Privacy Policy
Effective since 3 October 2026 · Version 2.2
This policy explains how Delta Labs processes the personal data of visitors to mydelta.app, people requesting a demonstration and users of the Delta Service. It distinguishes these activities from the processing of patient data on behalf of professional users.
1. Data controller and contact details
Delta Labs SAS, a French simplified joint-stock company with share capital of EUR 1,000, registered with the Niort Trade and Companies Register under number 102 094 448, SIRET 102 094 448 00010, with its registered office at 11 BIS Allée du Muguet, 79200 Parthenay, France, is the controller for the processing it determines to manage the Website and Service, accounts, security, billing, communications, demonstration requests, audience measurement and advertising campaign effectiveness, and to meet its legal obligations.
For any question relating to data protection: admin@mydelta.app.
2. Respective roles for patient data
The professional user determines the purposes and essential means of processing their patients' data. In principle, the professional acts as a controller, or as an initial processor when acting on behalf of another organisation.
For this entrusted data, Delta Labs acts on the professional's instructions and acts as a processor or sub-processor, depending on the applicable relationship. The corresponding obligations are set out in the Data Processing Agreement (DPA).
Delta Labs does not determine, in place of the professional, the legal basis applicable to health data, the information to be provided to patients, whether their consent is required or the retention periods specific to the professional's practice.
3. Data processed
3.1 Data relating to the user
- account and identity data, including first name, last name and email address;
- professional and configuration data, including declared professions, practice preferences, practice language, countries of practice and, where requested, administrative subdivisions;
- security and authentication data, including passwords stored in hashed form, email verification status, authentication factors, sessions, IP address, user agent and technical logs;
- subscription and billing data, including Stripe customer and subscription identifiers, plan, billing interval, payment status, promotions, invoices, billing address and tax information;
- legal evidence, including the documents and versions presented, language, content fingerprint, date and context of acceptance;
- usage data, preferences, support requests and communications with Delta Labs.
3.2 Data entrusted by the user
Depending on the features used, the Service may process:
- patient identity, contact details, administrative information and care information;
- information relating to appointments, sessions and consultations;
- free-form notes, observations and other content entered by the professional;
- optional audio recordings and their metadata;
- transcripts, draft reports, summaries, context and other generated documents;
- health data and other sensitive data that such content may reveal;
- technical identifiers, statuses, dates and durations required for the operation, security and diagnosis of the Service.
3.3 Sources of data
Data is provided directly by the user, produced when they use the Service, received from services they choose to connect, or generated technically by Delta and its providers. Patient data is provided or recorded under the responsibility of the professional user.
3.4 Public website visits, measurement and demonstration requests
When you allow the corresponding purpose, measurement tools may process browser and session identifiers, technical connection information, including your IP address, and a limited set of events: visiting an eligible public page, clicking a registration or booking button, viewing the calendar, booking a demonstration or confirming a registration. PostHog also measures certain clicks to download public resources. These events may include the displayed language and regional edition, a page category and campaign parameters limited to source, medium and campaign name.
To avoid counting the same booking or registration more than once, Delta uses a random event identifier. Event parameters prepared by Delta contain neither your email address nor your Delta account identifier, form contents or information about your patients. These precautions do not necessarily make the data anonymous: providers may receive browser identifiers and connection information.
To arrange a demonstration you request, Delta Labs uses Calendly to collect your name, email address, selected time slot and choice of a Google Meet video call or a telephone call. A telephone number is required if you choose a telephone call. You may also add guests; the contact details you provide about them are used to organise the appointment. Please inform them of this use and do not provide any patient data in the form.
The appointment is added to Delta Labs’ professional Google Calendar in Google Workspace. If you choose a video call, a Google Meet link is generated for the appointment. These booking details are not included in the marketing event parameters prepared by Delta.
