E
Log in

PRIVACY POLICY

Privacy Policy

Edith Care – Jobello Technology AB

Last updated: 24 July 2026

01

Introduction

Edith Care is provided by Jobello Technology AB, a company registered in Sweden under company registration number 559311-6907 (“Edith Care”, “we”, “us” or “our”). We take the protection of your personal data extremely seriously. This privacy policy describes how we collect, process, store and protect personal data when you use our service.

Edith Care is an AI-based documentation service that helps clinical staff transcribe clinical conversations and create draft clinical documentation. We are a Swedish company and process personal data in accordance with the EU General Data Protection Regulation (GDPR) — one of the strictest privacy regimes in the world — and, where applicable, US state privacy laws. Edith Care is preparing for a US launch; see section 9 for how this affects data location and health information.

This policy applies to the processing of personal data where Edith Care acts as controller — that is, data about you as a user of the Service. For the processing of patient data, where we act as processor (and, for US customers handling protected health information, as a business associate once BAAs are in place), please refer to the data processing agreement (DPA) entered into with each customer, which we provide as part of onboarding.

02

Controller

Jobello Technology AB (Edith Care)

Company registration number: 559311-6907

Registered in Sweden

fredrik[at]edithcare[dot]se

03

What personal data do we collect?

Data you provide to us

CategoryExamplesPurpose
Identity dataName, usernameAccount administration
Contact dataEmail addressCommunication, login
Account dataPassword (encrypted), role, organizationAuthentication, access control
User-generated contentReports, templates, notesProviding the Service
Enquiry dataName, email, phone, organization and your message when you book a demo, request an account or ask for a quote — including the assumptions you enter in our savings calculatorResponding to your enquiry

Data we collect automatically

CategoryExamplesPurpose
Technical dataIP address, browser type, operating systemSecurity, troubleshooting
Login logsTime, successful/failed loginsSecurity monitoring, legal requirements
Usage dataPage views, feature usageProduct improvement

Patient data (processor)

When you use Edith Care to transcribe clinical conversations and create draft clinical documentation, we process patient data as a processor on behalf of your organization (the controller). This processing is governed by the separate data processing agreement and covers:

  • Audio recordings of clinical conversations
  • Transcripts with speaker identification
  • Draft clinical documentation and reports created in the Service
  • Document attachments (PDF, DOCX) uploaded for AI context

Patient data is never used to train, improve or further develop AI models. All processing currently takes place within the EU/EEA; US-based hosting is planned ahead of our US launch.

04

How do we collect personal data?

  • Directly — when you create an account, log in, or contact us.
  • Automatically — technical data collected when you use the Service (see section 7 on cookies and tracking).
  • From your organization — your employer or principal may provide data when setting up accounts.

05

Legal basis for processing

Where the EU GDPR or UK GDPR applies to you, we rely on the following legal bases:

ProcessingLegal basisProvision
Account administration and authenticationPerformance of a contractArt. 6(1)(b) GDPR
Security logging and access trackingLegal obligationArt. 6(1)(c) GDPR
Product analytics and improvementLegitimate interestsArt. 6(1)(f) GDPR
Customer communication and supportPerformance of a contractArt. 6(1)(b) GDPR
Responding to demo, account and quote requestsSteps taken at your request prior to entering into a contractArt. 6(1)(b) GDPR
Compliance with healthcare legislationLegal obligationArt. 6(1)(c) GDPR

Patient data is different: we process it only as a processor, on our customers’ documented instructions. The customer, as controller, determines the lawful basis — for health data, the applicable Article 9 condition under the GDPR, and in the US the customer's own authority to disclose protected health information to a business associate — and our obligations are set out in the data processing agreement.

For US residents, we process personal information as described in this policy. We do not sell personal information and do not share it for cross-context behavioral advertising.

06

How we use your data

  • Providing the Service — creating and managing your account, authenticating logins, providing AI-assisted transcription and documentation.
  • Ensuring security — logging access, detecting unauthorized use, protecting against fraud and intrusion.
  • Meeting legal obligations — complying with logging and traceability requirements under applicable data protection and healthcare legislation.
  • Improving the Service — analysing pseudonymized and aggregated usage data to optimize the user experience.
  • Communicating with you — sending service information, security notices and support.

