Privacy Notice for Website, Platform and AI-Assisted Clinical Documentation Services
Version 2.0
| Term | Meaning |
|---|---|
| GDPR | Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016. |
| Personal data controller | an entity that determines the purposes and means of processing personal data, within the meaning of Article 4(7) GDPR. |
| Processor | an entity that processes personal data on behalf of the controller, within the meaning of Article 4(8) GDPR. |
| Recipient | an entity to which personal data are disclosed, within the meaning of Article 4(9) GDPR. |
| Service or Platform | the hiCora.ai software-as-a-service platform operated by iDocly sp. z o.o., which provides AI-assisted transcription and draft clinical documentation tools for healthcare professionals and healthcare organizations. |
| Patient Health Information | health data, voice recordings, transcripts, draft notes, visit summaries, clinical notes and other patient-related information entered, uploaded, recorded, transcribed or otherwise processed by a User through the Service. |
| User | a person or organization using the Website or Platform, including healthcare professionals and healthcare organizations. |
| Regional Addendum | a jurisdiction-specific privacy, healthcare, security or data processing document applicable to Users or individuals in a specific territory. |
| Subprocessor | a third-party provider engaged by iDocly to process personal data on behalf of iDocly in connection with the Service. |
The controller of personal data related to the operation of the Website, user accounts, subscriptions, billing, marketing, support, security and business communication is iDocly sp. z o.o. with its registered office in Krakow at ul. Bonarka 8, 30-415 Krakow, Poland, entered in the Register of Entrepreneurs of the National Court Register under KRS 0000960776; registry court: District Court in Rzeszow, 12th Commercial Division of the National Court Register; share capital: PLN 6,000; NIP: 8133876161; REGON: 521493568; email: [email protected].
Healthcare professionals and healthcare organizations using the Service are the controllers of Patient Health Information that they enter, upload, record, transcribe or otherwise process through the Service. iDocly processes such Patient Health Information on behalf of the User as a processor/service provider, in accordance with the applicable data processing agreement, Regional Addendum or other contractual documentation.
iDocly does not determine the medical purposes for which Patient Health Information is collected or used by the User. The User is responsible for providing patients with all required notices and obtaining all required consents or authorizations.
If iDocly participates in research, clinical studies or scientific projects, such processing will be governed by separate documentation provided to the relevant participants or organizations.
Where we use external authentication, analytics, payment, advertising or communication tools, the relevant third-party provider may act as an independent controller, joint controller or processor depending on the service and legal context. The applicable provider privacy notices and contractual documentation may apply. We avoid using advertising or analytics tools inside Platform areas where Patient Health Information is processed unless configured to prevent access to patient-identifiable information and permitted by applicable law.
| Matter | Contact |
|---|---|
| General contact | [email protected] |
| Privacy matters | [email protected] |
| Security incidents | [email protected] |
| Data Protection Officer / privacy contact | [email protected] |
| Postal address | iDocly sp. z o.o., ul. Bonarka 8, 30-415 Krakow, Poland |
If the Data Protection Officer address changes or if iDocly has not formally appointed a Data Protection Officer for a specific jurisdiction, privacy requests may still be submitted to [email protected].
| Category | Examples |
|---|---|
| Account information | name, email address, organization, role, login credentials, account settings, language, country and user preferences |
| Professional information | healthcare profession, organization, license or registration information, where provided or required |
| Subscription and billing information | plan, invoices, payment status, billing address, tax information, transaction metadata and payment provider identifiers |
| Patient Health Information | audio recordings, transcripts, draft documentation, clinical notes, visit summaries and other patient-related information entered by the User |
| Technical and security information | IP address, device information, browser information, access logs, audit logs, security events, authentication events and system diagnostics |
| Support information | support messages, attachments, communications with iDocly and troubleshooting metadata, excluding Patient Health Information unless the support channel is expressly approved for it |
| Website and cookie information | cookie identifiers, website analytics, marketing preferences and consent records, subject to applicable consent requirements |
| Marketing and communication data | email preferences, newsletter subscriptions, campaign interactions and event registrations |
| Compliance records | acceptance logs, document versions accepted, patient consent confirmation events, audit trails and records required to demonstrate compliance |
iDocly may process personal data for the purposes, on the legal bases and for the retention periods described below. Where a Regional Addendum provides stricter or more specific rules, that Regional Addendum applies for the relevant jurisdiction-specific matter.