4. Purposes and legal bases for Delta Labs' own processing
| Purpose | Main legal basis | Data concerned |
|---|---|---|
| Create and manage the account, provide the Service and deliver support | Performance of the contract or steps taken before entering into a contract | Account, profile, preferences, usage and support communications |
| Manage subscriptions, payments, taxes, invoices and accounting obligations | Performance of the contract and legal obligations | Identity, contact details, subscription, billing and tax data |
| Secure the Service, prevent abuse, diagnose incidents and ensure continuity | Legitimate interests and applicable legal obligations | Authentication, IP address, user agent, technical identifiers, logs and minimised error context |
| Manage legal documents and demonstrate notices and acceptances | Performance of the contract, legal obligation and legitimate interest in retaining evidence | Version, language, fingerprint, audience, date, IP address and user agent |
| Send communications relating to the account, Service or applicable obligations | Performance of the contract, legal obligation or legitimate interest, depending on the message | Identity, email address, language and technical delivery history |
| Arrange a demonstration at your request and the communications needed for that appointment | Steps taken at your request before entering into a contract | Contact details provided, time slot and information needed for the booking |
| Measure audience and journeys on the public website | Consent to audience measurement | Limited navigation and conversion events, browser identifiers, technical information, language, regional edition and campaign parameters |
| Measure advertising campaign effectiveness, including attributing confirmed registrations and booked demonstrations to campaigns | Separate consent to advertising measurement | Eligible commercial page visits, conversions, browser and event identifiers, technical information and advertising attribution information |
Where an optional communication requires consent, the user may withdraw it at any time. Messages essential to account operation, security, billing or compliance with a legal obligation are not marketing communications.
5. Recipients and service providers
Data is accessible to authorised Delta Labs personnel within the scope of their duties and to providers involved in the service you request or the purpose you have allowed, including:
- Amazon Web Services for application hosting, storage, databases, networking, logs, monitoring and technical email delivery through Amazon SES;
- Google Cloud for transcription, the temporary storage required for that transcription and artificial intelligence processing enabled by the user;
- Sentry for detecting and analysing technical errors, with a configuration intended to exclude known clinical content and sensitive fields;
- Stripe for creating and managing customers, subscriptions, payments, invoices, taxes and payment methods. Delta Labs neither receives nor stores full card numbers or security codes;
- advisers, authorities, courts or third parties to whom disclosure is necessary to comply with the law, establish or defend rights, or protect the Service.
- PostHog for optional audience measurement on the public website;
- Google for Google Analytics 4 and Google Tag Manager, used for optional audience measurement and the management of authorised tags, and Google Ads for advertising measurement subject to a separate choice;
- Meta for advertising measurement of eligible visits, confirmed registrations and booked demonstrations;
- Calendly to arrange requested demonstration appointments and process the related booking information;
- Google Workspace, including Google Calendar and Google Meet, to manage these appointments and the video calls you choose.
The use of each measurement tool depends on your choice for its purpose. Google Tag Manager manages the loading of tags; it does not represent an additional purpose authorised by default. Booking activities performed using Calendly are separate from marketing measurement and remain available when you refuse it.
PostHog processes measurement data on behalf of Delta Labs under its data processing agreement. Google acts as a processor for Google Analytics and Google Tag Manager, and as an independent controller for Google Ads, according to the terms applicable to each service.
Delta Labs and Meta Platforms Ireland Limited are joint controllers for the collection and transmission of data through the Meta Pixel, within the scope of their Controller Addendum. Delta Labs provides information and obtains consent on its website; Meta handles, in particular, requests to exercise rights over data it holds. You may exercise your rights against either party, including by contacting Delta Labs at admin@mydelta.app. Meta’s subsequent processing falls under its own responsibilities under its Business Tools Terms.
Calendly acts as a processor for bookings arranged for Delta Labs. It also acts as an independent controller for its own purposes and data collected through its cookies in the embedded calendar, under its data processing addendum and privacy notice.
Providers processing patient data on the user's behalf are also described in the DPA. Delta Labs does not sell personal data or patient data.
6. Location and international transfers
Delta's primary production infrastructure is configured in the AWS eu-west-3 region in Paris. Specialised transcription and artificial intelligence processing is configured in European Google Cloud locations compatible with the services used.
Some providers or their own subprocessors may process data from other countries, including for support, security, billing, observability, demonstration bookings and, when you allow it, audience or advertising measurement. These activities may involve countries outside the European Economic Area, including the United States. Delta Labs therefore does not give an absolute guarantee that no transfers outside the European Economic Area occur.
