Privacy Policy

PRIVACY NOTICE REGARDING THE PROCESSING OF PERSONAL DATA BY “MORF PRAKTIIS” DPK

This Privacy Notice regarding the processing of personal data by “Morf Praktis” DPK (the Company) is intended to help you understand what personal data we collect, why we collect it, and what we do with it. Please take the time to read this Privacy Notice carefully. We want you to be aware of how we use your information and the ways in which you can exercise your rights.

This Privacy Notice applies to the processing of your personal data when you visit and use the services available on the website morphpractice.com and all related subdomains (hereinafter collectively referred to as the “Platform(s)”). This notice does not apply to third-party platforms, websites, or services that are not under our control or ownership.

1. WHO ARE WE?

The company providing you with goods and services through this platform, acting as a Data Controller, is “Morf Praktis” DPK, UIC 208606913, with its registered office and address of management in Sofia, 1404, Triaditsa District, Gotse Delchev Residential Complex, 21 Louis Ayer St., Apt. 11, represented by Manager Teodora Nikolaeva Petrova.

The Data Protection Officer is: Teodora Nikolaeva Petrova, email: teodora@morphpractice.com, tel.: +359988219799

We respect the right to privacy and the protection of personal data, and we work continuously to ensure that the information we process is limited to the necessary minimum and is protected by appropriate technical and organizational measures.

In order to provide our online software platform for managing mental health practices, including the digitization, storage, and management of professional documentation and patient records, we need to process certain personal data.

By using any of the services we provide, you confirm that you are familiar with this Privacy Notice and understand how “MORPH PRACTICE” DPK processes personal data.

2. DATA WE COLLECT AND HOW WE USE IT

We collect and process personal data solely in connection with the provision of the mental health practice management services we have developed and offer through our online platform, including the administration of user profiles for professionals, subscription plans, payments, technical support, and maintaining system security.

The processing of personal data is carried out only where there is a lawful basis in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the GDPR for brevity) and applicable Bulgarian legislation in the field of personal data protection.

Roles of the parties

“Morf Praktis” DPK acts:

(1) as a Data Controller - with respect to the data of registered specialists (psychologists, psychotherapists, psychiatrists, and other mental health professionals);

(2) as a Personal Data Processor - with respect to the personal data of individuals - patients, whose data is entered and processed on the online platform by our clients - mental health professionals, as specified in point 1 above, who act in their capacity as independent personal data controllers. In these cases, “Morf Praktis” DPC processes personal data solely within the scope of the software service provided, without independently determining the purposes and means of processing, and does not use such data for its own purposes.

It should be explicitly emphasized that Patients are not clients of “Morph Praxis” DPC, and no direct contractual relationship arises or exists between them and the Company. They are patients/clients of the respective Specialist, who, in their capacity as an independent data controller, determines the purposes and means of the processing. “Morph Praxis” DPC provides only the technical infrastructure (the platform/software) through which the Specialist determines the content of the data entered.

As part of the services provided, the platform enables the processing of data that may include special categories of personal data within the meaning of Article 9 of the GDPR, including health data. This data is processed on behalf of and at the request of the relevant mental health professional-the data controller.

*The relationship between the Company and the relevant specialist regarding the processing of personal data is governed by a separate Personal Data Processing Agreement, which constitutes Annex No. 1 to the General Terms and Conditions of “Morf Praktis” DPK

Responsibilities of the Specialist

The mental health professional is fully responsible for:

- the lawfulness of the processing of Patients’ personal data;

- the existence of a valid legal basis;

- providing a privacy notice;

- maintaining professional confidentiality.

Clients of “Morf Praktis” DPK:

In connection with the provision of its services, “Morf Praktis” DPC processes, in its capacity as a Data Controller, personal data of the following categories of data subjects:

  • Potential customersIndividuals who have requested a demo of the platform; individuals who have submitted an inquiry; individuals filling out surveys and forms; and other potential customers.
  • Professionals - platform users

Individuals (psychologists, psychotherapists, psychiatrists, and other mental health professionals) who use the platform as part of their professional practice.

Representatives of corporate clients

When the specialist conducts business as a legal entity, the personal data of the following individuals is processed:

- legal representatives;

- authorized representatives;

- contact persons.

Categories of personal data:

  • Data processed in our capacity as Data Controller (with respect to our professional clients)

1.1. Identification and contact information - first and last name, professional qualifications, registration/license details; email address, phone number, mailing address, legal entity details (company name, EIK, registered office and business address, manager).

1.2. Data regarding access to and use of the Platform - IP address, system logs, account login history, data on features used, technical identifiers.

1.3. Financial and payment data - billing information, account information, issued invoices.

1.4. Communication data: query content, correspondence, technical support tickets.

1.5. Data contained in contractual agreements: including agreements on the processing of personal data.

1.6. Inquiry data: data from inquiries submitted through the Company’s official communication channels.

1.7. Data from surveys and questionnaires: information regarding professional experience, number of clients, preferred features, price sensitivity, and feedback.