| Purpose | Examples | Legal basis | Retention |
|---|---|---|---|
| A. Preparation, conclusion and performance of an agreement | account creation, user onboarding, subscription management, organization administration, provision of the Service, customer communication and support | GDPR Article 6(1)(b): taking steps prior to entering into an agreement and performance of an agreement. GDPR Article 6(1)(f): legitimate interest in processing data of representatives, employees and personnel designated by a healthcare organization. | For the period necessary to perform, terminate or otherwise expire the agreement, and thereafter for limitation periods or legal obligations. |
| B. Charging and settling payments, issuing invoices and accounting | payment processing, invoice issuance, tax documentation, accounting records, payment reconciliation and debt collection | GDPR Article 6(1)(c): compliance with legal obligations, including tax and accounting obligations. GDPR Article 6(1)(f): legitimate interest in payment administration and debt recovery. | For the period required by accounting and tax laws, generally 5 years counted from the beginning of the year following approval of the financial statements or as otherwise required. |
| C. Handling disputes, complaints and pursuing claims | complaint handling, legal analysis, defense or pursuit of claims, evidence preservation, communication with advisors and authorities | GDPR Article 6(1)(f): legitimate interest in establishing, pursuing and defending legal claims. GDPR Article 6(1)(b) may also apply where claims relate to performance of an agreement. | Until expiry of potential claims or for the period necessary to conduct proceedings, enforce rights or comply with legal duties. |
| D. Direct marketing to Users and website visitors | promoting iDocly and hiCora.ai services, product updates, newsletters, events, educational materials and commercial communications | GDPR Article 6(1)(f), where we rely on legitimate interest in B2B marketing. Consent, where required by electronic communications, cookie or marketing laws. | Until the data subject objects, withdraws consent, unsubscribes, or the marketing purpose ceases. |
| E. Ensuring proper functioning of the Website and Platform | technical operation, session management, login, preferences, security, diagnostics and necessary cookies | GDPR Article 6(1)(f): legitimate interest in operating, securing and maintaining the Website and Platform. GDPR Article 6(1)(b) where necessary to provide the Service. | For the period necessary for operation, security and troubleshooting, subject to log retention and limitation periods. |
| F. Analytics and improvement of the Website | website statistics, traffic analysis, user journey analysis, performance improvement and consent-based analytics | GDPR Article 6(1)(f) for limited necessary analytics where permitted. Consent where required for non-essential analytics cookies or similar technologies. | For the duration of the analytics purpose or until objection or withdrawal of consent, subject to cookie duration and retention settings. |
| G. Security monitoring and fraud prevention | access logs, audit trails, vulnerability response, account protection, abuse prevention, malware and spam prevention | GDPR Article 6(1)(f): legitimate interest in security, fraud prevention, service integrity and protection of Users, patients and iDocly. | For the period necessary to secure the Service and investigate incidents, typically in accordance with security log retention policies. |
| H. Processing Patient Health Information on behalf of Users | recording, transcription, draft clinical documentation, export, deletion, audit logs and support approved for health information | The User determines the legal basis as controller. iDocly processes such data as processor/service provider under Article 28 GDPR or applicable equivalent documentation. | For the duration of the agreement and according to the applicable data processing agreement, Regional Addendum, backup retention and deletion policy. |
| I. Legal and regulatory compliance | responding to lawful requests, audits, regulatory obligations, sanctions screening where applicable and mandatory disclosures | GDPR Article 6(1)(c): compliance with legal obligations. GDPR Article 6(1)(f): legitimate interest in compliance and risk management where no direct legal obligation applies. | For the period required by law or necessary to demonstrate compliance. |
| J. Product communication and service notices | service notices, security alerts, product changes, administrative messages and terms updates | GDPR Article 6(1)(b) where necessary for the agreement. GDPR Article 6(1)(f): legitimate interest in communicating important service information. | For the duration of the account or agreement and as needed to prove notification. |
| K. AI training and product improvement | see the dedicated section below | Patient Health Information is not used to train, fine-tune or improve AI models by default. Any exceptional use requires a separate written agreement and valid legal basis. | As defined in the separate written agreement or according to anonymization/de-identification rules and applicable law. |
Below are categories of recipients and the context in which personal data may be disclosed. Only approved subprocessors may process Patient Health Information.
| Context | Recipients | Purpose |
|---|---|---|
| Agreement and account administration | IT providers, hosting providers, authentication providers, support tools, email providers, advisors, entities authorized to inspect or audit where applicable | account setup, authentication, contract performance, customer support and administration |
| Payments, invoices and accounting | payment providers, banks, accounting providers, legal and tax advisors, debt collection providers where necessary | payment processing, invoicing, accounting, tax compliance and debt recovery |
| Disputes and claims | courts, public authorities, advisors, auditors, postal or courier providers and IT providers | handling claims, complaints, disputes, notices and evidence preservation |
| Direct marketing | email marketing providers, CRM providers, advertising platforms where consent or legal basis applies | marketing of iDocly and hiCora.ai services. Patient Health Information is not used for this purpose |
| Cookies and analytics | analytics providers, consent management providers, advertising providers where applicable and consented | website analytics, performance measurement and marketing attribution. Platform areas with Patient Health Information must not send patient-identifiable data to these tools |
| Clinical documentation service | cloud hosting, storage, AI inference, transcription, security and approved support providers listed in the Subprocessor List | hosting, storing, transcribing, generating draft documentation, securing and supporting the Service |
| Legal compliance | public authorities, regulators, courts and law enforcement where required or permitted by law | legal obligations, lawful requests, regulatory duties and compliance |
Data may be processed in the European Economic Area and, depending on the User location, selected service configuration and applicable Regional Addenda, in other jurisdictions such as the United States, Australia, Canada or the United Kingdom.
