Legal
Legal Notice
Last updated: 23/07/2026
Who are we? Connectoma Neurotech, S.L., developers of AI-based medical software for neuroimaging processing.
What does this website do? It provides informational content about our technology and gives restricted access to authorized healthcare professionals at portal.connectoma.com.
Medical guarantee: Our ConnectTarget_MDD tool supports, but never replaces, the decision and clinical judgement of the specialist physician (Human-in-the-Loop).
Your data and security: We operate under the strictest EU standards (GDPR, MDR and the AI Act) with encrypted infrastructure in Madrid. You can contact our Data Protection Officer at dpd@connectoma.com.
1. Institutional information and ownership
In compliance with article 10 of Spanish Law 34/2002, of 11 July, on Information Society Services and Electronic Commerce (LSSI-CE), users and healthcare professionals are expressly, clearly and directly informed that the websites corresponding to the connectoma.com domain, its restricted-access subdomain portal.connectoma.com, and any derived application or digital environment (hereinafter, “the Website”), are the exclusive property of and are managed by:
- Company name: Connectoma Neurotech, S.L. (hereinafter, “Connectoma”).
- Tax identification number (NIF): B70752795.
- Registered office and head office: Calle Padilla 26, 2.º, 28006 Madrid, Spain.
- Corporate email address: info@connectoma.com.
- Registry details: Company duly registered in the Madrid Commercial Registry.
2. Conditions of access and user acceptance
Accessing, browsing and using the Website grants user status and implies full, tacit and unreserved acceptance of all the provisions contained in this Legal Notice, in the version published at the time the platform is accessed.
The user is explicitly informed that merely accessing the informational content on this website does not in any way imply the start of a contractual, commercial or care relationship with Connectoma, which will require the prior formalization of the corresponding software licence agreements (SaaS), data processing agreements (DPA) and specific terms with the approved medical centres or organizations.
3. Responsible use of the Website and logical security
To guarantee maximum protection of the infrastructure supporting health data, the user undertakes to make ethical and secure use of the portal. Any action that may compromise the cybersecurity of the platform, or that may in any way overload, damage or disable the servers and logical infrastructure hosted in the Madrid cloud region (Google Cloud Platform), is expressly prohibited.
Under Regulation (EU) 2024/1689 (AI Act) and the Spanish Criminal Code, any denial-of-service attack (DoS/DDoS), the introduction or spread of malicious code (viruses, trojans), or any attempt at unauthorized access to the servers, computers or databases linked to Connectoma’s modular brain-processing pipeline is expressly prohibited. Connectoma will immediately report such conduct to the State Security Forces and Corps and will cooperate with the judicial authorities by disclosing the digital identity of the infringer.
4. Confidentiality of clinical credentials
In the areas of the restricted-access subdomain intended for healthcare professionals (portal.connectoma.com), access is subject to the prior enablement of corporate licences. The assigned user identification code and password are strictly confidential, personal and non-transferable.
The authorized clinical user or physician is solely responsible for the safekeeping and diligent use of their credentials. Connectoma reserves the right to immediately disable or suspend logical access if it detects fraudulent or negligent use, unauthorized transfer to third parties, or conduct contrary to the organization’s role-based segregation of duties (IAM) policies.
5. Exclusion of medical advice, human oversight and algorithmic ethics
5.1. Informational and educational nature
The content, research materials, graphics and methodological information on neuroimaging (fMRI), tissue-segmentation Artificial Intelligence (ANTsPyNet DeepAtropos) and transcranial magnetic stimulation (TMS) published on this Website are strictly informational and educational in purpose, aimed at the neuroscientific community. Under no circumstances do they constitute or replace a medical consultation, a psychiatric diagnosis or a personalized clinical prescription.
5.2. Mandatory human oversight (Human-in-the-Loop) and regulatory framework
In compliance with Regulation (EU) 2017/745 on Medical Devices (MDR) for Class IIa Medical Software and with article 14 of Regulation (EU) 2024/1689 (AI Act), the ConnectTarget_MDD tool operates exclusively as a Clinical Decision Support system.
The software is designed under the principle of mandatory human oversight, which means that all analytical results and connectivity models must be reviewed, ratified and approved as a prerequisite by a qualified specialist physician at the responsible healthcare centre before being applied in any therapeutic procedure.
5.3. Ethical commitment and algorithmic explainability
True to our commitment to ethical, transparent and bias-free Artificial Intelligence, Connectoma makes the technical documentation and methodological evidence of the ConnectTarget_MDD pipeline available to health authorities, clinical committees and conformity assessment bodies, guaranteeing at all times the principle of algorithmic explainability and scientific traceability.
