federal law.
Authority in the Argentine Republic
Pursuant to Act No. 25.326, it is reported that the Access to Public Information Agency is the supervisory body of the said Act and has the authority to deal with complaints and complaints that arise in connection with non-compliance with the rules on the protection of personal data. The USER and data holders have the right to turn to that authority to safeguard their rights of access, rectification, update or deletion.
Jurisdiction
Without prejudice to the powers of the above-mentioned administrative authorities, any legal dispute or dispute that is not resolved through the support channels of THE COMPANY (soporte@brauni.io), shall be subject to the exclusive jurisdiction of the state and federal courts located in Laramie County, Wyoming, in accordance with the provisions of Terms and Conditions.
Cooperation with authorities
THE COMPANY shall cooperate with public and judicial authorities when so required through a valid legal process, such as a court order, subpoena or administrative order, in order to comply with its legal obligations and protect the safety of its users and the general public.
15. Changes to the privacy policy
Right of amendment
THE COMPANY reserves the right to modify, update or supplement this PP at any time, at its sole discretion, to adapt it to new legislation, case law, industry practices or changes in the functionalities of EL SOFTWARE.
Notification of material changes
In the event of any changes that substantially affect the processing of personal data or the rights of the holders, THE COMPANY shall make reasonable efforts to notify THE USER at least thirty (30) calendar days in advance before such changes enter into force. This notification shall be sent to the email linked to the account or by means of a notice highlighted on the platform.
Non-significant changes
THE COMPANY may make minor or administrative changes that do not significantly affect the use of the information, for which publication of the updated version will suffice on the website. It is recommended that THE USER review this page periodically to keep informed about any updates.
Acceptance of changes
The access or continued use of the SERVICES after the entry into force of any modification shall constitute the full and express acceptance of the new PP by THE USER.
Right of termination
If the USER does not agree with the proposed modifications, he or she will have the right to terminate his or her subscription and stop using THE SOFTWARE before the changes enter into force, in accordance with the T&C procedure.
16. Acceptance and final consent
Declaration of conformity
By accessing, registering or using THE SOFTWARE, THE USER expressly declares that he has read, understood and accepted in full the content of this Privacy Policy.
Unequivocal consent
The name in the acceptance box during the account creation process constitutes the granting of free, express and informed consent for THE COMPANY to process its data and those of its patients under the terms stipulated herein.
Contractual integration
THE USER recognizes that this PP is an integral part of the binding legal contract it maintains with Majily LLC, complementing the provisions of the Terms and Conditions and the Business Association Agreement (BAA) where appropriate.
Channel of consultations
For any final doubt about the privacy of your data or the scope of this document, the official and exclusive channel of communication remains: soporte@brauni.io.