07

Cookies and tracking

Essential cookies

Edith Care uses technically necessary cookies for authentication and session management. These are required for the Service to function and do not require consent.

CookiePurposeDuration
Session cookieLogin and authentication8 hours

Analytics

We use one EU-hosted, privacy-preserving product analytics tool (PostHog, hosted in the EU) to understand how our website and Service are used. It is configured with the following privacy settings:

  • EU hosting — analytics data is processed on servers within the EU.
  • Nothing is stored on your device — no analytics cookies and no browser storage; the product analytics tool runs in a memory-only mode that writes nothing to your device.
  • Respects "Do Not Track" — if your browser has DNT enabled, no product analytics data is collected.
  • Session recording is switched off — we do not record or replay your screen, mouse movements or keystrokes.
  • IP addresses are not used to build profiles, and we never link analytics data to patient data.

Usage data is pseudonymized before it is processed for product analytics. Aggregated statistics that cannot be linked to individual users are processed anonymously. You can object to product analytics collection at any time by enabling “Do Not Track” in your browser.

Performance measurement

We use anonymized performance measurements to measure page load times and web performance. These measurements do not identify individual users.

08

Sharing and third-party processing

We never sell your personal data. We share data with the following categories of recipients, solely for the purpose of providing the Service.

Categories of sub-processors

We engage sub-processors in the following categories. All are bound by data processing agreements (DPAs) in accordance with applicable data protection law. A complete list of named sub-processors is provided as a schedule to the DPA with each customer.

CategoryPurposeData centre location
Cloud infrastructure and storageOperating the Service, data storage, file handlingSweden / EU
Database managementStoring user accounts, reports and metadataEU
AI text processingGenerating and editing draft clinical documentationSweden
Speech transcriptionConverting speech to text with speaker identificationSweden / EU
Observability and troubleshootingMonitoring AI usage and system performanceEU
Product analyticsPseudonymized and aggregated usage statisticsEU
Web hosting and deliveryMaking the Service available via the internetEU (Stockholm)
Email deliverySending the emails generated by our website formsEU (Ireland); provider is US-established — see international transfers below
Business emailReceiving and storing enquiries from our websiteEU

A named list of all sub-processors, including the processing location for each, is provided as a schedule to the data processing agreement.

AI processing

All AI processing takes place within the EU/EEA. We use established AI service providers for text processing and speech transcription.

  • No personal data or patient data is used to train, improve or further develop AI models.
  • The content of transcripts and AI responses is not stored in our monitoring systems. Anonymized metrics (response times, token counts, error codes) are logged for troubleshooting and quality assurance.
  • All data transfer is encrypted via TLS 1.3.

Other recipients

We may disclose personal data where required by law, regulation or an order of a competent authority, to protect our or others’ rights and safety, or in connection with a business transfer (with prior notice to affected data subjects).

09

Data storage and location

Storage locations

Data typeStorage locationEncryption
User accounts and metadataDatabase service within the EUAES-256 at rest, TLS in transit
Reports and draft clinical documentationDatabase service within the EUAES-256 at rest, TLS in transit
Audio files and recordingsCloud storage in SwedenAES-256 at rest, TLS in transit
Document attachmentsCloud storage in SwedenAES-256 at rest, TLS in transit
Access logsDatabase service within the EUAES-256 at rest, TLS in transit

International transfers

All patient data is currently stored and processed exclusively within the EU/EEA, with Sweden as the primary region. US-based hosting is planned ahead of our US launch. Until Business Associate Agreements (BAAs) and US infrastructure are in place, we do not onboard US customers’ protected health information (PHI).

One exception applies to contact details you send us through our website forms: our email delivery provider sends from EU infrastructure (Ireland), but the provider is established in the United States and its data processing agreement provides for processing in the US under the European Commission’s standard contractual clauses (SCCs). This affects enquiry data only — never patient data, which never leaves the EU/EEA.

