Privacy Policy
Version 1.4 — Last updated:
Translation. This English translation is provided for convenience only. The French version is the only legally binding version; in case of any discrepancy, the French version prevails. Version française.
This policy explains what data is used at each stage of your journey, by whom, and for what purpose. It applies to visitors to sokrate.fr, people who contact us, and patients and professionals using Sokrate services.
1. Scope of this policy
The platform is published by SOKRATE SAS, 25 rue de Ponthieu, 75008 Paris, France, SIREN 988 160 321. Processing is governed by the General Data Protection Regulation (GDPR), the French Data Protection Act (loi Informatique et Libertés), and the rules applicable to health data.
The features available to you depend on your journey and the organization supporting you. Signing up for the waitlist, submitting a contact request, and undergoing a medical check-up are different uses. Browsing the website does not enroll you in a care pathway or in research.
2. Who is responsible for your data?
2.1. The website and your relationship with Sokrate
SOKRATE SAS is the controller for processing contact requests, the waitlist, the management of its relationship with users and professionals, and the security of its own services.
2.2. The check-up and care coordination
The professional or organization that organizes your care is the controller for the processing carried out for that care. Sokrate provides the tools and processes the data on its behalf, on its instructions, within the framework set out in Article 28 of the GDPR. The identity of this organization appears in your invitation or is provided to you when your care begins. You can ask your contact person or our DPO for it.
Coordinators, consulted professionals, and support staff are intended to access only the information necessary for their role. Medical oversight of the service does not confer a general right of access to all records.
2.3. Other parties
A laboratory, a consulted professional, or an appointment booking service may be the controller of its own processing. Its obligations and privacy notice supplement those of Sokrate. A company or supplementary health insurer (mutuelle) that funds a program is not, on that basis alone, authorized to receive your medical record.
3. Why do we use your data?
A legal basis under Article 6 permits the processing of personal data. For health data, a condition under Article 9 must also be met. The basis applicable to care depends on the status and obligations of the professional or organization, which will inform you of the basis that applies to your care.
| Purpose | Controller | Legal basis — Article 6 | Health data — Article 9 |
|---|---|---|---|
| Responding to contact, demo, and partnership requests | SOKRATE SAS | Article 6(1)(f): legitimate interest in responding to requests and ensuring their professional follow-up. | No health data requested. |
| Managing the waitlist and offering a spot | SOKRATE SAS | Article 6(1)(a): your consent, given by ticking the box on the sign-up form; you can withdraw it at any time. | No health data requested. |
| Managing accounts and access to the service | SOKRATE SAS for its relationship with its users; the professional or organization for access to the care record | Article 6(1)(b): provision of the requested service; Article 6(1)(f) to prevent unauthorized access. | For access to the care record: Article 9(2)(h), in the context of your care. |
| Preparing the check-up, structuring responses, coordinating care and, where necessary, requesting a tele-expertise opinion | The professional or organization responsible for your care; Sokrate acts on its behalf | Article 6(1)(b) for the requested care; Article 6(1)(c) for applicable legal obligations; Article 6(1)(e) where a task carried out in the public interest is assigned to the controller by law. | Article 9(2)(h): prevention, care, and management of health services, subject to the professional secrecy conditions of Article 9(3). |
| Handling administrative follow-up and billing for the procedures in the care pathway | The professional or organization responsible for the procedure; Sokrate acts on its behalf | Article 6(1)(b) for managing the service; Article 6(1)(c) for applicable legal obligations. | Article 9(2)(h) for the management of health services, limited to the information necessary. |
| Offering prevention initiatives or optional sharing beyond your initial care | The partner center for its own initiatives; SOKRATE SAS for its own referral offers | Article 6(1)(a): separate consent for each optional use. | Article 9(2)(a): explicit consent where health data is used. |
| Sending optional personalized prevention communications | SOKRATE SAS, or the center identified when consent is collected | Article 6(1)(a): consent; you may unsubscribe at any time. | Article 9(2)(a) if personalization uses your health data. |
| Ensuring the security, support, and monitoring of the operation of the service | SOKRATE SAS for its service; the care controller for operations carried out on its record | Article 6(1)(f): legitimate interest in securing and maintaining the service; Article 6(1)(c) for applicable legal obligations. | Necessary access to the care record remains governed by Article 9(2)(h) and the instructions of the care controller. |
Consent to an optional use of your data is separate from agreeing to a medical procedure and from accepting the terms of use. Research is subject to its own framework and notice, described in §8; MR-004 (the CNIL reference methodology) is not, on its own, a legal basis.
