Privacy Policy for TalkToAlba
Svenska · English
TalkToAlba is a tool for recording, transcribing and AI‑analysing clinical conversations so that healthcare professionals can spend less time on documentation. TalkToAlba is a CE‑marked medical device (class IIa). This policy describes how we process personal data when you use the app.
1. Data controller
TalkToAlba AB, org.nr 559488‑8207, Magnus Stenbocksgatan 7, 222 24 Lund, Sverige. Data Protection Officer: dpo@talktoalba.com.
2. What data we process
- Account data: username, email address, password (stored only as a cryptographic hash), role and permissions.
- patient ID and associated content: a randomly generated patient ID (no name or national identity number required) and the content a professional links to it.
- Audio recordings: audio from clinical conversations that you start and record yourself.
- Transcriptions and assessments: text created from recorded audio and AI‑generated summaries/assessments that you can edit and save.
- Messages: text in secure communication between patients and clinicians.
- Technical logs: event logs for security and traceability (user ID, timestamp, action).
The content may include sensitive personal data, in particular health data (a special category under Art. 9).
3. Data on the device
- Microphone: used only while you are actively recording. The app does not listen in the background.
- Local files: audio files are stored temporarily on the device during transcription and are then deleted automatically according to your audio‑retention setting. Settings and login tokens are stored locally on the device.
4. Purposes and legal basis
We process data to provide the service: account management, recording, transcription, AI‑supported analysis, communication and security logging. The legal basis is performance of a contract (Art. 6(1)(b)) and a task carried out in the public interest in the area of healthcare (Art. 6(1)(e)). For special categories the basis is generally Art. 9(2)(h) (health and social care). Logging is carried out to comply with a legal obligation (Art. 6(1)(c)).
5. How data is shared (processors)
We never sell your data. We use the following processors, under data processing agreements:
- Transcription and AI analysis: Microsoft Azure (Sweden Central, EU) and OpenAI for speech‑to‑text and language models. Recorded audio is processed within the EU.
- Email: Loopia (Sweden) for transactional email (account confirmations, login codes, reminders).
- Operations/hosting: our server within the EU.
6. Storage and retention
- Audio is deleted automatically after transcription (or according to your configured retention period).
- Transcriptions, assessments and accounts are stored for as long as the account is active or as long as required for the purpose and applicable law.
- The database is encrypted at rest (SQLCipher/AES‑256) and all transfer takes place over an encrypted connection (TLS).
7. Security
Access is role‑ and permission‑based, passwords are hashed, optional two‑factor authentication is available for professionals, and a tamper‑evident event log is maintained. Only authorised users can reach patient ID data.
8. Your rights
You have the right of access, rectification, erasure, restriction, data portability and to object, under the GDPR. Contact dpo@talktoalba.com. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), www.imy.se.
9. Children
The app is intended for professionals and their patients by invitation, not for general use by children.
10. Changes
We may update this policy. Material changes are communicated in the app or by email. The date at the top shows the latest version.