Privacy policy · Tietosuojaseloste
How Treat handles your data.
Last updated 15 July 2026. Suomeksi.
This policy covers two Treat services that run on separate infrastructure:
-
The waitlist at
treat.health— a marketing page and email signup, described in section A. Runs on Cloudflare. No health data. - The Treat healthcare app — patient intake, a conversational symptom survey, and case review by a licensed healthcare professional, described in section B. Runs on Google Cloud in Finland.
A — The waitlist (Cloudflare only)
What we collect
Your email address, the time you joined, and — if you use social sign-in — the display name and identity-provider details needed to identify the signup. Do not send health information through this waitlist.
Why we collect it
Only to manage early-access invitations and launch updates. Legal basis: consent (GDPR Article 6(1)(a)), which you can withdraw at any time. We keep the record until the early-access programme ends or you withdraw consent, and review inactive records after 24 months.
How it is handled
The waitlist runs on Cloudflare Workers with a Cloudflare D1 database, both in Cloudflare's EU data-localisation region. OAuth access and refresh tokens are discarded after signup. We do not use advertising trackers on this page or sell waitlist data. No health data ever touches Cloudflare.
B — The Treat healthcare app (Google Cloud only)
The app itself runs on Google Cloud in Finland
(region europe-north1, Assured Workloads EU Data Boundary).
Cloudflare is not in this path. The sections below follow the
structure of a Finnish tietosuojaseloste.
1 — Controllers
The Treat service has two controllers, depending on the data concerned.
Treat Health Oy (business ID 3618620-6), Helsinki, Finland, is the controller for data related to your user account and use of the platform ("account data"): identification and contact details, authentication, acceptance of terms and marketing consents, billing, service logs, and feedback.
The reviewing healthcare professional — a physician, nurse, therapist, or other practitioner registered with the Finnish Supervisory Agency (Lupa- ja valvontavirasto) operating as an independent healthcare provider — is the controller (rekisterinpitäjä) for the patient records created in the care relationship, that is, the patient register under the Finnish Act on the Status and Rights of Patients (potilaslaki 785/1992) ("patient-record data"). Treat Health Oy processes patient-record data on the professional's behalf as a data processor (GDPR Article 28). The professional is bound by the professional secrecy duty in section 17 of the Finnish Act on Health Care Professionals (laki terveydenhuollon ammattihenkilöistä 559/1994).
2 — Contact
Data-protection contact: [email protected]. The same address also serves patient-record matters: we relay your request to the healthcare professional acting as controller. For complaints you may always contact the Office of the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), Ratapihantie 9, 00520 Helsinki.
3 — Purposes and legal bases
| Purpose | Controller | Legal basis |
|---|---|---|
| Providing the healthcare service (intake, healthcare-professional review, decision) | The professional (Treat as processor) | Contract (Art. 6(1)(b)) and the healthcare exception for special-category data (Art. 9(2)(h)); statutory obligation under potilaslaki |
| Maintaining the patient register | The professional (Treat as processor) | Statutory obligation (Art. 6(1)(c), potilaslaki) |
| Identifying and authenticating you (strong authentication) | Treat Health Oy | Contract (Art. 6(1)(b)) |
| Accessing your Kanta records with your consent | The professional (Treat as processor) | Explicit consent (Art. 9(2)(a)) |
| Invoicing, bookkeeping, and Kela-reimbursement handling | Treat Health Oy | Contract (Art. 6(1)(b)) and statutory obligation (kirjanpitolaki 1336/1997) |
| Monitoring service quality (post-case feedback) | Treat Health Oy | Legitimate interest (Art. 6(1)(f)) |
| Security, abuse prevention, and incident response | Treat Health Oy | Legitimate interest (Art. 6(1)(f)) |
| Product development on anonymised data | Treat Health Oy | Legitimate interest (Art. 6(1)(f)); data is anonymised before use |
4 — Data we process
Account data (Treat Health Oy as controller):
- Identification & contact: name, Finnish personal identity code (henkilötunnus, "hetu"), email, phone number, preferred language, and a stable authentication identifier.
- Consents: acceptance of Treat's terms of service and any marketing consent.
- Billing: invoice line items, payment status, and Kela-reimbursement identifiers where applicable.
- Service logs: IP address, request timestamps, and browser details; hetu and free-text clinical fields are redacted at the application boundary.
- Feedback: service rating, healthcare-professional rating, and free-text comment.
Patient-record data (the reviewing professional as controller; Treat as processor):
- Guardian data when the patient is a minor: the guardian's name, hetu, and contact details, plus proof of custodial rights.
