Privacy notice
This explains what we do with information about you, the clinician using Seneca. It is deliberately short and deliberately specific.
Your account — your name, email, billing, and the technical records we keep to run the service. We decide what happens to that, so we are the controller and this notice covers it.
Your clients' assessment records — everything about the person being assessed. You decide what happens to that; we only act on your instructions. You are the controller and we are your processor, under a written agreement you accept before you can open a case. The notice to the family is yours to give, and we provide a paste-ready paragraph for it.
Who we are
Daniel O'Loughlin, trading as Seneca, Ireland. Contact: hello@senecadocs.com.
What we collect about you, and why
| What | Why | Our legal basis | Kept for |
|---|---|---|---|
| Name, email, password, practice, role | Giving you an account and keeping it secure | Performing our contract with you | Your account, plus 30 days |
| Billing details and payment records | Taking payment and meeting tax obligations | Contract, and legal obligation for tax records | 6 years (Revenue) |
| Technical records: which page or request, whether it succeeded, how long it took, error messages | Finding and fixing faults. Clinical software that fails quietly costs you hours | Our legitimate interest in a service that works | 90 days |
| Security records: sign-in events, and an audit trail of who viewed, edited, generated, signed off or exported each report | Detecting unauthorised access, and giving you evidence of who did what | Our legitimate interest in security, and our security obligations to you | Life of the record |
| If your practice was setting up: which step of setup you reached, and when | Finding out where setting up goes wrong, so the next practice has an easier time of it | Our legitimate interest in a product that is possible to set up | 90 days |
| If you asked us for a diagnostic framework we do not support: your email, your practice name, and the framework you asked for | Deciding what to add next, and coming back to you if we add the one you asked for | Performing our contract with you | Your account |
| If you joined the waiting list: your email, and your role if you gave it | Replying to you | Your consent, which you can withdraw | Until you ask us to stop |
| If you started to sign up from outside Ireland: your email address and the country you named | Getting in touch about whether Seneca can work for you, and letting you know if it opens where you are | Your consent, which you can withdraw | Until you ask us to stop, or 24 months |
Clinical content never appears in any of those technical or security records. That is enforced in the software, not just promised here: it is one of the security measures written into the processing agreement.
Cookies and tracking
We use cookies to keep you signed in. That is all they do, and they are the only cookies this site sets.
We count visits to our public pages, and to those pages only. The marketing pages — the home page, the platform and feature pages, the security page, the waiting-list essay and the contact and application pages — carry Vercel Web Analytics, which records that a page was viewed: the address of the page, the site you arrived from, your country and city, your browser, and whether you are on a phone or a desktop. It sets no cookie and stores nothing on your device. Visitors are told apart by a short-lived code worked out from the request itself, which Vercel discards after 24 hours. We cannot tell who you are from any of it, and neither can they.
This page is not one of them, as it happens, and neither is the sub-processors page: both sit outside the marketing site in the software, so no visit to either is counted.
It is not on any page you have to sign in to see. That is deliberate and it is the important half. Inside the application the web address of a page contains the identifier of a case — so counting page views there would mean sending something about a real child to an analytics service. No page behind the login carries this or any other analytics.
There is no advertising, no advertising or cross-site tracking network, and no session recording anywhere on this site or in the application. We do not build profiles, and nothing here follows you to another website.
You have not been asked to accept cookies because none of this needs consent: the sign-in cookies are strictly necessary, and the visit counting stores nothing on your device at all. If we ever add something that does, you will be asked before it runs.
Who else sees your data
The full list, with what each one does and where, is on the sub-processors page. In short: our database and hosting are in Ireland; report drafting and audio transcription are done by providers in the United States; payments are handled by Stripe.
We do not sell your data, we do not share it for advertising, and no provider is permitted to use it for their own purposes — including training AI models.
Data leaving the EU
Your account data and your clients' records are stored in Ireland. Report drafting and transcription involve sending data to providers in the United States. Those transfers rely on a European Commission adequacy decision where one applies, and otherwise on the European Commission's standard contractual clauses. We will send you our assessment of any of those transfers if you ask.
Your rights
You can ask us for a copy of the information we hold about you, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, ask for it in a portable format, and object to the processing we do on the basis of legitimate interests. Where we rely on consent, you can withdraw it at any time.
Email hello@senecadocs.com. We answer within one month. One exception, stated plainly: we have to keep billing records for six years for tax purposes, so those survive a deletion request.
If a request reaches us about someone your practice assessed, we will not answer it. We will refer it to you, because you are the controller for that information, and we will help you respond. That help is built in, not a promise to do it by hand: you can export a case in full, erase a whole case, or erase a single record and the file attached to it, from inside the app.
Deleting a record from a case file is not the same as erasing it. The ordinary delete hides the record and keeps it, because assessment records are normally retained for years after last contact. Erasing is a separate, clearly marked action that deletes the file from our storage and cannot be undone. Erasure does not reach report text already drafted from that record, our AI provider's 30-day retention window, or backups already taken; those clear on their own schedules.
You can complain to the Data Protection Commission at any time.
How the drafting works
Seneca produces a first draft of each report section from the assessment data you enter. You review, edit and sign off every section, and nothing leaves the platform until you export it. You are the author of record of every report.
The software does not diagnose and does not decide anything about a patient. Every statement in a draft is traceable to the record it came from, so you can check it rather than trust it.
Security
Encryption in transit and at rest; access restricted so a clinician can only reach their own practice's records, enforced in the database and tested automatically; multi-factor authentication on administrative access; encrypted backups; and an audit trail of every access to a report. The full list is Schedule 2 of the processing agreement you accept when you set up your practice, and you can download that agreement from inside the app at any time.
Changes
If we change this notice we will update the date below, and we will tell you by email if the change is material.
Last updated 28 August 2026.