4. What data is collected and where does it come from?
4.1. Contact and waitlist on the website
The contact form uses your name, email address, professional profile, your organization if you provide it, and your message in order to respond to your request. Required fields are marked; without your contact details, we cannot reply to you.
The waitlist uses your email address to record your request, track your sign-up, and notify you when a spot can be offered to you. It is based on your consent, which you give by ticking the box on the form: without it, the sign-up is not recorded. It does not ask for any medical history or answers to a health questionnaire. Signing up does not authorize personalized medical campaigns or research.
The waitlist form sends your email address directly to the Sokrate service. It is stored separately from care records, together with the sign-up date, the date of your consent, and the version of this policy in force at that time. A confirmation is displayed once it has been recorded. A new request with the same address does not change your original sign-up.
Your sign-up is kept until you unsubscribe, the list is closed, or you join the service, and no longer than three years after you sign up. At any time, without having to give a reason, you can withdraw your consent, unsubscribe, or ask for your address to be deleted by writing to contact@sokrate.com or dpo@sokrate.com. Your address is then removed from the list, and from database backups within 30 days. Withdrawing your consent does not affect the use of your address before the withdrawal.
The contact form and email contact links open your email application: you must send the message for Sokrate to receive your request. This method remains available for the waitlist if the form does not work. The message passes through your email provider and Sokrate’s. Do not attach test results, medical documents, or health information; use the channel provided by your healthcare professional for such exchanges.
4.2. Invitation and identity
When a professional or center invites you, it provides the information needed to identify you and organize the check-up: identity, date of birth, sex, contact details, appointment, and the professional and organization concerned. This information may come from its scheduling system, notably Doctolib, or be entered when you are checked in. A record identifier links your questionnaire to this care episode.
4.3. Questionnaire and health documents
You provide the answers relevant to your check-up: lifestyle habits, medical history, treatments, symptoms, priorities, and any clarifications requested during the questionnaire. The record may also contain documents uploaded by you or a professional, laboratory results, summaries, prevention plans, and tele-expertise opinions. The questions asked depend on the pathway and on your answers.
The information required to complete a step is indicated to you during the process. A missing answer may prevent that step or limit the preparation of the check-up; your healthcare professional can explain the alternatives. Avoid naming relatives in free-text fields when identifying them is not necessary.
4.4. Coordination and use of the service
Follow-up may record the referrals offered, your choices, whether a professional is already following you, appointments, coordinator notes, messages, and their delivery status. Use of the pathway links may be recorded to track the progress of your care. This service follow-up is separate from any advertising audience measurement on the public website.
Technical data is also processed: account and session identifiers, IP address, browser information, login events, actions within the tools, and errors. Consents, withdrawals, and objections are recorded with the information needed to prove them, including their date and the version of the notice shown.
4.5. Professionals’ data and administrative management
For professionals, the service also uses the identity, contact, specialty, professional identification, and organizational affiliation information necessary for their access and their involvement. When a tele-expertise procedure is performed, information about the professionals involved, the date and type of procedure, and its billing status is used for administrative follow-up. Staff authorized for this management are intended to receive only the information necessary for that task.
4.6. Additional features
Connected devices, voice analysis, and camera-based measurements are not activated simply by your visit or your sign-up. Any such feature comes with its own notice when it is offered to you: data used, permissions requested, recipients, duration, and how to disable it.
5. Your patient journey, step by step
5.1. Invitation or access request
You may be invited by a professional or a center after an appointment, or you may ask to join a pathway. Invitations and reminders are sent by email or text message. A personal link lets you return to your questionnaire; do not forward it to anyone else.
5.2. Identity verification and resuming the questionnaire
Before entering or resuming your answers, you are asked to confirm your identity. Accessing the questionnaire through an invitation and logging in to your personal account may involve different steps. If there is an error in the recipient or identity, stop entering information and notify the organization that invited you.
5.3. Data entry and progressive saving
Answers are saved progressively on the service’s servers so that you can resume and so that the check-up can be prepared. Closing the window or letting the session expire does not delete answers already saved. Some questions or clarifications rely on automated assistance during the process, described in §7.9.
5.4. Personal account and documents
Depending on the pathway, an account is created or linked to your record to give you access to your personal account. It lets you find the items made available to you and the follow-up steps. Documents may be added by you or by authorized participants. Creating an account does not constitute consent to optional uses of your data.
