For DPOs, practice owners and HR

A European platform, also when you look under the hood.

Health data is the first question a DPO asks, not the last. This page is built to be forwarded: where the data lives, who can reach it, how it is protected, and what we deliberately do not claim.

Hosting
EU West, Amsterdam
Railway, application and database in the same region
Company
Veldegem, Belgium
Supervisor: Belgian Data Protection Authority
Health data
Art. 9, explicit consent
Encrypted at rest, withdrawal always possible
Messages
AES-256-GCM at rest
Own data key per message, key rotation
Data processing agreement
Before the first byte
The sub-processor list below is the annex
Advertising
None. Ever.
No resale, no retargeting inside the platform

Where your data lives

Per type of data: location, and whether it is encrypted

"In Europe" is only an answer once it holds per data type. This is the list as it stands in production.

DataWhereProtection
Accounts, profiles, matchesClients, coaches, psychologists, practicesPostgreSQL, Railway EU West (Amsterdam) EUEncrypted in transit (TLS), encrypted disk, Row-Level Security inside the database itself
Messages between client and professionalSame database, Amsterdam EUAES-256-GCM per message, envelope encryption (data, key-encryption and master keys), versioned keys with rotation
Mood journal and intakesHealth data, GDPR Art. 9Same database, Amsterdam EUOnly after explicit consent; notes encrypted; withdrawal starts a 30-day erasure process
AI conversations and summariesOnly if the client subscribes to the AI chatStored in Amsterdam EU; processed by OpenAI via OpenAI Ireland Ltd. EU contract, US transfer possibleDPA with SCCs; no training on API data; 50 messages/day cap; crisis detection routes to helplines
Profile photos and diplomasCloudinary US, SCCsOnly what the professional uploads themselves; diplomas show as a verified badge, never as a document
Product analyticsWhich screens, which buttonsPostHog Cloud EU, Frankfurt EUNo message content, no mood data; on the website only after cookie consent
Error reportingSentry US, SCCsTechnical stack traces, no message content; real errors only, no behavioural data
EmailConfirmations, notifications, password resetResend US, SCCsTransactional; no health data in emails, not even in the internal alerts sent to us
PaymentsStripe (web), Apple and Google (app)Card data never touches our servers; we store only the subscription status

EU stored and processed inside the EEA  ·  US, SCCs US processor under the European Commission's Standard Contractual Clauses. This is the same list as in our privacy policy, section 5.2; if the two ever diverge, the privacy policy prevails.

Security

What is in place, technically and organisationally

Concrete enough to test. No "bank-grade", just what it is.

Message encryption

Every message gets its own data key (AES-256-GCM). That data key is itself encrypted with a key-encryption key, which is encrypted with a master key held outside the database. Keys are versioned and rotated without old messages becoming unreadable.

Separation inside the database

Row-Level Security in PostgreSQL: the application reads through a database role that, per request, only sees the rows of the signed-in user. A bug in application code therefore cannot expose someone else's record. Administration runs through a separate, audited role.

Consent for health data

The mood journal and intakes are Art. 9 data. They are only processed after a separate, explicit consent in the app, independent of the terms of service. Withdrawal is a single action; a reminder follows after 20 days, and after 30 days the data is erased or anonymised.

Sharing with the coach is opt-in

AI insights about a client reach a coach only if the client enables that for that coach. The default is off: no setting means no sharing. An organisation never sees which of its people has a coach or what is discussed.

Access and authentication

Sessions use RS256-signed tokens and rotating refresh tokens with reuse detection. The web platform for professionals keeps no token in the browser: everything runs through httpOnly cookies and a server-side proxy. Administration requires two-factor authentication and IP allow-listing, and leaves an audit trail.

Deletion and retention

An account can be deleted inside the app, without emailing us. Inactive accounts and withdrawn consents are cleaned up by scheduled jobs, not by hand. Sessions expire after 24 hours.

Edge security

Content Security Policy enforced, HSTS with preload, rate limiting on every public form and on the chat, Cloudflare at the edge. The website loads no tracker at all for visitors who decline cookies, not even a Google tag in "anonymised" mode.

No advertising model

Mentranova earns from a professional subscription and one optional AI feature for clients. Not from data. There is no retargeting inside the platform and no resale, and the terms say so.

What we do not claim

A DPO will find this anyway. Better from us.

Four things that pages like this one usually keep vague.

Data processing agreement

Before data flows, not after

We sign a data processing agreement with every practice or employer before anything runs. The sub-processor list on this page is the annex; if it changes, you hear about it beforehand. Security questions from your DPO are answered in writing, even when it is a forty-page questionnaire.

Questions from DPOs

What we hear most often

The application and the PostgreSQL database run on Railway in the EU West region (Amsterdam, Netherlands). Product analytics lives on PostHog Cloud EU (Frankfurt). A small number of sub-processors are in the US and operate under Standard Contractual Clauses; they are named in the table above.
Yes. MentraNova is based in Veldegem, Belgium, falls under the GDPR and is supervised by the Belgian Data Protection Authority. No American parent company, no CLOUD Act question about the entity itself.
No, and we would rather say so ourselves. Messages are stored encrypted with AES-256-GCM and a per-message data key, but our servers can decrypt them. That is needed for features clients opt into themselves, such as AI insights for their coach, and for moderation when something is reported.
For the AI chat and for matching we use OpenAI models, contracted through OpenAI Ireland Ltd. under a data processing agreement with SCCs. OpenAI does not train on API data. The AI chat is a separate, paid choice made by the client; coach-client conversations do not pass through it unless the client explicitly enables AI insights for their coach.
No. That is a design rule fixed before organisation accounts exist, not a setting that can be flipped later. An organisation gets aggregated numbers at most (how many people used it), never names, never conversation content, never mood data. For small teams we also do not show counts that could be traced to one person.
Yes. We sign a data processing agreement with every organisation before any data flows. The sub-processor list on this page is the annex. Request it at [email protected].
No, not yet. We do not put a certificate on this page that we do not hold. What we do have is described above as concretely as possible so a DPO can assess it directly.

Last reviewed: September 2026. Something no longer accurate? Email [email protected]; we change the page, not the answer.