PRIVACY POLICY OF HICORA.AI

Privacy Notice for Website, Platform and AI-Assisted Clinical Documentation Services
Version 2.0

Table of contents

  1. Definitions
  2. Personal data controller and processing context
  3. Contact details
  4. Categories of information we process
  5. Purpose, legal basis and retention period
  6. Patient health information and processor role
  7. Data recipients and subprocessors
  8. Transfers to third countries and profiling
  9. Marketing
  10. Cookies and analytics
  11. Security
  12. Data retention and deletion
  13. Rights of the data subject
  14. Regional addenda
  15. Final provisions

1. Definitions

TermMeaning
GDPRRegulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
Personal data controlleran entity that determines the purposes and means of processing personal data, within the meaning of Article 4(7) GDPR.
Processoran entity that processes personal data on behalf of the controller, within the meaning of Article 4(8) GDPR.
Recipientan entity to which personal data are disclosed, within the meaning of Article 4(9) GDPR.
Service or Platformthe hiCora.ai software-as-a-service platform operated by iDocly sp. z o.o., which provides AI-assisted transcription and draft clinical documentation tools for healthcare professionals and healthcare organizations.
Patient Health Informationhealth data, voice recordings, transcripts, draft notes, visit summaries, clinical notes and other patient-related information entered, uploaded, recorded, transcribed or otherwise processed by a User through the Service.
Usera person or organization using the Website or Platform, including healthcare professionals and healthcare organizations.
Regional Addenduma jurisdiction-specific privacy, healthcare, security or data processing document applicable to Users or individuals in a specific territory.
Subprocessora third-party provider engaged by iDocly to process personal data on behalf of iDocly in connection with the Service.

2. Personal data controller and processing context

The controller of personal data related to the operation of the Website, user accounts, subscriptions, billing, marketing, support, security and business communication is iDocly sp. z o.o. with its registered office in Krakow at ul. Bonarka 8, 30-415 Krakow, Poland, entered in the Register of Entrepreneurs of the National Court Register under KRS 0000960776; registry court: District Court in Rzeszow, 12th Commercial Division of the National Court Register; share capital: PLN 6,000; NIP: 8133876161; REGON: 521493568; email: [email protected].

Healthcare professionals and healthcare organizations using the Service are the controllers of Patient Health Information that they enter, upload, record, transcribe or otherwise process through the Service. iDocly processes such Patient Health Information on behalf of the User as a processor/service provider, in accordance with the applicable data processing agreement, Regional Addendum or other contractual documentation.

iDocly does not determine the medical purposes for which Patient Health Information is collected or used by the User. The User is responsible for providing patients with all required notices and obtaining all required consents or authorizations.

If iDocly participates in research, clinical studies or scientific projects, such processing will be governed by separate documentation provided to the relevant participants or organizations.

Joint controllership and independent controller situations

Where we use external authentication, analytics, payment, advertising or communication tools, the relevant third-party provider may act as an independent controller, joint controller or processor depending on the service and legal context. The applicable provider privacy notices and contractual documentation may apply. We avoid using advertising or analytics tools inside Platform areas where Patient Health Information is processed unless configured to prevent access to patient-identifiable information and permitted by applicable law.

3. Contact details

MatterContact
General contact[email protected]
Privacy matters[email protected]
Security incidents[email protected]
Data Protection Officer / privacy contact[email protected]
Postal addressiDocly sp. z o.o., ul. Bonarka 8, 30-415 Krakow, Poland

If the Data Protection Officer address changes or if iDocly has not formally appointed a Data Protection Officer for a specific jurisdiction, privacy requests may still be submitted to [email protected].