Purposes of processing:

“Morf Praktis” DPC processes personal data for the following purposes:

  • When acting as a Controller (with respect to the Professionals)
  • Provision of the Company’s Services

- Creating and managing a profile;

- Providing access to the software (platform);

- Subscription plan management;

- Managing contractual relationships with the specialist;

- Provision of technical support;

Billing and Financial Administration

- Issuing invoices and accounting documents;

- Processing and confirming payment;

- Receivables management;

- Accounting.

Ensuring Information Security

- Maintaining system logs;

- Prevention of unauthorized access;

- Protection against abuse and cyberattacks;

- Ensuring data integrity and confidentiality.

Communication with specialists

- Responses to inquiries;

- Notifications regarding changes to the platform;

- Information about subscription plans and features.

Compliance with legal obligations

- Compliance with accounting and tax laws;

- Compliance with obligations to regulatory authorities;

- Legal defense.

Improving and developing the platform

- Analysis of the platform’s usability and features;

- Testing, developing, and implementing new features;

- Troubleshooting technical issues and errors;

- Statistical and analytical purposes related to service optimization.

7. Access Management and Permissions Control

- Managing user roles and access levels;

- Restricting access to certain features;

- Traceability of actions within the system;

Preventing Abuse and Fraud

- Detecting and preventing unauthorized use;

- Preventing attempts to compromise security;

- Investigation of security-related incidents;

Internal Administration and Management

- Internal audit;

- Contract and Partnership Management;

- Compliance with internal policies and procedures;

Platform Analysis and Optimization

- Analysis of the platform’s features;

- Platform optimization;

- Management of trial periods, platform demonstrations

- Communication regarding testing periods and platform demonstrations;

- Managing surveys and questionnaires and collecting customer feedback.

Legal basis for processing:

With regard to the experts’ data

- Article 6(1)(b) of the GDPR - performance of a contract or taking steps at the request of the data subject prior to entering into a contract (creating a profile, providing access to the platform, administering a subscription plan);

- Article 6, paragraph 1, subparagraph (c) of the GDPR - compliance with a legal obligation (accounting and tax legislation, obligations to competent authorities);

- Article 6(1)(f) of the GDPR - the Company’s legitimate interests (ensuring information security, defending against legal claims, preventing abuse);

- Article 6, paragraph 1, subparagraph (a) of the GDPR - consent, where applicable (e.g., for sending marketing communications)

Shelf life:

  • Data of Professionals (when the Company acts as a controller)

1.1. Personal data related to the contractual relationship between the Company and the specialists:

- for the duration of the contract (active profile);

- for a period of up to 5 years after the termination of the contractual relationship-for the purpose of protection against potential legal claims;

1.2. Data related to accounting documents and financial transactions:

- for a period of 10 years in accordance with applicable accounting and tax laws.

1.3. Data processed based on consent (e.g., for marketing communications):

- until consent is withdrawn;

1.4. System logs and technical data related to platform security:

- up to 12 months, unless long-term storage is necessary in connection with an incident investigation

1.5. Data related to communication and inquiries from specialists:

- for up to 3 years from the date of the specific correspondence between the Company and the relevant specialist, unless the correspondence relates to contractual or legal relationships that require a longer retention period.

III. DATA COLLECTION METHOD

” “Morf Praktis” DPC processes personal data provided directly by specialists when using the platform without registration (e.g., when filling out surveys and forms) and when using the platform after registration, as well as data entered by specialists in the course of their professional activities.

With regard to patients’ personal data, the Company does not collect the data directly from the patients themselves, but processes the data entered into the platform by the respective specialist in their capacity as an independent personal data controller.

The specialist is responsible for the lawfulness of the processing of patients’ personal data, including the existence of an applicable legal basis and the fulfillment of information disclosure obligations under the GDPR.

“Morf Praktis” DPC has no practical ability to control the content of the data entered by the specialist and does not conduct an independent verification of its lawfulness.

SAFETY MEASURES

“Morf Praktis” DPC implements appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, in accordance with the requirements of Article 32 of the GDPR.

Within the scope of the provided platform, measures are implemented, including but not limited to:

- controlling access to the system and restricting access to personal data to authorized personnel only;

- use of secure communication protocols;

- maintaining system logs and ensuring traceability of system activities;

- technical measures to protect against unauthorized access and misuse;

- measures to ensure the confidentiality, integrity, and availability of data;

- organizational procedures for managing security incidents.

Access to personal data is restricted to individuals who need it to perform their job duties. These individuals are bound by a duty of confidentiality and process personal data in accordance with applicable laws and internal security policies.