Where a transfer requires a particular safeguard, Delta Labs relies on a mechanism recognised by applicable law, such as an adequacy decision or the European Commission's standard contractual clauses, supplemented where necessary by appropriate measures.
Delta’s PostHog project is hosted in the European Union; this does not exclude some processing from other countries. Its agreement provides for the EU–US Data Privacy Framework and standard contractual clauses. Google also provides for this framework for covered transfers to the United States and for standard contractual clauses depending on the circumstances. Calendly processes data in the United States; its agreement provides for the EU–US Data Privacy Framework, with standard contractual clauses as a fallback. The applicable safeguards depend on the recipient and processing concerned.
Data sent to Meta may be transferred to the United States. For covered transfers from the European Economic Area or Switzerland, Meta states that it relies on the EU–US and Swiss–US Data Privacy Frameworks. Its disclosure specifically includes Meta Pixel data. Where Meta acts as a processor, its European Data Transfer Addendum also provides for recognised alternative mechanisms, including standard contractual clauses, depending on the transfer concerned.
You can request information about the safeguards applicable to transfers of your data and how to obtain a copy by writing to admin@mydelta.app.
7. Retention periods
Delta Labs retains data for a period proportionate to the relevant purpose, the user's instructions, technical cycles and legal obligations:
- account and profile data is retained for the lifetime of the account, then for the time required to close it, establish or defend rights and comply with applicable obligations;
- billing data and accounting records are retained for the applicable statutory periods, which may be up to ten years for accounting records;
- legal evidence is retained for the contractual relationship and then for the period required to demonstrate the parties' rights and obligations;
- the main cloud infrastructure technical logs are currently configured with a ninety-day retention period; other security or deliverability records may follow a different cycle where necessary and proportionate;
- the body of emails placed in the delivery queue is deleted after handover to the provider; metadata strictly required to track delivery may be retained for longer;
- patient data is retained according to the professional's instructions and use, subject to technical deletion periods, backups and applicable legal obligations.
Your decisions to accept or refuse measurement tools, their date and the cookie policy version are stored in the preference cookie for 180 days. The lifetimes of other cookies are described in the Cookie Policy. A cookie's lifetime in your browser does not, by itself, determine how long a provider retains events it has already received.
The mechanism Delta uses to confirm a new registration can be used for 24 hours from account creation, within the same browser session. After that period, it can no longer authorise sending a conversion. This validity period is separate from the retention of your account and of any events already sent to measurement tools.
Google Analytics 4 is configured with a two-month retention period for user and event data covered by this setting. Resetting retention on new activity is disabled. Data that has reached the end of its retention period is deleted according to Google's monthly cycle. This setting applies to detailed data and does not limit the retention of standard aggregated reports.
For the advertising logs described in its retention policy, Google states that it removes part of IP addresses after nine months, followed by cookie or advertising identifiers after eighteen months. Some data may be kept longer, including to combat fraud. These periods do not guarantee deletion of all Google Ads data. Meta’s Business Tools Terms provide for event data to be retained for a maximum of two years.
Information needed for your demonstration booking is retained for six months after the appointment takes place or is cancelled, then included in the next monthly cleanup of Calendly and the copies managed by Delta Labs in its calendars and emails. Providers’ technical processing times for deletion requests may add to this period. Data needed for another purpose, including managing your customer account, follows the retention periods applicable to that purpose.
8. Security
Delta Labs implements technical and organisational measures appropriate to the risks, including:
- encryption of exposed communications using secure protocols and encryption at rest for the main production storage systems;
- individual authentication, enhanced authentication mechanisms, server-side authorisation controls and logical data isolation;
- private networks and storage, restricted internal access and controlled secret management;
- backups, logs, monitoring tools and deployment procedures appropriate to the architecture;
- minimisation of information sent to diagnostic tools.
As no measure eliminates every risk, users must also protect their access credentials, use appropriate equipment and promptly report any suspicious use.
