DiagnosticMind
Assessments Scorecards
Manifesto Method About
Insights Contact
EN PT
How personal data is handled

Privacy Policy

Last updated: 18 August 2026 · Version 1.3

DiagnosticMind operates in regulated sectors where compliance is the baseline, not the achievement. This page exists to make the operating reality of how this platform handles personal data legible — not to perform compliance theatre. The detail below is the actual protocol.

On this page

  1. Identity and controller
  2. What data is collected, and why
  3. Lawful basis matrix
  4. Sub-processors
  5. International transfers
  6. Cookies and analytics
  7. Your rights
  8. Security
  9. AI processing
  10. Changes to this policy
  11. Acknowledged residual risks

01Identity and controller

The controller for personal data processed by this website is:

Legal namePaulo Fernando Marques Ramada (Empresário em Nome Individual)
NIF193385902
Country of establishmentPortugal
Tax addressAvailable on request to verified business contacts
Primary contactcontact@diagnosticmind.eu
Data protection contactprivacy@diagnosticmind.eu
DesignationData Protection Contact (not Data Protection Officer — a solo Empresário em Nome Individual cannot be operationally independent of itself, so the honest, equally credible designation is used)

The controller is established in the European Union; no Article 27 representative is required.

02What data is collected, and why

CategoryCollectedRetentionLawful basis
Email address — assessments and scorecardsNo. The tools do not ask for an address and none is collected. Reports are displayed in your browser, where you can read, save, or print them; nothing is emailed.N/AN/A
Email address, name, organisation, message and optional attachments — contact form onlyOnly what you submit through the contact formKept in the operator's mailbox while needed to handle the enquiry and any resulting business relationship, then deleted when no longer needed or following a valid erasure request, subject to legal obligationsSteps at your request / contract — Art. 6(1)(b); legitimate interest for ordinary business correspondence — Art. 6(1)(f)
Assessment and scorecard responsesNot retained by DiagnosticMind. Scoring occurs in your browser; when an AI narrative is requested, the relevant responses are sent through our Cloudflare Worker to the Anthropic API. Provider processing and retention are described in sections 4 and 9.No DiagnosticMind response database; Anthropic Standard API retention applies to AI requestsLegitimate interest — Art. 6(1)(f), subject to the review noted below
IP addressProcessed by Cloudflare for network delivery and security. The assessment API also supplies the address as a key to Cloudflare's Rate Limiting binding.No IP address is written to a DiagnosticMind database or Durable Object. Cloudflare may retain service and security data under its own service configuration and terms; no fixed DiagnosticMind-controlled log period is claimed here.Legitimate interest — service security and abuse prevention (Art. 6(1)(f))
Browser and device signalsCloudflare Turnstile processes technical signals to distinguish people from automated abuse. DiagnosticMind does not receive a reusable browser fingerprint from Turnstile.Handled by Cloudflare under its service terms; DiagnosticMind receives only the verification outcome and does not retain the Turnstile token.Legitimate interest — abuse prevention (Art. 6(1)(f))

03Lawful basis matrix

ActivityLawful basisGDPR Article
Public assessment scoringLegitimate interestArt. 6(1)(f)
Correspondence and pre-contractual steps you initiate through the contact formContract / legitimate interestArt. 6(1)(b) / 6(1)(f)
Security logging (IP addresses)Legitimate interestArt. 6(1)(f)
AI processing of responses (substantively considered legitimate-interest balancing — formal LIA documentation is deferred to lawyer review)Legitimate interestArt. 6(1)(f)

04Sub-processors

Personal data is processed by the providers below for the stated purposes. Their public data-processing terms apply where incorporated into the relevant service agreement; account-level applicability and transfer settings remain subject to operational and legal review.

Provider Service Region Transfer mechanism DPA
Cloudflare, Inc. Workers and Static Assets, Rate Limiting, Durable Objects budget counter, Turnstile, and Web Analytics Global edge (US HQ) SCC + EU-US Data Privacy Framework cloudflare.com
Anthropic, PBC Claude API (Sonnet 4.6) — AI inference for assessment narratives US SCC + EU-US Data Privacy Framework anthropic.com
Resend, Inc. Transactional email (contact-form correspondence only) US SCC + EU-US Data Privacy Framework resend.com
Proton AG Business mailbox receiving and retaining contact-form correspondence Switzerland EU adequacy decision for Switzerland; safeguards for any onward transfers under Proton's terms proton.me

Anthropic — additional facts. The Standard API tier is used. Inputs and outputs sent to the Anthropic API are not used to train Anthropic's models under its commercial-product terms. Anthropic states that Standard API inputs and outputs are automatically deleted within 30 days, subject to agreed exceptions, usage-policy enforcement, or legal obligations. DiagnosticMind does not currently have a Zero Data Retention agreement.

