PRIVACY POLICY
Privacy Policy
Edith Care – Jobello Technology AB
Last updated: 24 July 2026
01
Introduction
Edith Care is provided by Jobello Technology AB, a company registered in Sweden under company registration number 559311-6907 (“Edith Care”, “we”, “us” or “our”). We take the protection of your personal data extremely seriously. This privacy policy describes how we collect, process, store and protect personal data when you use our service.
Edith Care is an AI-based documentation service that helps clinical staff transcribe clinical conversations and create draft clinical documentation. We are a Swedish company and process personal data in accordance with the EU General Data Protection Regulation (GDPR) — one of the strictest privacy regimes in the world — and, where applicable, US state privacy laws. Edith Care is preparing for a US launch; see section 9 for how this affects data location and health information.
This policy applies to the processing of personal data where Edith Care acts as controller — that is, data about you as a user of the Service. For the processing of patient data, where we act as processor (and, for US customers handling protected health information, as a business associate once BAAs are in place), please refer to the data processing agreement (DPA) entered into with each customer, which we provide as part of onboarding.
02
Controller
Jobello Technology AB (Edith Care)
Company registration number: 559311-6907
Registered in Sweden
fredrik[at]edithcare[dot]se
03
What personal data do we collect?
Data you provide to us
| Category | Examples | Purpose |
|---|---|---|
| Identity data | Name, username | Account administration |
| Contact data | Email address | Communication, login |
| Account data | Password (encrypted), role, organization | Authentication, access control |
| User-generated content | Reports, templates, notes | Providing the Service |
| Enquiry data | Name, email, phone, organization and your message when you book a demo, request an account or ask for a quote — including the assumptions you enter in our savings calculator | Responding to your enquiry |
Data we collect automatically
| Category | Examples | Purpose |
|---|---|---|
| Technical data | IP address, browser type, operating system | Security, troubleshooting |
| Login logs | Time, successful/failed logins | Security monitoring, legal requirements |
| Usage data | Page views, feature usage | Product improvement |
Patient data (processor)
When you use Edith Care to transcribe clinical conversations and create draft clinical documentation, we process patient data as a processor on behalf of your organization (the controller). This processing is governed by the separate data processing agreement and covers:
- •Audio recordings of clinical conversations
- •Transcripts with speaker identification
- •Draft clinical documentation and reports created in the Service
- •Document attachments (PDF, DOCX) uploaded for AI context
Patient data is never used to train, improve or further develop AI models. All processing currently takes place within the EU/EEA; US-based hosting is planned ahead of our US launch.
04
How do we collect personal data?
- •Directly — when you create an account, log in, or contact us.
- •Automatically — technical data collected when you use the Service (see section 7 on cookies and tracking).
- •From your organization — your employer or principal may provide data when setting up accounts.
05
Legal basis for processing
Where the EU GDPR or UK GDPR applies to you, we rely on the following legal bases:
| Processing | Legal basis | Provision |
|---|---|---|
| Account administration and authentication | Performance of a contract | Art. 6(1)(b) GDPR |
| Security logging and access tracking | Legal obligation | Art. 6(1)(c) GDPR |
| Product analytics and improvement | Legitimate interests | Art. 6(1)(f) GDPR |
| Customer communication and support | Performance of a contract | Art. 6(1)(b) GDPR |
| Responding to demo, account and quote requests | Steps taken at your request prior to entering into a contract | Art. 6(1)(b) GDPR |
| Compliance with healthcare legislation | Legal obligation | Art. 6(1)(c) GDPR |
Patient data is different: we process it only as a processor, on our customers’ documented instructions. The customer, as controller, determines the lawful basis — for health data, the applicable Article 9 condition under the GDPR, and in the US the customer's own authority to disclose protected health information to a business associate — and our obligations are set out in the data processing agreement.
For US residents, we process personal information as described in this policy. We do not sell personal information and do not share it for cross-context behavioral advertising.
06
How we use your data
- •Providing the Service — creating and managing your account, authenticating logins, providing AI-assisted transcription and documentation.
- •Ensuring security — logging access, detecting unauthorized use, protecting against fraud and intrusion.
- •Meeting legal obligations — complying with logging and traceability requirements under applicable data protection and healthcare legislation.