5.5. Preparation and consultation
Your answers are used to prepare summaries, highlight topics to discuss, and suggest plan items. Preparatory documents may be generated automatically and made available to you. The healthcare professional assesses your situation and decides on the appropriate advice, tests, or referrals as part of your care.
5.6. Coordination and referrals
Authorized teams may track your steps, remind you of a step, record your preferences, help you find an appointment, and record the information needed for follow-up. Suggestions of partner professionals as part of an optional use depend on your consent choices. You remain free to choose your healthcare professional.
5.7. Tele-expertise, where offered
A professional may request a specialist’s opinion based on the relevant information in your record (tele-expertise). The process includes preparing the request, having it validated by an authorized participant, sending it to the specialist, and returning the specialist’s opinion. Validation of the tele-expertise request is conditional on your agreement to sharing with specialists, as recorded in your pathway. The communications, attachments, reports, and necessary administrative information are attached to that request. A response prepared by AI is not, in itself, the specialist’s opinion.
5.8. Transmission and continuity of care
The necessary documents may be made available to the professional or center in charge of your care, in particular in its record-keeping or appointment tools. Under Mon bilan prévention, France’s national prevention check-up program, the plan and screening findings are intended for your regular doctor (médecin traitant), unless you object. Any sharing outside the care team follows the applicable information requirements and, where required, consent requirements. You may also give your documents yourself to the healthcare professional of your choice.
6. Your choices for optional uses
Prevention initiatives beyond your initial care, certain partner referrals, and personalized medical communications must be presented separately, together with their controller and recipients. Where processing is based on your consent, that consent must be freely given, specific and, for health data, explicit.
You can refuse or withdraw consent without losing your right to care. Withdrawal stops the use concerned going forward; it does not make processing carried out before the withdrawal unlawful and does not necessarily result in the erasure of the medical record.
To change your choices, use the controls available in your account or contact dpo@sokrate.com. Specify the pathway and the use concerned, especially if you have more than one record. Invitations needed for an appointment and security information are separate from optional communications.
7. Recommendations and automated assistance
7.1. What the service prepares
Sokrate matches your answers against prevention rules and resources to organize information, identify risk factors, and suggest topics for discussion or follow-up steps.
7.2. Information to be considered in light of your situation
A summary, score, or suggestion may be incomplete or wrong. These items do not, on their own, constitute a diagnosis or a prescription and do not replace an assessment by a healthcare professional.
7.3. Oversight of the service and review of a record
Defining and revising the prevention rules falls under the medical oversight of the program. This general oversight is separate from the review of an individual document. An automatically generated preparatory document must not be treated as a plan validated or signed by a professional.
7.4. Your decision and the professional’s
Automated identification of risk factors may constitute profiling within the meaning of the GDPR. It is used to prepare and organize the pathway. You can discuss the suggestions; the clinical decision rests with the professional. The safeguards of Article 22 of the GDPR apply where a decision based solely on automated processing produces legal effects concerning you or similarly significantly affects you.
7.5. Prevention documents
Draft plans and letters are working materials. The professional must assess their relevance and correct or supplement them before using them as a clinical document under their own responsibility.
7.6. Asking for an explanation or a review
You can ask your healthcare professional to explain or review a recommendation. For questions about the data used or about exercising your rights, contact our DPO.
7.7. Reporting an error
Report an inaccurate answer, a document attributed to you in error, or a recommendation that does not fit your situation to your care contact. Correcting the source data may require the derived documents to be prepared again.
7.8. Support and improving how the service works
Authorized teams may consult the records needed to analyze an error, check a processing operation, or resolve an incident. Fixing how the service works and reusing records for research or model training are different purposes; the latter does not follow from your mere use of the service.
7.9. Use of artificial intelligence
Once your questionnaire has been submitted, an artificial intelligence system is used to prepare a draft of your Personalized Prevention Plan. Starting from the public health guidelines that match your answers — notably those of the French National Authority for Health (HAS), the French National Cancer Institute (INCa), and Santé publique France (the French public health agency) — it helps select the most relevant ones, group repetitions together, and identify a small number of health priorities, usually one or two. It rephrases them in plain language, with practical advice, useful resources, and follow-up arrangements drawn from the selected recommendations.