Where personal data are transferred outside the EEA, iDocly relies on appropriate safeguards under GDPR, such as adequacy decisions, standard contractual clauses, data processing agreements or other lawful transfer mechanisms. Details of subprocessors, processing locations and safeguards are provided in the applicable Subprocessor List and Regional Privacy Addendum.
| Purpose area | Transfers | Profiling |
|---|---|---|
| Agreement-related processing | May occur outside the EEA depending on service configuration, authentication provider, support provider and User location. | No profiling for contractual decision-making. |
| Payments and accounting | May involve payment providers and banks in the EEA or other jurisdictions depending on payment method and User location. | No profiling for this purpose. |
| Disputes and claims | May occur where a party, advisor, authority or court is located outside the EEA. | No profiling for this purpose. |
| Direct marketing | May involve marketing, CRM, analytics or advertising providers outside the EEA where applicable safeguards and consent requirements are met. | Marketing profiling may occur only where permitted and subject to consent where required. |
| Cookies and social tools | May involve third-party providers outside the EEA depending on cookie consent and provider configuration. | Website profiling may occur for analytics or advertising only where permitted. |
| Patient Health Information | Processing locations depend on the applicable Subprocessor List, Regional Addendum and service configuration. | No patient health profiling for marketing. No autonomous clinical profiling by iDocly for medical decisions. |
The Website uses cookies and similar technologies. Cookies are small text files stored on the user device. They may be used to enable Website functionality, remember preferences, improve performance, measure analytics and, where consented, support advertising or marketing.
| Cookie type | Purpose | Legal basis |
|---|---|---|
| Necessary cookies | enable page navigation, login, security, session management and core Website functions | legitimate interest or performance of agreement where applicable |
| Functional/preference cookies | remember choices such as language, region or user settings | consent where required or legitimate interest where permitted |
| Analytics/performance cookies | understand how the Website is used and improve performance | consent where required for non-essential analytics |
| Advertising/marketing/social cookies | measure ads, personalize ads, connect social media features and evaluate campaign effectiveness | consent where required |
Non-essential cookies, including analytics, advertising, personalization and social media cookies, are used only where the User has provided consent through the cookie banner or consent management tool, unless applicable law allows another legal basis. The User may withdraw or change cookie consent at any time through the cookie settings available on the Website.
We do not use advertising, analytics or retargeting tools inside areas of the Platform where Patient Health Information is processed, unless such tools are configured to prevent access to patient-identifiable information and are permitted under applicable law. Patient Health Information must not be included in analytics events, advertising pixels, URLs, page titles, logs or tracking parameters.
The Website may use analytics tools such as Google Analytics or similar services to compile statistics and analyze Website traffic. Where such tools use non-essential cookies, they are enabled only in accordance with applicable consent requirements.
We retain personal data only for as long as necessary for the purposes described in this Policy, unless a longer period is required or permitted by law, contract, Regional Addendum or legitimate business need.
| Data type | Typical retention approach |
|---|---|
| Account and subscription data | for the duration of the account or agreement and thereafter for limitation periods and legal obligations |
| Billing and accounting data | for periods required by tax and accounting laws, generally 5 years as applicable |
| Support communications | for the period necessary to handle the request and maintain evidence of support, security and quality actions |
| Security logs and audit logs | for the period necessary to secure the Service, investigate incidents and demonstrate compliance |
| Patient Health Information | according to the applicable agreement, data processing documentation, Regional Addendum, backup retention and deletion policy |
| Marketing data | until objection, withdrawal of consent, unsubscribe or cessation of marketing purpose |
| Cookie data | according to cookie duration, consent settings and provider configuration |
After termination of the Service, Patient Health Information is deleted or returned according to the applicable agreement or Regional Addendum. Backup copies may remain for a limited period according to backup retention cycles. The User remains responsible for maintaining medical records required by applicable law.
Depending on the purpose and legal basis, the data subject may have the following rights under the GDPR:
To exercise rights, contact [email protected]. Fulfilment of a request may require identity verification. Where a request concerns Patient Health Information processed on behalf of a User, iDocly may direct the request to the User or act according to the User instructions, because the User is normally the controller of such data.
If the User is located outside the EEA or processes information of individuals located outside the EEA, additional regional terms may apply. These may include U.S. HIPAA documentation, Australian privacy documentation, Canadian privacy documentation or other jurisdiction-specific privacy, healthcare or security terms.
In case of conflict between this Policy and an applicable Regional Addendum, the Regional Addendum prevails solely with respect to jurisdiction-specific privacy, healthcare, data protection, security or regulatory matters.
The Website may contain links to other websites. This Privacy Policy applies only to the Website and Platform operated by iDocly. After moving to another website, users should read the privacy policy of that website.
iDocly may update this Privacy Policy from time to time, including due to changes in law, Service functionality, subprocessors, security measures, international transfers, cookies or business operations. The current version will be made available on the Website or Platform.
For questions about this Privacy Policy, contact [email protected].