SUBCONTRACTORS

To provide the services on the platform, the Company uses service providers who have been carefully selected and are contractually bound by confidentiality and data protection obligations.

  • IT providers and other software and hardware service providers (hosting companies, cloud service providers, CRM system providers, ERP system providers, software support companies, cybersecurity service providers);Payment service providers (banks; payment institutions; electronic money institutions; virtual POS providers);
  • IT providers and other software and hardware service providers (hosting companies, cloud service providers, CRM system providers, ERP system providers, software support companies, cybersecurity service providers);
  • Payment service providers (banks; payment institutions; electronic money institutions; virtual POS providers);
  • Courier service providers;
  • Accounting and financial service providers (accountants, external accounting firms, auditors);
  • Lawyers;
  • Marketing and advertising partners (direct marketing service providers, marketing campaign platforms, advertising agencies, social media management agencies - SMMA);
  • Other processors acting in accordance with the needs of the services (Electronic identification service providers; Subscription service providers; Providers of online video conferencing consultation services);

In cases where required by law, your personal data may be disclosed to competent government authorities and institutions such as the National Revenue Agency (NRA), the Consumer Protection Commission (CPC), the Personal Data Protection Commission (PDPC), and other authorities within the scope of their powers.

“Morf Praktis” DPK does not disclose your personal data to third parties without a legal or contractual basis; we do not sell it or distribute it in any other way.

MINORS

The Company’s platform is intended for use solely by adults acting within the scope of their professional activities as mental health professionals.

With regard to patients’ personal data, the platform may process personal data of minors when they are in a therapeutic or consultative relationship with the relevant specialist. In such cases, the lawfulness of the processing, including the existence of appropriate consent or another applicable legal basis under applicable law, is the responsibility of the relevant specialist in their capacity as an independent data controller.

The Company does not directly collect personal data from minors and processes such data solely within the scope of the software service provided and in accordance with the specialist’s instructions.

VII. YOUR RIGHTS

You have the right to request a copy of your personal data at any time, to verify the accuracy of the information stored, to correct or update that information, and to request that your personal information be deleted if there are grounds for doing so, as described below. In addition, you have the right to file a complaint when your data protection rights have been violated. Below, we have provided a detailed description of your rights as data subjects:

(1) You have the right to request confirmation as to whether personal data concerning you is being processed and to request a copy of your personal data, as well as information regarding the collection, processing, and storage of your personal data;

(2) You have the right to request that your personal data be erased if any of the following grounds apply: the personal data is no longer necessary for the purposes for which it was collected; you have objected to the processing; the processing is unlawful; when the data is processed based on your consent and you withdraw that consent; when the personal data must be erased to comply with a legal obligation under Union law or the law of a Member State to which the Controller is subject. We may refuse to erase your personal data for the following reasons: to exercise the right to freedom of expression and the right to information; to comply with our legal obligation or to perform a task carried out in the public interest, or in the exercise of official authority vested in us; for reasons of public interest in the area of public health; for the establishment, exercise, or defense of legal claims.

(3) You have the right to request that your personal data be corrected if it is inaccurate, or completed if it is incomplete;

(4) You have the right to request that the processing of your personal data be restricted, if applicable and if there is a valid reason for doing so, for example: you contest the accuracy of the personal data, for a period that allows us to verify the accuracy of the personal data; the processing is unlawful, but you do not wish for the personal data to be deleted, but only for its use to be restricted; we no longer need the personal data for the purposes of the processing, but you require it for the establishment, exercise, or defense of your legal claims; you have objected to the processing pending verification of whether our legitimate grounds override your interests;

(5) you have the right to request to receive the personal data concerning you that you have provided in a structured, commonly used, and machine-readable format, and you have the right to transmit this data to another controller when the processing is based on consent or a contractual obligation and the processing is carried out by automated means;

(6) You have the right to object to such processing of your personal data before the Data Protection Officer if there are grounds for doing so.

You may address all requests to the Data Protection Officer listed above. To enable us to provide you with full assistance, please provide us with accurate information about yourself and specify your request. When you exercise your rights, we may request additional information to verify your identity.

Please note that if your requests are manifestly unfounded or excessive, particularly due to their repetitive nature, we may:

  • charge a fee, taking into account the administrative costs of providing the information or communication or taking the requested action, or
  • to refuse to take action on the request.

We will make reasonable efforts to comply with your request within 30 days of receiving it. If necessary, this period may be extended by two months, taking into account the complexity and number of requests.

VIII. SUPERVISORY AUTHORITY

If you believe that we have violated your rights regarding your personal data, you may file a complaint with Bulgaria’s supervisory authority-the Commission for Personal Data Protection-at the following address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592; kzld@cpdp.bg.

You can also file your complaint in the country where you live, at your workplace, or in the location where you believe we are violating your rights.