- •Improving the Service — analysing pseudonymized and aggregated usage data to optimize the user experience.
- •Communicating with you — sending service information, security notices and support.
07
Cookies and tracking
Essential cookies
Edith Care uses technically necessary cookies for authentication and session management. These are required for the Service to function and do not require consent.
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Login and authentication | 8 hours |
Analytics
We use one EU-hosted, privacy-preserving product analytics tool (PostHog, hosted in the EU) to understand how our website and Service are used. It is configured with the following privacy settings:
- •EU hosting — analytics data is processed on servers within the EU.
- •Nothing is stored on your device — no analytics cookies and no browser storage; the product analytics tool runs in a memory-only mode that writes nothing to your device.
- •Respects "Do Not Track" — if your browser has DNT enabled, no product analytics data is collected.
- •Session recording is switched off — we do not record or replay your screen, mouse movements or keystrokes.
- •IP addresses are not used to build profiles, and we never link analytics data to patient data.
Usage data is pseudonymized before it is processed for product analytics. Aggregated statistics that cannot be linked to individual users are processed anonymously. You can object to product analytics collection at any time by enabling “Do Not Track” in your browser.
Performance measurement
We use anonymized performance measurements to measure page load times and web performance. These measurements do not identify individual users.
08
Sharing and third-party processing
We never sell your personal data. We share data with the following categories of recipients, solely for the purpose of providing the Service.
Categories of sub-processors
We engage sub-processors in the following categories. All are bound by data processing agreements (DPAs) in accordance with applicable data protection law. A complete list of named sub-processors is provided as a schedule to the DPA with each customer.
| Category | Purpose | Data centre location |
|---|---|---|
| Cloud infrastructure and storage | Operating the Service, data storage, file handling | Sweden / EU |
| Database management | Storing user accounts, reports and metadata | EU |
| AI text processing | Generating and editing draft clinical documentation | Sweden |
| Speech transcription | Converting speech to text with speaker identification | Sweden / EU |
| Observability and troubleshooting | Monitoring AI usage and system performance | EU |
| Product analytics | Pseudonymized and aggregated usage statistics | EU |
| Web hosting and delivery | Making the Service available via the internet | EU (Stockholm) |
| Email delivery | Sending the emails generated by our website forms | EU (Ireland); provider is US-established — see international transfers below |
| Business email | Receiving and storing enquiries from our website | EU |
A named list of all sub-processors, including the processing location for each, is provided as a schedule to the data processing agreement.
AI processing
All AI processing takes place within the EU/EEA. We use established AI service providers for text processing and speech transcription.
- •No personal data or patient data is used to train, improve or further develop AI models.
- •The content of transcripts and AI responses is not stored in our monitoring systems. Anonymized metrics (response times, token counts, error codes) are logged for troubleshooting and quality assurance.
- •All data transfer is encrypted via TLS 1.3.
Other recipients
We may disclose personal data where required by law, regulation or an order of a competent authority, to protect our or others’ rights and safety, or in connection with a business transfer (with prior notice to affected data subjects).
09
Data storage and location
Storage locations
| Data type | Storage location | Encryption |
|---|---|---|
| User accounts and metadata | Database service within the EU | AES-256 at rest, TLS in transit |
| Reports and draft clinical documentation | Database service within the EU | AES-256 at rest, TLS in transit |
| Audio files and recordings | Cloud storage in Sweden | AES-256 at rest, TLS in transit |
| Document attachments | Cloud storage in Sweden | AES-256 at rest, TLS in transit |
| Access logs | Database service within the EU | AES-256 at rest, TLS in transit |
International transfers
All patient data is currently stored and processed exclusively within the EU/EEA, with Sweden as the primary region. US-based hosting is planned ahead of our US launch. Until Business Associate Agreements (BAAs) and US infrastructure are in place, we do not onboard US customers’ protected health information (PHI).
One exception applies to contact details you send us through our website forms: our email delivery provider sends from EU infrastructure (Ireland), but the provider is established in the United States and its data processing agreement provides for processing in the US under the European Commission’s standard contractual clauses (SCCs). This affects enquiry data only — never patient data, which never leaves the EU/EEA.