- Kanta consent: the Kanta records-access consent (scope, text version, and timestamp).
- Clinical intake: the symptoms and answers you type or dictate, allergies, current medication, and relevant medical history.
- AI intake transcript: the structured follow-up questions and your answers, used to compile a preparatory summary for the reviewing healthcare professional.
- Case & decision: the reviewing healthcare professional's summary, clarifying messages, prescriptions or referrals issued through Treat, and the case status.
- Kanta data you have consented to us fetching (prescriptions, selected records) — mirrored transiently for the case and not stored beyond the retention period.
5 — Data sources
- Directly from you when you sign up, chat, or submit a form.
- From the reviewing healthcare professional when they add notes, decisions, or clarifying messages to your case.
- From the Nordic identity broker Idura at sign-in: name, hetu (or the equivalent national identifier for other Nordic eIDs), and a stable OIDC subject identifier — see §10 for the full flow.
- From the Kanta national health archive when you have explicitly consented to us fetching a record.
- Generated by our servers during use of the app (case IDs, timestamps, logs).
6 — Retention
The healthcare professional, as controller, is responsible for the retention of patient-record data; Treat stores the data on the professional's behalf. Patient records follow the Finnish retention rules for patient records (potilaslaki and Ministry of Social Affairs and Health decree 298/2009): typically 12 years from the patient's death, or 120 years from birth. Consent records are kept for the same period so that consent can be demonstrated. Billing and bookkeeping records: six years (Finnish Accounting Act). Service logs: 90 days by default, longer only when needed for a specific security investigation. Waitlist retention is described in section A.
7 — Disclosure
Personal data is disclosed only where there is a legal basis to do so. Disclosures of patient-record data are decided by the healthcare professional acting as controller.
- Kanta (the national health archive operated by Kela): the reviewing professional is responsible for the patient-record entries; Treat submits prescriptions, patient records, and related structured data to Kanta on the professional's behalf, as required by law and your consent.
- Other healthcare providers when you consent, or when a statutory obligation requires it (for example continuity of care under section 13 of potilaslaki).
- Public authorities (courts, police, the Tax Administration, social insurance institutions, and supervisory authorities) when they have a legal basis for the request.
- A buyer of the Treat business in the event of a merger, acquisition, or restructuring — subject to the same safeguards, and we will notify you of the transfer.
- Debt-collection agencies and legal counsel only to the extent necessary to enforce an unpaid invoice.
We do not disclose your data to advertisers or data brokers, and we do not sell your data.
8 — Processors (sub-processors)
The following parties process personal data on Treat's behalf under a signed Data Processing Agreement (GDPR Article 28). For patient-record data they act as sub-processors in the chain professional → Treat → the processor listed below:
| Processor | Scope | Region | DPA |
|---|---|---|---|
| Google Ireland Limited (Google Cloud Platform) | Treat app: Cloud Run, Cloud SQL PostgreSQL, Cloud Storage, Secret Manager, KMS, and Vertex AI (Gemini) — all patient chats, case records, healthcare-professional accounts, and company data live here. | europe-north1 (Helsinki), Assured Workloads EU Data Boundary | Google Cloud DPA |
| Cloudflare, Inc. |
Marketing site and waitlist only: Cloudflare
Workers, Cloudflare D1 (waitlist storage), plus DNS, TLS, and DDoS
protection for treat.health. Never handles patient
chats, case data, or account records.
|
Cloudflare's EU data-localisation region (Workers and D1) | Cloudflare Customer DPA |
| Idura ApS (Denmark, CVR 35142207), Gammel Kongevej 3E, 1610 København V — a Nordic eID broker | Strong electronic identification (vahva sähköinen tunnistaminen) via Finnish bank credentials and Mobiilivarmenne, Swedish BankID and Freja ID, Norwegian BankID and Vipps, and Danish MitID. Idura brokers the authentication event and returns a signed OIDC token from which we store the claims we need (see §10). | EU only — Idura commits in its privacy policy not to transfer or store personal data outside the EU | Idura Privacy Policy · signed DPA on request |
When we add or replace a processor, we update this list before the new processor starts handling data. You can request the current signed DPAs at any time from [email protected].
Kanta (Kela) is not a processor in this chain. Kanta is a separate national register operated by Kela under its own statutory basis; the healthcare professional acting as patient-register controller and Kela act as independent controllers for the records exchanged under your explicit consent.
