PRIVACY POLICY
Privacy Policy
Edith Care – Jobello Technology AB
Last updated: 24 July 2026
01
Introduction
Edith Care is provided by Jobello Technology AB, a company registered in Sweden under company registration number 559311-6907 (“Edith Care”, “we”, “us” or “our”). We take the protection of your personal data extremely seriously. This privacy policy describes how we collect, process, store and protect personal data when you use our service.
Edith Care is an AI-based documentation service that helps clinical staff transcribe clinical conversations and create draft clinical documentation. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where applicable, the EU GDPR.
This policy applies to the processing of personal data where Edith Care acts as controller — that is, data about you as a user of the Service. For the processing of patient data, where we act as processor, please refer to the data processing agreement (DPA) entered into with each customer. Our standard UK DPA is published here: Data Processing Agreement (PDF).
02
Controller
Jobello Technology AB (Edith Care)
Company registration number: 559311-6907
Registered in Sweden
fredrik[at]edithcare[dot]se
We are in the process of appointing a UK representative under Article 27 of the UK GDPR. Their contact details will be published here once the appointment is complete. Until then, please direct all enquiries to us at the address above.
03
What personal data do we collect?
Data you provide to us
| Category | Examples | Purpose |
|---|---|---|
| Identity data | Name, username | Account administration |
| Contact data | Email address | Communication, login |
| Account data | Password (encrypted), role, organization | Authentication, access control |
| User-generated content | Reports, templates, notes | Providing the Service |
| Enquiry data | Name, email, phone, organization and your message when you book a demo, request an account or ask for a quote — including the assumptions you enter in our savings calculator | Responding to your enquiry |
Data we collect automatically
| Category | Examples | Purpose |
|---|---|---|
| Technical data | IP address, browser type, operating system | Security, troubleshooting |
| Login logs | Time, successful/failed logins | Security monitoring, legal requirements |
| Usage data | Page views, feature usage | Product improvement |
Patient data (processor)
When you use Edith Care to transcribe clinical conversations and create draft clinical documentation, we process patient data as a processor on behalf of your organization (the controller). This processing is governed by the separate data processing agreement and covers:
- •Audio recordings of clinical conversations
- •Transcripts with speaker identification
- •Draft clinical documentation and reports created in the Service
- •Document attachments (PDF, DOCX) uploaded for AI context
Patient data is never used to train, improve or further develop AI models. All processing currently takes place within the EU/EEA.
04
How do we collect personal data?
- •Directly — when you create an account, log in, or contact us.
- •Automatically — technical data collected when you use the Service (see section 7 on cookies and tracking).
- •From your organization — your employer or principal may provide data when setting up accounts.
05
Legal basis for processing
| Processing | Legal basis | Provision |
|---|---|---|
| Account administration and authentication | Performance of a contract | Art. 6(1)(b) UK GDPR |
| Security logging and access tracking | Legitimate interests | Art. 6(1)(f) UK GDPR |
| Product analytics and improvement | Legitimate interests | Art. 6(1)(f) UK GDPR |
| Customer communication and support | Performance of a contract | Art. 6(1)(b) UK GDPR |
| Responding to demo, account and quote requests | Steps taken at your request prior to entering into a contract | Art. 6(1)(b) UK GDPR |
| Traceability supporting our customers' regulatory obligations | Legitimate interests | Art. 6(1)(f) UK GDPR |
Patient data is different: we process it only as a processor, on our customers’ documented instructions. The customer, as controller, determines the lawful basis — for health data, Article 9(2)(h) UK GDPR together with paragraph 2 of Schedule 1, Part 1 of the Data Protection Act 2018 — and our obligations are set out in the data processing agreement.
06
How we use your data
- •Providing the Service — creating and managing your account, authenticating logins, providing AI-assisted transcription and documentation.
- •Ensuring security — logging access, detecting unauthorized use, protecting against fraud and intrusion.
- •Meeting legal obligations — complying with logging and traceability requirements under applicable data protection and healthcare legislation.
- •Improving the Service — analysing pseudonymized and aggregated usage data to optimize the user experience.
