Security

How we protect clinical data in Notefree

1

1. Security by design

Security and privacy are built into Notefree from day one. Our architecture is designed for healthcare use with strict controls, minimisation of data, and predictable deletion.

2

2. Data residency (EEA)

All processing and storage occur within the European Economic Area (EEA). Your data does not leave the EEA.

3

3. Audio handling

Ambient AI audio is processed in small, real‑time chunks. Each chunk is deleted immediately after processing. A full recording is never stored on our servers.

4

4. Encryption and access control

  • Encryption in transit (TLS) and at rest.
  • Role‑based access with least‑privilege enforcement.
  • Audit logging and monitoring for suspicious activity.
5

5. Retention and deletion

Clinical notes and transcripts are stored temporarily and deleted automatically after 24 hours. After deletion, the data is unrecoverable.

6

6. No model training on clinical data

Clinical inputs are not used to train models.

7

7. Incident response

We maintain incident response processes and will notify relevant authorities and customers as required by law.

8

8. Contact