9 — The AI intake assistant
The intake chat uses Google's Vertex AI (Gemini) hosted in the EU
(eu.rep.googleapis.com). We disable the prompt cache and
call the service with service-account authentication — we do not use
consumer Gemini. Gemini only asks structured follow-up questions; it
does not diagnose, treat, prioritise urgency, or make automated
decisions within the meaning of GDPR Article 22 — the clinical decision
always rests with the reviewing healthcare professional. We have
applied for a Google abuse-monitoring log exemption for the Treat
project; until it is approved, we do not assume strict zero retention
for Gemini calls and mark this clearly in our internal logs.
10 — Strong authentication (Idura)
To meet the identity-assurance requirements for a healthcare provider, sign-in uses Idura ApS (a Danish company, CVR 35142207, Gammel Kongevej 3E, 1610 København V; privacy notice), a Nordic identity broker. Idura fronts the national eID schemes for us, so we do not have to integrate each one individually:
- Finland: Finnish Trust Network bank credentials and Mobiilivarmenne.
- Sweden: BankID and Freja ID.
- Norway: BankID and Vipps.
- Denmark: MitID.
How the flow works. Your browser is redirected to Idura, which sends you on to the eID method you pick. That provider verifies your identity (for example with a fingerprint, PIN, or one-time code), and Idura returns a signed OpenID Connect token to Treat. Treat stores only the fields it needs from the token: your name, national identifier (hetu or its Nordic equivalent), and a stable subject identifier used to recognise you on later logins.
Roles. Idura is our processor for brokering the authentication event and is bound by a DPA (see §8). The underlying eID issuers — the banks, mobile operators, MitID, Freja, and others — are independent controllers for the authentication event on their side and publish their own privacy notices. Treat never receives your bank credentials, MitID code, or biometric data — only the verified identity claims listed above.
Where data flows. Idura commits in its own privacy policy that authentication traffic and any related personal data stay inside the European Union — Idura will not transfer or store such data outside the EU. The assertion is transient at Idura, and we do not retain it beyond the immediate sign-in exchange; the durable record lives in your Treat account (see §4 and §6).
Idura's own sub-processors. Idura publishes its sub-processor list at trustcenter.idura.eu/subprocessors. As of the date of this policy the list comprises Microsoft Azure (Ireland / Netherlands) and AWS (Germany) as hosting providers for the authentication traffic, and HubSpot as Idura's internal CRM — HubSpot does not receive Treat authentication data. Idura holds FTN, MitID, NSIS, DORA, GDPR, and NIS 2 attestations.
Assurance level. We require the FTN "substantial" assurance level (or its equivalent in the other Nordic countries), which is the level Finnish regulators expect for access to healthcare services.
11 — International transfers
Personal data stays inside the EEA. All processors are contractually
restricted to EU regions for Treat's data (Google Cloud
europe-north1 with Assured Workloads EU Data Boundary;
Cloudflare EU data localisation; Idura EU-only, see §10). If a future
exception ever requires a transfer outside the EEA, we will rely on
European Commission Standard Contractual Clauses and inform you.
12 — Security
Concrete measures we operate under GDPR Article 32:
-
Encryption at rest for the database, object storage,
and secrets, using customer-managed KMS keys in
europe-north1. - Encryption in transit via TLS 1.2 or later on all endpoints; the database accepts only encrypted connections.
- Least-privilege access: production access is restricted through Google IAM with per-service accounts; there are no shared credentials, and all access is audit-logged.
- Strong authentication for patients (Idura eID) and passkey-based sign-in; passwords are hashed with Argon2.
- Pseudonymisation and redaction of hetu and free-text clinical fields in application-level service logs.
- Backups with point-in-time recovery, encrypted with the same KMS keys and retained within statutory limits.
- Confidentiality obligations in every employment and subcontractor agreement; healthcare professionals are additionally bound by section 17 of the Finnish Act on Health Care Professionals (559/1994).
- Incident response: we notify the Finnish Data Protection Ombudsman within 72 hours and affected users without undue delay of any breach that meets the GDPR threshold.
13 — Your rights
You may request access to your data, its correction or deletion, restriction of processing, or a portable export; withdraw a consent; or object to processing based on legitimate interest. Some rights are limited when the data forms part of a statutory patient record under potilaslaki. Contact [email protected] — we reply within one month, and we relay requests concerning patient-record data to the healthcare professional acting as controller. You always retain the right to complain to the Office of the Finnish Data Protection Ombudsman.
14 — Cookies
The app uses only strictly necessary cookies (session, CSRF protection, and language). No third-party advertising or analytics cookies are set. The marketing site may set an anonymous first-party analytics cookie, described in its own cookie notice.
15 — Changes
If we materially change this policy, we will update the date at the top and notify signed-in users in the app before the change takes effect.