4. Categories of information we process

CategoryExamples
Account informationname, email address, organization, role, login credentials, account settings, language, country and user preferences
Professional informationhealthcare profession, organization, license or registration information, where provided or required
Subscription and billing informationplan, invoices, payment status, billing address, tax information, transaction metadata and payment provider identifiers
Patient Health Informationaudio recordings, transcripts, draft documentation, clinical notes, visit summaries and other patient-related information entered by the User
Technical and security informationIP address, device information, browser information, access logs, audit logs, security events, authentication events and system diagnostics
Support informationsupport messages, attachments, communications with iDocly and troubleshooting metadata, excluding Patient Health Information unless the support channel is expressly approved for it
Website and cookie informationcookie identifiers, website analytics, marketing preferences and consent records, subject to applicable consent requirements
Marketing and communication dataemail preferences, newsletter subscriptions, campaign interactions and event registrations
Compliance recordsacceptance logs, document versions accepted, patient consent confirmation events, audit trails and records required to demonstrate compliance

5. Purpose, legal basis and retention period

iDocly may process personal data for the purposes, on the legal bases and for the retention periods described below. Where a Regional Addendum provides stricter or more specific rules, that Regional Addendum applies for the relevant jurisdiction-specific matter.

PurposeExamplesLegal basisRetention
A. Preparation, conclusion and performance of an agreementaccount creation, user onboarding, subscription management, organization administration, provision of the Service, customer communication and supportGDPR Article 6(1)(b): taking steps prior to entering into an agreement and performance of an agreement. GDPR Article 6(1)(f): legitimate interest in processing data of representatives, employees and personnel designated by a healthcare organization.For the period necessary to perform, terminate or otherwise expire the agreement, and thereafter for limitation periods or legal obligations.
B. Charging and settling payments, issuing invoices and accountingpayment processing, invoice issuance, tax documentation, accounting records, payment reconciliation and debt collectionGDPR Article 6(1)(c): compliance with legal obligations, including tax and accounting obligations. GDPR Article 6(1)(f): legitimate interest in payment administration and debt recovery.For the period required by accounting and tax laws, generally 5 years counted from the beginning of the year following approval of the financial statements or as otherwise required.
C. Handling disputes, complaints and pursuing claimscomplaint handling, legal analysis, defense or pursuit of claims, evidence preservation, communication with advisors and authoritiesGDPR Article 6(1)(f): legitimate interest in establishing, pursuing and defending legal claims. GDPR Article 6(1)(b) may also apply where claims relate to performance of an agreement.Until expiry of potential claims or for the period necessary to conduct proceedings, enforce rights or comply with legal duties.
D. Direct marketing to Users and website visitorspromoting iDocly and hiCora.ai services, product updates, newsletters, events, educational materials and commercial communicationsGDPR Article 6(1)(f), where we rely on legitimate interest in B2B marketing. Consent, where required by electronic communications, cookie or marketing laws.Until the data subject objects, withdraws consent, unsubscribes, or the marketing purpose ceases.
E. Ensuring proper functioning of the Website and Platformtechnical operation, session management, login, preferences, security, diagnostics and necessary cookiesGDPR Article 6(1)(f): legitimate interest in operating, securing and maintaining the Website and Platform. GDPR Article 6(1)(b) where necessary to provide the Service.For the period necessary for operation, security and troubleshooting, subject to log retention and limitation periods.
F. Analytics and improvement of the Websitewebsite statistics, traffic analysis, user journey analysis, performance improvement and consent-based analyticsGDPR Article 6(1)(f) for limited necessary analytics where permitted. Consent where required for non-essential analytics cookies or similar technologies.For the duration of the analytics purpose or until objection or withdrawal of consent, subject to cookie duration and retention settings.
G. Security monitoring and fraud preventionaccess logs, audit trails, vulnerability response, account protection, abuse prevention, malware and spam preventionGDPR Article 6(1)(f): legitimate interest in security, fraud prevention, service integrity and protection of Users, patients and iDocly.For the period necessary to secure the Service and investigate incidents, typically in accordance with security log retention policies.
H. Processing Patient Health Information on behalf of Usersrecording, transcription, draft clinical documentation, export, deletion, audit logs and support approved for health informationThe User determines the legal basis as controller. iDocly processes such data as processor/service provider under Article 28 GDPR or applicable equivalent documentation.For the duration of the agreement and according to the applicable data processing agreement, Regional Addendum, backup retention and deletion policy.
I. Legal and regulatory complianceresponding to lawful requests, audits, regulatory obligations, sanctions screening where applicable and mandatory disclosuresGDPR Article 6(1)(c): compliance with legal obligations. GDPR Article 6(1)(f): legitimate interest in compliance and risk management where no direct legal obligation applies.For the period required by law or necessary to demonstrate compliance.
J. Product communication and service noticesservice notices, security alerts, product changes, administrative messages and terms updatesGDPR Article 6(1)(b) where necessary for the agreement. GDPR Article 6(1)(f): legitimate interest in communicating important service information.For the duration of the account or agreement and as needed to prove notification.
K. AI training and product improvementsee the dedicated section belowPatient Health Information is not used to train, fine-tune or improve AI models by default. Any exceptional use requires a separate written agreement and valid legal basis.As defined in the separate written agreement or according to anonymization/de-identification rules and applicable law.

