Privacy Policy

Sémio — LA TOUR DE BABEL CORPORATION (LTB SARL)

Version française »

PRIVACY POLICY OF THE SEMIO APPLICATION

Version: 2.1.0 — Last updated: 2026-07-17.


1. DATA CONTROLLER

The Semio application is published by LA TOUR DE BABEL CORPORATION ("LTB SARL"), a limited liability company governed by Cameroonian law (the "Publisher"), controller of the processing of personal data.
Contact and exercise of rights: semio.ltdb@gmail.com. Further company identification details are provided on request.


2. NATURE OF THE APPLICATION

Semio is an educational training tool, including a medical observation simulator for clinical-reasoning practice. It is neither a medical device, nor an electronic health record, nor a care tool. The User undertakes to enter only training, fictitious, or duly anonymized data, and never data identifying a real patient.


3. DATA PROCESSED

3.1. User data. Email address and account identifier required for authentication; first name, last name, and sex, provided when the profile is created; where applicable, date of birth, professional role, specialty, and affiliated institution. This data identifies the User, not a patient.

3.2. Observation content (form). The content of training cases entered by the User in the observation form: complaint, history, background, examination, additional tests, hypotheses, treatments, and monitoring parameters, including images. Such content may constitute health data, a special category within the meaning of Article 9 of Regulation (EU) 2016/679 ("GDPR"), and is treated as such. Before any transmission to a server, an AI service, or remote storage, this content is anonymized on the User's device, an application check blocking transmission where an identifying field is present.

3.3. Messages sent to the conversational assistant. When the User uses the conversational assistant, the text of their messages, the recent conversation history, and, where applicable, the content of documents they upload are transmitted to the Publisher's servers and then to the AI model providers referred to in Article 8, for the sole purpose of producing the response. Unlike the observation form, these messages are not anonymized on the device: the User undertakes not to enter any data allowing a real person to be identified. A safety filter — pattern-based detection, supplemented where applicable by an automated check performed by an AI model, which itself involves transmitting the message concerned to such a provider — blocks sending where identifying data is detected; this filter is a precautionary measure and does not guarantee the anonymization of the content. A temporary copy of the conversation is kept on the server for no more than two hours to ensure session continuity.

3.4. AI-generated outputs. Summaries, hypotheses, and suggestions produced for learning purposes, with no diagnostic or prescription value.

3.5. Voice recordings. When the User uses dictation, an audio recording is captured and then transmitted to a voice-recognition provider, for the sole purpose of its transcription into text. The recording passes through the Publisher's servers in memory only and is not retained there beyond transcription.

3.6. Technical, security, and device data. User identifier, notification token, timestamps, synchronization status, account sign-in history, as well as technical and security logs including the IP address, from which an approximate country may be derived for the purpose of applying regional restrictions. These logs serve the security of the Service, abuse prevention, and technical diagnostics; the Publisher strives to minimize the presence of conversation content in them. Usage logs of the AI features (volumes and costs, linked to a pseudonymized identifier) are also kept for credit-management and security purposes.

3.7. Biometric unlock data. Biometric unlocking is handled by the device operating system. No biometric data is transmitted to the Publisher or stored on its servers; it remains on the device.

3.8. Permissions. The Application may request access to the camera and gallery, microphone, notifications, and biometrics. These permissions are optional and enabled on the User's request.


4. PURPOSES AND LEGAL BASES

4.1. Operation of the Application and account management: performance of the contract with the User (Article 6.1.b GDPR).

4.2. Processing of content constituting health data: the User's explicit consent (Articles 6.1.a and 9.2.a GDPR), obtained separately and revocable at any time. The Publisher does not rely on the "health care" basis of Article 9.2.h, the Application being an educational tool.

4.3. Improvement and security of the Service, abuse prevention: the Publisher's legitimate interest (Article 6.1.f GDPR), respecting the User's rights.

Data is used neither for advertising, commercial profiling, resale to third parties, nor for training artificial intelligence models absent a separate, revocable consent.


5. STORAGE AND SECURITY

5.1. Local storage. Data is stored primarily on the User's device. Sensitive observation content is encrypted there using an AES-256-GCM algorithm, the key being kept in the device's hardware secure component.

5.2. Optional remote storage. Where the User enables synchronization or an online feature, the corresponding data — observation content in anonymized form, account data, uploaded documents, and operational data — is transmitted to the host's infrastructure, whose region is configured within the European Union. Transmissions are encrypted in transit using TLS and data is encrypted at rest.

5.3. Security measures. The Publisher implements appropriate technical and organizational measures: encryption in transit and at rest, mandatory authentication, per-user data partitioning, access logging, and regular updates.