Provider changes. This list and the updated date will be revised when a provider that processes personal data is added, removed, or materially repurposed.

05International transfers

Cloudflare, Anthropic, and Resend may process data outside the EEA, including in the United States. Their published terms describe mechanisms such as Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. Proton is established in Switzerland, which is covered by an EU adequacy decision. DiagnosticMind does not claim that a transfer impact assessment or every account-level contractual option has been independently verified; that review remains an acknowledged legal work item.

06Cookies and analytics

This platform does not use advertising cookies or third-party advertising analytics. Cloudflare Web Analytics collects performance and traffic measurements; Cloudflare states that this service does not collect or use visitors' personal data or track individuals across customer sites. Cloudflare Turnstile may use strictly necessary browser storage and technical signals to prevent automated abuse. These security functions are not used for advertising.

07Your rights

Under the GDPR, you have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erasure — request deletion (Art. 17)
  • Restriction of processing (Art. 18)
  • Portability of data you provided (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw consent at any time, where processing is based on consent (Art. 7(3))

How to exercise your rights

Send your request to privacy@diagnosticmind.eu. We respond without undue delay and in principle within one month of receipt. That period may be extended by up to two further months where Article 12(3) permits, with notice within the first month.

Identity verification

  • We request only the additional information necessary to confirm identity where there are reasonable doubts. A government-issued identity document is not required by default. Any verification evidence is minimised and deleted when no longer needed for the request and accountability record.

Right to lodge a complaint

The lead supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD) in Portugal. You retain the right to lodge a complaint with the CNPD or with your local supervisory authority — cnpd.pt.

08Security

The technical and organisational measures protecting personal data are documented on the Security page. Highlights:

  • HTTPS enforced with HSTS preload
  • Encryption in transit via HTTPS and provider-managed encryption for active storage
  • No public user accounts or stored passwords
  • Risk-based breach handling: the authority is notified within 72 hours where Article 33 requires it; affected individuals are informed where Article 34's high-risk threshold is met

09AI processing

The AI processing relevant to data handling is summarised below:

  • The model used is Claude Sonnet 4.6, accessed via the Anthropic Standard API.
  • Inputs and outputs are not used to train Anthropic's models.
  • The AI generates the diagnostic report from your assessment responses. Its output is informational; no automated decision with legal or similarly significant effect on an individual is made (Article 22 GDPR).
  • Self-classification under the EU AI Act: Limited Risk (Article 50 transparency obligations apply from 2 August 2026; the Digital Omnibus deferral of high-risk obligations does not affect this classification).

10Changes to this policy

This policy is versioned. Changes are reflected in the updated date and version at the top of this page. Where applicable law or a customer agreement requires direct or advance notice of a material change, that notice will be given under the applicable requirement; no broader notice period is claimed here.

11Acknowledged residual risks

For full transparency:

  • A formal Data Protection Impact Assessment has not been conducted. Assessment responses are disclosed to Anthropic for AI inference, contact correspondence is handled by email providers, and security processing includes IP addresses and Turnstile signals. Whether a DPIA is required, and the documented legitimate-interest balancing, remain deferred to lawyer review.
  • Lawyer-reviewed legal documentation is committed at the first enterprise contract. The current pages are best-effort defensible — accurate, considered, and reflective of operational reality, but not yet externally counsel-reviewed.
  • Formal Records of Processing Activities (Article 30) and a documented Legitimate Interest Assessment are committed at the first enterprise contract. The substantive analysis underlying both has been performed; only the formal documentation is deferred.

These residuals are accepted consciously, not concealed.

Last updated 18 August 2026 · Version 1.3 Privacy · Security
DiagnosticMind
Assessments Scorecards
Manifesto Method About
Newsletter Contact
© 2026 DiagnosticMind
Privacy Security