6. Intellectual and industrial property rights
Connectoma Neurotech, S.L. is the legitimate owner or exclusive licensee of all intellectual and industrial property rights in the Website, including its graphic designs, source code, logical interfaces and, strictly, the analytical algorithms developed in Python and their associated databases.
The reproduction, distribution, transformation, reverse engineering, decompilation, extraction or public communication, in whole or in part, of this content or these tools is strictly prohibited, even citing the sources, except with the prior, express and written consent of Connectoma. Merely accessing or browsing the portal confers no licence, waiver, transfer or assignment whatsoever of the company’s industrial and intellectual property rights.
7. Third-party links
Links established on the Website to third-party portals or resources are purely informational or for reference. Connectoma exercises no control over such sites and assumes no responsibility whatsoever for their content, accuracy, technical availability or reliability.
Should any external website be found to link to Connectoma while incorporating inappropriate, defamatory or unlawful content, or content contrary to health or data protection legislation, Connectoma will pursue the appropriate legal actions and formal requests for its immediate removal.
8. Data protection, privacy and cookies
The processing of personal data and the management of storage and data retrieval devices on terminal equipment (cookies) arising from access to and browsing of the Website are governed exclusively by the provisions of our Privacy Policy and our Cookie Policy, directly accessible in the footer of the portal and drafted in strict compliance with the GDPR, the LOPDGDD and the LSSI-CE.
9. Applicable law and competent jurisdiction
These Legal Notice conditions and the relationships arising from them are governed in each and every respect by applicable Spanish law.
At Connectoma we are committed to transparency and collaborative resolution. Before initiating any formal claim, we invite users and centres to contact our management team directly or our DPO (dpd@connectoma.com) to resolve any incident swiftly and directly. Notwithstanding the foregoing, for the resolution of judicial disputes the parties submit to the jurisdiction of the Courts and Tribunals of Madrid.
10. Amendments
Connectoma reserves the right to review, update or modify these terms of use at any time in order to adapt them to legislative, case-law, technical or regulatory developments (particularly those arising from the regulation of AI and medical software).
The amendments introduced will take effect from the moment they are published on the Website. Users are advised to consult this section periodically to know the version in force at any given time, the date of last update of which appears in the heading of this document.
Privacy Policy
Last updated: 17/08/2026
Connectoma Neurotech, S.L. — Public website (www.connectoma.com/en)
At Connectoma, we take the protection of your privacy and the security of your information very seriously. We want you to understand with complete clarity and peace of mind how we process your personal data, what measures we apply to protect your health information and how we guarantee your rights under the European Union General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
1. Who is the controller of your data?
The entity responsible for processing the personal data collected on this website and in our applications is:
- Company name: Connectoma Neurotech, S.L.
- Tax ID (NIF): B70752795
- Registered office: Calle Padilla 26, 2.º, 28006 Madrid, Spain
- Data Protection Officer (DPO): dpd@connectoma.com
2. How do we process your information? (Our roles)
Depending on how you interact with us, we take on different roles to safeguard your privacy:
- When you browse our website or use the mobile app (controller): if you contact us through web forms, subscribe to our news or use our well-being tracking mobile application, Connectoma manages your information directly under the highest guarantees of confidentiality.
- When you receive treatment at a clinic or medical centre (processor): when a medical team uses our clinical support software (ConnectTarget_MDD), the clinic or hospital is the entity responsible for your health record. Connectoma processes only technical images and dissociated information on the direct instruction of the healthcare centre and in order to provide technical support for the treatment.
- Research collaborations (R&D): in research projects with entities such as the Complutense University of Madrid (UCM) or other academic centres, the information used undergoes advanced protection processes (pseudonymization and anonymization), so that it is not possible to re-identify the user.
3. Categories of data processed
We process only the information necessary to offer you the best experience and to guarantee maximum technical accuracy:
- Contact and web browsing data: name, email, telephone and technical browsing data (IP address, access logs).
- Tracking in our mobile application: records of mood, well-being, self-reported symptoms and reminders.
- Neuroimaging data and clinical information (defacing and pseudonymization): magnetic resonance images (MRI/fMRI) and numerical reference codes (without your name or direct ID number). We apply automated algorithms that remove facial features from structural images before they are processed, protecting your visual and personal identity at all times.
- Research and continuous improvement (optional): anonymized or pseudonymized clinical neuroimaging data in order to collaborate with science or audit our systems under the European AI Regulation (EU 2024/1689).