When delivering web pages, static assets may be distributed via a CDN with nodes outside the EU. These assets contain no personal data. To the extent such distribution technically constitutes a transfer, we ensure appropriate safeguards are in place in accordance with Chapter V of the GDPR, such as the European Commission’s standard contractual clauses (SCCs).

10

Retention

DataRetention periodReason
Account dataWhile the account is active + 30 days after closureContract, legal requirements
Login logs12 monthsSecurity, legal retention obligations
Audio recordingsDeleted after successful transcription; backup copies, created only if real-time transcription is unavailable, are deleted automatically within about 8 daysData minimization
TranscriptsWhile the report exists in the ServiceContract
Draft clinical documentationDeleted within 30 days of contract expiryContract
Analytics dataPseudonymized, max 24 monthsLegitimate interests
Enquiry data from our website formsKept in our business email for as long as needed to handle your enquiry and any resulting customer relationship, and in any event deleted no later than 24 months after our last contact with you — or earlier on requestPre-contractual steps

On expiry of the contract, all customer data is permanently deleted or returned within 30 days, in accordance with the customer’s instructions.

11

Security

  • Encryption: AES-256 at rest, TLS 1.3 in transit.
  • Authentication: individual user accounts with encrypted passwords (bcrypt).
  • Access control: role-based permission model.
  • Logging: complete tracking of logins and data access.
  • Incident management: documented process for handling personal data breaches, including notification duties under applicable data protection law.
  • Automatic session management: sessions expire after 8 hours.
  • Infrastructure: the Service runs in EU/EEA data centres (Microsoft Azure Sweden Central as the primary region), operated by a cloud provider holding ISO 27001 and SOC 2 certifications. Edith Care's own SOC 2 Type II attestation is in progress ahead of our US launch.

12

Your rights

Because Edith Care is established in the EU (Sweden), the EU GDPR applies to our processing wherever you are located, and you have the following rights; where the UK GDPR applies to you, you hold the equivalent rights under it:

Access (Art. 15)You have the right to request a copy of the personal data we process about you.
Rectification (Art. 16)You have the right to request correction of inaccurate or incomplete data.
Erasure (Art. 17)You have the right to request deletion of your personal data ("the right to be forgotten"), subject to legal obligations.
Restriction (Art. 18)You have the right to request that the processing of your data be restricted.
Data portability (Art. 20)You have the right to receive your personal data in a structured, machine-readable format.
Objection (Art. 21)You have the right to object to processing based on legitimate interests.
Withdraw consent (Art. 7(3))Where processing is based on consent, you have the right to withdraw it at any time.

US state privacy rights

Depending on your state of residence (for example under the California Consumer Privacy Act as amended by the CPRA, or similar laws in Colorado, Connecticut, Virginia and other states), you may have rights to know what personal information we hold about you, and to access, correct, delete and port it, as well as to opt out of the sale or sharing of personal information and of targeted advertising. We do not sell personal information and do not share it for targeted advertising. We honor verifiable requests from all US residents regardless of statutory thresholds, and we will never discriminate against you for exercising your rights.

How to exercise your rights

Contact us at fredrik[at]edithcare[dot]se with your request. We respond within one month where the UK or EU GDPR applies, and within 45 days where US state privacy law applies. We may need to verify your identity before processing the request.

Complaints

If you have concerns about how we process your personal data, please contact us first — we take every complaint seriously. If you are in the EEA, you also have the right to lodge a complaint with your local supervisory authority or with the Swedish Authority for Privacy Protection (IMY, imy.se), our lead supervisory authority.

13

Third-party links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these parties. We recommend that you read their respective privacy policies.

14

Children

The Service is not directed at persons under 18. We do not knowingly collect personal data from children. If we discover that we have collected such data, we delete it immediately.

15

Changes to this policy

We may update this privacy policy. In the event of material changes, we will notify you by email or through a notice in the Service at least 30 days in advance. The latest version is always available at edithcare.us/privacy-policy.

16

Contact us

Do you have questions about this privacy policy or about how we process your personal data?

Edith Care (Jobello Technology AB)

Company registration number: 559311-6907

fredrik[at]edithcare[dot]se

This privacy policy applies from 24 July 2026.