6. SUB-PROCESSORS AND INTERNATIONAL TRANSFERS

6.1. The Publisher uses technical service providers acting on its instructions, bound by a processing agreement compliant with Article 28 GDPR, falling within the following categories: a hosting, authentication, and storage provider; artificial intelligence model providers, which receive the content described in Article 8 under the regime set out there; document-recognition providers; a notification-delivery provider, which receives the notification token and the content of notifications (which may include first names or display names, email addresses of invited users, and project titles); a subscription-management provider; a technical-monitoring provider, to which no clinical data is transmitted. The detailed named list of sub-processors is kept up to date by the Publisher and provided on request.

6.2. Some sub-processors are established outside the European Union, in particular in the United States and, for one AI model provider, in the People's Republic of China. Such transfers are framed by the European Commission's standard contractual clauses, supplemented where appropriate by additional measures (pseudonymization of identifiers, minimization of the data transmitted, encryption in transit). Transmissions are limited to the data necessary for the service concerned: observation content from the form is transmitted in anonymized form; messages sent to the assistant are transmitted after application of the filter described in Article 3.3, without guaranteed anonymization, the User being required to refrain from entering identifying data in them. The detailed register of sub-processors is maintained by the Publisher and provided on request.


7. DATA RESIDENCY AND REGULATED REGIONS

Remote storage and synchronization may be disabled for Users located in certain strict-framework jurisdictions, in particular the European Union, the United Kingdom, and the United States. In that case, the Application operates in local mode, data remaining encrypted on the device, and the User is informed.


8. AUTOMATED PROCESSING AND ARTIFICIAL INTELLIGENCE

The AI model providers used by the Publisher are Google Gemini, DeepSeek, and Mistral. Content transmitted to them is transmitted for the sole purpose of generating an educational response and is not used to train the models absent a separate, revocable consent. Two regimes apply depending on the feature:

a) the content of the observation form is anonymized on the device before any transmission, an application check blocking sending where an identifying field is present;

b) messages sent to the conversational assistant are not anonymized on the device: they are subject to the safety filter described in Article 3.3, which blocks detected cases without guaranteeing anonymization, and are then transmitted, together with the recent conversation history and the relevant document context, to the aforementioned providers — including, depending on the feature used, DeepSeek — to produce the response. The User undertakes not to enter any data identifying a real person in them.

The suggestions produced have no legal or similarly significant effect on the User, who retains the decision.


9. SDKS AND ABSENCE OF ADVERTISING TRACKERS

The Application integrates third-party services for its operation: authentication and database, notification delivery, subscription management, and technical monitoring (with personal data filtered). The Application integrates no advertising network and no advertising tracker, and performs no tracking of the User's activity across applications or websites. Non-essential trackers, if any, are placed only with the User's prior consent.


10. RETENTION PERIODS

Account data is retained for the duration of account use. Locally stored data is retained until deleted by the User. Upon an account-deletion request, data is permanently erased after a thirty-day grace period. The following periods further apply: voice recordings are not retained beyond transcription; the temporary conversation copy referred to in Article 3.3 is deleted no later than two hours after the last activity; access logs including the IP address are retained for no more than twelve months; usage logs of the AI features are anonymized beyond twelve months; records of attempts to enter identifying data (detected types, excluding message content) are retained for no more than six months; proofs of consent are retained for as long as necessary to demonstrate compliance with the Publisher's legal obligations; the ledger of credit and subscription transactions is retained for the statutory retention period applicable to accounting records.


11. RIGHTS OF DATA SUBJECTS

The User has the rights of access, rectification, erasure, restriction, objection, and portability, as well as the right to withdraw consent at any time without retroactive effect. These rights are exercised with the Publisher at semio.ltdb@gmail.com. The User also has the right to lodge a complaint with the competent supervisory authority.


12. CALIFORNIA USERS

For Users residing in California, the Publisher collects identifiers, user content, any health data qualifying as sensitive personal information, commercial information relating to purchases and subscriptions, and technical data, for the purpose of operating the Application and excluding any advertising purpose. The Publisher does not sell or share personal data within the meaning of the California Consumer Privacy Act as amended. Concerned Users have the rights to know, access, delete, correct their data, opt out of its sale or sharing, limit the use of sensitive information, and to non-discrimination. These rights are exercised at the address in Article 11.


13. MINORS

The Application is reserved for adults practising or training for a healthcare profession. It is not intended for children. The Publisher does not knowingly collect data concerning minors within the meaning of the Children's Online Privacy Protection Act and Article 8 GDPR. Any data relating to a minor brought to its attention is deleted.


14. DATA BREACH

In the event of a data breach likely to result in a risk to the rights and freedoms of individuals, the Publisher notifies the competent supervisory authority as soon as possible, and at the latest within seventy-two hours of becoming aware of it, and informs the concerned individuals where the risk is high.


15. CHANGES TO THIS POLICY

The Publisher may amend this policy. In the event of a material change, the User is informed at the next login and, where required, invited to renew their consent.


16. CONTACT

For any question regarding this policy or to exercise rights, the User may contact the Publisher, LA TOUR DE BABEL CORPORATION ("LTB SARL"), at semio.ltdb@gmail.com.