In short: ClinLog ICU processes only the data needed to deliver the service. Patient-identifying details are removed as a fixed first step before any note is processed or stored. All processing runs on EU infrastructure, and you can access or delete your data at any time.
1. Data controller
ClinLog ICU is developed and operated by Clin-Log ApS, Denmark.
Data protection enquiries: pott@clinlog.dk
2. Who can use ClinLog ICU
ClinLog ICU is intended solely for trained healthcare professionals with clinical experience. Access requires manual approval. The tool assists the documentation of ward rounds but does not replace clinical judgement. The final assessment and the recorded note are always your responsibility.
3. What data is processed
3.1 Account information
- Email address and name on sign-up, used solely for authentication and approval.
- Approval status (pending, approved or rejected).
3.2 Clinical data from the health record
- Current patient data that you pull from the electronic health record via a tailored Smartphrase, without patient-identifying information.
- This data serves as context during dictation and is structured into your department's note format.
3.3 Dictation and structured notes
- The audio and transcript of your dictation are used to produce the structured note. Audio is not stored as an audio file after transcription.
- The structured note is shown for your review before you copy it into the patient record yourself.
3.4 Usage data
- Timestamps for creating and editing notes. No behavioural analytics, advertising or tracking.
4. Anonymisation first
Patient-identifying details (names, dates, place names and so on) are removed automatically before any note is processed or stored. Anonymisation is a fixed first step, not an option. ClinLog does not collect personal ID numbers or other direct identifiers.
5. Structuring and data processors
Speech structuring is powered by Corti, a clinical AI platform purpose-built for medical documentation. Personally identifiable information is never sent for structuring.
We use the following sub-processors:
- Corti (transcription and structuring), anonymised data only. Data processing agreement in place.
- Supabase Inc. (database and authentication), EU Standard Contractual Clauses.
6. Storage and security
- Hosting: All processing and storage take place on infrastructure within the EU/EEA under data processing agreements built for healthcare.
- Encryption: All data in transit uses TLS. Data at rest is encrypted.
- Access control: Row Level Security ensures you can only access your own data.
- Retention: Notes are never stored longer than necessary. On account deletion, all your data is deleted within 30 days.
7. Data sharing
We never share your data with third parties for commercial purposes, and there is no public sharing in ClinLog ICU. All notes are private and accessible only to you.
8. Your rights (GDPR)
You have the right to:
- Access: receive a copy of the data we hold about you.
- Rectification: have inaccurate information corrected.
- Erasure: have your account and all associated data deleted.
- Portability: receive your data in a common format.
- Objection: object to the processing of your data.
Send your request to pott@clinlog.dk. We respond within 30 days. You may also complain to the UK Information Commissioner's Office (ICO).
9. Microphone and device access
The microphone is used solely for dictation, when you start a recording yourself. No background recording takes place.
10. Cookies
ClinLog ICU uses only functionally necessary cookies and local storage (a session token for authentication). We do not use tracking, analytics or marketing cookies.
11. Demo on clinlog.dk
The demo at clinlog.dk/demo is for fictional cases only. Nothing you say is stored. Audio and transcript are deleted immediately after the session.
12. Changes to this policy
Material changes are announced at least 14 days before they take effect. The latest version is always available at clinlog.dk/en/privacy.
13. Contact
Questions about data security or personal data: pott@clinlog.dk