Security
How we protect clinical data in Notefree
1. Security by design
Security and privacy are built into Notefree from day one. Our architecture is designed for healthcare use with strict controls, minimisation of data, and predictable deletion.
2. Data residency (EEA)
All processing and storage occur within the European Economic Area (EEA). Your data does not leave the EEA.
3. Audio handling
Ambient AI audio is processed in small, real‑time chunks. Each chunk is deleted immediately after processing. A full recording is never stored on our servers.
4. Encryption and access control
- Encryption in transit (TLS) and at rest.
- Role‑based access with least‑privilege enforcement.
- Audit logging and monitoring for suspicious activity.
5. Retention and deletion
Clinical notes and transcripts are stored temporarily and deleted automatically after 24 hours. After deletion, the data is unrecoverable.
6. No model training on clinical data
Clinical inputs are not used to train models.
7. Incident response
We maintain incident response processes and will notify relevant authorities and customers as required by law.
8. Contact
- Security and privacy inquiries: [email protected]