Privacy Policy
Last updated: June 5, 2026
This Privacy Policy explains how Eclio collects, uses, stores, and protects information when you use our website (eclio.io) and the Eclio application. We are committed to protecting your data and the data of your clients, and we comply with the EU General Data Protection Regulation (GDPR).
1. Who we are
Eclio is operated by Veronese Limited Company, 8206 Louisiana Blvd NE, Ste A, Albuquerque, NM 87113, USA (“Eclio”, “we”, “us”).
For privacy questions or to exercise your rights, contact us at mathieu@veronese.ai.
2. Our two roles
As a controller: for your own account data (your name, email, settings, billing), we decide how and why it is processed.
As a processor: for the clinical data you create about your clients (session recordings, transcripts, notes), you are the data controller and Eclio processes that data on your behalf, under your instructions. A separate Data Processing Agreement (DPA) governs this relationship and is available on request.
3. What data we collect
Account data
Name, email address, profession, language preference, and authentication details.
Client and session data (health data)
When you record or upload a session, we process the audio, the resulting transcript, AI-generated clinical notes, and any client information you enter (such as first name, last name, and notes). This is special-category health data under GDPR Article 9 and is treated with heightened protection.
Audio recordings
Session audio is processed only to generate a transcript and is permanently deleted immediately after transcription. We do not retain audio recordings.
Google Calendar data (optional)
If you connect your Google Calendar, we request read-only access (calendar.readonly) for the sole purpose of displaying your upcoming sessions inside Eclio. See Section 8 for details.
Website and usage data
We collect standard analytics (pages visited, device type, approximate location) through Vercel Analytics, Google Analytics, and Google Search Console to understand and improve our website.
4. How we use your data
We use the data described above to:
- Provide the service — transcription, note generation, client management, and calendar display.
- Authenticate you and secure your account.
- Communicate with you about your account and the service.
- Understand and improve our website (analytics).
- Comply with legal obligations.
5. We do not train AI on your data
We neveruse your sessions, transcripts, notes, or client data to train, fine-tune, or improve any artificial intelligence model — neither ours nor a third party's. We do not claim ownership of your content, and we do not sell or share it for advertising. Your clinical data is used only to provide the service to you.
6. Legal bases (GDPR)
We process personal data under the following legal bases:
- Contract — to provide the service you sign up for.
- Consent — for processing client health data and connecting Google Calendar.
- Legitimate interests — for securing and improving the service and basic analytics.
- Legal obligation — where required by law.
7. Sub-processors
We rely on a small set of trusted providers to deliver the service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | EU (Stockholm) |
| Mistral AI | Audio transcription | EU (France) |
| OpenAI | Clinical note generation | USA |
| Vercel | Website hosting & analytics | USA |
| Calendar integration, Analytics, Search Console | USA |
During our beta, your database and storage are hosted in the EU (Stockholm). After beta, we plan to move to EU-hosted infrastructure with AI models running on our own servers, further reducing reliance on third-party processors.
8. Google Calendar integration
If you choose to connect Google Calendar, Eclio's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We request read-only access to your calendar, used solely to display your upcoming sessions within Eclio.
- We do not store your calendar data beyond what is needed to display it, and we never write to or modify your calendar.
- We do not transfer Google user data to third parties, do not use it for advertising, and do not use it to train AI models.
- You can revoke access at any time from your Google Account settings or from within Eclio.
9. International data transfers
Some sub-processors (OpenAI, Vercel, Google) are located in the United States. When data is transferred outside the European Economic Area, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) and/or the EU-US Data Privacy Framework, to ensure your data receives an equivalent level of protection.
10. Data retention
- Audio: deleted immediately after transcription.
- Account, client, and note data: retained while your account is active.
- After cancellation: retained for 30 days, then permanently deleted.
11. Your rights
Under GDPR, you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data. You may also withdraw consent at any time and lodge a complaint with your local data protection authority. To exercise any of these rights, email mathieu@veronese.ai.
12. Security
Data is encrypted in transit (TLS) and at rest (AES-256). Access to clinical data is restricted, and audio recordings are deleted immediately after processing. No system is perfectly secure, but we apply industry-standard safeguards appropriate to the sensitivity of health data.
13. Cookies & analytics
Our website uses Vercel Analytics, Google Analytics, and Google Search Console to measure traffic and improve the site. These tools may set cookies or collect device and usage information. You can control cookies through your browser settings.
14. Children
Eclio is intended for licensed professionals and is not directed at children under 16. We do not knowingly collect data from children.
15. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top reflects the latest version. Material changes will be communicated through the service.
16. Contact
Veronese Limited Company
8206 Louisiana Blvd NE, Ste A, Albuquerque, NM 87113, USA
mathieu@veronese.ai