Legal
Privacy Policy
How Mantis AI handles personal data, including health data processed on behalf of healthcare and care organizations.
Draft document. This text is provided as a starting point and must be reviewed and adapted by qualified legal counsel before publication. Placeholders such as [Legal Entity Name], [Registered Address], and [Data Protection Contact] must be completed.
Last updated: [Effective Date]
1. Who We Are
Mantis AI is operated by [Legal Entity Name], registered at [Registered Address]. For questions about this policy or about how personal data is handled, contact [Data Protection Contact].
This policy explains how we handle personal data on our website, in our commercial relationships, and when we provide the Mantis Clinic and Mantis Care documentation platform to healthcare and care organizations.
2. Controller and Processor Roles
For our website, marketing communications, and demo requests, Mantis AI acts as the data controller.
When a healthcare or care organization uses the Mantis platform, that organization is the controller of the patient, resident, and staff data processed through the service. Mantis AI acts as a processor and handles that data only on the documented instructions of the organization, under a data processing agreement.
3. Data We Process
Depending on the relationship, we may process the following categories of data:
- —Contact and professional data you provide through the demo request form, such as name, work email, phone number, organization, job title, and country.
- —Organization and workflow information, such as organization type, number of users, and existing EHR, EMR, HBYS, or care management systems.
- —Technical data such as IP address, device type, browser, and pages visited, collected through essential website logs.
- —Platform content processed on behalf of customer organizations, which may include audio captured during healthcare interactions, transcripts, and generated documentation. This content can include special categories of personal data concerning health.
4. Purposes and Legal Bases
We process contact and professional data to respond to demo requests, to evaluate fit, and to manage our commercial relationship. The legal basis is the performance of a contract or the taking of steps prior to entering into a contract, and our legitimate interest in responding to business enquiries.
We process technical website data on the basis of our legitimate interest in operating a secure and functional website.
Platform content is processed on behalf of customer organizations under their instructions. The legal basis for the underlying processing of health data is determined by the customer organization, typically explicit consent, the provision of health care, or a legal obligation under applicable health legislation.
5. Health Data and Special Categories
Health data is treated as a special category of personal data under the GDPR and as data of special nature under KVKK. Mantis applies additional safeguards to this data, including de-identification options, encryption in transit and at rest, role-based access control, audit logging, configurable retention, and the option of local or on-premise processing.
Mantis produces draft documentation only. Records must be reviewed and approved by authorized healthcare professionals before use or system integration.
6. Sharing and Subprocessors
We do not sell personal data. We share personal data only with service providers acting on our behalf, with the customer organization that controls the relevant records, and with authorities where required by law.
A current list of subprocessors, their function, and their hosting region is available on request from [Data Protection Contact] and is maintained as an annex to our data processing agreement.
7. International Transfers
Where data is transferred outside the country of origin, we rely on an appropriate transfer mechanism such as an adequacy decision, standard contractual clauses, or an explicit consent or undertaking recognized under KVKK. Customer organizations may select regional hosting or on-premise deployment to keep data within a defined jurisdiction.
8. Retention
Demo request and commercial contact data is retained for [Retention Period] unless a longer period is required for legal or accounting purposes.
Platform content is retained according to the retention configuration agreed with the customer organization. On termination, data is returned or deleted according to the data processing agreement.
9. Your Rights
Subject to applicable law, you have the right to request access to your personal data, correction, erasure, restriction of processing, objection to processing, and data portability, as well as the right to lodge a complaint with a supervisory authority.
If your data is processed by a healthcare or care organization through the Mantis platform, please direct your request to that organization. We will support them in responding.
To exercise your rights in relation to data for which Mantis AI is the controller, contact [Data Protection Contact].
10. Security
We maintain technical and organizational measures appropriate to the risk, including encryption, access control, logging, segregation of environments, secure development practices, and staff confidentiality obligations. No system can be guaranteed to be fully secure, and we continue to review and improve these measures.
11. Changes to This Policy
We may update this policy to reflect changes in our services, legal obligations, or deployment configurations. Material changes will be communicated through this page and, where appropriate, directly to customer organizations.