6. Patient health information and processor role

7. Data recipients and subprocessors

Below are categories of recipients and the context in which personal data may be disclosed. Only approved subprocessors may process Patient Health Information.

ContextRecipientsPurpose
Agreement and account administrationIT providers, hosting providers, authentication providers, support tools, email providers, advisors, entities authorized to inspect or audit where applicableaccount setup, authentication, contract performance, customer support and administration
Payments, invoices and accountingpayment providers, banks, accounting providers, legal and tax advisors, debt collection providers where necessarypayment processing, invoicing, accounting, tax compliance and debt recovery
Disputes and claimscourts, public authorities, advisors, auditors, postal or courier providers and IT providershandling claims, complaints, disputes, notices and evidence preservation
Direct marketingemail marketing providers, CRM providers, advertising platforms where consent or legal basis appliesmarketing of iDocly and hiCora.ai services. Patient Health Information is not used for this purpose
Cookies and analyticsanalytics providers, consent management providers, advertising providers where applicable and consentedwebsite analytics, performance measurement and marketing attribution. Platform areas with Patient Health Information must not send patient-identifiable data to these tools
Clinical documentation servicecloud hosting, storage, AI inference, transcription, security and approved support providers listed in the Subprocessor Listhosting, storing, transcribing, generating draft documentation, securing and supporting the Service
Legal compliancepublic authorities, regulators, courts and law enforcement where required or permitted by lawlegal obligations, lawful requests, regulatory duties and compliance

Subprocessor rules

8. Transfers to third countries and profiling

Data may be processed in the European Economic Area and, depending on the User location, selected service configuration and applicable Regional Addenda, in other jurisdictions such as the United States, Australia, Canada or the United Kingdom.

Where personal data are transferred outside the EEA, iDocly relies on appropriate safeguards under GDPR, such as adequacy decisions, standard contractual clauses, data processing agreements or other lawful transfer mechanisms. Details of subprocessors, processing locations and safeguards are provided in the applicable Subprocessor List and Regional Privacy Addendum.

Purpose areaTransfersProfiling
Agreement-related processingMay occur outside the EEA depending on service configuration, authentication provider, support provider and User location.No profiling for contractual decision-making.
Payments and accountingMay involve payment providers and banks in the EEA or other jurisdictions depending on payment method and User location.No profiling for this purpose.
Disputes and claimsMay occur where a party, advisor, authority or court is located outside the EEA.No profiling for this purpose.
Direct marketingMay involve marketing, CRM, analytics or advertising providers outside the EEA where applicable safeguards and consent requirements are met.Marketing profiling may occur only where permitted and subject to consent where required.
Cookies and social toolsMay involve third-party providers outside the EEA depending on cookie consent and provider configuration.Website profiling may occur for analytics or advertising only where permitted.
Patient Health InformationProcessing locations depend on the applicable Subprocessor List, Regional Addendum and service configuration.No patient health profiling for marketing. No autonomous clinical profiling by iDocly for medical decisions.