The AI’s role is not to make a diagnosis or to prescribe a test or treatment. It is instructed to rely on the guidelines framework developed and validated by our medical committee, without inventing any recommendation. Errors remain possible: your plan is a starting point for a conversation with your doctor, who assesses its relevance for you.
Some processing removes the first name, last name, email address, and phone number fields before sending data to the AI. This removal is neither anonymization nor a safeguard applied to all uses of AI. Depending on the pathway, AI assistance may also be used while you enter your answers, in particular to clarify them.
Learn more about how it works and how your data is used
When is AI used?
The plan is prepared after the questionnaire is submitted. Other functions may use AI while you enter your answers to clarify or structure them. It may also help prepare a consultation summary, a tele-expertise request, or a draft tele-expertise response.
How is your plan built?
- Identifying the recommendations that apply to you. Rules compare your answers with the criteria of the prevention profiles in the medical guidelines framework, which is based on recommendations from the HAS, INCa, Santé publique France, and learned societies. This first matching step is deterministic: with identical answers, rules, and framework version, the result is identical.
- Organizing and explaining priorities. AI is applied to the selected recommendations. It is asked to select the most relevant ones, group repetitions together, and usually formulate one or two priorities, written in the first person. It takes into account the obstacles you reported and includes the advice, resources, useful contacts, and follow-up arrangements available in the recommendations.
- Preserving the source of the recommendations. The references associated with the recommendations are kept so that a healthcare professional can trace their source and review the plan’s suggestions.
What are the limits of this assistance?
The system is instructed not to invent any advice, resource, or contact beyond the recommendations provided. This instruction does not guarantee the absence of errors or omissions. The preparatory document is not a diagnosis, a prescription, or an individual validation by a professional; clinical decisions rest with the professional.
What data is sent to it?
Depending on the function, the information sent may include age, sex, medical history, lifestyle habits, answers and free-text clarifications, calculated scores, risk factors, the context of the request, relevant consent choices, and necessary excerpts from documents.
Removing identity fields in some processing does not remove identifying information that may be present in free text or in the clinical context. Other functions may also send identifying data present in the answers. The data used by the AI therefore remains personal health data.
AI services are technical recipients separate from the host of the main record. Requests, responses, and operational information may also be recorded in Sokrate’s tools for monitoring, error diagnosis, and returning results. The categories of services are listed in the appendix; transfers are covered in §10.3 and retention in §11.
Human oversight and your rights
The guidelines framework and system settings are overseen and reviewed by our medical committee, under the responsibility of our medical director. This oversight does not mean that each plan has been reviewed before being displayed. A healthcare professional may correct its content.
You can request an explanation, ask for a human review of your plan, express your point of view, or report an error to your healthcare professional or to dpo@sokrate.com. The specific safeguards of Article 22 of the GDPR apply where a decision based solely on automated processing produces legal effects concerning you or similarly significantly affects you, as stated in §7.4.
8. Scientific research
Reusing data for a research project is separate from the check-up and its follow-up. This policy does not constitute a general authorization to reuse your record for any future research.
Before a project begins, its controller must determine and document the legal basis under Article 6, the applicable condition under Article 9 — in particular Article 9(2)(j) for research where its conditions are met — and the required formalities. The CNIL reference methodology MR-004 governs certain research not involving human subjects; a declaration of compliance does not constitute a general certification of the platform.
Each project falling under MR-004 must comply with its requirements and be registered in the public directory of the French Health Data Hub (Plateforme des données de santé). You must receive the project-specific notice or have access to the prior information mechanism meeting the conditions of this methodology: objectives, controller, data used, recipients, duration, and how to exercise your rights.
Pseudonymized data remains personal data: an identifier replaces direct identifiers, but a link to an individual may remain. The pseudonymization methods, separation of access, and quality control are defined for each project. The CNIL’s 2026 appendices serve as security references; whether they are mandatory depends on the framework to which the project is actually subject.
You can object to reuse for research by writing to dpo@sokrate.com, with no consequences for your care. How to exercise your rights for an ongoing project is specified in its project-specific notice.
9. Who may receive your data?
- The professionals and organization responsible for your care, authorized coordinators and, where involved, the specialists consulted for tele-expertise.
- Authorized Sokrate staff for support, operations, and security, limited to what their role requires.
- The technical service providers necessary for the processing, notably hosting, communications, and AI assistance.
- The partners involved in your pathway and introduced to you, in particular laboratories and the professionals to whom you choose to be referred.
- Authorities to which disclosure is legally required, within the limits of their request and their powers.