4. Purposes and legal bases
The legal bases and purposes that legitimize the processing of your data under the GDPR are set out below:
| Processing purpose | General legal basis (Art. 6 GDPR) | Special legal basis (Art. 9 GDPR) |
|---|---|---|
| Handling enquiries and incidents on the website | Express consent of the user (Art. 6.1.a) | Explicit consent (Art. 9.2.a) |
| Clinical follow-up in the Mobile App | Explicit consent (Art. 6.1.a) | Explicit consent (Art. 9.2.a) |
| Calculation of therapeutic targets (ConnectTarget_MDD) | Performance of a contract / processing instruction (Art. 6.1.b) | Health care / medical diagnosis (Art. 9.2.h) |
| Retention of the record and continuity of care | Legal obligation (Art. 6.1.c — Spanish Law 41/2002) | Health care (Art. 9.2.h) |
| Scientific research and innovation (R&D) | Modular explicit consent (opt-in) | Explicit consent (Art. 9.2.a) / Spanish Law 14/2007 |
| Marketing and commercial news mailings | Explicit consent (opt-in) | N/A |
| Recommendation and referral to partner clinics | Informed consent of the user | N/A |
| Detection and mitigation of bias in Artificial Intelligence | Legal obligation / public interest | Art. 10.5 AI Regulation (EU 2024/1689) |
Transparency about centre recommendations: please note that Connectoma may receive payment for technology services from the approved clinical centres it recommends, with the user always retaining the ability to object (opt-out).
5. How long do we keep your information?
We keep your data only for as long as necessary to provide you with the service or to comply with legal requirements:
- Web enquiries: until your enquiry is resolved + 1 year (kept in secure reserve for possible follow-up).
- App account: for as long as you keep the application active. You can request the deletion of your account at any time.
- Health record at clinics: in accordance with health legislation (Spanish Law 41/2002), clinical documentation is kept for a minimum of 5 years in the custody of the healthcare centre.
- News and marketing: until you decide to unsubscribe by clicking the cancellation link.
6. Where do we keep your information and who do we share it with?
- We do not sell or trade your data: your personal or health information will never be sold or transferred to commercial third parties.
- European sovereignty and residency: we store and process health databases on servers located in Madrid, Spain (Google Cloud Platform).
- International safeguards: should occasional technical support be required from European technology providers or providers certified under the EU-US Data Privacy Framework (such as Google or Microsoft), the data travels fully encrypted (TLS 1.3 / AES-256) and without data that can directly identify you.
Recipients: processors
In order to provide you with the service we rely on providers that process personal data on Connectoma’s behalf, always under a data processing agreement in accordance with article 28 GDPR and solely on our instructions. We group them by functional category:
- Email service and marketing automation providers (e.g., MailerLite and MailerSend).
- Cloud infrastructure, hosting and database providers (e.g., Vercel, Supabase, Google Cloud and Hostinger, where we host our own instance of the automation tooling).
- Workflow automation and internal management tools (e.g., n8n and Notion).
The names given are representative examples of each category and may change over time. You can request the current list of processors at any time by writing to dpd@connectoma.com.
7. Your rights and how to exercise them
As the data subject, the law grants you full control over your personal information. You can ask us at any time for:
- Access: to know what data of yours we are processing.
- Rectification: to correct inaccurate or outdated information.
- Erasure (right to be forgotten): to request the deletion of your data.
- Objection and restriction: to ask us not to process your data for specific purposes or to limit its use.
- Portability: to receive your information in a structured digital format.
- Human oversight: we guarantee that therapeutic decisions are not taken automatically; they always have the validation of a medical professional.
How to exercise your rights
Send a request by email to our Data Protection Officer at dpd@connectoma.com or by post to Calle Padilla 26, 2.º, 28006 Madrid, attaching a copy of your ID document or equivalent so we can verify your identity. We will respond to your request within a maximum of one month.
If you believe we have not properly addressed your right, you are entitled to lodge a complaint with the Spanish Data Protection Agency (AEPD) through its official website www.aepd.es.
8. Security and protection of your information
At Connectoma we have implemented the highest organizational and technical cybersecurity standards (Privacy by Design):
- Automatic encryption of all communication channels and of stored files.
- Strict access restriction by authorized professional roles.
- Continuous monitoring systems to prevent and react to any incident.
9. Changes to the Privacy Policy
We may update this policy to adapt it to legislative developments or technical improvements in our platforms. Any relevant change will be clearly published on this same website.