- •Communicating with you — sending service information, security notices and support.
07
Cookies and tracking
This section explains what we store on your device and why, as required by the Privacy and Electronic Communications Regulations (PECR) and the UK GDPR.
Essential cookies
Edith Care uses technically necessary cookies for authentication and session management. These are required for the Service to function and do not require consent.
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Login and authentication | 8 hours |
Analytics
We use one EU-hosted, privacy-preserving product analytics tool (PostHog, hosted in the EU) to understand how our website and Service are used. It is configured with the following privacy settings:
- •EU hosting — analytics data is processed on servers within the EU.
- •Nothing is stored on your device — no analytics cookies and no browser storage; the product analytics tool runs in a memory-only mode that writes nothing to your device.
- •Respects "Do Not Track" — if your browser has DNT enabled, no product analytics data is collected.
- •Session recording is switched off — we do not record or replay your screen, mouse movements or keystrokes.
- •IP addresses are not used to build profiles, and we never link analytics data to patient data.
Usage data is pseudonymized before it is processed for product analytics. Aggregated statistics that cannot be linked to individual users are processed anonymously. You can object to product analytics collection at any time by enabling “Do Not Track” in your browser.
Performance measurement
We use anonymized performance measurements to measure page load times and web performance. These measurements do not identify individual users.
08
Sharing and third-party processing
We never sell your personal data. We share data with the following categories of recipients, solely for the purpose of providing the Service.
Categories of sub-processors
We engage sub-processors in the following categories. All are bound by data processing agreements (DPAs) in accordance with applicable data protection law. A complete list of named sub-processors is provided as a schedule to the DPA with each customer.
| Category | Purpose | Data centre location |
|---|---|---|
| Cloud infrastructure and storage | Operating the Service, data storage, file handling | Sweden / EU |
| Database management | Storing user accounts, reports and metadata | EU |
| AI text processing | Generating and editing draft clinical documentation | Sweden |
| Speech transcription | Converting speech to text with speaker identification | Sweden / EU |
| Observability and troubleshooting | Monitoring AI usage and system performance | EU |
| Product analytics | Pseudonymized and aggregated usage statistics | EU |
| Web hosting and delivery | Making the Service available via the internet | EU (Stockholm) |
| Email delivery | Sending the emails generated by our website forms | EU (Ireland); provider is US-established — see international transfers below |
| Business email | Receiving and storing enquiries from our website | EU |
A named list of all sub-processors, including the processing location for each, is provided as a schedule to the data processing agreement — see Annex 2 of our UK DPA (PDF).
AI processing
All AI processing takes place within the EU/EEA. We use established AI service providers for text processing and speech transcription.
- •No personal data or patient data is used to train, improve or further develop AI models.
- •The content of transcripts and AI responses is not stored in our monitoring systems. Anonymized metrics (response times, token counts, error codes) are logged for troubleshooting and quality assurance.
- •All data transfer is encrypted via TLS 1.3.
Other recipients
We may disclose personal data where required by law, regulation or an order of a competent authority, to protect our or others’ rights and safety, or in connection with a business transfer (with prior notice to affected data subjects).
09
Data storage and location
Storage locations
| Data type | Storage location | Encryption |
|---|---|---|
| User accounts and metadata | Database service within the EU | AES-256 at rest, TLS in transit |
| Reports and draft clinical documentation | Database service within the EU | AES-256 at rest, TLS in transit |
| Audio files and recordings | Cloud storage in Sweden | AES-256 at rest, TLS in transit |
| Document attachments | Cloud storage in Sweden | AES-256 at rest, TLS in transit |
| Access logs | Database service within the EU | AES-256 at rest, TLS in transit |
International transfers
All patient data is stored and processed exclusively within the EU/EEA. Transfers from the UK to the EEA are covered by the UK Government’s adequacy regulations for the EEA, and transfers from the EU to the UK are covered by the European Commission’s adequacy decision. For those flows, no additional transfer safeguards (such as SCCs or the IDTA) are required.