9.1. Laboratory tests and Nightingale Health
When an additional metabolomics analysis is offered to you, the process may involve the prescribing professional, the laboratory collecting the sample, and Nightingale Health, a technology partner based in Finland. Organizing the sample collection, identifying the sample, analyzing it, and returning the results require data exchanges that are separate from the questionnaire.
Before confirming this service, review the information provided by the laboratory and the partner: it must identify the controllers, the data sent with the sample, the processing locations, the retention of the data and of the sample, and any possible reuse. Results communicated to Sokrate and to the professionals in your pathway become part of your care record. The analysis does not constitute agreement to reuse for research.
9.2. Employers, supplementary health insurers, and other funders
Funding a program does not give access to individual answers, results, medical documents, or opinions. The administrative information needed to manage the program is kept separate from the medical record. Any group report intended for the funder must be aggregated and anonymized so that no participant can be identified, including in a small group.
Sokrate does not sell your health data. Enrolling in a program does not authorize disclosure of that data to your employer or your insurer.
10. Hosting, security, and transfers
10.1. Hosting of the Sokrate record
The main Sokrate record is hosted in France on Google Cloud Platform. Google publishes the scope of its HDS v2.0 certification (the French certification for health data hosting), which applies to the covered services and their terms of use. This certification of the hosting provider does not constitute an overall certification of Sokrate.
Where the record is stored does not, on its own, describe all processing: sending messages, a laboratory analysis, or a call to an AI service involve other services.
10.2. Protection of access and documents
Measures include securing communications with the service, authentication for personal accounts, role-based access permissions, and logging of operations. Documents uploaded to the document vault are protected by application-level encryption. Access and backup arrangements differ depending on the component and the pathway.
The end of a session does not mean the record is destroyed. Likewise, hiding or deleting a document in an interface does not guarantee the immediate erasure of all its copies: the retention rules and the procedure for exercising your rights apply.
10.3. Service providers and international transfers
The main GCP hosting and the Mailjet and M-target services are provided in France. AI services and other partners in the pathway must be considered separately. Depending on the service and its configuration, processing in or access from a country outside the European Economic Area may be involved. Primary storage in France is therefore not a general guarantee that no transfer takes place.
A transfer must be covered by a mechanism applicable to the recipient: an adequacy decision, or appropriate safeguards such as standard contractual clauses supplemented, where necessary, by additional measures. HDS certification and the removal of identifiers do not exempt a transfer from this assessment.
You can ask the DPO for information about the service providers involved in your pathway, the countries of processing, and the applicable safeguards, as well as how to obtain a copy of those safeguards.
10.4. Incidents
When acting as a processor, Sokrate notifies the controller without undue delay after becoming aware of a breach. The controller notifies the CNIL, the French data protection authority, under the conditions of Article 33 of the GDPR, where feasible within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals. Individuals are informed when a high risk is likely to affect them, under the conditions of Article 34.
11. How long is data retained?
Retention periods depend on the purpose, the controller, and the applicable obligations. Where a specific period cannot be stated for all pathways, the criteria below explain what ends active use and what may justify separate archiving.
| Data | Active use | Archiving and exceptions |
|---|---|---|
| Waitlist | Until you unsubscribe or withdraw your consent, the list is closed, or you join the service, and no longer than three years after you sign up. If you join the service, only the information necessary for the new relationship is carried over. | Signing up does not create a medical record. Communications needed to prove your request are kept separate from the list used to contact you. A deleted address disappears from database backups within 30 days. |
| Contact and professional requests | While the request is being handled and during the exchanges necessary to resolve it. If a contractual relationship begins, the data then falls under that relationship. | Only the information necessary for a legal obligation or for the defense of a legal claim is kept, for the period applicable to that obligation or claim. |
| Questionnaire, check-up, documents, and care coordination | During your care, according to the instructions of the responsible professional or organization. A saved response may remain after your session is closed. | Retention of the medical record depends on the status of the professional or facility and the rules that apply to it. It is separate from the lifetime of your account; the party responsible for your care can tell you the applicable period. |
| Account and access permissions | While you use the service; access is closed when the account is closed or the permission ends. | Closing an account does not erase medical documents or records that must be retained. Each category follows its own retention period. |
| Consents, withdrawals, and objections | For the duration of the processing concerned, in order to apply your choices. | Limited proof is kept for the period necessary to demonstrate that your choices were respected. An objection must remain applicable to any later reuse of the data. |
| Logs, notifications, and AI processing records | To verify message delivery, diagnose errors, and secure the processing concerned. Medical content relevant to the record follows the retention of the care record. | Information needed to investigate an incident or a dispute is set aside for as long as it is being handled and for the applicable appeal periods. Session expiration does not delete these records. |
| Research, where a project falls under MR-004 | Until two years after the last publication of the results or, if there is no publication, until the final report is signed. | Archived according to the rules applicable to the project, as specified in its project-specific notice. |
11.1. Account closure and erasure
To request the closure of your account or the erasure of your data, write to the DPO. The request is reviewed by data category and, for care, together with the relevant controller. Data that no longer has any justification for retention must be erased or anonymized; a retention obligation or the defense of a legal claim may justify keeping certain items, with restricted access.