9. Personal data breaches
Delta Labs analyses security incidents and takes appropriate measures to contain and remedy them. Where a personal data breach concerns Delta Labs as controller, it makes the required notifications within the statutory time limits. Where it concerns data entrusted by a professional, Delta Labs informs the professional without undue delay after becoming aware of it and provides the available information needed for the professional to meet their own obligations.
10. Data subject rights
Subject to the conditions provided by applicable law, any person concerned, whether visiting the Website, requesting a demonstration or using the Service, may request access to, rectification or erasure of their data, data portability or restriction of processing, and may object to certain processing activities or withdraw consent.
Requests may be sent to admin@mydelta.app or by post to Delta Labs SAS, 11 BIS Allée du Muguet, 79200 Parthenay, France. Delta Labs may request information reasonably necessary to verify identity and respond to the request.
For patient data processed in Delta on a professional's behalf, the request should generally be addressed to that professional. Delta Labs assists the professional under the conditions set out in the DPA.
The data subject may also lodge a complaint with the competent supervisory authority. In France, this is the CNIL: www.cnil.fr.
To change your measurement choices, use “Manage my cookies” at the bottom of public pages. Withdrawal stops the corresponding new optional collections; it does not automatically erase data a provider has already received or affect the lawfulness of processing before withdrawal. You can request erasure of your data under the applicable conditions by contacting us at admin@mydelta.app.
11. Artificial intelligence and automated decisions
Artificial intelligence features help the professional produce transcripts, drafts, summaries or documents. The professional must review, correct and validate the content before using it.
Delta does not use these features to make, in place of the professional, a decision producing legal effects or similarly significantly affecting a person based solely on automated processing.
12. Cookies and local storage
The Website and Service use cookies or storage mechanisms needed for authentication, security, preferences and interface operation. A cookie also stores your choices concerning optional tools.
On the public website, two optional purposes are offered separately: audience measurement with PostHog and Google Analytics 4, and advertising measurement with Google Ads and Meta. Measurement tools load only with your prior permission for the corresponding purpose. Google Tag Manager loads only after you accept at least one of these purposes; each tag remains subject to the relevant choice.
Measurement covers explicitly defined events, including confirmed registrations and booked demonstrations. Clicking “Sign up” is not enough to count a registration. A registration is measured after the first email confirmation for a new account, in the same browser session and within 24 hours of account creation. The purpose must be allowed both at account creation and at confirmation. Visiting the thank-you page alone is not enough to count a booking.
This integration does not measure the application's clinical screens or patient information pages. Advertising measurement is limited to eligible commercial pages and the registration confirmation page; it excludes the blog and private resource downloads, among other pages. Blog audience is measured without including article titles or addresses in Delta's event parameters. For this integration, Delta does not enable session recordings, automatic form capture, enhanced conversions using account contact details, remarketing or advertising personalisation features.
These configuration choices at Delta Labs do not eliminate Meta’s own uses, including improving and personalising its services and advertisements, as described in its Business Tools Terms.
The demonstration calendar loads when you choose to display it. You can also open the Calendly link. Calendly then receives the information needed for the connection and booking and presents its own cookie preferences. Choosing to display the calendar does not constitute acceptance of Delta's measurement tools.
You can separately accept, refuse or withdraw your choices using “Manage my cookies”. Refusing measurement tools does not prevent you from creating an account or booking a demonstration. Accepting the Service documents does not constitute consent to these tools. The Cookie Policy details the tools, cookies and their lifetimes.
13. Required data
Fields marked as required are necessary to create the account, describe the professional context, determine the applicable documents, provide the Service or issue bills. Without them, certain steps or features may not be available. Other information is optional unless it becomes necessary for a feature expressly requested by the user.
14. Changes to this policy
Each change results in an identifiable, dated version. Depending on the nature of the change, the new version may be published without specific notice, be the subject of a notice, or require renewed explicit acceptance.
The version and language presented upon acceptance are retained as part of the corresponding evidence. The French version is the reference version; translations are provided to facilitate understanding, subject to any applicable mandatory rules.
15. Contact
Delta Labs SAS
11 BIS Allée du Muguet
79200 Parthenay, France
+33 7 66 80 89 66