9. Marketing

10. Cookies and analytics

The Website uses cookies and similar technologies. Cookies are small text files stored on the user device. They may be used to enable Website functionality, remember preferences, improve performance, measure analytics and, where consented, support advertising or marketing.

Cookie typePurposeLegal basis
Necessary cookiesenable page navigation, login, security, session management and core Website functionslegitimate interest or performance of agreement where applicable
Functional/preference cookiesremember choices such as language, region or user settingsconsent where required or legitimate interest where permitted
Analytics/performance cookiesunderstand how the Website is used and improve performanceconsent where required for non-essential analytics
Advertising/marketing/social cookiesmeasure ads, personalize ads, connect social media features and evaluate campaign effectivenessconsent where required

Non-essential cookies, including analytics, advertising, personalization and social media cookies, are used only where the User has provided consent through the cookie banner or consent management tool, unless applicable law allows another legal basis. The User may withdraw or change cookie consent at any time through the cookie settings available on the Website.

We do not use advertising, analytics or retargeting tools inside areas of the Platform where Patient Health Information is processed, unless such tools are configured to prevent access to patient-identifiable information and are permitted under applicable law. Patient Health Information must not be included in analytics events, advertising pixels, URLs, page titles, logs or tracking parameters.

The Website may use analytics tools such as Google Analytics or similar services to compile statistics and analyze Website traffic. Where such tools use non-essential cookies, they are enabled only in accordance with applicable consent requirements.

11. Security

12. Data retention and deletion

We retain personal data only for as long as necessary for the purposes described in this Policy, unless a longer period is required or permitted by law, contract, Regional Addendum or legitimate business need.

Data typeTypical retention approach
Account and subscription datafor the duration of the account or agreement and thereafter for limitation periods and legal obligations
Billing and accounting datafor periods required by tax and accounting laws, generally 5 years as applicable
Support communicationsfor the period necessary to handle the request and maintain evidence of support, security and quality actions
Security logs and audit logsfor the period necessary to secure the Service, investigate incidents and demonstrate compliance
Patient Health Informationaccording to the applicable agreement, data processing documentation, Regional Addendum, backup retention and deletion policy
Marketing datauntil objection, withdrawal of consent, unsubscribe or cessation of marketing purpose
Cookie dataaccording to cookie duration, consent settings and provider configuration

After termination of the Service, Patient Health Information is deleted or returned according to the applicable agreement or Regional Addendum. Backup copies may remain for a limited period according to backup retention cycles. The User remains responsible for maintaining medical records required by applicable law.

13. Rights of the data subject

Depending on the purpose and legal basis, the data subject may have the following rights under the GDPR:

How to exercise rights

To exercise rights, contact [email protected]. Fulfilment of a request may require identity verification. Where a request concerns Patient Health Information processed on behalf of a User, iDocly may direct the request to the User or act according to the User instructions, because the User is normally the controller of such data.

Necessity of providing data

14. Regional addenda

If the User is located outside the EEA or processes information of individuals located outside the EEA, additional regional terms may apply. These may include U.S. HIPAA documentation, Australian privacy documentation, Canadian privacy documentation or other jurisdiction-specific privacy, healthcare or security terms.

In case of conflict between this Policy and an applicable Regional Addendum, the Regional Addendum prevails solely with respect to jurisdiction-specific privacy, healthcare, data protection, security or regulatory matters.

15. Final provisions

The Website may contain links to other websites. This Privacy Policy applies only to the Website and Platform operated by iDocly. After moving to another website, users should read the privacy policy of that website.

iDocly may update this Privacy Policy from time to time, including due to changes in law, Service functionality, subprocessors, security measures, international transfers, cookies or business operations. The current version will be made available on the Website or Platform.

For questions about this Privacy Policy, contact [email protected].