Privacy Policy
Version 1.0 · September 2026. This policy applies to the publicly accessible pages of the PraxisOS platform (sign-in, online appointment booking, self check-in, call display, legal pages). For content within a practice tenant (patient, client and health data), the privacy policy of the respective practice (controller) applies additionally. Target markets: Germany and Switzerland.
1. Controller / Provider
Controller within the meaning of Art. 4 No. 7 GDPR and Art. 5 lit. j revDPA for processing on the public pages of this platform:
Strattons Oakmont LLC
1501 South Greeley Highway, Suite C, 82007 Cheyenne, Wyoming, USA
Filing ID (Wyoming Secretary of State): 2026-001871090
Contact (general & privacy): oakmont-strattons@proton.me
EU representative (Art. 27 GDPR) and contact for EU/Switzerland:
Grenzenlos Limited, CRO Reg.: 822268, 77 Camden Street Lower, Dublin 2, D02 XE80, Ireland — mail@grenzenlos.ie. All privacy requests from the EU and Switzerland are handled centrally by Grenzenlos Limited.
2. Role Separation: Public Pages vs. Practice Tenants
- Public platform pages (sign-in, booking, check-in and info pages): Strattons Oakmont LLC is the controller. This policy describes these processing activities.
- Practice tenants: Personal data processed by a practice within its own tenant (e.g. patient records, client/animal data, appointments, recordings, invoices) is processed exclusively on behalf of and under the instructions of the respective practice. Strattons Oakmont LLC acts as processor pursuant to Art. 28 GDPR / Art. 9 revDPA; the practice is the controller. Details are governed by the Data Processing Agreement (DPA).
3. Specific Processing on the Public Pages
3.1 Website provision / server log files. Our hosting automatically processes technical connection data: IP address, timestamp, user agent, referrer, requested URL, HTTP status code. Purpose: technical provision, abuse prevention, IT security. Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Retention: max. 30 days.
3.2 Sign-in / authentication. We process e-mail address, password hash (argon2id) and, where applicable, a second factor (WebAuthn/passkey: public key, signature counter, credential identifier). Purpose: access security. Legal basis: Art. 6(1)(b) GDPR; for MFA additionally Art. 6(1)(f) GDPR. Retention: for the duration of the account; security logs max. 90 days.
3.3 Online booking and self check-in. On the public booking and check-in pages, patients or animal owners enter their data (name, date of birth, e-mail, optionally phone) directly. The respective practice is the controller of this data; the platform processes it as processor (Art. 28 GDPR). Reminders are sent on behalf of the practice if it has configured a sending provider. Cancellation is possible at any time via the link in the confirmation.
3.4 Health data (Art. 9 GDPR). Practice tenants may process health data. The platform encrypts defined sensitive fields at application level (AES-256-GCM) and keeps a tamper-evident, append-only audit trail. The practice is the sole controller of these special categories; the platform makes no medical decisions and produces no diagnoses.
3.5 Contact by e-mail. When contacting oakmont-strattons@proton.me we process the transmitted content to handle your request. Legal basis: Art. 6(1)(b/f) GDPR.
3.6 Cookies and local storage. These pages set no tracking, marketing or analytics cookies and embed no external font CDNs, analytics or consent banners (fonts are self-hosted at build time). We use strictly necessary mechanisms only: praxisos_session (httpOnly session cookie), praxisos_sim_role (httpOnly admin role simulation), server-side WebAuthn challenges (5 minutes, single-use), and a short-lived OAuth state cookie when connecting a Google account in the admin area. No consent is required for strictly necessary mechanisms.
4. Hosting / Data Location
The application runs on Vercel (serverless functions, Frankfurt region, fra1); the database is hosted by Neon (PostgreSQL, Frankfurt region, eu-central-1). Document content is stored in the database or in an S3-compatible EU object store, configurable per tenant.
5. Recipients / Sub-processors
- Vercel Inc. — application runtime (functions in Frankfurt), USA (compute EU), DPF-certified.
- Neon Inc. — PostgreSQL database (Frankfurt region), USA (storage EU), DPF-certified.
- Mistral AI — optional AI features (only if the practice configures its own key), France (EU) — no third-country transfer.
- Google LLC — optional Gmail sending via OAuth (only if the practice connects its Google account), USA, DPF-certified.
- Grenzenlos Limited — EU representative, Ireland (EU/EEA — no third-country transfer).
Where a practice configures its own SMTP or AI provider, the practice's contract with that provider governs; the platform transmits content to the endpoint chosen by the practice.
6. Third-Country Transfers (USA)
The platform provider is a company established in the USA. To the extent access from the USA occurs in the context of operation, support or processing, the following applies: for the DPF-certified recipients listed above, transfer is based on the EU Commission adequacy decision on the EU-U.S. Data Privacy Framework (Implementing Decision (EU) 2023/1795); for Strattons Oakmont LLC itself (currently not DPF-certified), the EU Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914) together with additional technical and organisational measures (encryption, strict role and access control, EU data location).
7. Data Subject Rights
Subject to statutory requirements you have the rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20 GDPR / Art. 28 revDPA), objection (Art. 21), withdrawal of consent, and the right not to be subject to automated individual decision-making (Art. 22). Exercise by e-mail to oakmont-strattons@proton.me. For personal data within a practice tenant, the respective practice is your first point of contact.
8. Use of AI Systems (EU AI Act)
The platform provides AI-assisted documentation and assistance features (e.g. structuring of spoken recordings, suggestions for billing codes, classification of incoming documents, letter drafts). We inform transparently pursuant to Art. 50 of Regulation (EU) 2024/1689:
- Labelling: AI-generated content is marked as draft in the interface.
- Human oversight: All AI outputs are drafts that practice staff review, edit or discard before they take effect (approval workflow). No automated decision with legal effect takes place.
- No diagnosis: The AI systems do not produce medical diagnoses or treatment recommendations; PraxisOS is not a medical device within the meaning of the MDR.
- No prohibited practices: No emotion recognition, social scoring or biometric categorisation within the meaning of Art. 5 AI Act.
- No training: Customer data is not used to train foundation models; this is contractually excluded with the AI service providers used.
- Provider choice: The practice selects its AI provider itself (EU endpoint by default) and confirms review of data processing and third-country transfer when doing so.
9. Right to Complain to Supervisory Authorities
Data subjects in the EU may contact the data protection supervisory authority of their habitual residence or of the place of the alleged infringement. Data subjects in Switzerland may contact the Federal Data Protection and Information Commissioner (FDPIC).
10. Changes to this Policy
We update this policy when processing activities, recipients or legal bases change. The current version is always available at this URL.
Version 1.0 · September 2026.