The response time stated in §12 is not a commitment to erase all medical records and backups within that same period. Backup copies, archives, and logs must be taken into account when carrying out the request.
11.2. Continuity and return of data
If the relationship with an organization ends or a service is discontinued, the arrangements for returning and retaining records are organized with the party responsible for your care. You remain able to request access to your data and, where the conditions are met, its portability.
12. Your rights and how to exercise them
- Access and rectification: find out what data concerns you, obtain a copy, and request the correction of inaccurate information.
- Erasure and restriction: request the deletion of data or the restriction of processing under the conditions set out in the GDPR, in particular subject to retention obligations.
- Objection: object, on grounds relating to your particular situation, to processing based on legitimate interest or on a task carried out in the public interest; you can object to direct marketing at any time. The arrangements for research are set out in §8.
- Portability: receive the data you have provided in a structured format where the automated processing is based on consent or a contract.
- Withdrawal of consent: stop an optional use based on your consent, without retroactive effect on processing already carried out.
- Automated decisions: benefit from the applicable safeguards where the conditions of Article 22 are met, in particular human intervention in the cases provided for by that article.
Write to dpo@sokrate.com or to SOKRATE SAS — DPO, 25 rue de Ponthieu, 75008 Paris, France. State the service concerned and the details needed to locate your record, without spontaneously attaching any medical document or identity document. Additional information may be requested if there is reasonable doubt about your identity.
You will receive a response within one month of receipt of your request. This period may be extended by two months where necessary, taking into account the complexity or number of requests; you will be informed of any extension, together with the reasons, within the first month. If Sokrate acts on behalf of a care organization, the request is coordinated with that organization.
You may lodge a complaint with the CNIL, the French data protection authority, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.
13. Changes to this policy
The date and version of this policy make it possible to identify changes. Any significant change to the purposes, recipients, or methods of processing will be communicated to you appropriately before the new use. If new consent is required, updating this page and continuing to use the service do not replace it.
14. Your contacts
SOKRATE SAS — 25 rue de Ponthieu, 75008 Paris, France — SIREN 988 160 321.
Data Protection Officer: Actecil, external DPO — dpo@sokrate.com.
Medical Director: Dr. Jérôme Bouaziz. Clinical questions about your care should be addressed to your healthcare professional.
Appendix — Service providers and partners in the pathways
The technical services below are separate from the professionals and laboratories that are controllers of their own processing, described in §9.
| Provider | Role | Location | Data |
|---|---|---|---|
| Google Cloud Platform | Hosting of the Sokrate health infrastructure | France, for hosting of the main record. | Records, documents, and technical data necessary for the service. |
| Mailjet | Sending service emails | France. | Recipient contact details, message content, delivery and tracking information. |
| M-target | Sending service text messages (SMS) | France. | Phone number, message content, and delivery status. |
AI assistance: the features described in §7.9 rely on language generation and processing services, notably OpenAI and Google. The service also provides for the use of Anthropic, depending on its configuration. This processing is separate from the GCP hosting of the record; the answers, clinical context, and instructions necessary for the task may be sent to these services. Where the processing takes place depends on the AI service used and its configuration.
Website email: for requests sent by email, email providers are involved in routing and storing the message. Contractual information and transfer safeguards relating to your pathway may be requested from the DPO in accordance with §10.3.
Cookies and session mechanisms are described in the cookie policy.
Sokrate relies on the official recommendations of the French National Authority for Health (HAS), French National Health Insurance (Assurance Maladie – Ameli) and medical societies. The service is not designed to handle emergencies and does not replace a medical consultation. In a medical emergency in France, call 15 (SAMU) or 112.