Trust

Privacy is the architecture.

psylab handles some of the most sensitive material there is — recordings of therapy. Confidentiality isn’t a policy bolted on afterwards; it’s built into how the platform works. Here’s what that means for you and your clients.

Last updated 25 June 2026

You decide everything

You are the data controller for your clients’ information. psylab, operated by Build AS, acts only as your data processor — handling data on your instructions and nothing more. You choose what to record, what to transcribe, and what to keep. Nothing reaches a supervisor or anyone else unless you choose to send it, and you can delete any session or client at any time. Every AI output is a draft for you to review — psylab never makes automated decisions about a client’s care.

Processed in Europe, under European law

All personal and health data is processed and stored within the EU/EEA and governed by the GDPR. Processing of clinical data rests on the health-professional basis under Article 9(2)(h) GDPR, with you acting in your professional capacity. The few providers we rely on operate within the EU/EEA (or a jurisdiction with an EU adequacy decision) and are bound by data-processing agreements.

Encrypted in transit and at rest

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256, across databases, file storage, and backups. Plaintext connections are not accepted.

Pseudonymised by default

psylab is built so that identity stays out of it. You’re encouraged to use project pseudonyms rather than real names, and transcripts are pseudonymised automatically before they’re stored. Session audio is pseudonymised too — the client’s voice is converted to a synthetic one while the clinical signal is preserved, and identifying details are replaced. These protections are on by default; you can opt out per session if a particular case calls for it. By default, raw audio is deleted within 24 hours and only the pseudonymised transcript persists.

Never used to train models

Your clients’ data is never used to train AI models. The AI providers behind psylab perform inference only — they receive what a single step needs, such as the audio to transcribe, the transcript to pseudonymise, or your questions about a case — and return a result. Nothing is retained by them to improve their models.

A workbench, not your patient journal

psylab is a professional workbench and quality-assurance tool — not an electronic patient record (EPJ/EHR). Your official record stays in your own journal system. psylab holds professional work product: recordings you choose to process, pseudonymised transcripts, and draft documentation you transfer into your own system.

The providers we rely on

We deliberately keep our supply chain small: a handful of EU-based cloud-infrastructure and AI-inference providers, each under a data-processing agreement. We don’t sell data, and we don’t share it for advertising. A current list of sub-processors is available to customers on request.

Your rights under the GDPR

You and your clients have the full set of GDPR rights — to access, correct, erase, restrict, port, and object to the processing of personal data. Within psylab you can delete your data directly at any time; to exercise any of your other rights, our team and Data Protection Officer will help.

Governance and contact

psylab is operated by Build AS, Ensjøveien 21L, 0655 Oslo, Norway (org. no. 930 335 584). We’ve appointed an external Data Protection Officer. For any privacy or security question, or to exercise your rights, contact privacy@psylab.eu.

This page is a plain-language summary of how psylab protects data. Our full Privacy Policy and Data Processing Agreement are provided to customers and available on request, and they govern in case of any difference.