When delivering web pages, static assets may be distributed via a CDN with nodes outside the EU. These assets contain no personal data. To the extent such distribution technically constitutes a transfer, we ensure appropriate safeguards are in place in accordance with Chapter V of the GDPR, such as the European Commission’s standard contractual clauses (SCCs).
10
Retention
| Data | Retention period | Reason |
|---|---|---|
| Account data | While the account is active + 30 days after closure | Contract, legal requirements |
| Login logs | 12 months | Security, legal retention obligations |
| Audio recordings | Deleted after successful transcription; backup copies, created only if real-time transcription is unavailable, are deleted automatically within about 8 days | Data minimization |
| Transcripts | While the report exists in the Service | Contract |
| Draft clinical documentation | Deleted within 30 days of contract expiry | Contract |
| Analytics data | Pseudonymized, max 24 months | Legitimate interests |
| Enquiry data from our website forms | Kept in our business email for as long as needed to handle your enquiry and any resulting customer relationship, and in any event deleted no later than 24 months after our last contact with you — or earlier on request | Pre-contractual steps |
On expiry of the contract, all customer data is permanently deleted or returned within 30 days, in accordance with the customer’s instructions.
11
Security
- •Encryption: AES-256 at rest, TLS 1.3 in transit.
- •Authentication: individual user accounts with encrypted passwords (bcrypt).
- •Access control: role-based permission model.
- •Logging: complete tracking of logins and data access.
- •Incident management: documented process for handling personal data breaches, including notification duties under applicable data protection law.
- •Automatic session management: sessions expire after 8 hours.
- •Infrastructure: the Service runs in EU/EEA data centres (Microsoft Azure Sweden Central as the primary region), operated by a cloud provider holding ISO 27001 and SOC 2 certifications. Edith Care's own SOC 2 Type II attestation is in progress ahead of our US launch.
12
Your rights
Because Edith Care is established in the EU (Sweden), the EU GDPR applies to our processing wherever you are located, and you have the following rights; where the UK GDPR applies to you, you hold the equivalent rights under it:
| Access (Art. 15) | You have the right to request a copy of the personal data we process about you. |
| Rectification (Art. 16) | You have the right to request correction of inaccurate or incomplete data. |
| Erasure (Art. 17) | You have the right to request deletion of your personal data ("the right to be forgotten"), subject to legal obligations. |
| Restriction (Art. 18) | You have the right to request that the processing of your data be restricted. |
| Data portability (Art. 20) | You have the right to receive your personal data in a structured, machine-readable format. |
| Objection (Art. 21) | You have the right to object to processing based on legitimate interests. |
| Withdraw consent (Art. 7(3)) | Where processing is based on consent, you have the right to withdraw it at any time. |
US state privacy rights
Depending on your state of residence (for example under the California Consumer Privacy Act as amended by the CPRA, or similar laws in Colorado, Connecticut, Virginia and other states), you may have rights to know what personal information we hold about you, and to access, correct, delete and port it, as well as to opt out of the sale or sharing of personal information and of targeted advertising. We do not sell personal information and do not share it for targeted advertising. We honor verifiable requests from all US residents regardless of statutory thresholds, and we will never discriminate against you for exercising your rights.
How to exercise your rights
Contact us at fredrik[at]edithcare[dot]se with your request. We respond within one month where the UK or EU GDPR applies, and within 45 days where US state privacy law applies. We may need to verify your identity before processing the request.
Complaints
If you have concerns about how we process your personal data, please contact us first — we take every complaint seriously. If you are in the EEA, you also have the right to lodge a complaint with your local supervisory authority or with the Swedish Authority for Privacy Protection (IMY, imy.se), our lead supervisory authority.
13
Third-party links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these parties. We recommend that you read their respective privacy policies.
14
Children
The Service is not directed at persons under 18. We do not knowingly collect personal data from children. If we discover that we have collected such data, we delete it immediately.
15
Changes to this policy
We may update this privacy policy. In the event of material changes, we will notify you by email or through a notice in the Service at least 30 days in advance. The latest version is always available at edithcare.us/privacy-policy.
16
Contact us
Do you have questions about this privacy policy or about how we process your personal data?
Edith Care (Jobello Technology AB)
Company registration number: 559311-6907
fredrik[at]edithcare[dot]se
This privacy policy applies from 24 July 2026.