One exception applies to contact details you send us through our website forms: our email delivery provider sends from EU infrastructure (Ireland), but the provider is established in the United States and its data processing agreement provides for processing in the US under standard contractual clauses. This affects enquiry data only — never patient data, which never leaves the EU/EEA.
When delivering web pages, static assets may be distributed via a CDN with nodes outside the UK and EU. These assets contain no personal data. To the extent such distribution technically constitutes a restricted transfer, we ensure appropriate safeguards are in place in accordance with the UK GDPR and Chapter V of the EU GDPR.
10
Retention
| Data | Retention period | Reason |
|---|---|---|
| Account data | While the account is active + 30 days after closure | Contract, legal requirements |
| Login logs | 12 months | Security, legal retention obligations |
| Audio recordings | Deleted after successful transcription; backup copies, created only if real-time transcription is unavailable, are deleted automatically within about 8 days | Data minimization |
| Transcripts | While the report exists in the Service | Contract |
| Draft clinical documentation | Deleted within 30 days of contract expiry | Contract |
| Analytics data | Pseudonymized, max 24 months | Legitimate interests |
| Enquiry data from our website forms | Kept in our business email for as long as needed to handle your enquiry and any resulting customer relationship, and in any event deleted no later than 24 months after our last contact with you — or earlier on request | Pre-contractual steps |
On expiry of the contract, all customer data is permanently deleted or returned within 30 days, in accordance with the customer’s instructions.
11
Security
- •Encryption: AES-256 at rest, TLS 1.3 in transit.
- •Authentication: individual user accounts with encrypted passwords (bcrypt).
- •Access control: role-based permission model.
- •Logging: complete tracking of logins and data access.
- •Incident management: documented process for handling personal data breaches, including notification duties under applicable data protection law.
- •Automatic session management: sessions expire after 8 hours.
- •Infrastructure: the Service runs in EU/EEA data centres, primarily Sweden (Microsoft Azure Sweden Central), operated by a cloud provider holding ISO 27001 and SOC 2 certifications.
12
Your rights
As a data subject, you have the following rights under the UK GDPR:
| Access (Art. 15) | You have the right to request a copy of the personal data we process about you. |
| Rectification (Art. 16) | You have the right to request correction of inaccurate or incomplete data. |
| Erasure (Art. 17) | You have the right to request deletion of your personal data ("the right to be forgotten"), subject to legal obligations. |
| Restriction (Art. 18) | You have the right to request that the processing of your data be restricted. |
| Data portability (Art. 20) | You have the right to receive your personal data in a structured, machine-readable format. |
| Objection (Art. 21) | You have the right to object to processing based on legitimate interests. |
| Withdraw consent (Art. 7(3)) | Where processing is based on consent, you have the right to withdraw it at any time. |
How to exercise your rights
Contact us at fredrik[at]edithcare[dot]se with your request. We respond within one month, as required by the UK GDPR. If your request is complex, we may extend this by up to a further two months and will tell you if we do. We may need to verify your identity before processing the request.
Complaints
If you believe we are processing your personal data in breach of the UK GDPR, you have the right to lodge a complaint with:
Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
0303 123 1113
ico.org.uk
The ICO is the competent authority for complaints under the UK GDPR. Where your data is processed under the EU/EEA GDPR, you may instead lodge a complaint with the Swedish Authority for Privacy Protection (IMY, imy.se), our lead supervisory authority in the EU.
13
Third-party links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these parties. We recommend that you read their respective privacy policies.
14
Children
The Service is not directed at persons under 18. We do not knowingly collect personal data from children. If we discover that we have collected such data, we delete it immediately.
15
Changes to this policy
We may update this privacy policy. In the event of material changes, we will notify you by email or through a notice in the Service at least 30 days in advance. The latest version is always available at edithcare.uk/privacy-policy.
16
Contact us
Do you have questions about this privacy policy or about how we process your personal data?
Edith Care (Jobello Technology AB)
Company registration number: 559311-6907
fredrik[at]edithcare[dot]se
This privacy policy applies from 24 July 2026.